Privacy notice.
1. Controller
J. van Huuksloot Asset Management B.V. ("JvHAM", "we"), registered in the Netherlands under KvK 76675602, with registered office at Herengracht 433, 1017 BR Amsterdam, is the controller of personal data processed via jvham.com. Contact: [email protected].
2. What we collect — inbound enquiries
When you submit the enquiry form we collect: the legal and registration details of the merchant entity, contact details of the named representative (name, role, email, phone), details of the regulated PSP counterparty, the merchant services agreement metadata, an estimate of the amount in dispute, the heads of claim asserted, the documentary completeness of the file, and any free-text information you provide.
Booking a call. When you book an introductory call on this website, we collect your name, your company (optional) and the email address the invitation goes to, together with the time you chose; after an enquiry form, the call uses the contact details from that form. The call is created as a Google Calendar event with a Google Meet link, with you as a guest, in the calendar of the JvHAM colleague who takes it. We use these details to hold and prepare the call, on the basis of our legitimate interest in answering your request (Art. 6(1)(f) GDPR).
Server logs (IP address, user-agent, request path) are processed by our hosting provider for security and operational purposes.
Site statistics. To understand which pages are read and how visitors find the site, our server records each page load: the page address, the country derived from your IP address, the referring website, any campaign tags in the link, and whether the device is a mobile, tablet or desktop. Your IP address and browser details are not stored. They are combined with a random value that is replaced every day into a one-way code, which lets us count unique visitors per day; the random value is deleted once the day has passed, so the code cannot be linked to you or to your visits on other days. Nothing is stored on or read from your device for this purpose, and it does not depend on your cookie choices. Legal basis: legitimate interest in running and improving the website (Art. 6(1)(f) GDPR). The records are kept in our database at Cloudflare (D1) for thirteen (13) months.
3. Purpose and legal basis — inbound
- Initial fit assessment of the prospective recovery file — legitimate interest (Art. 6(1)(f) GDPR) and, where you have provided the data, performance of pre-contractual steps at your request (Art. 6(1)(b) GDPR).
- Communications with you in response to the enquiry — same basis.
- Anti-spam verification via Cloudflare Turnstile — legitimate interest in protecting the service.
- Compliance with legal obligations — where applicable.
4. Outbound prospect research
The firm operates an outbound research function in connection with the recovery of merchant claims against regulated payment service providers. The function identifies prospective merchants who appear, on public information, to hold accrued claims against a regulated counterparty, and approaches the merchant's directors or senior officers in their public regulated capacity to indicate the firm's potential interest in assessing a recovery engagement.
What we process. Company information (legal entity name, registered office, public register references, regulator filings) — not personal data under the GDPR. Where we identify named directors or senior officers in their public capacity, we record name, public role, public-source URL and the date of capture. We do not process special category data. We do not automate the capture of personal data from social platforms; director records are captured manually from legitimate sources.
Legal basis. Legitimate interest under Article 6(1)(f) GDPR. The firm's interest is in identifying and approaching merchants in connection with regulated activity in which both the merchant and the counterparty are public-facing. The data subjects are recipients in their public regulated capacity, not private capacity. A Legitimate Interest Assessment is maintained internally and is available to data subjects on written request.
Jurisdiction-specific posture. In Germany and Austria, the firm operates a narrower variant of outbound research that adheres to UWG §7 — communications are limited to recipients in publicly disclosed regulated roles, opt-out is presented in the first paragraph of every communication, and persistence following opt-out is treated as a hard violation. In Italy, the firm applies an opt-in posture in keeping with the more conservative national interpretation of B2B electronic communications.
Opt-out and erasure. Every outbound communication contains a one-click opt-out link. You may also submit an opt-out via the unsubscribe page. The unsubscribe page offers three scopes — suppression of the specific outreach in progress, suppression of all outreach from the firm, and full erasure under Article 17 GDPR. Opt-out requests are honoured immediately and recorded indefinitely as proof of compliance, separately from any other prospect data. Erasure requests submitted via data subject requests are processed under the formal procedure on that page.
Retention of outbound prospect records. Where outbound research does not lead to engagement, the prospect record and any associated artefacts are retained for up to twenty-four (24) months from closure of the record, and then deleted. Opt-out records are retained indefinitely as evidence of compliance with the opt-out request.
5. Referral partners, the partner portal and the PSP Health Check
Partners. JvHAM works with referral partners — typically payment consultancies — that introduce merchants to us. For each partner we process the company details needed for the referral and cooperation agreement (legal name, registration number, registered office, the signatory and a notice address) and the names and email addresses of the people who use the partner portal. When the agreement is signed in the portal, we also record, for each signer, the name and title entered, the email address the signing link was sent to, the time of signing, the IP address and a fingerprint of the signed document, as evidence of the signature; these records are kept with the agreement. The legal basis is the performance of the agreement with the partner and our legitimate interest in administering it (Art. 6(1)(b) and (f) GDPR).
