Privacy Policy

Processing of personal data

Version 1.0 — Effective from 18 August 2026

1. Who we are and what this Policy covers

DropNext B.V. ("DropNext", "we", "us") is a private limited company incorporated under Dutch law, with its registered office at Westerstraat 10, 3016 DH Rotterdam, Netherlands, registered with the Dutch Chamber of Commerce under number 99989697.

This Privacy Policy explains how we collect, use, share and protect personal data when we operate our business-to-business platform for the supply of consumer goods (the “Platform”). It is addressed to:

  • Retailers that register an account with us, whether legal entities or natural persons acting in the course of a trade, business or profession (and the directors, ultimate beneficial owners, authorised representatives and authorised users of those Retailers);
  • End-Customers of Retailers whose personal data is shared with us in order to dispatch goods (typically name, delivery address, telephone number and email address);
  • Suppliers, carriers and service providers whose contact persons we interact with;
  • Visitors to our website and Platform.

This Policy is issued in accordance with Regulation (EU) 2016/679 (the “GDPR”) and the Dutch Uitvoeringswet AVG (the “UAVG”).

2. Controller and contact details

Unless explicitly stated otherwise, DropNext is the controller within the meaning of Article 4(7) GDPR for the processing described in this Policy. For the personal data of End-Customers that we process in order to fulfil a Retailer's orders (section 3.3), the Retailer is the controller and DropNext acts as processor on the Retailer's documented instructions; that processing is governed by the Data Processing Agreement with the Retailer, and the Retailer is responsible for informing End-Customers.

You can contact us about this Policy at: legal@dropnext.com, or by post at Westerstraat 10, 3016 DH Rotterdam, The Netherlands.

We have not appointed a Data Protection Officer (Functionaris voor Gegevensbescherming). Our processing does not meet the mandatory criteria of Article 37 GDPR. If this changes, we will update this Policy and publish the DPO’s contact details.

3. Categories of personal data we process

3.1 Counterparty onboarding data (Retailers and Suppliers)

In order to onboard a Retailer or Supplier, to comply with sanctions law and to protect our business and our partners against financial crime and fraud, we may collect personal data relating to the Counterparty’s directors, authorised representatives, authorised users and ultimate beneficial owners (each a “Connected Person”):

  • Full name, date of birth, place of birth, nationality.
  • Residential address.
  • Identity-document data (type, number, issuing country, expiry). A copy of the document is not collected as standard; a copy may be requested only where strictly necessary to resolve a screening hit. On any copy, the document photograph and any national identification number (such as the Dutch BSN) may be shielded by the Connected Person where not strictly necessary for verification. We do not process biometric data: identity verification does not involve facial recognition or automated 'liveness' checks. Where enhanced verification is required, we use a live video call with the director or UBO, cross-checks against public and UBO registers, and verification of the paying bank account instead.
  • Role within the Retailer and percentage of ownership/control (for ultimate beneficial owners).
  • Tax identification number, where applicable.
  • Sanctions, PEP and adverse-media screening results.

3.2 Retailer relationship data

  • Business contact details (name, business address, business email, telephone).
  • Account credentials, log-in records and activity logs.
  • Communication content (email, chat, support tickets).
  • Order history, invoices, payment records and chargebacks.
  • Device and connection information (IP address, browser type, language, time-zone).

3.3 End-Customer fulfilment data

To enable shipment by a Supplier to an End-Customer, the Retailer shares the following data with us, which we forward to the Supplier to which the corresponding Supplier Order was issued; the Supplier discloses to the carrier it engages only the data strictly necessary to effect delivery:

  • name and salutation;
  • delivery address;
  • telephone number and email address, where required for delivery;
  • order details (product references, quantity, value);
  • where required for customs, an identification or tax number (such as a national ID number for shipments to certain destination countries that require it).

We do not request and do not wish to receive sensitive personal data (special categories within the meaning of Article 9 GDPR) about End-Customers.

3.4 Website and Platform usage data

We process server log data, such as IP address, browser type, timestamps and pages requested, for security, abuse prevention and troubleshooting. The Website and the Platform use only strictly necessary cookies and similar technologies (authentication, session management, security, load balancing); these do not require consent under article 11.7a(3) of the Dutch Telecommunications Act (Telecommunicatiewet). We do not use analytical, advertising or tracking cookies. If we introduce such cookies in the future, we will first publish a cookie notice and, where legally required, request consent before placing them.

