Lake-Project / Trust & Privacy
Legal & privacy

Trust &
Legal

How Lake-Project handles personal data, what cookies we use, who our sub-processors are, and how to exercise your rights under the GDPR.

Last updated: July 2026  ·  Lake Project · KvK 29816688
01 · GDPR Art. 13 / 14

Privacy statement

Lake-Project (the trade name of Lake Project, KvK 29816688, Rotterdam) is the data controller for the personal data described below. We process personal data only where we have a lawful basis and only for the stated purpose.

Contact enquiries
Data Name, company name, email address, enquiry text, topic Purpose Responding to inbound enquiries and evaluating potential engagements Legal basis Legitimate interest (Art. 6(1)(f)): responding to a request initiated by the data subject Retention 2 years from last contact; deleted on request Processor Resend (email delivery); Cloudflare (form spam protection)
Client portal accounts
Data Name, business email address, phone number, company name and address Purpose Providing secure access to the client portal (invoice viewing, document download, account management) Legal basis Performance of a contract (Art. 6(1)(b)) Retention Duration of the business relationship, plus 7 years fiscal retention (Art. 52 AWR) Processor Cloudflare (D1 database, R2 storage, Pages hosting)
Invoice administration
Data Company name, address, VAT number, invoice contact name and email, invoice data Purpose Issuing invoices, bookkeeping, and fiscal compliance Legal basis Legal obligation (Art. 6(1)(c)): Art. 52 AWR requires 7-year retention of the administration Retention 7 years from the end of the fiscal year Processor Cloudflare (D1 database, R2 storage)

We do not sell personal data, do not use it for automated decision-making or profiling, and do not transfer it to countries outside the EU/EEA without the safeguards described in the sub-processor section below.

02 · ePrivacy / Cookie law

Cookies & local storage

Lake-Project uses no tracking, analytics, or advertising cookies. Only two types of cookies are set, both strictly necessary for the site to function correctly. No consent banner is required under the Dutch ePrivacy rules (Telecommunicatiewet art. 11.7a) for strictly necessary cookies.

Cloudflare Turnstile · cf-bm
Set by Cloudflare, Inc. (challenges.cloudflare.com) Purpose Bot and spam protection for the contact form. No personal data beyond the visitor's IP is sent to Cloudflare; the challenge is privacy-preserving by design. Duration Session / 30 minutes Category Strictly necessary, set only when the contact form is rendered
Portal session · portal_session
Set by portal.lake-project.com Purpose Maintains an authenticated session in the client portal after sign-in. HttpOnly and Secure; not accessible to JavaScript. Duration 24 hours, rolling Category Strictly necessary, set only for portal users after successful authentication
03 · GDPR Art. 28

Sub-processors

Lake-Project uses the following third-party sub-processors. Data processing agreements (DPAs) are in place with each. Where data leaves the EEA, EU Standard Contractual Clauses (SCCs) apply.

Processor Purpose Data location Safeguard
Cloudflare, Inc. (US) Web hosting (CF Pages), file storage (R2), database (D1), DDoS protection, email routing, Turnstile spam protection EU-West (Amsterdam) as primary; CDN globally EU SCCs + Cloudflare DPA · cloudflare.com/cloudflare-customer-dpa.pdf
Resend (WorkOS, Inc., US) Transactional email delivery: contact form acknowledgements, portal magic links, invoice delivery US EU SCCs · resend.com/legal/dpa

This list is kept up to date. Any new sub-processor is reviewed before use and added here within 30 days of adoption.

04 · GDPR Art. 15–22

Your rights

As a data subject you have the following rights with respect to personal data we hold about you. To exercise any of these rights, contact us at [email protected]. We respond within 30 days.

Art. 15
Right of access
Request a copy of the personal data we hold about you and information on how it is used.
Art. 16
Right to rectification
Request correction of inaccurate or incomplete personal data.
Art. 17
Right to erasure
Request deletion of your personal data where there is no overriding legal obligation to retain it.
Art. 18
Right to restriction
Request that we restrict processing of your data in certain circumstances.
Art. 20
Right to portability
Receive your personal data in a structured, machine-readable format where processing is based on consent or contract.
Art. 21
Right to object
Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling grounds.

You also have the right to lodge a complaint with the Dutch supervisory authority:

To exercise your rights or ask a privacy question, email us directly. We respond within 30 days.

Email privacy request →
06 · GDPR Art. 32

Security measures

Lake-Project applies the following technical and organisational security measures (TOMs) to protect personal data against unauthorised access, loss, or disclosure, in line with GDPR Art. 32.

Authentication
Admin access WebAuthn passkeys only (FIDO2 / W3C Web Authentication standard). No passwords exist. Passkeys are device-bound, phishing-resistant, and qualify as MFA AAL2 under NIST SP 800-63B. Portal access Single-use, time-limited login tokens (magic links) sent to verified email addresses and valid for 24 hours. No reusable passwords.
Encryption
Data at rest All personal data is stored in Cloudflare D1 (SQLite) and Cloudflare R2 (document storage), both encrypted at rest with AES-256 by Cloudflare. Data in transit All connections use TLS 1.2 or higher. HTTP requests are automatically redirected to HTTPS. TLS termination is handled by Cloudflare at its edge network.
Access control
Admin Access restricted to one person: Alexander van der Plas (sole trader). No third-party administrators. Access rights are reviewed annually as part of the internal compliance audit. Portal isolation Each portal session is bound to a single company at the database level. All queries are constrained server-side to that company's data, so cross-company access is architecturally impossible.
Infrastructure & patching
Platform All processing runs on Cloudflare's infrastructure (Pages, Workers, D1, R2), which holds SOC 2 Type II and ISO 27001 certifications. No personal data is processed on local hardware. Patching The Cloudflare Workers and Pages runtime is maintained and patched by Cloudflare. Application dependencies are reviewed and updated periodically. No data is stored in third countries without the safeguards described in §03.

These measures are reviewed at least annually. If a security incident occurs that poses a risk to your personal data, we will notify the Autoriteit Persoonsgegevens within 72 hours and inform affected individuals where required.

07 · Disclaimer

Disclaimer

Lake-Project maintains this website with reasonable care. The content is intended for general informational purposes and does not constitute professional advice. Lake-Project accepts no liability for any direct or indirect damages resulting from reliance on the information on this website.

This website may contain links to third-party websites. Lake-Project has no control over, and accepts no responsibility for, the content, privacy policies, or practices of those sites.

All content on this website, including text, design, graphics, and code, is the intellectual property of Lake-Project (Alexander van der Plas) and may not be reproduced without prior written consent.

Governing law: Dutch law applies to all matters arising from this website. Any disputes are subject to the exclusive jurisdiction of the competent court in Rotterdam, Netherlands.

Changes to this page: This trust page may be updated periodically. The "Last updated" date at the top reflects when material changes were last made. We will not reduce your rights under existing privacy commitments without clear notice.