Privacy Policy
Last updated: 21 August 2026
Who we are
Fidget Labs B.V. is a private limited company registered in the Netherlands.
| Legal entity | Fidget Labs B.V. |
| KVK number | 97512583 |
| BTW / VAT number | NL868085418B01 |
| Registered in | Breda, Netherlands |
| Contact | hello@fidgetlabs.io |
For the personal data described in this policy, Fidget Labs B.V. is the data controller under the General Data Protection Regulation (GDPR).
What this policy covers
This policy covers personal data we collect through fidgetlabs.io and the tools we run at readiness.fidgetlabs.io and on this site.
It does not cover personal data we process on behalf of a client during an engagement. In that situation we act as a processor, not a controller, and the terms of the relevant Data Processing Agreement apply instead.
What we collect, and why
We collect only what a specific interaction needs. There is no tracking profile built across your visit.
When you book a call or send a message
| Data | Why | Lawful basis |
|---|---|---|
| Name | To know who we are talking to | Article 6(1)(b), steps prior to entering a contract |
| Work email address | To reply | Article 6(1)(b) |
| Company | To understand the context of the enquiry | Article 6(1)(f), legitimate interest in qualifying enquiries |
| Your message, role, and company size, where given | To answer usefully | Article 6(1)(b) |
Booking a call is a two-step form. The first step records your name, work email and company before the calendar loads. That means we hold your details even if you never choose a time. If you would rather that did not happen, email us instead.
Scheduling itself is handled by Calendly, which collects the time you pick and any answers you give it. Calendly is a separate controller for that data.
When you subscribe to Focal Point
We record your email address and the fact that you subscribed. Lawful basis is your consent, Article 6(1)(a). Every email carries an unsubscribe link, and unsubscribing withdraws that consent immediately.
When you use the EU AI Act Risk Check
The questions are answered in your browser and your result is shown before we ask for anything. Nothing is sent to us unless you choose to request the written report.
If you do request it, we receive your email address, optionally your name and company, and the answers you gave, so we can generate the report and send it. Lawful basis is your consent, given by the checkbox on that form.
Analytics
We use Google Analytics to understand which pages are read. It sets cookies. See the Cookie Policy.
Where your data goes
Enquiries and subscriptions are stored in our customer relationship management system, which runs on Supabase in the eu-central-1 region, inside the EU.
These are the processors and services that may handle personal data on our behalf:
| Processor | Purpose | Where |
|---|---|---|
| Vercel | Website hosting and delivery | EU and US |
| Supabase | Database for enquiries and contacts | EU (eu-central-1) |
| Resend | Transactional email, including the AI Act report | EU and US |
| Buttondown | Focal Point newsletter delivery | US |
| Calendly | Call scheduling | US |
| Google (Workspace and Analytics) | Email, documents, site analytics | EU and US |
| Anthropic | AI assistance in our own working tools | US |
Where a processor is outside the European Economic Area, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
We do not sell personal data. We do not share it with advertisers.
How long we keep it
| Data | Retention |
|---|---|
| Enquiries and booking details | While the relationship is live, then 3 years from last contact |
| Newsletter subscribers | Until you unsubscribe |
| AI Act Risk Check submissions | 3 years, or until you ask us to delete them |
| Analytics | Per Google Analytics defaults, currently 14 months |
Your rights
Under the GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict or object to how we use it, to receive a copy in a portable format, and to withdraw consent at any time where consent is the basis we rely on.
Email hello@fidgetlabs.io and we will respond within one month.
If you are not satisfied with how we have handled a request, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl.
Automated decision-making
We do not make decisions about you by automated means that produce legal effects or similarly significant effects.
The EU AI Act Risk Check applies a fixed, published rule set to the answers you give. It is informational and is not a decision about you.
Security
Data is encrypted in transit and at rest. Access to the customer relationship system is limited to the two of us, protected by strong passwords and row-level security policies in the database. The website itself holds no key capable of reading stored contacts.
Changes
If this policy changes materially we will update the date at the top and, where the change affects you directly, tell you.