Controller, service identity and contact
Altroverso VOF is the controller for enquiries and professional services presented through 4URight, except where a specific mandate identifies the practice as processor for a business client. Chamber of Commerce 56530021; VAT NL852171936B01; BECON 746393; 4URight office De Stuwdam 33–35, 3815 KM Amersfoort, the Netherlands; Pavan Geraedts business address Rigaweg 9, 3825 PP Amersfoort, the Netherlands; telephone +31 (0)85 40 12 459; privacy contact privacy@altroverso.nl.
On this website, Altroverso VOF trades as 4URight. Pavan Geraedts is a separate trading identity of the same legal entity. This notice applies the same privacy framework across Altroverso VOF.
Introduction
Information is necessary for responsible professional work. That necessity does not create unlimited permission to collect, combine, disclose or retain it.
This page contains two connected parts: our Privacy Manifesto, which explains the principles by which we handle information; and our Privacy Notice, which provides the information required by the General Data Protection Regulation and applicable Dutch implementation law.
Privacy is part of professional judgement
Privacy is not a sentence placed beneath a form. It is the discipline of deciding what information is relevant, why it is needed, who may use it, what may be disclosed and when the information should leave the file.
Fiscal advice, juridical advice and business mediation all depend on context. The same information can be necessary in one role and inappropriate in another. We therefore connect access to purpose and professional capacity.
Purpose comes before collection
We do not collect personal data merely because it may become useful. Every processing activity must have a defined purpose, a lawful basis and a proportionate scope.
Data minimisation does not mean collecting too little to provide responsible professional services. It means obtaining enough reliable information for the accepted work while resisting unnecessary accumulation.
Confidentiality and privacy are connected, but not identical
We protect confidential professional information and personal data. Contractual confidentiality, mediation confidentiality and the GDPR may apply at the same time, but they perform different functions.
Pavan Geraedts does not claim the statutory professional secrecy or right of non-disclosure attached to acting as an advocate. Where advocate privilege is important, an advocate should be involved through an appropriate arrangement.
Professional roles remain visible
Pavan Geraedts may act as fiscal adviser, juridical adviser, business mediator or adviser on a connected company matter. Each role has a different purpose and relationship with the people involved.
When acting as mediator, we do not process one participant's information as the representative of another participant. The mediation process is governed by a separate Mediation Agreement, including its confidentiality and information-sharing rules.
Human responsibility remains
Digital and AI-assisted tools may support research, extraction, comparison, organisation, translation, security and drafting. They do not replace professional judgement.
Pavan Geraedts does not issue a final professional conclusion solely because a system produced it. We do not make decisions about individuals based solely on automated processing where those decisions would produce legal or similarly significant effects.
Security must be demonstrable
An automated flag, similarity result or generated draft is not treated as proof, a final professional conclusion or a decision about a person.
We do not use claims such as "perfect security", "highest standard" or "risk-free" as substitutes for evidence.
Retention must have a reason
Information is not kept simply because storage is available. It is retained while a professional, contractual, fiscal, regulatory, evidential or legal reason continues, and is then deleted, anonymised or placed under a justified restricted hold.
We do not sell personal data
Pavan Geraedts does not sell or rent personal data. We disclose it only for a defined professional, contractual, security or legal purpose and only to a recipient with an appropriate role.
2. Who this Notice concerns
This Notice may concern:
Our website and ordinary services are directed to businesses and adult professionals. We do not intentionally invite children to create accounts or send information. A professional file may nevertheless contain information about a child where that information is relevant and lawful, for example in a succession, ownership or family-connected company matter. Additional care is applied in such circumstances.
people who visit our website or contact us;
prospective, current and former clients;
directors, shareholders, ultimate beneficial owners, partners and authorised representatives;
employees, contractors, applicants, advisers and other people connected with a client;
customers, suppliers, creditors, debtors and counterparties appearing in client or transaction records;
participants, representatives, advisers and other attendees in a business mediation;
people involved in a contract, objection, proceeding, complaint, investigation, incident, due-diligence review or transaction;
our own suppliers, professional advisers and business contacts; and
another person whose personal data is lawfully relevant to our professional work.
