1. Who is responsible?
De Kruijf & De Waal adviseurs B.V. is responsible for processing personal data within Maxus and the related portals.
Weverstraat 81
6862 DL Oosterbeek
KvK-nummer: 09203261
Telefoon: (026) 482 00 90
For questions about privacy or your personal data, please contact us through our contact page.
Privacy officer and contact person for security issues: Max Kirschbaum RPP RBc. Use the contact page and choose privacy request or security report as the subject.
2. Which data do we process?
Depending on your use, we process data such as name, email address, phone number, organization, client or administration number, user roles, sign-in and security data, invoice data, documents, payment statuses, technical logs and preferences such as language and theme.
For HR or onboarding features we may also process data needed for personnel administration, identification, payroll administration and document flows. These data are used only within the relevant client environment and with the configured access.
3. What do we use data for?
- Creating and managing accounts, roles and access rights.
- Showing invoices, documents, payslips, annual statements and other portal information.
- Security, such as two-step verification, passkeys, session management and audit logging.
- Communication about invitations, password resets, payment requests, incident reports and account settings.
- Processing payments, direct debit mandates and administrative checks.
- Improvement, troubleshooting and administration of Maxus.
4. Legal bases
We process personal data when this is necessary to perform our services, comply with legal obligations, based on a legitimate interest such as security and administration, or based on consent where specifically required.
5. Sharing with third parties
We share data only when needed for our services, for example with hosting providers, email services, payment providers, accounting integrations or software suppliers. We make agreements with processors about security and confidentiality.
6. Security and retention
We secure Maxus with appropriate technical and organizational measures, including encrypted connections, access control, two-step verification, passkeys where available, logging and periodic maintenance.
We do not retain personal data longer than necessary for the purpose for which they were collected, unless a legal retention obligation or administrative need requires a longer period. Technical audit logs are generally retained for a maximum of 180 days, unless longer retention is needed for security or investigation.
7. Cookies, local storage and sessions
Maxus uses functional cookies and local storage to remember sign-in, security, language, theme and temporary portal choices. These data are needed for the application to work properly and securely. We do not use them for advertising tracking.
8. Your rights
You have the right to access, correct, delete and transfer your personal data, restrict processing and object to processing where the law allows. Submit your request through our contact page and choose privacy request as the subject. We may ask for additional information to verify your identity.