Privacy statement

How SVS Warmteservice handles your personal data. Last updated 15 September 2026.

In short. This website sets no cookies, uses no trackers and loads nothing from external servers. We collect only what you enter yourself in the contact or fault form, and use it solely to deal with your question or report. We do not sell anything on. You can always ask to see your data or have it erased.

Who is responsible

SVS Warmteservice is the data controller for the personal data described in this statement. That means we decide what those data are used for and how.

If you have a question about your data, you can reach us using the details above. We are not required to appoint a data protection officer and have not done so; your question goes to a member of staff who can decide on it directly.

Where we work on the instructions of your heat supplier, housing association or managing agent, for that work we act as processor and your client is the controller. For the data you leave on this website yourself, we are.

What data we process, and why

Contact form

When you complete the contact form we process your first name and surname, company name, telephone number, email address, the subject you chose and your message.

Purpose: to answer your question and contact you where needed. Legal basis: performance of a contract or, where none exists yet, steps taken at your request prior to entering into one (Article 6(1)(b) GDPR). For a general enquiry the basis is our legitimate interest in being able to respond to business questions (Article 6(1)(f)).

Fault form

For a fault report we additionally process the address where the fault occurs, the postcode and, if you provide them, the project name and reference number.

Purpose: to be able to resolve the fault. Without an address and a telephone number no engineer can attend and no appointment can be made. Legal basis: performance of the contract with you or with the party that has placed the maintenance with us, and our legitimate interest in handling it properly.

This form does not ask about your health, your household or your financial situation. None of that belongs in it. If you do enter such details in the free text field, we use them solely to deal with your report.

Job applications

If you send us a CV and a covering letter, we process the data you include in them: usually your name, contact details, education, work experience and whatever else you mention.

Purpose: to assess whether you fit the role and to run the application process. Legal basis: steps prior to entering into an employment contract, taken at your request.

We carry out no background checks and approach no references without your prior agreement. We only ask for a certificate of conduct once there is a concrete offer, not during the process.

Visiting the website

Our web server keeps technical logs recording, among other things, the IP address, the time, the page requested and the type of browser. Every website does this; it is necessary to deliver the site, to trace faults and to counter abuse. Legal basis: our legitimate interest in a working and secure website.

To limit abuse of the forms we briefly record how many submissions each visitor has made in the past hour. For that we store only an irreversibly hashed representation of the IP address together with timestamps and for no longer than an hour. We do not store the IP address itself and the hash cannot be reversed.

Cookies and measurement

As long as you choose nothing, nothing happens. On your first visit a choice appears at the bottom. If you choose nothing there, or choose Essential only, no cookie is placed, no script from another party loads and no data leaves at all. The website is then exactly as quiet as it was before.

What we remember without consent

Only your choice itself. We store it in the browser under the name svs-toestemming, holding which categories you allowed and when. That is not a cookie and never reaches our server; it stays on your own device. Without it we would have to ask again on every page.

Statistics, if you allow them

If you say yes to statistics, we load Google Analytics 4. That shows us which pages are read, how visitors arrive and where they drop off. We use it to improve the site, not to follow you personally. Our reports contain no names, email addresses or telephone numbers.

CookieWhat forHow long
_ga Recognises a returning device, so a visitor is not counted twice 13 months
_ga_<nummer> Keeps track of whether this is still the same visit 13 months

Legal basis: your consent (article 6(1)(a) GDPR and article 11.7a of the Dutch Telecommunications Act). Retention period: the measurement data is deleted at Google after fourteen months. Google also processes your IP address to determine which country or region you come from; the address itself is not stored in our reports.

Google Ireland Limited is our processor for this. For the transfer to the United States we rely on the EU-US Data Privacy Framework, for which Google is certified. We have set the options so that Google does not use this data for its own advertising purposes.

Marketing

This category appears in the choice because we may start using it for advertising on LinkedIn, for example. At this moment no advertising service is active at all, not even if you tick the category. As soon as that changes, you will read here which service it is and what it does.

What we do not do

We load no fonts, maps, videos or embedded social media posts. There are no buttons on the site that pass your visit to another company. If you do not allow statistics, your visit therefore reaches nobody but our own hosting provider.

Log file and recognising organisations

Like every web server, ours keeps a log file: the address of your internet connection, the time, the page requested and the type of browser. No cookie or script is involved; it is separate from the choice above, and nothing goes to any other party.

We use that log file for two things. First, to secure the website and trace faults. Second, to see which organisations visit our website: we look up in the public internet registries whose name the network address is registered under, and compare that with our own customer records. That way we can see, for example, that someone on the network of a heat supplier looked at our service pages. We do not see who that was. An address from a home internet provider or a mobile network leads nowhere.

The legal basis for this is our legitimate interest (Article 6(1)(f) GDPR): knowing which organisations show interest, so that we can focus our work accordingly. The log file is deleted after thirty days. In the weekly overview we keep only the name of the organisation, the date and the pages viewed. Would you prefer your network address to be left out? Email info@svs-warmte.nl and we will exclude it.