3.1 Pavan Geraedts as independent controller
Pavan Geraedts ordinarily acts as an independent controller for:
The fact that a business client supplies personal data does not automatically make Pavan Geraedts a processor. The role depends on who actually determines the purpose and essential means of the processing.
website operation, enquiries and relationship administration;
proposals, mandates and engagement administration;
client acceptance, identity, authority, conflict, Wwft, sanctions and integrity checks;
its own fiscal, juridical, mediation and professional files;
professional judgement about the method, evidence and records needed for its work;
security, quality management, insurance, billing, complaints and legal claims; and
compliance with duties imposed directly on Pavan Geraedts.
3.2 Pavan Geraedts as processor
Pavan Geraedts acts as processor only where it handles personal data solely on a client's documented instructions for an agreed service and does not determine its own incompatible purpose.
That processing is governed by an Article 28 GDPR Data Processing Agreement. The client is responsible for the lawfulness of its purpose, instructions and disclosure to Pavan Geraedts. A rights request concerning that processing may need to be handled by the client as controller.
3.3 Pavan Geraedts as business mediator
When Pavan Geraedts accepts a business mediation, it acts independently for the administration and professional conduct of the mediation. It does not act as processor or representative for one participant against another.
The separate Mediation Agreement defines the participants, the process, confidentiality, separate conversations, attendance, document handling and settlement formation. This Privacy Notice does not replace that agreement.
3.4 Joint controllers and independent recipients
If Pavan Geraedts and another organisation genuinely determine a processing purpose and essential means together, the parties will document their responsibilities under Article 26 GDPR where required.
Advocates, civil-law notaries, statutory auditors, banks, insurers, authorities and certain other professionals or verification providers may act as separate controllers under their own legal responsibilities.
4. Personal data we may process
The categories depend on the relationship, professional role and accepted work.
4.1 Identity and contact information
Name, title, business and private contact details where relevant, date and place of birth, nationality, preferred language, signature and identity-document information.
We process a BSN or identity-document copy only where permitted and necessary. Information that is not needed should be masked or omitted where appropriate.
4.2 Company, ownership and authority information
Company name, registration data, legal form, organisational role, group relationships, ownership and control, directorships, shareholder interests, UBO information, mandates, powers of attorney and signing authority.
4.3 Client-acceptance and integrity information
Identity-verification results, conflict information, sanctions and politically exposed person indicators, source-of-funds or source-of-wealth information where required, risk classifications and records needed for Wwft or other integrity duties.
4.4 Fiscal and financial information
Tax numbers, returns, assessments, elections, calculations, correspondence with tax authorities, financial statements, ledgers, invoices, bank and payment information, remuneration information, assets, liabilities and transaction evidence.
4.5 Juridical, contractual and governance information
Contracts, obligations, correspondence, claims, objections, procedural documents, board and shareholder records, delegated authorities, policies, decisions, disputes, regulatory communications and supporting evidence.
4.6 Mediation information
Participant details, authority to settle, mediation requests, position summaries, communications, meeting information, documents supplied for the process, separate-conversation information, proposals, drafts and any signed settlement.
Pavan Geraedts does not make an audio or video recording of mediation meetings unless every affected participant has received specific information and the recording has an agreed lawful purpose, basis, access rule and retention period.
4.7 Digital, data and intellectual-property information
System and supplier information, privacy and AI documentation, incident records, access information, content, authorship and ownership information, licences, permissions, image and portrait-right records, brand and trademark information and connected technical evidence.
4.8 Transaction and business-change information
Due-diligence materials, ownership and financing structures, management information, employee and supplier information, transaction communications, findings, disclosure records, negotiation materials and completion information.
4.9 Communications and professional work records
Emails, letters, call and meeting notes, calendar information, instructions, approvals, advice, drafts, final deliverables, file history, complaints and records of professional decisions.
4.10 Website, device and security information
IP address, browser and device information, time and page activity, cookie or consent choices, form-submission information, authentication and access logs, security events and technical diagnostic information.
