Your privacy matters to us
Easystep2 B.V. takes the protection of your personal data seriously. This statement explains in plain language what we process, why, how long we keep it and what you can expect from us.
How we secure your data
Some of the measures we take to keep your information safe.
Protection against security threats
We protect our mail against spam and viruses, block ransomware and phishing, and keep workstations secure and patched.
Protection of company data against leaks
We limit copying and storing of company information, block the sharing of sensitive data, and back up to a secured archive.
Managing access to company information
We restrict access to company information, protect shared documents, manage data on mobile devices and enforce multi-factor authentication.
Last updated: 1 September 2026
Who we are
Easystep2 B.V. is a Dutch Microsoft partner. We deliver consultancy, our own apps and day-to-day support for Microsoft Dynamics 365 Business Central, Microsoft 365 and Azure. For the personal data described in this statement, we are the controller.
Arsenaalpoort 8
6511 PNNijmegen
The Netherlands
Chamber of Commerce09195847
VAT numberNL820634463.B01
We are a Dutch company and process your data inside the European Union. Dutch and EU law apply to this statement.
What personal data we process
We process personal data because you use our services or because you provide it to us yourself — for example when you call, e-mail or raise a ticket with our servicedesk.
- Contact details — first and last name, telephone number, e-mail address
- Business information — company name, job title and the systems you work with
- Support communications — tickets, e-mails and call notes, including anything you write in them
- Website usage information — the request data our hosting provider logs to keep this site available and secure, such as your IP address and browser type
- Recruitment information — your CV, motivation and correspondence if you apply for a job
Why we process it
- To deliver our services, and to call or e-mail you when that is needed
- To handle and resolve tickets raised with our servicedesk
- To prepare quotations and perform our agreement with you, including invoicing
- To keep our own and our customers' systems secure, and to prevent fraud and abuse
- To inform you about changes to our services and products
- To improve our services, based on what we learn from support work
- To meet legal obligations, such as the statutory retention period for records
The legal basis is the performance of our agreement with you, compliance with a legal obligation, or our legitimate interest in serving and protecting our customers.
Customer data and support access
Supporting Business Central, Microsoft 365 and Azure sometimes means working inside your environment. We treat that access as borrowed, not given.
- We access customer systems only when it is needed to deliver support or an agreed project
- Access to Microsoft cloud tenants follows Microsoft's Granular Delegated Admin Privileges (GDAP) model, so a consultant gets the least privilege the job needs, for a limited time, instead of standing admin rights
- Access is role based — a consultant reaches only the systems their work requires
- Access is logged and auditable, on our side and in your own Microsoft audit logs
- We do not use customer data for anything other than the service you asked for
How we protect your data
- Multi-factor authentication on every account that can reach customer data
- Microsoft Entra ID for identity, conditional access and sign-in monitoring
- Managed devices — company workstations are enrolled, encrypted and kept patched
- Encryption in transit and at rest for the data we hold in Microsoft 365 and Azure
- Security awareness training for our people, because phishing is still the most common way in
- Incident management — a defined procedure for detecting, containing and reporting incidents, including notifying you and the Dutch Data Protection Authority where the law requires it
Sharing with others
We do not sell personal data. We share it only where that is necessary to perform our agreement or to meet a legal obligation:
- Our own employees, limited to those who need it for their work
- Contractors working on our behalf, bound by a confidentiality agreement
- Microsoft and the other service providers we need to deliver the service. Our principal processor is Microsoft, for Microsoft 365, Azure and Dynamics 365; that data sits in European data centres
- Authorities, where we are legally obliged to provide information
With every party that processes personal data on our instructions we conclude a processor agreement under Article 28 of the GDPR.
How long we keep data
We keep personal data only as long as we need it for our agreement, our operations and the law.
- Account data: for the duration of the contract with your employer, then a maximum of 7 years
- Servicedesk history: 7 years
- Invoices and records: 7 years, under the statutory retention period
- Job applications: up to 4 weeks after the process ends, or 1 year with your consent
Cookies and analytics
This website setsno tracking or advertising cookiesand uses no analytics that follow you across websites. We only store your own preferences in your browser's storage: your language choice and whether you want the light or dark theme. That stays on your device and is never sent to us. You can clear it through your browser settings.
We embed no maps or videos that would set third-party cookies. If you follow a link to LinkedIn, YouTube, Facebook, Instagram or our servicedesk portal, that party's privacy policy applies from that point on. If we ever introduce analytics, we will update this section first and ask for your consent where that is required.
Special categories and minors
Our website and services are aimed at business users. We do not intend to collect data about visitors under 16 and we do not collect special categories of personal data. If you believe we hold data about a minor without consent, contact us and we will delete it.
Automated decision-making
We do not make decisions with significant consequences for individuals on the basis of automated processing without human involvement.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and request a copy
- Have inaccurate data corrected
- Have your data deleted
- Restrict how we process your data
- Object to processing we base on a legitimate interest
- Receive your data in a portable form
- Withdraw consent you gave earlier, without that affecting what we did before you withdrew it
- Lodge a complaint with the Dutch Data Protection Authority atautoriteitpersoonsgegevens.nl
To exercise a right, e-mailor call+31 (0) 24 747 02 00. We respond within four weeks. To be sure the request comes from you, we may ask you to identify yourself.
Changes
We review this statement periodically and update it when our services or the law give us reason to. The date at the top of this page shows when we last did so.
Need more information?
Call us and we will take the time to explain how we handle your personal data.



