Legal

Privacy Policy

How we collect, use, and protect your personal information.

Effective date: 26 July 2026. This policy is published by Disco Volante B.V., trading as The Pareto Project.

1. Who We Are

The Pareto Project is a trading name of Disco Volante B.V., a company registered in the Netherlands. Disco Volante B.V. is the controller for the personal data described in this policy, and the entity against which you exercise the rights in section 10.

Disco Volante B.V.
trading as The Pareto Project
KvK 51433443
Charlotte de Bourbonlaan 12
3708 CC Zeist
Netherlands

This policy covers our website, our own marketing, and the enquiries and applications you send us. It explains what we collect, why, how long we keep it, and what you can ask us to do about it.

2. When We Are a Processor Instead

One distinction matters before the detail. For everything in this policy we are the controller: we decide what is collected and why. For personal data inside client projects we are not. There the client is the controller, we act on their instructions, and a data processing agreement (verwerkersovereenkomst) forming part of the engagement contract governs how that data is handled, where it is stored, who may access it, and what happens at the end of the engagement.

That agreement, not this policy, is the document to read for project data. Clients and prospective clients can request a copy of our standard terms at any time.

3. What We Collect

You give us directly:

  • Your name, email address, company name and job title when you complete a contact or application form, along with whatever you write in the message itself
  • For "Apply as Expert": the professional background you choose to share — experience, skills, links, and anything else you include
  • If you create an account: your email address and a password, which we store hashed and never in readable form. If you sign in with Google instead, Google confirms your identity to us and passes your name, email address and profile picture

Our own measurement software records, for each page view:

  • The page path and the language you are reading in
  • The site and path that referred you, and any campaign parameters in the link
  • Your country and the broader region within it — a province or state, resolved by the hosting network at the edge
  • Device type, browser, operating system and screen width
  • A one-way daily visitor hash, and — only if you accept analytics cookies — a random visitor identifier

What we deliberately do not record: your IP address, your city or any more precise location, and your name or email address alongside usage data. Your IP address is used once, to compute the daily hash described in section 11, and is discarded in the same request. There is no third-party tracker on this site, so no other party receives any of it.

4. Why We Use It

We use what we collect to:

  • Answer your enquiry, prepare a proposal, and deliver the services you engage us for
  • Assess your application and talk to you about working together
  • Run the website and keep it secure — sign-in sessions, your language preference, and preventing abuse of our forms
  • Understand which pages are actually read, so we can write better ones
  • Send occasional updates about our services, which you can stop at any time
  • Meet our legal, tax and accounting obligations

5. Legal Basis for Processing (GDPR)

Each purpose rests on one of four bases:

  • Performance of a contract, or steps before one (Art. 6(1)(b)) — responding to your enquiry, preparing a quote, delivering an engagement, and handling your application
  • Legitimate interests (Art. 6(1)(f)) — following up with business contacts, keeping the site secure, and measuring usage in the anonymous form described in section 11. We weigh these against your interests, and you can object at any time
  • Consent (Art. 6(1)(a)) — analytics cookies, and nothing else. You can withdraw it whenever you like via "Cookie settings" in the footer
  • Legal obligation (Art. 6(1)(c)) — the contract and invoice records we are required to retain

Note what is not on that list. Sending an enquiry form is not consent: it is a step towards a contract, so there is no consent for us to lose track of and none for you to have to withdraw. Marketing email to business contacts rests on legitimate interest and the business opt-out regime of the Dutch Telecommunicatiewet, not on consent. Every such message carries an unsubscribe link and we act on it immediately.

6. AI and Automated Decisions

Our proposition is that AI agents handle most of the execution in software delivery, which makes "what happens to my data" a fair question rather than a formality. Three commitments, in plain terms.

  • Your personal data is not used to train AI models — not ours, and not a vendor's. We use commercial APIs whose terms exclude training on submitted data
  • Personal data you send through this website — an enquiry, an application, an account — is not placed into model prompts. Our agents work on code, specifications and documentation
  • Where AI is used inside client delivery, the client's data processing agreement governs it, including which providers may be used and on what terms

No decision about you is made solely by automated means. A person reads every application and answers every enquiry. You are not subject to automated decision-making or profiling that produces legal or similarly significant effects for you, within the meaning of Art. 22 GDPR.

7. Who Else Processes Your Data

We do not sell personal data and we do not share it for advertising. Four providers process data on our behalf, each acting only on our instructions as a processor under Art. 28 GDPR:

  • Vercel — hosting and delivery of this website
  • Neon — the managed PostgreSQL database holding accounts and usage records, hosted in the United States (see section 8)
  • Resend — delivery of transactional email such as address verification and password resets, and of form notifications to our own team
  • Google — only if you choose to sign in with a Google account, and only to confirm your identity to us

Beyond these we disclose personal data only where the law requires it — for example a valid order from a competent authority. If that happens we will tell you, unless we are legally barred from doing so. We will update this list when it changes.

