Privacy Statement – FORZ Consultancy B.V.

Last updated: 31 August 2026

FORZ Consultancy B.V. (“FORZ”, “we”, “us” or “our”) attaches great importance to protecting personal data. This Privacy Statement explains which personal data we process, why we process it, with whom we share it, how long we retain it and which rights you have.

1. Who is responsible for your personal data?

FORZ Consultancy B.V. is the controller for the processing described in this Privacy Statement.

NameFORZ Consultancy B.V.
AddressRooswijck 5 B, 1081 AJ Amsterdam, the Netherlands
Privacy contactcompliance@forzconsultancy.com
Websitewww.forzconsultancy.com

2. Who does this Privacy Statement apply to?

This Privacy Statement applies when you:

  • visit our website, portals or other digital services;
  • apply to FORZ or contact us about a role, assignment or career opportunity;
  • are a candidate, specialist, self-employed professional, contractor, supplier employee or other professional;
  • are a contact person at a current or prospective client, end client, supplier, business partner or other professional relationship;
  • participate in a call, meeting or other communication with FORZ.

3. How do we obtain personal data?

We obtain personal data:

  • directly from you, for example through a CV, form, email, conversation, agreement, portal or identity check;
  • from clients, suppliers, referees or other business contacts;
  • from public professional sources, such as LinkedIn, company websites, the Trade Register and public professional registers;
  • through service providers that support recruitment, contract management, communications, invoicing, security and IT;
  • automatically when you use our website or digital services, for example through cookies, log files and similar technologies.

4. Which personal data do we process?

Website visitors

  • IP address, browser and device information, language settings, usage data and security logs;
  • cookie data and similar online identifiers, depending on your cookie preferences;
  • name, email address, telephone number and message when you use a contact form.

Candidates, specialists and applicants

  • name, contact details, place of residence and other information provided in your CV or profile;
  • work experience, education, qualifications, diplomas, certificates, languages, availability, preferences and rate or salary expectations;
  • interview notes, correspondence, references and information about the progress of a recruitment or mediation process;
  • photographs or other profile information that you provide or that comes from a public professional source;
  • where necessary for a role or assignment, a Certificate of Conduct or evidence of professional qualifications.

Self-employed professionals, contractors and other deployed professionals

  • company name, address, Chamber of Commerce number, VAT identification number, bank details, insurance details and contract and invoice data;
  • assignment details, time records, rates, payments, performance and administrative data;
  • for identity checks: official name, nationality, type of identity document, document number and validity period;
  • where applicable, information about entitlement to work in the Netherlands and its validity period;
  • a copy of relevant pages of an identity or residence document only where a legal obligation requires this.

Important. For the identity check of a Dutch, EEA or Swiss self-employed professional, we do not generally retain a copy of the identity document or record the citizen service number (BSN). We record only the information necessary for the check.

Clients, suppliers and business relations

  • name, role, organisation, business contact details and communication preferences;
  • quotation, contract, assignment, purchasing, invoice and payment information;
  • correspondence, meeting notes and information needed for relationship management, services and compliance with agreements.

Special-category or criminal-offence data

We generally do not request special-category personal data, such as health data, or criminal-offence data. If such information is necessary, we process it only where a specific legal exception applies or where you have given explicit consent. A Certificate of Conduct does not list criminal offences; we process it only where necessary for the relevant role or assignment.

