ASE Cloud Services Chatbot Interface
ASE Cloud Services B.V.
Last updated: 10 September 2026
Version: 2.1
ASE Cloud Services B.V. (“ASE Cloud Services”) places the highest value on the privacy of its business relationships and the security of the data it processes. In this Privacy Statement, we explain how we collect, use and protect personal data, with a specific focus on our core value: European Data Sovereignty.
Data Controller:
ASE Cloud Services B.V.
Prinsessenlaan 30
2761 PB Zevenhuizen
The Netherlands
Chamber of Commerce number: 98388967
E-mail: info@asecloud.nl
Website: www.asecloud.nl
Telephone: 0180-201 789
1.1 Data Protection Officer (DPO). ASE Cloud Services is currently not required to appoint a Data Protection Officer within the meaning of Article 37 GDPR. For all privacy-related questions, requests or complaints, the contact point listed above serves as the primary point of contact.
This Privacy Statement applies to all processing of personal data by ASE Cloud Services in the context of its B2B services, including website visitors, (potential) customers, suppliers and business partners. It does not apply to users of chatbot services that we provide to our customers.
Where ASE Cloud Services acts as a processor for its customers (e.g. when hosting chat logs for a specific customer solution), the relevant data processing agreement applies to that specific data flow, and the customer is the Data Controller of all personal data collected or processed.
2.1 Role of ASE Cloud Services. Depending on the nature of the service, ASE Cloud Services acts as (i) the data controller for its own business processes (such as relationship management, invoicing and website use), and/or (ii) a processor on behalf of its customers when providing AI services. Where processing is carried out as a processor, the customer’s instructions and the applicable data processing agreement shall prevail.
ASE Cloud Services maintains a strict policy regarding data protection and territorial sovereignty:
3.1. Exclusive EU Processing: All personal data is processed and stored exclusively on infrastructure within the European Economic Area (EU/EEA) or in countries with a current adequacy decision from the European Commission, with the exception of the US.
3.2. Sovereign Hosting: We exclusively use European cloud providers that are not subject to extraterritorial legislation of non-EU powers (such as the US CLOUD Act).
3.3. No Data Export: ASE Cloud Services does not transfer personal data to entities in “third countries” (countries outside the EU/EEA or without an “adequacy” assessment by the European Commission).
3.4 No International Transfers. ASE Cloud Services does not use appropriate safeguards as referred to in Chapter V GDPR (including Standard Contractual Clauses), as no transfers of personal data outside the EU/EEA take place. If this policy were to change in exceptional circumstances, data subjects will be informed in advance and only GDPR-compliant safeguards will be applied.
We process the following categories of data:
4.1A Cookies. ASE Cloud Services only uses functional and analytical cookies that have no or minimal impact on the privacy of data subjects. Consent is requested via a cookie banner where legally required. Further information is available through the cookie policy on the website.
4.2 Forms and spam protection. All forms on this website (contact forms, one-pager downloads and the AI Readiness Assessment) are protected by a self-hosted proof-of-work check (Altcha). Your browser solves a small computational puzzle before the form is submitted. This check sets no cookies, does not profile or fingerprint your device and sends no data to third parties; it runs entirely on our own server in the EU. In addition, we use a hidden control field and a minimum completion time. Legal basis: legitimate interest (Art. 6(1)(f) GDPR), namely protecting our systems against abuse and spam.
4.3 Sovereign AI Readiness Assessment. When you complete the free AI Readiness Assessment on our website, we process your answers and the scores calculated from them, together with the business details you enter at the end (name, business email address, organisation, job title, sector and, optionally, telephone number and organisation size), the time and wording of your consent, the version number of the scan and a hashed derivative of your IP address that cannot be traced back to you, used to detect abuse (a maximum of five submissions per hour). Purpose: delivering your result on screen and by email, linking the result to your organisation and, only if you separately opt in, contacting you about the outcome. Legal basis: consent (Art. 6(1)(a) GDPR) for delivering the result; for any subsequent contact, your separate consent or our legitimate interest in acquisition (Art. 6(1)(f) GDPR). Interim answers are stored only in the local storage of your own browser (for a maximum of 30 days) and are deleted on completion; they are only sent to us after you click ‘View my result’. The result is a management inventory and not legal advice, a DPIA or a formal classification under the AI Act. Retention period: a maximum of 24 months after the last contact (see chapter 6). In addition, we use the answers and scores in aggregated, anonymised form (for example the average per sector) to show respondents a comparison and to publish statistics; no individual organisations or persons can be identified from them.
