What happens to the address file you send us?
We process it only for your job and for nothing else. You remain the owner and the controller; we are the processor. Exactly what we may do with the file is set out in a data processing agreement.
Last updated: 22 August 2026 · Jannie van der Vaart, finance director of Vogelaar and privacy contact
Controller and processor: who is which
This is the distinction everything hangs on, and it is often muddled.
You are the controller. They are your customers or members, you collected their data, you decide what it is used for and you are the one accountable for it.
We are the processor. We do only what you instruct us to do with it. We do not decide that a mailing goes out, we do not enrich your file with data from elsewhere, and we do not use it for ourselves.
| You | Us | |
|---|---|---|
| Decides what the data is used for | ✔ | |
| Decides who receives mail | ✔ | |
| Actually processes the data | ✔ | |
| Secures the processing on our side | ✔ | |
| Reports a data breach to the Dutch Data Protection Authority | ✔ | |
| Reports an incident to the other party immediately | ✔ | ✔ |
Those last two lines surprise people most often. If something goes wrong at our end, we report it to you immediately, but the report to the supervisory authority is yours to make, because you are the controller. That is why the data processing agreement states how quickly we inform you.
What belongs in a data processing agreement
A data processing agreement is not a formality; it is the arrangement you fall back on when something happens. What it should state:
- What we may process the data for, and that we use it for nothing else
- Which data it concerns and whose
- How long we keep it, and what happens to it afterwards
- Which security measures we take
- Whether we involve others, and who they are
- How quickly we inform you of an incident, and what you get from us so you can make your own report
- What happens at the end: return or destruction
We have one ready. Ask for it and put it alongside your own procurement terms; that is exactly what it is for.
How to get the file to us securely
Not as an email attachment. An address file in your mailbox stays there for years, both at your end and at ours.
Use our own secure form at sending us files. You upload the file, we get a notification, and the file is then available for seven days and disappears automatically after that.
How long we keep your file
That depends on the route it arrives by. These periods are set out this way in our privacy statement.
| Route | Period |
|---|---|
| Our secure upload form | Seven days after uploading |
| Received by email (an exception, and not the intention) | At most three months after receipt |
| The working files attached to the order in our system | Thirty days after invoicing, provided the invoice has been paid. If it has not been paid or there is a dispute, at most two years after the invoice date, solely so that we can substantiate our claim |
| Continuous connection for fulfilment orders | Two years, as evidence that the orders were dispatched |
If you want us to keep a file longer, for instance for a repeat of the mailing, that happens only on written instruction and with a stated period. Never indefinitely.
Watch out for a common misunderstanding: the seven-year retention obligation applies to our order and invoice administration, not to the address files themselves.
Where your data sits, and who can access it
Our systems run at Rootnet, in a data centre in Ede, the Netherlands. Within our company not everyone can access everything: access is tied to a person's role, and that is reviewed periodically.
Why ISO 27001 is the answer here
We have been ISO 27001 certified since 2018, now to the current standard NEN-EN-ISO/IEC 27001:2023, and we have ourselves re-audited every year.
The standard contains 93 controls, and all 93 apply to us. We exclude none of them. That is unusual: most organisations drop a number of them on the basis of their risk analysis. For each of those 93 we have to be able to show how we have arranged it and that it works that way in practice, and an external auditor tests that annually.
More about that is on Security & certification.
We use AI when processing files, and we simply say so
For analysing and processing files we use AI software from Anthropic. Data may reach the United States in the process. The safeguard for that is the European Commission's standard contractual clauses; our agreement runs through Anthropic Ireland, Limited.
Two things belong with that. We supply only what the task requires, and no training happens on our data.
If you want this excluded for your job, that can be arranged in writing or by email and we record it on the order. It is part of how we work, so excluding it may mean the work takes more time or is done on different terms. We owe it to you to say that before you place the order, not after.
Postfilter and the deceased register
Anyone sending addressed advertising mail has to consult Postfilter and the Overledenenregister, the Dutch deceased register, in advance. We have access to both registers and will screen your file if you instruct us to. You decide whether that happens: as a processor we may not check a supplied file against a register on our own initiative.
What that means for what you may and may not send is on Postfilter and the YES sticker.
And if something does go wrong
A data breach is not only a break-in. It is any situation in which personal data has been lost or unlawfully processed, or in which you cannot rule that out. Emailing a file to the wrong address is one too.
If it concerns your address file, you report it to the Dutch Data Protection Authority: you are the controller, after all. You have 72 hours for that, counted from the moment you know about it.
We inform you without delay, with what you need in order to make that report: what happened, which data it concerns and what we are doing about it. Our data processing agreement states the maximum number of hours within which we do that, so it is not an effort but a deadline you can hold us to. If it happens at a party we have engaged, that same deadline applies, counted from the moment we hear about it.
If it concerns data for which we are the controller, such as your contact at our company or a quote request, we make that report ourselves, within 72 hours, and inform you.
Questions about how we handle your data? Our privacy statement describes it in full, and you can always email us at administratie@vogelaargroep.nl. If you want to know what else we do on security, see Security & certification.
More in Insights
This article belongs to Direct mail. Back to the overview, or carry on with one of these.

