Privacy Policy

This privacy policy applies to the public Stramigo website. It explains which personal data we process through this website, why we do so, and what rights you have.

1. Who is responsible for this website?

Stramigo is a trade name of Commercialreview B.V., based in Rotterdam and registered with the Dutch Chamber of Commerce under number 85608033. For privacy questions, you can contact us at [email protected].

2. Which processing does this policy cover?

This privacy policy covers personal data we process through the public Stramigo website, for example when you submit a research request, contact us, visit the website, or send us an email. External websites we link to, such as LinkedIn or commercialreview.nl, are governed by their own privacy policies.

3. Which personal data do we process?

Depending on how you use this website, we may process the following personal data:

  • contact details you provide, such as your name, email address, company name, and information included in a message or email;
  • data from a research request, such as the research description, country, target audience criteria, number of respondents, deadline, and additional notes;
  • technical data required for the safe and stable operation of the website, such as server logs, error messages, and security information;
  • analytics data about website usage where you consent, such as pageviews, sessions, approximate location, browser and device information, and page interactions through Google Analytics;
  • correspondence when you email us directly or share additional information about a request.

Providing this data is not mandatory. Without contact details and a description of your question, however, we cannot handle a research request or a contact request.

4. What do we use this data for?

  • to review and follow up on your research request;
  • to respond to contact requests and emails;
  • to keep the website secure and technically functioning;
  • to detect or prevent misuse, failures, and security incidents;
  • to analyze website usage and improve content, navigation, and performance where you accept analytics cookies;
  • to handle our services administratively where a request leads to follow-up contact or work.

5. What legal bases do we rely on?

We only process personal data when there is a valid GDPR legal basis. For this website, that usually means:

  • the performance of a request or pre-contractual steps, for example when you submit a research request;
  • legitimate interests, for example website security, fraud prevention, and responding to business inquiries;
  • consent, for placing and using Google Analytics analytics cookies;
  • legal obligations, where we need to retain data for administrative or compliance reasons.

6. Who do we share personal data with?

We do not sell personal data. We only share data where necessary for the operation of the website or for handling your request, for example with hosting or email providers, with processors supporting website operations and security, and with Google as the provider of Google Analytics where you consent. Where required, we put appropriate data processing agreements in place or rely on applicable contractual privacy terms.

7. Transfers outside the European Economic Area

If personal data is processed by a service provider outside the European Economic Area, we will ensure appropriate safeguards, such as standard contractual clauses, an adequacy decision, or another valid transfer mechanism. This may be relevant where you consent to Google Analytics. Google is certified under the EU-US Data Privacy Framework, for which the European Commission has adopted an adequacy decision, and applies standard contractual clauses for transfers that fall outside its scope.

8. How long do we retain data?

We do not retain personal data longer than necessary for the purpose for which it was collected. We keep contact requests for up to 12 months after they have been handled, and research requests for up to 24 months after the last contact about them, so that we can follow up. Data collected through Google Analytics is retained according to the retention settings configured there. Administrative records that we are legally required to keep, such as invoicing data, are retained for 7 years under the Dutch fiscal retention obligation.

9. How do we protect personal data?

We take appropriate technical and organizational measures to protect personal data against loss, unauthorized access, and misuse. This includes secure connections, access restrictions, monitoring for errors and security incidents, and protecting forms against abuse.

10. Cookies

This website uses necessary cookies for technically secure operation and, after consent, analytics cookies from Google Analytics. More information is available in our cookie policy.

11. Your rights

You have the right to:

  • request access to your personal data;
  • have inaccurate data corrected;
  • have data deleted where there is a valid reason;
  • object to certain processing activities;
  • request restriction of processing where the GDPR allows it;
  • request data portability where applicable;
  • withdraw your consent for analytical cookies at any time; our cookie policy explains how.

You can contact us about these rights at [email protected]. If you believe we are not handling your personal data correctly, you also have the right to lodge a complaint with the relevant data protection authority.

12. Changes to this privacy policy

If this website changes or if we start processing personal data in a different way, we will update this privacy policy. The most recent version will always be available on this page.

Last updated: 17 August 2026