← Back to Home
Privacy Policy
Last Updated: June 20, 2026
Boughty Canton Consulting B.V. (trading as "Helderpath" and "Helderpath Consulting") ("we", "our", or "us") operates the website helderpath.com. We are registered with the Netherlands Chamber of Commerce (KVK) under registration number 42014356. Your privacy is highly important to us. This Privacy Policy explains exactly what personal data we collect when you visit our website or use our services, how we handle it, and the strict measures we take to protect it in compliance with the General Data Protection Regulation (GDPR) [1].
1. General Principles: Privacy by Design
We operate strictly on a data minimization blueprint. We do not use commercial tracking cookies, we do not monitor your behavior across other web assets, and we do not lease, share, or sell your data to advertising tracking networks.
2. Data We Process and Why We Process It
A. Native Email Client Intake (No Database Storage Logs)
We do not use server-side database registers or third-party lead form scraping utilities. When you select choices on our intake questionnaire panel, your criteria settings are packed client-side into a secure native draft email. No data leaves your machine until you choose to hit send inside your personal email application.
- What is transmitted: Your chosen inquiry topic, your current operational stage, your desired service start path, and any additional context notes you type.
- Purpose: To evaluate your current partner positioning, review your consulting requirements, and respond to your outreach with an appropriate proposal strategy.
- Legal Basis: Performance of a Contract / Pre-contractual Measures (GDPR Article 6(1)(b)). We process this incoming text data strictly to take steps at your request before entering into a potential formal consulting agreement.
- Retention Period: Initial outreach inquiries are routed through our dedicated public intake address (
info@boughty.com), which is governed by an automated server retention policy that permanently deletes all message records after exactly 2 years. If our conversation leads to a formal engagement, active communications shift to our internal corporate accounts and are retained securely as part of your active client profile record.
B. Website Infrastructure and Hosting (Cloudflare)
To deliver this workspace quickly and securely, we use the infrastructure network hosting services of Cloudflare, Inc.
- What is processed: Your web browser automatically transmits essential technical network access logs (including your IP address, browser hardware type, and operating system).
- Purpose: To defend our site layout from cyberattacks (such as DDoS attacks) and optimize delivery loading speeds.
- Legal Basis: Legitimate Interest (GDPR Article 6(1)(f)). Maintaining a stable, secure, and functional digital workspace is a core business necessity.
- Data Transfers: Cross-border transfers to Cloudflare are legally secured because Cloudflare, Inc. is formally certified under the EU-US Data Privacy Framework (DPF).
C. Privacy-First Website Metrics
We measure basic performance statistics to monitor technical site health via Cloudflare Web Analytics.
- What is processed: Aggregated, anonymous metrics including total page views, generalized visitor locations (country-level only), device profiles, and page rendering speeds.
- Privacy Guard: This tool does not load tracking cookies into your browser and does not build unique user tracking fingerprints.
3. Data Sharing and Trusted Processors
We do not sell or lease your personal communications. Your data is purely hosted and handled by essential enterprise infrastructure platforms who act strictly as Data Processors on our behalf under Data Processing Agreements (DPAs):
- Google Cloud EMEA Limited (Google Workspace): We use corporate Google Workspace as our corporate email provider. Your incoming inquiry emails are securely routed directly to and hosted within our business mail boxes using robust encryption frameworks aligned with EU data protection compliance models.
- Cloudflare, Inc.: For standard network security protection, edge content routing, and anonymous technical web health analysis parameters.
4. Your Legal Rights Under the GDPR
As a resident of the European Union, you hold the following rights regarding the personal data we store inside our secure communication emails [1]:
- Right of Access: You can ask us for a complete copy of the email correspondence files we hold regarding your communication.
- Right to Rectification: You can request that we update or modify incorrect professional details inside our file notes.
- Right to Erasure ("Right to be Forgotten"): You can demand that we permanently and securely wipe your email inquiry logs from our corporate inboxes.
- Right to Restriction: You can ask us to temporarily halt processing your context files.
To exercise any of your data rights, simply email us directly at info@boughty.com. We will process your verification request free of charge within 30 days.
5. Authority Complaints
If you believe that we are handling your personal data incorrectly, we invite you to reach out to us directly so we can address your concerns. However, you also maintain the full legal right to file an official compliance complaint at any point with the Dutch Data Protection Authority [1]:
Autoriteit Persoonsgegevens
PO Box 93374
2509 AJ The Hague
Netherlands
Website: www.autoriteitpersoonsgegevens.nl