Privacy Policy
Last updated: 1 August 2026 · Applies to: nativework.org
In short
This page explains what we do with your information.
- Reading this website: we collect nothing about you. There are no cookies at all — not even for statistics.
- Writing to us: we keep your message and your email address so we can answer you, and for two years afterwards so we can look up what was said.
- The reviewer list: if someone put your name forward to review the specification, we hold your username or email address. We never send you anything from that list. Ask us and we will remove you.
You can ask us to show you your data, correct it, or delete it. Write to info@nativework.org and we will answer within a month. If you are unhappy with our answer, you can complain to the Dutch privacy regulator.
This is the baseline. NativeWork services that do more than this website — anything with a login, a conversation or a payment — publish their own extra page explaining what they collect. That page adds to this one.
This summary is here to help you understand the policy. The full text below is what applies.
1. Who we are
NativeWork is a project of Centipod B.V., registered in the Netherlands, KvK number 67295444, registered address Mauritsstraat 40, 2271 SE Voorburg, the Netherlands.
We are the data controller for the personal data described in this policy.
Contact for privacy matters: info@nativework.org.
We have not appointed a Data Protection Officer. Our processing does not meet the conditions in Article 37 GDPR that would require one.
2. What this policy covers
This is the baseline policy for NativeWork. It covers Centipod as an organisation and the public website at nativework.org — the specification material, the participation process and any correspondence with us.
Separate services publish an addendum. Where a NativeWork service processes more than this baseline describes — an account, a conversation, a payment — that service publishes its own privacy addendum naming its processors, its retention periods and its legal bases. The addendum adds to this policy; it does not replace it. Where the two differ on a point specific to that service, the addendum governs.
3. What we collect and why
3.1 When you visit nativework.org
Nothing that identifies you. The site is static. It sets no analytics, advertising or tracking cookies, and we do not build a profile of your visit.
Our hosting provider processes the technical information any web server receives in order to deliver a page and to defend itself against attack — IP address, user agent, requested path. We do not combine this with anything else or use it to identify you.
3.2 When you contact us
| Data | Purpose | Legal basis |
|---|---|---|
| Your email address, name and the content of your message | Answer you, and keep a record of what was agreed | Legitimate interests (Art. 6(1)(f)) — responding to someone who contacted us |
| Correspondence about participation or licensing | Assess and administer the request | Legitimate interests; steps prior to a contract (Art. 6(1)(b)) |
We keep correspondence for as long as the matter is live, and afterwards for 24 months, so that we can reconstruct what was said. Contractual and accounting records are kept for the periods law requires.
3.3 If you are on the reviewer list
We keep a short list of people we would like to have review the specification before it is published. The list holds an identifier — a GitHub username or an email address — for people who do not yet hold access.
We do not send anything from this list. No email, no invitation, no notification. It exists only so that someone we have invited is recognised when they ask for access. If you never do, nothing happens.
| Data | Purpose | Legal basis |
|---|---|---|
| The GitHub username or email address on the list | Recognise you and grant the access you were offered | Legitimate interests (Art. 6(1)(f)) |
| A short note on who added you and why | Keep the list accountable and avoid duplicates | Legitimate interests |
This is the only case in which we hold personal data about someone who has no relationship with us yet. We keep an entry until the access is granted, or for 12 months if it never is, whichever comes first.
If you are on the list and would rather not be, say so and we will remove you. Nothing else is attached to it.
4. Who processes your data
For the public website:
| Processor | Role | Location | Safeguards |
|---|---|---|---|
| Vercel | Hosting and content delivery | EU region (Frankfurt); operational metadata may be processed outside the EU | ISO 27001:2022, SOC 2 Type 2, EU–US Data Privacy Framework, Standard Contractual Clauses |
A data processing addendum applies to this relationship, incorporated into the provider’s terms of service.
Correspondence reaches us through our email provider. Any further processor used by a NativeWork service is named in that service’s addendum.
5. Where your data is stored
Website requests are served from EU regions. Correspondence is held in the European Union.
Platform operational metadata — deployment records, infrastructure logs — may be processed outside the EU by our hosting provider under Standard Contractual Clauses and the EU–US Data Privacy Framework.
Where a service transfers personal data outside the EU, its addendum says so plainly and states the transfer mechanism.
6. How long we keep it
| Data | Retention |
|---|---|
| Correspondence | 24 months after the matter closes |
| Contract and accounting records | 7 years (Dutch tax law) |
| Reviewer-list entries never taken up | 12 months |
Deletion is deletion. We do not retain flagged copies of deleted records.
7. Your rights
Under the GDPR you may:
- Access the personal data we hold about you
- Rectify anything inaccurate
- Erase your data (“right to be forgotten”)
- Port your data in a machine-readable format
- Restrict or object to processing based on legitimate interests
- Withdraw consent where processing relies on it
Write to info@nativework.org. We respond within one month. Services that offer self-service access, export and deletion say so in their addendum.
You may lodge a complaint with the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), the Dutch supervisory authority, or with the authority in your country of residence.
8. Cookies
The public website sets no cookies at all. No analytics, no advertising, no third-party tracking. There is no consent banner because there is nothing to consent to.
Services that need a session or a security token list those cookies in their addendum.
9. Security
See our Security Statement.
10. Children
NativeWork is intended for professional use and is not directed at anyone under 16. We do not knowingly collect data from children.
11. Changes
The revision date at the top always reflects the current version. Material changes are published here before they take effect.
12. Contact
info@nativework.org
Centipod B.V., Mauritsstraat 40, 2271 SE Voorburg, the Netherlands