Privacy
Privacy statement
20 September 2026
This privacy statement is for information only and does not constitute legal advice.
1. Who is responsible?
Bridly (website: bridly.eu) is the data controller for personal data collected via the website, contact forms, applications, and related intake (including Typeform) in connection with our services and website.
Bridly provides search & selection, temporary staffing (uitzenden), secondment (detacheren), and in-house recruitment support.
Dual audience — candidates and employers
- Candidates / applicants: when you apply or share data for matching, staffing, secondment, or search & selection, we process that data as controller for our recruitment activities, unless otherwise agreed.
- Employers / clients: contact and company data you share via the site or Signal Brief are processed by us as controller for relationship management, quotes, and service delivery. Where Bridly processes candidate data strictly on behalf of an employer in an intermediary role, the employer may remain the controller for that HR/recruitment data and Bridly may act as processor or intermediary. In that case, additional arrangements (e.g. a data processing agreement) apply between Bridly and the employer.
2. What data do we process?
Depending on how you use Bridly, we may process categories such as:
| Category | Examples |
|---|---|
| Identity | name, and other identifying details you provide |
| Contact | email, phone, address, company name, job title |
| Application / CV data | CV, motivation, work history, education, preferences (sector, region, hours), portfolio links |
| Employer data | contact person, company, vacancy information, intake details |
| Communications | messages via Typeform, email, or other channels you use |
| Technical | IP address, device/browser data, logs, cookie identifiers (where applicable) |
We do not seek special-category data (e.g. health, religion) unless strictly necessary and voluntarily provided; please avoid sharing such data via general forms.
3. Purposes and legal bases
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Matching & recruitment | staffing, secondment, search & selection, in-house support | contract / pre-contractual steps; legitimate interest (matching) |
| Contact & intake | replies to contact, application, or Signal Brief forms | pre-contractual / contract; legitimate interest (B2B relationship) |
| Signal Brief / content | newsletter or content updates you subscribe to | consent (where required); otherwise legitimate interest with unsubscribe |
| Site operations & security | availability, fraud prevention, technical logs | legitimate interest |
| Legal compliance | e.g. relevant labour/staffing frameworks (such as WAADI where applicable), GDPR, tax/admin duties | legal obligation |
| Marketing (non-essential) | non-necessary cookies/analytics or promotional messages | consent |
You are not obliged to provide data, but without certain data we may be unable to respond to an application, matching request, or quote enquiry.
4. How we obtain data
- Directly from you (website forms, Typeform, email, conversations)
- From employers or partners in the course of an assignment, where lawful
- Automatically via the website (technical logs / cookies — see cookies)
Contact and application intake via Typeform is processed operationally through the forms on bridly.eu.
5. Sharing with third parties / processors
We share personal data only as needed for the purposes above, for example:
- Typeform — intake of contact, application, and Signal Brief forms (processor / subprocessor)
- Hosting and email providers — as needed for the website and correspondence (EEA where applicable)
- Clients / employers — candidate data only in the context of matching or placement, on the applicable legal basis (see privacy for candidates)
- Advisors or authorities — where legally required or necessary for our legal position
An up-to-date list of (sub)processors is available on request. We do not sell your personal data.
6. Transfers outside the EEA
We aim to host and process data within the EEA where reasonably possible. Some tools (including Typeform or future providers) may process data outside the Netherlands or the EEA. In that case we implement appropriate safeguards, such as EU Standard Contractual Clauses (SCCs) and supplementary measures where needed.
7. Retention
We retain personal data no longer than needed for the purposes for which it was collected, including legal retention duties and dispute resolution. Application and relationship data are reviewed and deleted or anonymised when no longer relevant, unless a longer period is legally or contractually required. Exact periods may vary by file; contact us for your specific situation.
8. Security
We take appropriate technical and organisational measures to protect personal data against loss, misuse, and unauthorised access, taking into account the state of the art and the nature of the processing. No method is 100% secure; please report suspected incidents promptly via the contact channels below.
9. Cookies and similar technologies
On bridly.eu we may use necessary cookies for basic functionality and security. For non-essential cookies (e.g. analytics or marketing) we request consent via a cookie banner or settings when live. Details of cookies in use appear in the banner/settings on the live site; we do not invent cookie names here.
You may also manage cookies via your browser. Refusing non-essential cookies does not affect strictly necessary functionality.
10. Your rights
Where the GDPR applies, you have rights including:
- access, rectification, and erasure
- restriction of processing
- data portability (where applicable)
- objection to processing based on legitimate interest
- withdrawal of consent (without affecting prior lawful processing)
- not being subject to solely automated decision-making with legal effects (we do not take recruitment decisions solely by automated means)
To exercise your rights: use the contact form or Typeform on bridly.eu. We may request identification before fulfilling requests.
11. Complaints
You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): https://www.autoriteitpersoonsgegevens.nl. We appreciate the chance to resolve issues first if you contact us.
12. Minors
Our services are not directed at persons under 16. Do not submit minors’ data via our forms without appropriate parental/guardian consent where required.
13. Changes
We may update this statement. The “Last updated” date above indicates the latest version. Material changes may be highlighted on the website or, where appropriate, by email.
14. Contact
Bridly — bridly.eu
Privacy enquiries: via Typeform / forms on bridly.eu