UbertAI engineering for SMEs← Back
Privacy

Short and without small print.

You share data with us in a number of places: during an intro call, in the free AI scan, in the chat with Ubbe, with a comment in Insights, with an access request for the restricted part of About us, and with a job application or a referral for a vacancy. This is what happens with it. The controller for the processing is Ubert (Chamber of Commerce (KvK) 93266200 · VAT NL866333411B01 · Torenlaan 5B, 1402 AT Bussum), reachable at info@ubert.online. This is a translation for your convenience; the Dutch version prevails.

What we collect, and why

Intro call: your name, email address, possibly your phone number and company name, plus what you write yourself. We use that only to schedule and hold the intro call.

AI scan: your answers about your company (industry, size, processes) and, if you have the report emailed to you or choose a next step, your contact details. We use the answers to produce the report; the contact details to send the report and to schedule the next step you asked for — and, only if you tick that box, to ask you once after two weeks whether the report was useful.

Chat with Ubbe: the conversation you have with our AI assistant, plus what you tell it about yourself (name, company, email address, phone number). We use that to answer your question, schedule an appointment and follow up on your request. If you schedule an intro call, it goes into our calendar and you receive a confirmation by email.

No newsletter, no reselling, no profiles for advertising.

What allows us to do that: for an intro call, the AI scan, a job application and a referral it is a step at your own request, in anticipation of a possible agreement (article 6(1)(b) GDPR). For a comment in Insights, an access request and the recognition of returning or business visitors it is your consent (point (a)), which you can always withdraw. For security logs and countering abuse it is our legitimate interest (point (f)); for our administration a legal obligation (point (c)).

Comments, access requests, job applications and referrals

If you comment on an article in Insights, we keep your name, email address, possibly your company, your comment and an encrypted fingerprint of your IP address. We use the latter only to prevent someone from posting a hundred comments in a row; we do not store the IP address itself. You receive a confirmation email to confirm that the address is yours; only after that does the comment appear. A thumbs up, heart, lightbulb or question mark we store without a name or email address, only with that fingerprint so that one visitor does not count a hundred times.

If you request an access code for the restricted part of About us, we keep your name, email address, role or company, your reason and the same encrypted fingerprint. We use that only to assess whether we issue the code. A code that has been issued expires automatically.

If you apply for a job or refer someone for a vacancy, that reaches us by email and we use it only for that procedure.

Comments stay up for as long as the article is online, or until you ask us to remove them. We keep access requests and signals for a maximum of twelve months. We keep job applications until four weeks after the procedure has been completed, or longer if you give consent for that. We keep security logs from our hosting for a maximum of thirty days.

Recognition in the chat

If you have chatted with Ubbe before, we recognise you on a next visit. We do that in two ways: our own cookie in your browser, and as a fallback an encrypted fingerprint of your IP address. We record those two as soon as you start the chat; we only recognise you if you also gave your name at the time. We do not store the IP address itself and we cannot retrieve it from that fingerprint.

We only do that if you switched on analytical or marketing cookies in the consent window. Without that choice every visit starts blank: no cookie, no fingerprint, no recognition. You can always withdraw your choice via Cookie settings at the bottom of every page; the recognition is then erased immediately. The recognition works only on our own site, we do not follow you elsewhere, and we do not link any advertising to it.

Recognition can go wrong, for example if several people use the same office network or the same computer. That is why the bottom of the chat window always shows the button "Is this not you, or would you like to be forgotten?". One click erases your data, your conversations and the recognition.

Chat data without a follow-up we erase automatically after six months. If a request or appointment has come out of it, the retention periods below apply.

What happens to your request

If you request an intro call, a core session or the AI scan, it comes into our own work system. There we automatically start a short preliminary study of your company, so that we go into the conversation prepared and you do not have to tell us what is already public.

For that we look at public sources: the Trade Register of the Chamber of Commerce (KvK), your own website (a handful of pages), public news and the public company page on LinkedIn. A language model makes a short summary of that and gives the request a score, so that we know which requests we take on first.

That score and summary are aids, not a decision: an employee reads them and decides themselves what happens. Nothing is decided automatically that has legal consequences for you. The legal basis is our legitimate interest in preparing and assessing requests properly; you can object to that by emailing us, and we will then delete the study.

It is about your company, not about you as a person: we do not look up private data and we do not consult personal profiles. We keep the study with your request and it disappears together with that request (see the retention periods below).