4. Sources of personal data

We collect personal data:

  • Directly from the Retailer when an Account is opened, when Retailer Order Requests are submitted or when the Retailer communicates with us.
  • From the Retailer’s e-commerce systems (for example, Shopify) where the Retailer integrates such systems with our Platform.
  • From public registers (such as the Dutch Kamer van Koophandel, equivalents in other jurisdictions, and sanctions lists).
  • From third-party data and screening providers used by us or by our Payment Service Provider to verify identity, perform sanctions, PEP and adverse-media screening, and to detect fraud.
  • From our Payment Service Provider, our banking partners and our carriers.

We process personal data for the following purposes and on the following legal bases (Article 6(1) GDPR):

Purpose: Performance of the contract with the Retailer, including onboarding, order processing, invoicing, customer support and delivery coordination.

Legal basis: Article 6(1)(b) GDPR — performance of a contract or pre-contractual steps.

Purpose: Verifying identity, conducting Know-Your-Business and Know-Your-Customer checks, and screening against sanctions, politically-exposed-persons and adverse-media databases.

Legal basis: For sanctions screening: Article 6(1)(c) GDPR — compliance with legal obligations under the Sanctiewet 1977 and directly applicable EU sanctions regulations. For all other identity-verification and Know-Your-Business processing: Article 6(1)(f) GDPR — our legitimate interest in preventing financial crime and fraud and in meeting the compliance requirements that our Payment Service Provider imposes on us contractually, on the basis of a documented balancing test. As a trader in general consumer goods, DropNext is not a Wwft-obligated institution; we therefore apply strict data minimisation and collect identity documents only in the limited cases described in section 3.1.

Purpose: Issuing and storing invoices and other accounting records.

Legal basis: Article 6(1)(c) GDPR — legal obligation under the Dutch General Tax Act (Algemene wet inzake rijksbelastingen) and the Dutch Civil Code (article 2:10 BW), under which records must be retained for 7 years (10 years for certain real-estate and immovable-property records).

Purpose: Detecting and preventing fraud, abuse, security incidents and breaches of our agreements with Counterparties (including the General Terms and Conditions and the Partner Compliance Agreement).

Legal basis: Article 6(1)(f) GDPR — our legitimate interest in protecting our business, our customers and our service providers.

Purpose: Sharing personal data with our Payment Service Provider so that it can perform its own services and meet its own regulatory obligations.

Legal basis: Article 6(1)(b) and (f) GDPR — performance of the contract and our legitimate interest in being able to receive payment services. Our Payment Service Provider processes this data for its own regulatory obligations as an independent controller.

Purpose: Sharing personal data with Suppliers and carriers so that goods can be dispatched and delivered.

Legal basis: Article 6(1)(b) GDPR — performance of the contract.

Purpose: Improving the Platform, performing analytics, and developing new products or features (in aggregated or pseudonymised form where reasonably practicable).

Legal basis: Article 6(1)(f) GDPR — our legitimate interest in improving our service.

Purpose: Direct B2B marketing of our own goods and services to existing Retailer contacts.

Legal basis: Article 6(1)(f) GDPR — our legitimate interest in promoting our business, with a right to object at any time.

Purpose: Responding to data-subject requests, legal claims and regulatory enquiries.

Legal basis: Article 6(1)(c) GDPR — compliance with legal obligations, and Article 6(1)(f) — our legitimate interest in defending claims.

6. Recipients of personal data

We share personal data with the following categories of recipients, only to the extent necessary for the purposes set out in section 5:

  • Suppliers located outside the European Union (in particular in the People’s Republic of China), to whom we transmit End-Customer fulfilment data so that goods can be dispatched;
  • Carriers and customs brokers — engaged by the Supplier for the international shipment of goods; they receive personal data from the Supplier as independent controllers (see section 7);
  • Payment Service Provider — a payment institution or electronic money institution authorised in the European Economic Area — which processes payments from Retailers and payments made by DropNext to its Suppliers in settlement of DropNext's own purchase obligations, and conducts its own KYB, AML, sanctions and transaction-monitoring activity;
  • Banking partners in connection with the operation of our bank accounts;
  • E-commerce platforms (including Shopify) where a Retailer has integrated its store with our Platform;
  • Identity-verification, screening and fraud-prevention service providers;
  • Accountants, auditors, lawyers and insurers;
  • IT, hosting, communication and analytics service providers, where appointed as processors;
  • Competent authorities, regulators, courts and other public bodies, where required by Applicable Law or to respond to a valid legal request;
  • Successors in title in the event of a sale, merger, reorganisation or insolvency of DropNext.