4.11 Special-category and criminal-offence information
A matter may contain health data, political opinions, religious or philosophical beliefs, trade-union information, biometric identifiers, sexuality-related information, allegations or criminal-offence data.
We do not seek such information routinely. It is processed only where necessary, proportionate and supported by an applicable Article 9 or Article 10 GDPR condition and Dutch law. Access is restricted according to the sensitivity and purpose.
5. Where personal data comes from
We may obtain personal data:
Where Articles 13 or 14 GDPR require individual information, we provide it at the appropriate time. If information was not obtained from you, this will ordinarily occur within one month, or earlier at the first communication with you or first disclosure to another recipient where the GDPR requires that timing. A legal restriction, legally protected confidentiality obligation or applicable Article 14 exception may limit what can be disclosed. We document the reason rather than assuming that indirect collection removes the duty of transparency.
directly from you;
from a client, participant or authorised representative;
from a director, shareholder, employee, contractor or adviser connected with a matter;
from a counterparty or another mediation participant;
from an advocate, civil-law notary, accountant, auditor, tax professional, bank, insurer or other adviser;
from the Dutch Tax Administration, a court, regulator, municipality or other authority;
from the Trade Register, UBO register, insolvency register, sanctions list, court register, intellectual-property register or another lawful public source;
from identity, authority, sanctions, fraud-prevention or professional-verification providers;
from the systems, records or website through which you interact with us; and
from another source where obtaining and using the information is lawful and relevant to the stated purpose.
6. Why we process personal data and the legal grounds
Pavan Geraedts uses the legal basis appropriate to each purpose. Consent is not the default basis for professional work.
Where legitimate interests are used, the relevant interests may include responsible client acceptance, performance and documentation of professional services, business communication, conflict management, network and information security, fraud prevention, quality control, defence of claims and proportionate development of the practice. We assess necessity, reasonable expectations and the effect on the individual before relying on this basis.
7. When information is required
Some information is required by law, contract, professional necessity or the rules of an authority or platform. Other information is optional.
If required information is not supplied, Pavan Geraedts may be unable to assess an enquiry, accept or continue an engagement, verify authority, meet a deadline, submit a document, conduct a mediation responsibly or comply with a legal duty.
We will not describe information as voluntary where declining to provide it would prevent the requested service. Consent is used only where a genuine choice exists.
8. Wwft, sanctions, tax disclosure and lawful restrictions
Depending on the service and circumstances, Pavan Geraedts may be required to:
The law may prohibit Pavan Geraedts from informing a person that a report has been made, considered or investigated. Rights and transparency requests cannot be handled in a manner that violates such a prohibition.
Pavan Geraedts does not have a universal duty to report every suspicion, allegation or disagreement. Disclosure is connected to a specific legal power or duty.
identify and verify a client, representative and ultimate beneficial owner;
understand the purpose and intended nature of a relationship;
assess risk and conduct ongoing monitoring;
examine source of funds or source of wealth where required;
screen relevant sanctions and politically exposed person information;
retain client-due-diligence and transaction records;
report an unusual transaction to FIU-Netherlands;
comply with DAC6 or another mandatory tax-disclosure duty; or
disclose information under a binding order or another specific legal obligation.
9. Business mediation and privacy
Mediation requires both confidentiality and controlled information sharing.
Pavan Geraedts may receive information jointly, separately or through a participant's adviser. Information received in a separate conversation is not shared with another participant without permission, except where the Mediation Agreement or mandatory law permits or requires disclosure.
Each participant should provide only information that is relevant and lawfully available for the mediation. A participant must not use the process to obtain or disclose personal data improperly.
Data-protection rights do not automatically entitle one participant to another participant's confidential information, private communications or legally protected data. Pavan Geraedts will assess access and other requests against the rights, freedoms, confidentiality and legal position of every affected person.
A draft proposal or mediation note is not a final agreement. A signed settlement is retained as a professional and contractual record for the people entitled to it.
10. Who may receive personal data
We disclose personal data only where relevant and proportionate. Recipients may include:
Processors may use personal data only for the contracted processing and under appropriate data-protection terms. Independent controllers determine their own processing under their applicable duties.