5. For which purposes and on what legal bases do we process data?

PurposeWhat do we do?GDPR legal basis
Contact and requestsAnswer questions, arrange meetings and provide information.Performance of a contract or legitimate interests.
Recruitment and matchingAssess profiles, discuss careers, identify suitable roles or assignments and represent professionals to clients.Pre-contractual steps, performance of a contract and/or legitimate interests.
Sharing a profileShare a CV or profile with a specific current or prospective client.Generally only after discussing this with you; performance of our services and/or legitimate interests.
Contracts and assignmentsEnter into and perform agreements, manage time and performance and process payments.Performance of a contract and legal obligations.
Identity checksVerify the correct contracting party, prevent person substitution and fraud, and comply with applicable SNA/NEN requirements.Legitimate interests; legal obligation where specific employment or immigration legislation applies.
Administration and complianceTax administration, audits, insurance, checks and compliance with laws and regulations.Legal obligations and legitimate interests.
Security and misuseProtect systems and data and prevent and investigate fraud, misuse and incidents.Legitimate interests and, where applicable, legal obligations.
Relationship management and marketingMaintain professional relationships and send relevant information about our services.Legitimate interests or consent where legally required.
Website and analyticsOperate the website, analyse its use and improve the user experience.Legitimate interests for strictly necessary technologies; consent for non-essential cookies and similar technologies.
Privacy requestsHandle requests under data protection law and demonstrate that they were handled.Legal obligation.

6. Identity checks and entitlement to work in the Netherlands

When deploying a self-employed or other professional, FORZ may verify the person’s identity using a valid and authentic identity document. The purposes are to prevent person substitution and fraud, confirm that we are contracting with the correct person and comply with applicable SNA scheme requirements and relevant legislation.

For Dutch, EEA or Swiss self-employed professionals, we record only the data necessary for the check. We do not routinely make or retain a copy. Additional verification and retention duties may apply under the Dutch Foreign Nationals Employment Act to people from outside the EEA or Switzerland. In those cases, we process only the documents and data required by law.

We do not routinely provide the identity declaration to the end client or an external hiring platform. Where possible, we confirm only that the check has been completed. Relevant data may be provided, or controlled access may be granted, only where necessary, contractually agreed and permitted under the GDPR. A citizen service number (BSN) or copy of an identity document is processed or disclosed only where a specific statutory obligation or authority applies.

7. Call recordings, transcripts and AI-assisted tools

FORZ may use tools to record, transcribe or summarise conversations, for example to document agreements accurately, improve our services or support recruitment and contract processes. We inform participants in advance when a conversation is recorded or transcribed. Where consent is the legal basis, you may refuse without affecting the core of our services.

We may use AI-assisted tools for activities such as summarisation, search, administrative support or matching. Human staff remain responsible for relevant decisions. FORZ does not make decisions producing legal or similarly significant effects based solely on automated processing.

8. Are you required to provide the data?

You are not always required to provide personal data. However, certain information is needed to enter into an agreement, perform an assignment, assess suitability, verify identity or entitlement to work, or comply with a legal obligation. Without that information, we may be unable to provide mediation, enter into or perform an agreement or provide other services. Data used for non-essential cookies and certain marketing activities is voluntary.

9. With whom do we share personal data?

We do not sell your personal data. We may share data with:

  • clients and end clients, where needed for a specific role, assignment, site access or performance of an agreement;
  • operators of external hiring platforms, vendor management systems, brokers or intermediary platforms, such as Flextender, where necessary for submission, assessment, contracting, performance or administrative handling of an assignment;
  • suppliers processing data on our behalf, such as hosting, CRM, communications, e-signing, contract management, time registration, invoicing, analytics and security providers;
  • accountants, auditors, insurers, banks, lawyers and other professional advisers;
  • public authorities, regulators, law-enforcement bodies or other parties where we are legally required to do so or where necessary to protect rights and safety;
  • a prospective buyer, investor or business partner in connection with a reorganisation, merger or acquisition, subject to appropriate confidentiality safeguards.

Where required, we enter into data processing agreements with parties that process personal data on our behalf. They may use the data only on our instructions and for the agreed purposes. An external hiring platform may process data on behalf of FORZ or the client and may act as an independent controller for certain purposes of its own. Where possible, FORZ informs the professional in advance about the use of the platform and limits disclosure to the data necessary for the relevant assignment.

10. Processing outside the European Economic Area

We aim to process personal data within the European Economic Area (EEA). However, some suppliers or subprocessors may process data outside the EEA or make it accessible from a third country. Where this occurs, we ensure there is a valid transfer mechanism, such as an adequacy decision of the European Commission or approved Standard Contractual Clauses, and implement supplementary safeguards where necessary.