7. International transfers

The performance of our service involves transfers of personal data outside the European Economic Area (the “EEA”). The principal transfers are:

  • transfers to Suppliers in the People's Republic of China and other non-EEA countries for order fulfilment; carriers are engaged by the Supplier and receive data from the Supplier as independent controllers — that disclosure is an onward transfer governed by clause 8.8 of the Standard Contractual Clauses concluded with the Supplier;
  • transfers, where applicable, within our Payment Service Provider’s group: our payment service provider may process data through group entities outside the EEA, subject to appropriate safeguards (Chapter V GDPR);
  • transfers to other service providers that may store or process data outside the EEA.

Where the destination country has not been the subject of an adequacy decision by the European Commission (this is the case, in particular, for the People’s Republic of China), we rely on:

  • the European Commission’s Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as the transfer mechanism;
  • a Transfer Impact Assessment documenting the risks of the destination country and the supplementary technical, contractual and organisational measures we apply;
  • for the United Kingdom: transfers take place on the basis of the European Commission's adequacy decision;
  • for the United States, where applicable, certification under the EU-U.S. Data Privacy Framework.

You can request a copy of the safeguards in place for a specific transfer by contacting us at the address in section 2.

8. Retention periods

We retain personal data only for as long as necessary for the purposes for which it was collected, and in any event no longer than required by Applicable Law. Indicative retention periods are:

  • Retailer onboarding and KYB data: for the duration of the relationship and for 5 years thereafter (applying the five-year standard of article 33 Wwft by analogy, as our internal standard; DropNext is not itself a Wwft-obligated institution), or such longer period as may be required by a competent authority. This period aligns with the record-keeping standards that payment service providers and banking partners apply to their own customer files, and enables us to substantiate historical counterparties and transactions when they so request.
  • Order, invoice and accounting data: 7 years from the end of the financial year (article 52 AWR and article 2:10 BW);
  • End-Customer fulfilment data: for the period necessary to deliver the goods and to handle any post-delivery dispute, and in any event the period required by accounting law where the data forms part of an invoice;
  • Communications and support tickets: typically 3 years, longer if relevant to an ongoing matter;
  • Marketing data: until the data subject objects, with a periodic review every 2 years;
  • Server log data: up to 12 months, unless longer retention is necessary for the investigation of a security incident.

9. Your rights

Subject to the conditions and exceptions in the GDPR, you have the right to:

  • access the personal data we hold about you (Article 15);
  • rectify inaccurate or incomplete data (Article 16);
  • request erasure (Article 17), subject to legal retention obligations;
  • restrict processing (Article 18);
  • data portability for data you have provided to us and that we process by automated means on the basis of contract or consent (Article 20);
  • object to processing carried out on the basis of legitimate interests, including direct marketing (Article 21); and
  • where processing is based on consent, withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

To exercise these rights, please contact us at legal@dropnext.com. We may ask you for additional information to verify your identity before responding. We will respond within 1 month, extendable by 2 further months for complex requests, in accordance with Article 12(3) GDPR.

If you are not satisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, www.autoriteitpersoonsgegevens.nl) or with the data-protection supervisory authority of your habitual residence.

10. Automated decision-making

We use automated tools to support sanctions screening, fraud-prevention scoring and onboarding-risk assessment. Decisions to reject an application, suspend an Account, or block a transaction are not taken solely on the basis of automated processing within the meaning of Article 22 GDPR: a human reviewer is involved before any decision with legal or similarly significant effect is taken.

11. Security

We apply appropriate technical and organisational measures, taking into account the state of the art and the risks of the processing, to protect personal data against accidental or unlawful destruction, loss, alteration or unauthorised disclosure. These measures include access controls, encryption in transit, segregation of environments, logging, regular review of access rights, and processor due diligence.

12. Personal data breaches

In the event of a personal data breach within the meaning of Article 4(12) GDPR, we will notify the Dutch Data Protection Authority within 72 hours where required by Article 33 GDPR, and we will notify affected data subjects where required by Article 34 GDPR.

13. Changes to this Policy

We may amend this Policy from time to time. The current version is the one published on the Platform. Material changes will be communicated to Retailers by email or by a notice on the Platform.