Learn more

Achtergrond met zachte blauwe en grijze vervaagde strepen en tinten.

Privacy Policy

We believe in being transparent about how we handle data. Read our privacy policy below, or get in touch if you have a question.

Last updated: 14 August 2026

1. Who are we?

Overflow Agency is a digital agency specialising in Webflow websites, branding, SEO, automation and digital marketing for B2B service providers.

Company name: Overflow Agency (VOF)
Address: Oude Delft 37, 2611 BB Delft, the Netherlands
Chamber of Commerce (KvK): 94278903
Email: privacy@overflow.nl
Website: https://www.overflow.agency

We handle personal data with care. This Privacy Policy explains what personal data we collect, why we process it, which parties may receive it, how long we retain it and what rights you have.

2. What personal data do we collect?

We process personal data that you provide to us directly, that is generated when you use our website, or that we receive through our business tools and integrations.

2.1 Forms and enquiries

Depending on the form you use, we may collect:

  • Name
  • Email address
  • Phone number
  • How you heard about us / referral source
  • Requested services
  • Your message or project description
  • Website URL
  • Website goals and preferences submitted through the AEO Audit form

Newsletter forms generally collect your email address and, where applicable, your name.

2.2 Automatically collected website data

When you visit our website, we and our service providers may process technical and usage data such as:

  • IP address and derived company information where applicable
  • Browser, device and operating-system information
  • Pages viewed, interactions and referral information
  • Cookie identifiers, advertising identifiers and consent choices

3. Why do we process your data?

We process personal data for the following purposes:

  • To respond to enquiries and assess potential projects or collaborations
  • To provide requested services, including the AEO Audit
  • To send confirmations and other transactional communications
  • To manage client and prospect relationships
  • To send newsletters and other marketing communications where you have consented
  • To analyse and improve our website, services and marketing
  • To measure advertising performance and carry out remarketing where consent is required and has been given
  • To secure our website, systems and business operations
  • To comply with legal, tax and administrative obligations

Depending on the context, our legal basis may be your consent, the steps necessary to enter into or perform an agreement, our legitimate interests in operating and improving our business, or compliance with a legal obligation.

4. AEO Audit and automated processing

If you request an AEO Audit, the information you provide, including your name, email address, website URL and selected website goals, is submitted through Webflow and may be passed through Zapier to our backend workflows hosted on Trigger.dev.

These workflows may use third-party APIs, including OpenAI and Anthropic, to analyse publicly available information about your website and generate the requested audit. Data submitted to those services is limited to what is reasonably necessary to perform the audit.

The resulting audit and related transactional emails may be sent to you using MailerSend. We do not use this automated processing to make decisions that produce legal effects or similarly significant effects about you.

5. Newsletters and transactional email

If you subscribe to our newsletter, your contact details are transferred to MailerLite. We only send marketing communications where we have a valid basis to do so, including consent where required. You can unsubscribe at any time using the unsubscribe link in our emails.

Transactional emails, such as form confirmations or delivery of an AEO Audit, are sent through MailerSend and may be triggered through Zapier or our backend workflows.

6. Cookies and tracking

We use cookies and similar technologies for essential functionality, analytics and marketing. Cookie consent is managed through Cookiebot CMP.

Where consent is required, non-essential analytics and marketing technologies are only activated after you have given the relevant consent. You can change or withdraw your cookie preferences through the cookie settings on our website.

6.1 Tools we use

  • Plausible Analytics
  • Google Analytics 4 (GA4)
  • Google Tag Manager
  • Google Ads
  • Meta Pixel
  • LinkedIn Insight Tag / LinkedIn Pixel
  • Leadinfo, which may identify visiting organisations based on business IP information
  • Cookiebot CMP

We may also implement server-side tagging to improve measurement, performance and privacy controls. Where such tagging processes personal data or requires consent, it will be subject to the same legal and consent requirements as the underlying analytics or marketing technology.

7. Who do we share data with?

We do not sell your personal data. We use service providers that process data on our behalf or provide services needed to operate our business. These may include:

  • Webflow – website hosting, forms and website infrastructure
  • Google – analytics, advertising and business services
  • Meta – advertising measurement and remarketing
  • LinkedIn – advertising measurement and remarketing
  • Leadinfo – business visitor identification
  • Usercentrics / Cookiebot – consent management
  • Zapier – workflow automation
  • Trigger.dev – backend workflow orchestration
  • OpenAI – API-based processing used in certain automated workflows such as the AEO Audit
  • Anthropic – API-based processing used in certain automated workflows such as the AEO Audit
  • MailerLite – newsletters
  • MailerSend – transactional email
  • Notion – CRM, project and client administration
  • Cal.com – meeting scheduling on pages where its booking functionality is embedded

Where required, we rely on data processing agreements or other appropriate contractual arrangements with these service providers.

8. International transfers

Some service providers may process or store personal data outside the European Economic Area. Where this happens, we use or rely on appropriate safeguards required under applicable data-protection law, such as adequacy decisions, the EU Standard Contractual Clauses, or other lawful transfer mechanisms.

9. How long do we retain your data?

We do not keep personal data longer than necessary for the purpose for which it was collected, unless a longer retention period is required by law.

  • Enquiries and prospect information are retained for as long as reasonably necessary to follow up on the enquiry and maintain relevant business records.
  • Newsletter data is retained until you unsubscribe or we otherwise no longer need it for that purpose.
  • Form submissions and CRM records are retained in accordance with their business purpose and are periodically reviewed.
  • Analytics and advertising data is retained according to the settings and retention periods of the relevant platforms.
  • Business and tax administration records that fall within statutory record-keeping requirements are generally retained for seven years.

10. Security

We take appropriate technical and organisational measures to protect personal data. Measures may include:

  • SSL/TLS encryption
  • Multi-factor authentication
  • Access controls and account security
  • Cloudflare security measures
  • VPN use where appropriate
  • Device screen-lock and security policies
  • Anti-phishing and staff security practices

11. Your rights

Subject to the conditions of applicable law, you may have the right to:

  • Access your personal data
  • Correct inaccurate or incomplete data
  • Request deletion of your data
  • Restrict certain processing
  • Object to processing based on legitimate interests
  • Receive certain data in a portable format
  • Withdraw consent at any time where processing is based on consent

To exercise your rights, contact us at privacy@overflow.nl. We may ask for additional information where necessary to verify your identity.

12. Complaints

If you have a concern about how we process your personal data, please contact us first so we can try to resolve it.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): autoriteitpersoonsgegevens.nl

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example when our services, tools or legal obligations change. The most recent version will always be available on overflow.agency/privacy.