Privacy Notice


Privacy Notice – Website, business contacts, recruitment and Imprima services

Version: 2.0
Version date: 5 August 2026

Privacy Notice

This Privacy Notice explains how Imprima collects and uses personal data when we act as a controller. It also explains the limited circumstances in which Imprima processes personal data on behalf of clients as a processor.

It applies to visitors to our website, people who contact or deal with us in a personal or professional capacity, clients and prospective clients, suppliers, event attendees, job applicants, visitors to our premises and authorised users of Imprima services. It does not replace any more specific privacy information provided for a particular activity.

This Notice should be read together with our Cookie Policy and, where relevant, the privacy notice issued by the client that invited you to use an Imprima data room.

1. WHO WE ARE

Imprima (Nederland) B.V., De Boelelaan 7, 1083 HJ Amsterdam, Netherlands, is the principal controller for the Imprima website and central group marketing activities. Where you contract with, apply to, visit or otherwise deal with another Imprima group company, that company may also act as an independent controller for the relevant relationship or activity.

In this Notice, “Imprima”, “we”, “us” and “our” refer to Imprima (Nederland) B.V. and the relevant Imprima group company involved in the processing.

Questions, rights requests and data protection complaints may be sent to customer.success@imprima.com or by post to the Amsterdam address above. Please use “Data Protection Request” or “Data Protection Complaint” in the subject line where appropriate.

2. WHEN WE ACT AS PROCESSOR FOR CLIENT DATA ROOMS

When a client uses Imprima’s virtual data room or related services, the client normally decides the business purpose of the room, what documents and personal data are uploaded, which users may access them and which permissions apply. For that processing, the client acts as controller and Imprima acts as processor, hosting and operating the service under the client’s documented instructions.

The client, not Imprima, is responsible for deciding whether the content it uploads is lawful, necessary and appropriate. Imprima does not select or determine the substantive content placed in a data room.

If your personal data appears in a client data room and you wish to exercise a data protection right, you should normally contact the client that controls the room. If you contact Imprima, we may acknowledge the request, verify sufficient details to identify the relevant client and forward the request to that client. We will not disclose or alter client-controlled data without the client’s instruction or another lawful basis.

Imprima may act as controller for limited processing carried out for its own legal obligations, security, fraud prevention, corporate administration or legal claims, and for interactions with you outside the client-controlled data room. Those activities are covered by this Notice.

3. PERSONAL DATA WE MAY COLLECT

Category Examples
Contact and business information Name, employer, job title, business email address, telephone number, correspondence, meeting details, enquiries, preferences and information about the organisation you represent.
Website and device information IP address, browser and device information, operating system, approximate location, referring page, pages viewed, interaction data, timestamps, cookie identifiers and similar technical information.
Marketing and event information Newsletter choices, event registrations, campaign engagement, expressed interests, communication history and suppression or opt-out records.
Service account and access information Name, business email address, username, authentication information, role, permissions, account status, IP and device information, support information and audit or usage records.
Support, security and complaint information Support requests, incident details, logs, recordings or notes where applicable, identity or authority evidence, investigation records and complaint outcomes.
Recruitment information Application and CV details, employment and education history, references, interview notes, right-to-work information and, where lawful and relevant, screening or background-check information.
Premises and visitor information Visitor name, organisation, host, visit date and time, access or security records and, where applicable, images captured by security systems.
Client-controlled data room content Any personal data contained in documents, files, messages, metadata or other information uploaded by or for a client. Imprima normally processes this information as processor.

We do not generally seek special-category personal data or criminal-offence data through the public website. Such information may nevertheless be provided in recruitment, legal, security or client-controlled data room contexts. We process it only where permitted by law and, for client data rooms, under the client’s instructions.

4. WHERE PERSONAL DATA COMES FROM

  • directly from you, including through forms, email, telephone, meetings, events, applications, account registration and support contacts;
  • from your employer, organisation, advisers, colleagues, referees or the Imprima client that designates you as an End User;
  • from publicly available and professional sources, such as company websites, professional directories and business networking platforms;
  • from recruitment, identity, screening, event, marketing and other service providers where lawful;
  • automatically from your device and use of our website or services through logs, cookies and similar technologies; and
  • from Imprima group companies where necessary to manage a group-wide relationship or provide the requested service.

