Skip to content
HomeSecurity & certification

Your files are in safe hands with us.

Information security is not a side issue here but a certification. ISO 27001, and re-audited every year.

NEN-EN-ISO/IEC 27001:2023
ISO 9001:2015

Information security, set down and tested.

It is rare for a PDF to arrive here on its own. There is usually a file with it: addresses, a member list, the entrants to a campaign. That is personal data belonging to your customers, and we handle it as we should. We have been ISO 27001 certified since 2018, now to the current standard NEN-EN-ISO/IEC 27001:2023, and we have ourselves re-audited every year. That is the international standard for information security, and it is not a piece of paper.

93
of 93

The standard contains 93 controls: from cryptography and access management to back-ups, spam filters and the lock on the door. All 93 apply to us; we exclude none of them. For each one we have to be able to show how we have arranged it and that it works that way in practice. An external auditor tests that every year.

Five Vogelaar staff with the ISO 27001 and ISO 9001 certificates.
The moment both certificates came through.
Certification

Set down, and re-audited every year.

We have been ISO 27001 certified since 2018 and ISO 9001 certified since 2021. An external auditor tests both every year.

What that means for your file.

Delivered securely

You upload your address file yourself in your customer portal in VOS, or you send it through a secure link. Not as an email attachment: that is not a secure channel.

Stored confidentially

Your file sits in a secure environment, not loose on a workstation or in a mailbox.

Only those who need it

Access is limited to the people working with that file for your job. Not the department, not the company.

Deleted automatically

If you send a file through the secure link, the system wipes it after seven days. Files attached to an order go thirty days after invoicing, provided the invoice has been paid; if it has not been paid or there is a dispute, then at the latest two years after the invoice date. Nobody has to remember it.

Data processing agreement

The GDPR requires you to set those arrangements down in writing. We have one ready and are happy to share it.

ISO 9001: quality.

Since 2021 we have also been ISO 9001 certified, to the ISO 9001:2015 standard. That is not about data but about our processes: do they do what they promise, and what happens when they once do not. Underneath it sits a fixed cycle: plan, do, check, act. Set down how we work, measure whether it actually goes that way, adjust where it can be better, and then again. Not right once, but a little better every time.

What we have on paper for this

Both certificates are audited annually by an external auditor. Not achieved once and then forgotten.

  • ISO 27001 certificate for information securityInformation security: all 93 controls.
  • ISO 9001 certificate for quality managementQuality management of our processes.
Postfilter

We do not mail to people who do not want it.

Addressed advertising mail also raises the question of who is not waiting for it. The Netherlands has a register for that: Stichting Postfilter, the Dutch mail preference foundation, chaired by our owner Mark Bonenkamp. Would you like us to take care of that for you? We have access to the register and can screen your address file against it. The addresses in the register are then filtered out before anything is printed or mailed. That is not only decent towards the recipient. It also saves you print and postage, and it keeps your campaign out of the complaints corner.

Mark Bonenkamp
Mark Bonenkamp
Chair of Stichting Postfilter and of the Postal Committee of the KVGO

What you can get from us.

For your own file, tender or supplier assessment we will send you, on request, a copy of our ISO 27001 and ISO 9001 certificates, our data processing agreement, and information about how we process your type of data. One phone call is enough. Also on request: our information document "PPWR and your print work". It sets out what the European packaging regulation asks of you, which requirements take effect when, and what substantiation we have obtained from our suppliers per material group. Useful for anyone who has to build a packaging file.

Questions from your privacy officer or procurement?

Vraag een prijsOr call us: we will send the certificates and the data processing agreement straight over.