Recognising business visitors

If you have allowed analytical cookies, then on a page view we check whether the network you visit our site from belongs to a company. We derive that from two public sources: the name attached to the IP address (the reverse DNS record) and the registration of the IP block with RIPE NCC, the European administrator of IP addresses. If that produces a company name, we look it up in the Trade Register of the Chamber of Commerce (KvK) for the KvK number, the place of business and the industry.

At most that tells us which company has viewed our site, never which person. If you visit us from a mobile connection or from home, it produces nothing, because that IP address belongs to your provider and not to a company.

We use this to see which companies are interested and to approach them if appropriate. We do not keep the IP address itself: we only store an encrypted fingerprint, the company details found and the pages that have been viewed. We erase page views after ninety days.

This only happens with your consent. If you switch off analytical cookies via "Cookie settings" at the bottom of every page, it stops immediately. If you do not agree with the processing of this data about your organisation, email us; we will remove it.

How you use the site (statistics and heatmaps)

If you have allowed analytical cookies, we also measure how the site is used: which pages are viewed, for how long, how far you scroll, and where you click and move the mouse. From this we create heatmaps: a picture of which parts of a page get the most attention. That way we see what works and what we need to improve.

This is explicitly not camera or eye-tracking measurement: we do not use your webcam and we do not measure your gaze. We only look at mouse, scroll and clicks on the page. We do not store keystrokes and not what you type into form fields — only coordinates on the page and, on a click, which element (for example a button with its label).

We prefer to look at this data in aggregate: which pages are popular and are read well, including from visitors we cannot link to a company. It is not meant to follow you as a person, and we do not link it to advertising or to other websites. We erase the data points after ninety days.

If you switch off analytical cookies, we measure none of this. You can always change your choice via "Cookie settings" at the bottom of every page.

Who else has access (processors)

We send email via our own mail server. We store requests, chat conversations and scan reports in a Supabase database (Postgres) within the EU. The AI scan and the chat assistant Ubbe use the language model of Anthropic; for that we send along your question and your answers about your company. The site runs on Netlify.

We work with these parties on the basis of their processor terms. Some of these parties are established outside the EU; a transfer then takes place under a valid mechanism, such as the EU-US Data Privacy Framework or the standard contractual clauses of the European Commission. We do not share data with anyone else, unless the law requires it.

How long we keep it

A request for an intro call we keep for as long as the conversation is running and after that for a maximum of 12 months, unless an assignment comes out of it. We keep scan reports for a maximum of 12 months. Would you like it gone sooner? One email is enough.

Data of clients with an assignment we keep during the assignment and after that for as long as the law requires (invoices and administration seven years). Data that we host for you can be exported within thirty days after the end; after that we erase it (article 16 of our terms and conditions).

During a core session on site we make conversation notes and AI-supported records of conversations with managers and employees of the client. We do that on the basis of our legitimate interest: the assessment that the client asks of us. Conversation partners receive a short privacy notice in advance, participation is voluntary, we only make recordings with consent, and we erase the raw notes within thirty days after the proposal has expired, or earlier on request. We then anonymise the internal report.

Cookies

We place no advertising cookies and we use no services that follow you across other websites. What is necessary to make the site work is always on; the rest asks for your consent, which you can change or withdraw at the bottom of every page via "Cookie settings".

If you chat with Ubbe, we place our own cookie so that he recognises you on a next visit. It lasts half a year and goes as soon as you click "be forgotten" in the chat.

If you say yes to analytical cookies, we count which pages are viewed and check whether the network you come from belongs to a company. How that works is set out above under "Recognising business visitors". If you say no, that does not happen.

Your rights

You may always ask for access to what we hold about you, have it corrected, have it erased, have the processing restricted and object. You may also ask to receive your data in a readable file or to have it sent directly to another party (data portability).

If we hold something on the basis of your consent — recognition in the chat, company recognition, a comment in Insights — you can always withdraw that consent. You can do that via "Cookie settings" at the bottom of every page or with one email. What we did on the basis of your consent up to that moment remains lawful; after that it stops.

Email us; we respond within one working day with substance or with a planning, and in any event within a month. None of these rights comes with a price tag. If you and we cannot work it out, you can file a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

We do not take decisions about you that are based solely on automated processing and that have legal consequences for you. The AI scan and the lead study are aids; the decision whether or not to make a proposal is always taken by a human.

// Last updated: September 2026. See also our terms and conditions.