5. HOW AND WHY WE USE PERSONAL DATA

Purpose Typical lawful basis
Responding to enquiries, arranging demonstrations, preparing proposals and taking steps requested before a contract. Steps before entering a contract; performance of a contract; legitimate interests in responding to enquiries and developing business relationships./td>
Managing client, supplier and partner relationships, contracts, billing, administration and service communications. Performance of a contract; legal obligations; legitimate interests in operating and administering our business.
Creating and administering service accounts, access, permissions, support and user communications. Performance of a contract; legitimate interests in delivering and supporting secure services; where we act as processor, the client’s documented instructions.
Protecting our website, services, personnel and premises; preventing misuse, fraud and unauthorised access; investigating incidents. Legal obligations; legitimate interests in security, fraud prevention, service integrity and protection of legal rights.
Operating, monitoring, troubleshooting, testing and improving our website and services. Legitimate interests in reliable and effective services; consent where non-essential cookies or similar technologies are used.
Sending business-to-business marketing, newsletters, invitations and information about relevant Imprima services. Consent where required; otherwise legitimate interests in promoting our services to relevant professional contacts. You can object or unsubscribe at any time.
Managing recruitment, assessing applications, conducting interviews and, where lawful, completing relevant pre-employment checks. Steps before entering an employment contract; legal obligations; legitimate interests in recruitment and workforce security; consent or another permitted condition where special-category data is involved.
Handling rights requests, data protection complaints, disputes, audits, legal claims and regulatory matters. Legal obligations; legitimate interests in compliance, accountability and establishing, exercising or defending legal claims.
Corporate transactions, restructuring, due diligence and business continuity. Legitimate interests in managing and protecting the business, subject to appropriate confidentiality and data-protection safeguards.

Where we rely on legitimate interests, we consider whether the processing is necessary and proportionate and whether your interests or rights override those interests. You may contact us for further information about a relevant assessment.

Where providing personal data is required by contract or law, or is necessary for us to provide a requested service, we will indicate this where appropriate. If required information is not provided, we may be unable to respond, establish an account, enter into a contract or provide the relevant service.

6. MARKETING AND PROFILING

We may use professional contact details, organisation information, communication history, website engagement and expressed interests to select and tailor business communications. This may involve limited segmentation or profiling, for example by industry, role, location or level of engagement. We do not use this activity to make solely automated decisions that produce legal or similarly significant effects.

You may unsubscribe from marketing emails using the link in the message or object at any time by contacting us. We may retain minimal suppression information so that we continue to respect your choice.

7. COOKIES AND SIMILAR TECHNOLOGIES

Our website uses cookies and similar storage or access technologies for operation, security, preferences, analytics, embedded content and marketing. Non-essential technologies are controlled through the website’s Cookie Settings mechanism. Further details, including the current categories, providers, purposes and retention periods, are set out in our Cookie Policy (UK): https://www.imprima.com/cookie-policy-uk.

8. AI-ASSISTED FUNCTIONALITY AND AUTOMATED TOOLS

Imprima services may include AI-assisted search, review, summarisation, translation, indexing, redaction or other document-processing functionality. AI-generated outputs are supporting or advisory outputs and remain subject to authorised user review and client-controlled access.

When AI-assisted functionality is used within a client data room, Imprima generally processes the relevant Client Personal Data as processor under the client’s instructions and the applicable service terms. We may use aggregated or irreversibly anonymised information to develop, test and improve proprietary Imprima services where the information no longer constitutes personal data and cannot reasonably identify the client or an individual.

If a specific feature may use identifiable Client Content or Client Personal Data for proprietary model improvement or training beyond aggregated or irreversibly anonymised information, the limited use will be described in the applicable feature terms, service notice or configuration before it begins, and the client will be given a reasonable opportunity to object, opt out or disable that use. Imprima does not provide identifiable Client Personal Data to a third party to train a public, shared or generally available model, or make client-specific training data available to other clients, unless separately agreed in writing and permitted by law.

We do not normally make decisions about individuals based solely on automated processing that produce legal or similarly significant effects. If this changes for a particular activity, we will provide specific information about the logic, significance, consequences and available safeguards before the processing begins.

9. WHO WE SHARE PERSONAL DATA WITH

  • Imprima group companies where necessary to manage a relationship, provide services, administer the business or maintain security;
  • service providers supporting hosting, infrastructure, communications, customer relationship management, analytics, marketing, recruitment, professional services, security, support and other business functions;
  • clients and persons authorised by clients where Imprima acts as processor or where disclosure is required to provide the service;
  • professional advisers, insurers, auditors and financing providers where reasonably necessary;
  • courts, regulators, law-enforcement bodies and other public authorities where required or permitted by law; and
  • a purchaser, investor, successor or relevant adviser in connection with an actual or proposed corporate transaction, subject to appropriate safeguards.

We do not sell personal data. Where a service provider processes personal data for us, we require appropriate contractual, confidentiality and security protections.

10. INTERNATIONAL TRANSFERS

Imprima operates internationally and some recipients or service providers may be located outside the country in which personal data was collected. Where a transfer is restricted under applicable law, we use an approved transfer mechanism, such as an adequacy decision or regulation, the European Commission’s then-current Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, binding corporate rules or another lawful mechanism, together with supplementary safeguards where required.

The standard hosting arrangement for Client Personal Data in Imprima virtual data rooms uses Microsoft Azure within the European Economic Area, with the Netherlands as the primary location and Ireland for disaster-recovery purposes, subject to the applicable Service Agreement and DPA.