8. Where Your Data Is Stored

Plainly, because this is the question a security reviewer asks first: our database runs in the United States — Amazon Web Services region us-east-1, in Northern Virginia, operated on our behalf by Neon. Accounts, sign-in credentials and the usage records described in section 3 are therefore stored outside the European Economic Area. The pages of this site are delivered through a content network with European points of presence, but that is caching; the database behind it is US-hosted, and that is the location that matters for your data.

The other providers in section 7 are US companies too. Email delivery runs through Resend, hosting through Vercel, and Google sign-in through Google, each of which may involve access to data from outside the EEA.

That makes this a transfer requiring a legal basis of its own. We rely on the European Commission's Standard Contractual Clauses, incorporated into our agreements with these providers, and on the Commission's adequacy decision of 10 July 2023 for the EU-U.S. Data Privacy Framework where a provider is certified under it. Alongside those we rely on technical measures that reduce what is exposed in the first place: connections are encrypted, data is encrypted at rest, passwords exist only as hashes, and — as section 3 describes — no IP address is ever written to the database.

If you are assessing us as a supplier and need to know which mechanism applies to a specific provider, or want the sub-processor detail in writing, ask at privacy@pareto.ooo and we will send it.

9. How Long We Keep It

  • Enquiries and form messages — these reach us as email. We keep them for up to 24 months after our last contact with you, then delete them
  • Applications — four weeks after we finish considering you, unless you explicitly agree that we may keep your details on file, in which case twelve months. You can withdraw that agreement at any time and we will delete them on request
  • Accounts — for as long as you keep the account. Ask us to close it and we remove your profile data
  • Contracts, invoices and accounting records — seven years, which Dutch tax law requires of us (Art. 52 Algemene wet inzake rijksbelastingen). This is a legal obligation, so we cannot delete these earlier on request
  • Usage measurement — the daily visitor hash cannot be linked back to you and is retained as long-run aggregate statistics. The optional visitor identifier behaves as described in section 11

10. Your Rights

You can ask us to:

  • Give you access to the personal data we hold about you (Art. 15)
  • Correct it if it is wrong or incomplete (Art. 16)
  • Erase it, where we have no overriding obligation to keep it (Art. 17)
  • Restrict our processing — pause our use of your data while a dispute about its accuracy or our lawful basis is resolved (Art. 18)
  • Stop processing based on legitimate interest, including all marketing (Art. 21)
  • Send you a portable copy of the data you gave us (Art. 20)
  • Withdraw consent for analytics cookies, which you can also do yourself at any time via "Cookie settings"

Write to privacy@pareto.ooo. We respond within one month, as Art. 12(3) GDPR requires. If a request is unusually complex we may extend that by a further two months, and will tell you why inside the first month. There is no charge.

If our answer does not satisfy you, you can lodge a complaint with the Dutch data protection authority — the Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl — or with the supervisory authority in your own country of residence. You can also take the matter to court. We would rather you came to us first, but that is your choice and not a precondition.

11. Cookies

Necessary cookies keep the website working — sign-in sessions, your language preference and security. They are always active and require no consent. We measure how the site is used with our own software, running on our own servers: there is no Google Analytics, no advertising pixel and no third-party tracker of any kind, and usage data is never shared with or sold to anyone. Anonymous measurement stores nothing on your device: our server counts a page view using a one-way hash of your IP address and browser, which is regenerated daily and cannot be traced back to you. Your IP address itself is never stored. If you additionally accept analytics cookies, we store a random identifier in your browser so that a returning reader can be recognised across days; declining leaves that identifier unset, and withdrawing consent deletes it. You can change or withdraw your choice at any time via "Cookie settings" in the footer.

12. Security and Data Breaches

Traffic to this site is encrypted in transit. Passwords are stored hashed, never in readable form. Access to the database and to the mailboxes receiving your messages is limited to the people who need it. No method of electronic transmission or storage is completely secure, and we will not pretend otherwise.

If a breach occurs that is likely to present a risk to your rights and freedoms, we report it to the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, as Art. 33 GDPR requires. Where the risk to you is high, we contact you directly and without undue delay, and tell you what happened, which data was involved, and what we are doing about it.

13. Changes to This Policy

We may update this policy. Material changes are announced on this page and the effective date at the top of it changes with them. Earlier versions are available on request.

14. Language

This policy is published in English and in Dutch. Should the two versions differ, the Dutch version prevails, since we are established in the Netherlands and Dutch law governs this policy.

15. Contact

For any question about this policy, or to exercise the rights in section 10, write to privacy@pareto.ooo or to the postal address below. We are not required to appoint a Data Protection Officer; privacy questions reach the people who can actually answer them.

Disco Volante B.V.
Charlotte de Bourbonlaan 12
3708 CC Zeist
Netherlands