House Arrow Contact

Privacy at House Arrow

Version 1.1 · Last updated 5 October 2026

Download this notice (PDF)

1. Who is responsible

Tessa Frankes, trading as House Arrow, a Dutch sole proprietorship registered under KvK 42070994, is responsible as controller for the processing described here where we determine its purposes and means. Our address is Meilag 24, 1619 XX Andijk, the Netherlands. Contact [email protected] for privacy questions and requests.

House Arrow is the contracting and transacting business behind separately branded products and services. This notice covers our central business administration, this website and processing for services where House Arrow is identified as the controller. A different brand name does not, by itself, identify a different controller.

Service-specific information explains processing particular to the service, including additional data, recipients, retention or technology. It supplements this notice and must be read alongside it. Where we act as a processor on a business customer's instructions, that customer determines the purposes of the processing and its own privacy notice applies; our obligations are also set out in the applicable data-processing agreement.

2. Data, purposes and legal bases

The data we process depends on your relationship with us and the service you use. The following describes the common activities; a category does not mean every service collects every item.

  • Enquiries and correspondence. Names, email addresses, business contact details and the contents of messages help us answer questions, provide support and resolve complaints. The basis is taking steps at your request before a contract or performing a contract with you, where applicable; otherwise our legitimate interest in responding to enquiries and managing business relationships.
  • Orders, contracts and billing. Customer and business names, contact and billing addresses, relevant VAT identifiers, order details, invoices, payment status and transaction references, refunds and dispute records are used to conclude and administer agreements, collect payments and handle disputes. The basis is contract performance where you are the contracting individual, our legitimate interests in administering relationships with business customers and resolving claims, and legal obligations for accounting and tax records.
  • Accounts and service delivery, where applicable. Registration details, account identifiers, authentication information, preferences and content you submit are used to provide and secure the service. The basis is contract performance where necessary for your agreement, or our legitimate interests in delivering and administering services provided to a business customer. Where we process a customer's data solely on its instructions, we act as processor rather than relying on this controller basis.
  • Website operation and security. Technical information, such as IP addresses, request times, browser or device information and security logs, may be processed in delivering and protecting this website and services. The basis is our legitimate interest in reliable operation, abuse prevention and investigating security incidents. Any additional analytics or optional tracking must be explained by the relevant service, with consent obtained where required.
  • Legal compliance and claims. Relevant transaction, correspondence and service records may be used to meet legal obligations, respond to lawful requests, or establish, exercise or defend legal claims. We rely on the relevant legal obligation or our legitimate interests in protecting legal rights, as appropriate.

When relying on legitimate interests, we assess the purpose, necessity and impact on individuals and balance those interests against their rights. Where processing relies on consent, it is requested separately and can be withdrawn without affecting the lawfulness of earlier processing. We do not sell personal data or use it for third-party advertising.

3. Sources and information you provide

We receive information from you when you contact us, place an order or use a service. Where relevant, we also receive information from the organisation arranging your access, people authorised to act for you, and payment providers confirming payment, refund or dispute status. Additional sources used by a particular service must be explained in its privacy information.

Information necessary for an agreement, billing or a legal obligation must be supplied for that purpose. If it is missing, we may be unable to provide the requested service or complete the transaction. Optional information is identified as such where it is requested. Please do not provide sensitive personal data unless the service expressly calls for it and explains the applicable safeguards and legal basis.

4. Recipients and data-processing roles

Depending on the activity, relevant data may be shared with hosting, infrastructure, storage, communications and support providers; payment providers and banks; accounting and professional advisers; and authorities where legally required. Housearrow.org is hosted using Cloudflare Pages.

A provider processing data on our instructions is a processor and requires an appropriate data-processing agreement. Other recipients, including banks, payment providers or professional advisers for their own legal obligations, may act as independent controllers. Their role depends on the activity; they do not all act solely on our instructions. Their own privacy information applies to their independent processing.

