Legal

Privacy Policy

Last updated: 1 September 2026

1. Who we are

Nebor is a go-to-market infrastructure agency based in the Netherlands. We are the controller for the personal data described in this policy.

Nebor

Assendelverstraat 42B, 2013 SK Haarlem, the Netherlands

Chamber of Commerce (KvK): 99806045

2. What this policy covers

This policy explains what personal data we collect when you visit nebor.ai, contact us, or work with us, why we collect it, and what rights you have. We are based in the EU and follow the General Data Protection Regulation (GDPR). We work with clients internationally, so we apply the same standard of care to visitors and clients outside the EU.

3. What we collect

Information you give us. When you fill in a contact form, book a call, or email us, we receive the details you share: typically your name, work email, company, and whatever you tell us about your situation. When you book a meeting, our scheduling tool processes the booking details.

Information collected automatically. With your consent, our analytics collect technical data about your visit: pages viewed, time on page, approximate location based on IP address, device, and browser. We use this to understand which content is useful and to improve the site. We do not use it to identify you personally.

4. Why we use your data

โ€ข

To respond and deliver. When you contact us or become a client, we use your details to reply, prepare proposals, and perform our agreement with you.

โ€ข

To improve the site. We analyze anonymized usage patterns to see what works and what does not. This runs on your consent, given through the cookie banner.

โ€ข

To stay in touch. If you have opted in, or if you are a client, we may send you relevant updates. Every message includes a way to opt out.

โ€ข

To meet legal obligations. Some data, such as invoices, we must keep for tax and accounting law.

Our legal bases under the GDPR are: performance of a contract, your consent, our legitimate interest in running and promoting our business, and legal obligations.

5. Cookies

Our website uses cookies. When you first visit, a consent banner asks which categories you accept:

โ€ข

Necessary cookies make the site work and store your cookie choices. They are always on.

โ€ข

Analytics cookies (Google Analytics) tell us how visitors use the site. They only load after you accept them.

โ€ข

Marketing cookies, where used, help us measure campaigns. They also only load after you accept them.

You can change or withdraw your choices at any time through the cookie settings link on our website, or by clearing cookies in your browser. Your consent is stored for 12 months, after which we ask again.

For guidance on managing and deleting cookies on your own device, see the Dutch Data Protection Authorityโ€™s cookie guidance.

6. Who we share data with

We never sell your data. We share it only with service providers that help us run our business, and only for the purposes above:

โ€ข

Framer hosts our website.

โ€ข

Google Analytics processes anonymized site usage data, with your consent.

โ€ข

Cal.com processes meeting bookings.

โ€ข

HubSpot stores our client and prospect relationships.

Each provider is bound by a data processing agreement and may only use your data to provide its service to us. We may also disclose data where the law requires it, or as part of a business transfer, in which case this policy continues to protect it.

7. International transfers

Some of our providers process data outside the EU, mainly in the United States. Where that happens, the transfer is protected by an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework, or by Standard Contractual Clauses.

8. How long we keep data

We keep personal data only as long as we need it. Contact inquiries that do not lead to a working relationship are deleted within two years. Client data is kept for the duration of our engagement plus the retention periods that tax and accounting law require (generally seven years for financial records). Analytics data is retained according to the limits we set in Google Analytics. You can request deletion earlier at any time; see your rights below.

9. Your rights

Under the GDPR you can ask us at any time to:

โ€ข

Access the personal data we hold about you and receive a copy

โ€ข

Correct data that is wrong or incomplete

โ€ข

Delete your data

โ€ข

Restrict or object to how we use it, including for marketing

โ€ข

Receive your data in a portable format

โ€ข

Withdraw consent you gave earlier

Email hello@nebor.io and we will respond within one month. If you are unhappy with how we handled your data, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl. If you live outside the EU, you can also contact your local privacy regulator, and we will cooperate with them.

10. Security

We protect personal data with appropriate technical and organizational measures: encrypted connections, access controls, and vetted providers. No system is perfectly secure, but if a breach ever creates a real risk for you, we will inform you and the authorities as the law requires.

11. Children

Our website and services are for businesses. We do not knowingly collect data from anyone under 16. If you believe we have, contact us and we will delete it.

12. Changes to this policy

We update this policy when our practices, tools, or the law change. The date at the top shows the latest version. For significant changes we will post a clear notice on the website.

13. Contact

Questions about this policy or your data? Email hello@nebor.io or write to Nebor, Assendelverstraat 42B, 2013 SK Haarlem, the Netherlands.

Services

Case Studies

Resources

About

Services

Case Studies

Resources

About

Nebor logo, a go-to-market and RevOps agency based in Amsterdam

Services

Case Studies

Resources

About

Nebor logo, a go-to-market and RevOps agency based in Amsterdam