The partner portal at jvham.com/partner is used by partners to see their referral links and how they perform. Partners log in with a one-time link sent to their email address; there are no passwords. The portal shows each referral by reference number, date and a general stage only. It never shows a merchant's name, contact details, answers or provider — that information is shared with JvHAM, not with the partner.
The PSP Health Check. Merchants who reach us through a partner may answer four questions about a previous payment provider on a page hosted by JvHAM. Nothing is sent to us until the merchant ticks the consent box and submits; before that, only an anonymous count that the page was shown (the partner's code and nothing else) is recorded. Submitted answers, and an email address if the merchant books a call, are used to assess whether we can help — on the basis of the merchant's consent and, once a call is booked, pre-contractual steps at their request (Art. 6(1)(a) and (b) GDPR). Consent can be withdrawn at any time by writing to us.
Introductions. A partner may also introduce a merchant who has asked to be put in touch with us, through a form in the partner portal: the company, a contact name, an email address and optionally a phone number and a short description. We use these details only to contact the merchant at their request and to assess whether we can help (Art. 6(1)(b) and (f) GDPR), and tell the merchant how we obtained them when we first write. The partner confirms that the merchant asked to be contacted.
Which partner introduced a merchant is recorded from the link the merchant arrived through; no cookie or other identifier is stored on the merchant's device for this purpose. JvHAM and each partner act as independent controllers of the data each holds.
6. Recipients and processors
We use the following processors:
- Cloudflare, Inc. — hosting, CDN, anti-spam (Turnstile), email routing, and database (D1). Data may be processed in the EU and other regions where Cloudflare operates.
- Resend, Inc. — transactional email delivery.
- Google — Google Workspace: our email, calendars and Google Meet for booked calls, and documents such as partner agreements.
- Crisp IM SAS (France) — live chat on this website. Chat transcripts and the contact details you choose to provide in a conversation are processed on Crisp's EU infrastructure.
- A specialist recovery fund the firm cooperates with — to the extent necessary to assess eligibility for, and execute, an outright claim purchase in selected cases.
Data may be disclosed to external counsel, supervisory authorities, courts and tribunals to the extent strictly necessary for the conduct of a recovery file, after a separate instrument — the Claim Assignment and Recovery Agreement or, in selected cases, a claim purchase instrument — has been executed.
7. International transfers
Where personal data is transferred outside the EEA, transfers are subject to appropriate safeguards under Chapter V GDPR (Standard Contractual Clauses or equivalent).
8. Retention
Enquiry submissions assessed as not a fit are retained for up to twenty-four (24) months from receipt to permit follow-up and to maintain an audit trail. Submissions leading to executed engagement are retained for the duration of the engagement and for seven (7) years thereafter consistent with professional record-keeping obligations.
Site statistics records (section 2) are deleted thirteen (13) months after the page load.
PSP Health Check answers are anonymised twenty-four (24) months after receipt unless they have led to a file: free text, email address, booking reference and page details are deleted, and only the anonymous answers are kept for our records with the partner. Name, company and email address of a call booked on this website are deleted twenty-four (24) months after booking; the time of the call is kept. Partner portal logins and sessions are deleted when a partner relationship ends; partner company details and the signed agreement are kept for as long as claims under the agreement can arise.
9. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction, objection, and data portability in respect of your personal data, subject to applicable exceptions. You also have the right to lodge a complaint with a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.
To exercise any of these rights, follow the formal procedure on the data subject requests page. Requests are acknowledged within seventy-two (72) hours and substantively answered within thirty (30) calendar days.
10. Cookies and tracking
jvham.com operates a category-based consent model. On first visit, a banner is presented allowing you to accept all categories, reject all non-essential categories, or set granular preferences. Your choice is stored in your browser's local storage and can be changed at any time via the control in the page footer.
The categories are:
- Strictly necessary — Cloudflare security cookies and the Turnstile anti-bot challenge. Always on; required for the site to function. For partners only:
jv_partner, the partner portal login session, set when a partner logs in and removed at logout (at most 30 days). It is not used on any other part of the site and not for tracking. - Analytics — Cloudflare Web Analytics, a cookie-less aggregate measurement of site traffic with no fingerprinting, no profile building, and no cross-site tracking; and Apollo website visitors, which resolves the organisation behind a visitor's IP address and stores an identifier in your browser so repeat visits by the same organisation can be recognised; it identifies organisations, not individuals. Both are off by default and loaded only with your consent.
The server-side site statistics described in section 2 set no cookie and store nothing on your device, so they are not a cookie category and are not affected by these choices.
We do not use marketing or advertising cookies. Sentry is used for error monitoring on a per-request, cookie-less basis as part of the strictly necessary category.
Live chat. The chat widget (Crisp) loads no code and sets no cookie until you open it. Opening the chat is a request for the service; Crisp then sets a session cookie strictly necessary to keep your conversation connected across pages. If you never open the chat, nothing is loaded from Crisp.
11. Changes
We may update this notice from time to time. Material changes will be flagged on this page.