Changing or withdrawing your choice

At the bottom of every page you will find Cookie preferences. That reopens the choice so you can still refuse. Withdrawing is just as easy as allowing, and so it should be. If you clear your browser data, your choice is gone and we will ask again.

Who we share data with

We do not sell your data and do not share it with third parties for commercial purposes. We do engage the following parties as processors:

PartyWhat forLocation
Microsoft Ireland Operations Limited Our email environment (Microsoft 365), where the messages from the forms arrive and are kept European Union
Hetzner Online GmbH Running the website Germany
Google Ireland Limited Statistics about the use of the website, only if you give consent for it Ireland, with transfer to the United States

We have a data processing agreement with these parties setting out what they may do with the data and what security they must provide. For transfers to the United States we rely on the EU-US Data Privacy Framework. Where that is not sufficient, we rely on the European Commission's standard contractual clauses.

We also share your report with the client responsible for your installation. That is your heat supplier, housing association or managing agent, for example. Sharing is necessary in order to carry out the work and account for it, and it follows from the agreements they have with you. We share no more than that handling requires.

Beyond that we disclose data only where a legal obligation requires it, for example to the tax authorities or at the demand of a regulator.

How long we keep data

We keep data no longer than is necessary for the purpose we received it for. In concrete terms:

DataRetention periodWhy
Enquiries that do not lead to an assignment Two years after the last contact So that we can find an earlier enquiry if you contact us again
Fault reports and work carried out Seven years Statutory retention requirement for business records, and evidence for your client
Job applications Four weeks after the process ends. With your consent, one year So that we can approach you about a suitable vacancy
Web server log file Thirty days Tracing faults, investigating abuse and recognising organisations (see Cookies and measurement)
Weekly overview of recognised organisations Thirteen months Seeing how interest develops over the year
Counter against form abuse One hour Longer serves no purpose: the limit applies per hour

Once the period ends we erase the data or make it untraceable. Where a dispute or legal proceedings are running, we keep what is needed for that until it is concluded.

How we protect your data

We take appropriate technical and organisational measures. The main ones, so that you can judge whether that is more than a sentence:

  • The website is reachable only over a secure connection; unsecured traffic is redirected
  • The browser may load content only from our own domain, which blocks scripts injected from outside
  • The forms have an invisible trap against automated submissions and a limit on submissions per hour
  • Line breaks are stripped from every field, so the form cannot be used as a relay for spam
  • The recipient of the form email is fixed in the server settings and cannot be influenced through the form
  • Access to the mailbox where your message arrives is restricted to staff handling your question or report
  • Our staff are bound by a duty of confidentiality

Complete certainty does not exist. If you notice something wrong, or think you have found a weak spot, please report it to us at info@svs-warmte.nl. We take such reports seriously and will tell you what we did about it.

What we do in the event of a data breach

If something goes wrong despite everything and personal data ends up in the wrong hands, we immediately establish what happened, which data it concerns and how we stop it.

Where there is a risk to your rights and freedoms, we report it to the Dutch data protection authority within 72 hours. Where that risk is high, we also tell you directly in plain language: what happened, which data it concerns, what we are doing about it and what you can do yourself. Where the data are the responsibility of your client, we notify them without delay.

Your rights

The GDPR gives you a number of rights. You can exercise all of them with us:

  • Access: ask which data we hold about you and what we do with it
  • Rectification: have incorrect data corrected or incomplete data completed
  • Erasure: have your data deleted, unless we are legally required to keep it
  • Restriction: have the processing paused, for instance while a correction is pending
  • Objection: object to processing based on our legitimate interest
  • Portability: receive your data in a common file format
  • Withdrawing consent: without affecting anything done before that point

Send your request to info@svs-warmte.nl. We respond within one month; if your request is complex we may extend that by two months and will tell you so within the first month. To prevent us handing data to the wrong person, we may ask you to identify yourself. There is no charge for a request.

Making a complaint

If you disagree with how we handle your data, please tell us first. In most cases we resolve it together, and that is quicker.

You also always have the right to lodge a complaint with the supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl. If you live in another EU country, you can also go to the supervisory authority there.

Automated decision-making and profiling

We take no decisions about you on the basis of automated processing. Every report, every enquiry and every application is read and assessed by a member of staff. There is no system that ranks your report, screens your application or builds a profile of you.

Children

This website is aimed at business clients and at residents with a fault. We are not directed at children under sixteen and do not ask for their details. If you believe we have received a minor's data without consent, please contact us and we will delete it.

Links to other websites

Our website carries a link to our company profile on LinkedIn. If you click it you leave our site and that party's privacy statement applies. We have no influence over what they record, and nothing of theirs is loaded while you stay on our site.

Changes to this statement

If our way of working changes, we update this statement. The date at the top shows when that last happened. For a significant change we announce it clearly on the website rather than amending it quietly. That applies if we engage a new processor, for instance, or start measuring after all.

This statement was last updated on 15 September 2026.