Pavan Geraedts does not sell or rent personal data.
authorised Pavan Geraedts personnel and subcontractors;
providers of hosting, email, communications, document management, electronic signatures, client administration, security, backup, identity verification, accounting and professional software;
the Client and its authorised representatives, subject to purpose, confidentiality and rights of others;
mediation participants and their authorised advisers, within the Mediation Agreement;
advocates, civil-law notaries, accountants, auditors, tax specialists, patent or trademark professionals, technical experts and other independent professionals;
the Dutch Tax Administration, FIU-Netherlands, courts, regulators, municipalities, law-enforcement bodies and other authorities where legally authorised;
banks, payment providers and insurers where necessary;
counterparties, transaction parties, financiers and due-diligence recipients where the purpose and authority permit disclosure; and
a successor or relevant adviser in a proposed reorganisation or transfer of Pavan Geraedts, subject to appropriate confidentiality and data-protection safeguards.
11. International transfers
Verified transfer position: Amsterdam
A statement that servers are located in the Netherlands or European Union does not by itself prove that no transfer occurs. Remote support, authentication, email routing, analytics and subprocessors must also be considered.
Where personal data is transferred outside the European Economic Area, Pavan Geraedts uses a lawful GDPR Chapter V mechanism, such as:
You may ask for information about the relevant safeguard, subject to necessary protection of security, confidentiality and commercial information.
an adequacy decision of the European Commission;
the European Commission's Standard Contractual Clauses, together with a transfer assessment and supplementary measures where required;
Binding Corporate Rules where applicable; or
another mechanism or exception permitted by the GDPR.
12. How long we retain personal data
We use the periods below as the standard position. A longer or shorter period may apply where required by law, an authority, a Data Processing Agreement, the Mediation Agreement, an insurance condition, an active dispute, a legal hold or a documented professional need.
When Pavan Geraedts acts as processor, return and deletion are governed by the DPA and lawful client instructions.
When a retention period ends, information is deleted, irreversibly anonymised or restricted under a justified legal hold. Pseudonymised information remains personal data where re-identification is possible.
13. Security
Pavan Geraedts uses technical and organisational measures appropriate to the nature, context and risk of the processing. Depending on the system and engagement, measures may include:
No storage or transmission method is entirely risk-free. We review measures when the system, information, threat or legal requirement changes.
If you believe personal data or an Pavan Geraedts system has been compromised, contact us immediately and mark the communication Security Incident.
role-based and least-privilege access;
individual accounts and appropriate authentication;
encryption in transit and at rest where appropriate;
separated client workspaces or access areas;
logging and review of material access and changes;
secure backup and continuity arrangements;
confidentiality duties and staff awareness;
supplier assessment and processing agreements;
vulnerability, patch and configuration management;
secure transfer routes for sensitive material; and
incident response and breach assessment.
14. Personal data breaches
Pavan Geraedts records and assesses suspected personal data breaches.
Where Pavan Geraedts is controller, it notifies the Autoriteit Persoonsgegevens without undue delay and, where feasible, within 72 hours after becoming aware of a breach where Article 33 GDPR requires notification. Affected people are informed where Article 34 requires it.
Where Pavan Geraedts is processor, it informs the relevant client controller without undue delay and provides reasonably available information in accordance with the DPA.
Not every security event is a reportable personal data breach, but every suspected breach must be assessed and documented appropriately.
15. Digital and AI-assisted tools
Pavan Geraedts may use digital or AI-assisted tools for research support, extraction, comparison, classification, translation, workflow, security or drafting where appropriate safeguards and human professional review are applied.
An automated flag, similarity result or generated draft is not treated as proof, a final professional conclusion or a decision about a person.
At the effective date of this Notice, Pavan Geraedts does not make decisions based solely on automated processing, including profiling, where the decision produces legal or similarly significant effects for an individual.
Confidential or personal information is not entered into an external AI service unless the intended use is consistent with the professional purpose, confidentiality, data roles, supplier terms, security and any required transfer or subprocessor arrangements.