You may contact us to request further information about the safeguards relevant to a particular transfer. We may redact commercially confidential information or information relating to other individuals where necessary.

11. HOW LONG WE KEEP PERSONAL DATA

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide services, maintain security and audit records, comply with legal and accounting obligations, resolve disputes and establish, exercise or defend legal claims.

Information Retention criteria
Enquiries, prospects and business contacts For the active relationship and a reasonable period afterwards, taking account of the sales cycle, the last meaningful interaction, objections or withdrawals, and any legal or record-keeping requirement.
Client, supplier and contractual records For the relationship and the applicable legal, accounting, audit and limitation periods after it ends.
Marketing records Until consent is withdrawn, an objection is received or the information is no longer relevant. Minimal suppression records may be kept for as long as needed to honour an opt-out.
Recruitment records For the recruitment process and a limited period afterwards to manage queries or legal claims, unless a longer talent-pool period is separately agreed or required by law.
Website, cookie and analytics information For the duration stated in the Cookie Settings panel or according to the relevant provider settings, subject to consent and applicable law.
Support, security, access and audit records For as long as needed for service delivery, security, incident investigation, accountability, legal obligations and the protection of legal rights.
Rights requests and complaints For the time needed to handle the matter and a reasonable period afterwards to demonstrate compliance and manage any related claim or regulatory enquiry.
Client-controlled data room content In accordance with the client’s instructions, the Service Agreement and the DPA. The client is responsible for its own retention decisions.

Information may be retained for longer where required by law, subject to a legal hold, needed for an investigation or legal claim, or preserved at a client’s request. Information that has been irreversibly anonymised so that it no longer constitutes personal data may be retained and used without reference to an identifiable individual.

12. SECURITY

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include governance, access controls, confidentiality obligations, encryption, monitoring, vulnerability management, incident response, business continuity and supplier controls appropriate to the nature and risk of the processing.

No transmission or storage system can be guaranteed to be completely secure. You are responsible for keeping passwords, authentication codes and other credentials confidential and for notifying us or the relevant client promptly if you suspect misuse.

13. YOUR DATA PROTECTION RIGHTS

Depending on the applicable law and the circumstances, you may have the right to:

  • request access to personal data and information about how it is used;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data where the legal conditions are met;
  • request restriction of processing in certain circumstances;
  • receive certain personal data in a structured, commonly used and machine-readable format and request its transfer where the right to portability applies;
  • withdraw consent at any time where processing is based on consent, without affecting earlier lawful processing;
  • object to processing based on legitimate interests, including related profiling; and
  • object at any time to the use of personal data for direct marketing.

YOUR RIGHT TO OBJECT TO DIRECT MARKETING
We will stop using your personal data for direct marketing when you object. You can use the unsubscribe link in a marketing message or contact us directly.

To protect personal data, we may ask for information needed to confirm your identity or authority. Requests are handled through a controlled process with restricted access, appropriate records, secure retrieval and secure delivery. We may review information to avoid unauthorised disclosure of third-party personal data, confidential information or legally protected material.

Rights are subject to legal conditions, exemptions and the rights of others. Requests are normally free of charge, but applicable law may permit a reasonable fee or refusal where a request is manifestly unfounded or excessive. We will explain any lawful refusal or limitation.

Where Imprima acts as processor for a client data room, the client remains responsible for deciding and responding to the request. We will provide reasonable assistance to the client and will direct or forward the request as appropriate.

14. DATA PROTECTION COMPLAINTS

You may make a data protection complaint directly to Imprima by emailing customer.success@imprima.com and marking the message “Data Protection Complaint”. Please explain the issue and include enough information for us to identify the relevant interaction, account or service. We may request identity or authority evidence where necessary to protect personal data.

Where UK data protection law applies, we will acknowledge receipt of a data protection complaint within 30 days, investigate and take appropriate steps without undue delay, keep you informed where appropriate and communicate the outcome without undue delay. This process does not prevent you from contacting a supervisory authority at any time.

You may complain to the data protection supervisory authority in the country where you live or work or where you believe an infringement occurred. In the United Kingdom, this is the Information Commissioner’s Office (ICO). In the Netherlands, this is the Autoriteit Persoonsgegevens.

15. CHILDREN

Our public website and business services are not directed to children. We do not knowingly use the public website to collect personal data from children for marketing. Personal data about children may appear in client-controlled data room content, in which case the client is responsible for the lawful basis and Imprima processes the data as processor.

16. CHANGES TO THIS NOTICE

We may update this Notice to reflect changes in law, guidance, our services or processing activities. We will publish the revised version and update the version date. Where a change materially affects how we use personal data, we will take reasonable steps to bring it to the attention of affected individuals before the new use begins where required.

17. CONTACT DETAILS

Imprima (Nederland) B.V.
De Boelelaan 7
1083 HJ Amsterdam
Netherlands
Email: customer.success@imprima.com
Website: https://www.imprima.com