We process data on the basis of the following legal bases (Article 6 GDPR):
|
Purpose |
Legal Basis |
|
Functional/Preference Retention |
Art. 6(1)(a) GDPR (Consent) |
|
Performance of the agreement (provision of AI services) |
Art. 6(1)(b) GDPR (Performance of agreement) |
|
Invoicing and financial administration |
Art. 6(1)(c) GDPR (Legal obligation) |
|
Customer relationship management and acquisition |
Art. 6(1)(f) GDPR (Legitimate interest) |
|
AI Readiness Assessment: delivering the result |
Art. 6(1)(a) GDPR (Consent) |
|
Protecting forms against spam and abuse |
Art. 6(1)(f) GDPR (Legitimate interest) |
Withdrawal of Consent. Where not otherwise facilitated by consent controls on the ASE Cloud Services website or our Customers’ websites, data subjects may withdraw their consent at any time by e-mailing info@asecloud.nl.
Balancing Test for Legitimate Interest. Where processing takes place on the basis of legitimate interest (Article 6(1)(f) GDPR), ASE Cloud Services has carried out a balancing test and determined that the interests, fundamental rights and freedoms of data subjects do not override the processing purposes. Where not otherwise facilitated by controls on the ASE Cloud Services website or by “unsubscribe” links in marketing e-mails or messages, data subjects may object at any time to processing based on legitimate interest by e-mailing info@asecloud.nl or by otherwise contacting their ASE Cloud Services sales representative to register their objection to the use of personal data for marketing purposes.
We do not retain personal data for longer than necessary for the stated purposes:
In exceptional circumstances, personal data may be retained for longer where necessary for the establishment, exercise or defence of legal claims, in accordance with Article 5(1)(e) GDPR.
We carefully select our processors to ensure their European sovereignty by choosing processors established in the EU/EEA or in countries with valid, current EU Commission adequacy decisions. We do not export personal data to the US through our processors. These include:
|
Processor |
Country |
Processing Purpose |
Possible Transfer of Personal Data Outside EU/EEA |
Transfer Basis |
|
OVH Groupe SA |
France |
Website hosting, cloud storage, DNS, infrastructure, e-mail services and the environment of the IRIS chatbot (chatbot.asecloud.nl) |
No |
Not applicable |
|
Mistral AI |
France |
Language model behind the IRIS chatbot on asecloud.nl: processes the questions visitors ask in the chat |
No |
Not applicable |
|
Meetergo GmbH |
Germany |
Online appointment scheduling (cal.meetergo.com) |
No |
Not applicable |
|
Rapidmail GmbH |
Germany |
Sending the newsletter and managing newsletter subscriptions |
No |
Not applicable |
|
Complianz (Really Simple Plugins B.V.) |
Netherlands |
Cookie consent; runs entirely on our own server, no data is shared with the supplier |
No |
Not applicable |
|
Bricks Builder |
Germany |
WordPress theme for the website design; runs entirely on our own server, no data is shared with the supplier |
No |
Not applicable |
ASE Cloud Services implements enterprise-level security measures:
8.1 Data Breaches. If a security breach occurs that is likely to result in a high risk to the rights and freedoms of data subjects under our responsibility as Data Controller, ASE Cloud Services will inform data subjects in accordance with Article 34 GDPR, unless a legal exception applies.
Data subjects have the following rights under the GDPR:
You may exercise these rights via info@asecloud.nl. We will respond within 30 days at the latest.
Identity Verification. To protect personal data, ASE Cloud Services may request additional information when rights are exercised in order to verify the identity of the requester.
If you believe that we are processing your data unlawfully, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP).
This Privacy Statement is governed by Dutch law. We reserve the right to amend this statement to comply with legislation (including the AI Act). Significant changes will be communicated directly to our customers.