Any service-specific recipients, including AI providers where used, and relevant processing purposes must be explained in that service's privacy information. Processing necessary for one brand is not a general authorisation to reuse data for an unrelated service or purpose.

5. International transfers

Providers may process data outside the European Economic Area. Such transfers require a lawful mechanism, such as a relevant adequacy decision or appropriate safeguards including the European Commission's Standard Contractual Clauses, together with additional measures where necessary. The mechanism depends on the recipient, location and processing involved.

You may contact us for information about the mechanism applicable to your data and how to obtain a copy of relevant safeguards, subject to necessary protection of confidential information and others' rights. This notice does not itself create a transfer safeguard.

6. Retention and deletion

We retain data for the purpose for which it is needed and any applicable legal retention period. The following criteria apply:

  • Accounting and tax records: core Dutch business records, including relevant invoices and transaction records, are generally retained for seven years under the applicable tax rules. Longer statutory periods apply where required, including ten years for records covered by relevant VAT One Stop Shop rules.
  • Enquiries, support and disputes: for the time needed to handle the matter and any reasonably anticipated follow-up or related claim, assessed against applicable limitation periods and legal obligations.
  • Accounts and service content: while needed to provide the service, followed by the applicable closure, export and deletion process. Service-specific information sets out any more precise period, including backup retention where relevant. Limited data may remain necessary for legal obligations, security investigations or claims.
  • Technical and security records: for the period proportionate to operating, protecting and troubleshooting the relevant system, with longer retention only where needed for an identified incident, claim or legal obligation.

Deletion requests are assessed under the GDPR; closing an account does not require erasure of records we must legally keep. We delete or anonymise data when no longer needed. This notice does not reduce any shorter deletion commitment already made to you in a previous notice or agreement. You can ask us for the retention information applicable to a particular service or category of data.

7. Security

We are responsible for maintaining technical and organisational measures appropriate to the nature of the processing and its risks. Measures must address access, confidentiality, integrity and availability. No system can guarantee absolute security. Where a personal-data breach requires notification, we notify the relevant authority and affected individuals as required by law.

8. Cookies and this website

Housearrow.org is a static company-information website. Its application code does not set advertising or analytics cookies or load third-party advertising or analytics scripts. Our hosting provider may use necessary technologies to deliver the website securely. Fonts are hosted locally.

This statement is specific to housearrow.org. Separately branded services may use different technologies and must provide their own applicable cookie information and consent choices.

9. Service-specific processing

Before a service introduces processing requiring further information, that information must explain the relevant purposes, data, legal bases, recipients and retention. This includes, where applicable, sensitive data, information obtained from other sources, AI-assisted processing and profiling.

If a service uses solely automated decisions producing legal or similarly significant effects, its privacy information must explain the applicable basis, meaningful information about the logic, significance and envisaged consequences, and the safeguards and rights available to you. General agreement to service terms or this notice is not consent to such processing.

Housearrow.org is not directed at children. Age requirements and, where necessary, parental consent for a particular service must be explained by that service. Contact us if you believe a child's data has been processed inappropriately.

10. Your rights

Subject to the GDPR's conditions, you may request access, correction, erasure, restriction or portability of your data, and object to processing based on legitimate interests. You may withdraw consent at any time where consent is the basis. You may object to direct marketing at any time.

Send a request to [email protected] and, where possible, name the service concerned. We may request proportionate information to verify your identity. We normally respond within one month. Where the GDPR permits an extension because of complexity or the number of requests, we explain the reason and extension within that first month. Requests are normally free of charge, subject to the GDPR's limited exceptions.

If we hold the relevant data solely as processor for a business customer, we will direct you to that controller or assist it as required by our obligations.

11. Complaints and updates

You may contact us about a concern, but you do not have to do so before complaining to a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens. You may also complain to the authority competent for your habitual residence, workplace or the alleged infringement.

We update this notice when relevant processing or legal requirements change. The version and date above identify this notice. Where required, material changes are brought to your attention before the changed processing begins. Updating a notice does not itself create a lawful basis or override your rights.