11. Cookies and similar technologies

We use strictly necessary cookies to operate and secure our website and digital services. We use analytics, preference and marketing cookies only where consent is required and you have provided it. You can change your preferences at any time through the cookie settings on our website. Current information about cookies, providers and retention periods is available in our cookie settings or separate cookie statement.

12. Security

We implement appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, unauthorised alteration and unwanted disclosure. Depending on the risk, these measures include access controls, authentication, logging, encryption, backups, supplier assessments and periodic reviews. No storage or transmission method is completely risk-free. If you suspect a security incident involving FORZ, please contact compliance@forzconsultancy.com immediately.

13. How long do we retain personal data?

We retain personal data no longer than necessary for the purposes for which it was obtained, unless a legal obligation, audit requirement, ongoing dispute or demonstrable legitimate interest requires a longer period. The retention period differs by data category and is determined in part by the duration of the relationship or assignment, applicable statutory duties and the need to demonstrate compliance and agreed arrangements. Where possible, FORZ applies the customary maximum periods below. We then delete or anonymise the data.

CategoryRetention period
Contact requests and general correspondenceGenerally up to 4 years after the last substantive contact. Correspondence forming part of a candidate, relationship, assignment, contract, tax or dispute file follows the retention period of that file.
Application for employment at FORZ without hireUp to 4 weeks after the procedure ends; with explicit consent, up to 1 year.
Candidates and talent pool for external roles/assignmentsGenerally up to 4 years after the last substantive contact. New substantive contact about availability, career preferences, a role or assignment restarts the period. FORZ periodically checks whether the data remains current.
Identity declaration for Dutch/EEA/Swiss self-employed professionalFor the duration of the assignment and up to 2 years after termination of the final agreement.
Legally required ID or work-document copy for non-EEA personAt least 5 years after the end of the calendar year in which the work ended, where required by the Dutch Foreign Nationals Employment Act.
Contracts, invoices and tax recordsGenerally 7 years where the statutory tax retention duty applies.
Other assignment and relationship filesFor the duration of the relationship and up to 2 years afterwards, unless a specific statutory period or tax file requires longer retention.
Call recordings and raw transcriptsGenerally up to 2 years after the recording. Relevant agreements and business information may be recorded in the related candidate, relationship or assignment file and follow that file’s retention period. A specific recording or transcript may be retained longer where necessary for an ongoing dispute, investigation or to establish agreed arrangements.
Website and security logsGenerally up to 12 months, unless longer retention is needed to investigate a security incident.
Cookie and analytics dataAccording to the period shown in the cookie settings and generally no longer than 14 months.
Marketing dataUntil you unsubscribe or up to 2 years after the last substantive contact.
Disputes, investigations and claimsFor as long as necessary to handle them and generally up to 2 years after final resolution, unless a longer statutory limitation or retention period applies.

14. Your data protection rights

Depending on the circumstances, you have the right to:

  • obtain access to your personal data;
  • have inaccurate or incomplete data corrected;
  • have data erased;
  • restrict processing;
  • object to processing based on legitimate interests or to direct marketing;
  • receive or transfer data where the right to data portability applies;
  • withdraw consent at any time, without affecting the lawfulness of earlier processing.

You can send a request to compliance@forzconsultancy.com. We generally respond within one month. Where necessary to prevent misuse, we may ask for additional information to verify your identity. Do not send an unredacted copy of your identity document; if a copy is necessary, redact at least the BSN, photograph and document number.

15. Complaints

If you have a complaint about how we handle your personal data, please contact us first. You also have the right to lodge a complaint with the Dutch Data Protection Authority at www.autoriteitpersoonsgegevens.nl.

16. Changes to this Privacy Statement

We may amend this Privacy Statement when our services, systems or applicable law change. The latest version is available on our website. The date of the latest update appears at the top. Where reasonably necessary, we will provide additional notice of material changes.

17. Contact

If you have questions about this Privacy Statement or our processing of personal data, contact compliance@forzconsultancy.com or write to FORZ Consultancy B.V., Rooswijck 5 B, 1081 AJ Amsterdam, the Netherlands.