If Pavan Geraedts introduces solely automated significant decision-making, the relevant people will first receive the information required by Articles 13, 14 and 22 GDPR, including meaningful information about the logic, significance, consequences and available human intervention.
16. Your data-protection rights
Subject to the GDPR and applicable limitations, you may ask Pavan Geraedts to:
These rights are not absolute. For example, Pavan Geraedts may need to protect another person's rights, mediation confidentiality, tax or Wwft records, legal claims, professional records or information whose disclosure is restricted by law. We explain the applicable reason if a request cannot be fulfilled in full.
We review this Notice when our services, processing purposes, technology, recipients or legal duties change.
confirm whether we process your personal data;
provide access to your personal data and the required processing information;
correct inaccurate data or complete incomplete data;
erase personal data where no continuing lawful ground requires or permits retention;
restrict processing in the circumstances provided by the GDPR;
provide data you supplied in a structured, commonly used and machine-readable form where portability applies;
transmit portable data to another controller where technically feasible;
consider an objection to processing based on legitimate interests or a public-interest basis;
stop direct marketing following your objection;
https://www.autoriteitpersoonsgegevens.nl
You may also have the right to complain to the supervisory authority in the EU or EEA country where you live, work or believe an infringement occurred.
17. How to exercise a right
Email privacy@altroverso.nl (mail domain altroverso.nl, operated by Altroverso VOF) with Privacy Request in the subject line, or write to Pavan Geraedts at the postal address in Section 1.
Please identify the relationship or matter in which Pavan Geraedts is likely to hold the information and describe the right you wish to exercise. Do not send a full identity-document copy unless we specifically request it through an appropriate route.
We may request proportionate information to verify identity and authority. We normally respond within one month after receiving a complete request. The GDPR permits an extension of up to two further months for a complex request or several requests. We will explain an extension within the first month.
Where a change materially affects an active relationship or requires new consent, we provide an appropriate notice or request before the changed processing begins.
Pavan Geraedts depends on information to understand a company, a decision or a disagreement. That dependence creates responsibility, not ownership over another person's life.
18. Direct marketing and service communications
For every material use of personal data, we should be able to answer four questions:
Why is this information here?
Who is permitted to use it?
19. Cookies and similar technology
What professional or legal purpose does it support?
When should it leave the file?
That is how privacy becomes part of professional practice rather than a promise placed at the end of a page.
20. Forms and first contact
When you use a contact form, Pavan Geraedts uses the information to assess and respond to the enquiry and, where relevant, to conduct preliminary acceptance and conflict checks.
Fiscal advice, juridical advice and business mediation in Amersfoort.
Do not send complete archives, passwords, unrestricted identity-document copies, special-category data, criminal-offence information or highly sensitive evidence with an initial enquiry. If further information is necessary, we will agree an appropriate purpose and transfer route.
21. Third-party websites and services
Privacy is part of the professional judgement applied to every accepted matter.
22. Complaints and the supervisory authority
We invite you to contact Pavan Geraedts first so that we can understand and address the concern. This is not a condition for exercising the right to complain to a supervisory authority.
This Manifesto explains our principles. The Notice explains how personal data is processed, protected and retained.
Autoriteit Persoonsgegevens Website: https://www.autoriteitpersoonsgegevens.nl
You may also have the right to complain to the supervisory authority in the EU or EEA country where you live, work or believe an infringement occurred.
23. Changes to this Notice
We review this Notice when our services, processing purposes, technology, recipients or legal duties change.
The version and effective date appear at the top of the page. A new notice applies from its stated effective date. It does not make earlier unlawful processing lawful.
Where a change materially affects an active relationship or requires new consent, we provide an appropriate notice or request before the changed processing begins.
24. Our closing commitment
Pavan Geraedts depends on information to understand a company, a decision or a disagreement. That dependence creates responsibility, not ownership over another person's life.
For every material use of personal data, we should be able to answer four questions:
That is how privacy becomes part of professional practice rather than a promise placed at the end of a page.
Why is this information here?
Who is permitted to use it?
What professional or legal purpose does it support?
When should it leave the file?