Privacy statement Paragin Group

Paragin Group attaches great importance to the protection of personal data and the privacy of users of its products and services. Paragin Group processes personal data solely for legitimate purposes and in accordance with the General Data Protection Regulation ("GDPR") and other applicable data protection laws and regulations.

This privacy statement relates to the processing of personal data in connection with the services described in Article 2(2).

1. Identity of the Controller

Paragin Group Holding B.V., with its registered office in Nijkerk (the Netherlands) and its business address at Bunschoterweg 39, 3861 MK Nijkerk, together with its subsidiaries forms the Paragin Group. The Paragin Group includes, among others, the following subsidiaries:

  • B3net B.V.
  • InnoPhase B.V.
  • Paragin B.V.
  • Sowiso B.V.
  • Xebic Onderwijs B.V.

The processing of personal data as described in this privacy statement is carried out by the relevant subsidiary within Paragin Group that determines the purpose and means of the processing. This entity acts as the Controller within the meaning of the General Data Protection Regulation ("GDPR").

Paragin Group Holding B.V. does not, in principle, act as the Controller, unless expressly stated otherwise.

2. Processing of personal data

Paragin Group processes personal data on the basis of various legal grounds and in various roles, depending on the nature and purpose of the processing.

2.1 Processing in connection with the performance of an agreement

An agreement is entered into with the client or partner (hereinafter: client) for the use of Paragin's applications. In connection with this agreement, the client acts as the Controller and Paragin Group as the Processor within the meaning of the GDPR.

Paragin Group processes personal data in this context solely on behalf of, and in accordance with the instructions of, the client, as set out in the applicable Data Processing Agreement and/or contractual arrangements.

Further information about this processing is included in the privacy disclaimer within the applications and the privacy and information center.

2.2 Processing of personal data for Paragin Group's own purposes

Without prejudice to the processing of personal data in connection with the performance of the agreement with the client as referred to in Article 2.1, Paragin Group processes personal data for its own purposes that do not form part of the services agreed with the client.

This processing takes place in connection with the functioning of the organization, the maintenance of relationships with users and other data subjects, and the safeguarding and improvement of the quality, effectiveness, and continuity of its products, services, and business processes. This may include processing feedback, optimizing communication, carrying out analyses, and applying (automated) tools to support these purposes.

To the extent that Paragin Group does not process this personal data on behalf of a client, it acts as the Controller within the meaning of the GDPR.

The processing of personal data under this article takes place on the basis of one or more of the following legal grounds:

  • Consent of the data subject;
  • The legitimate interest of Paragin Group;
  • Compliance with a legal obligation.

If personal data is processed on the basis of consent, the data subject has the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

Paragin Group takes appropriate technical and organizational measures to ensure that personal data is processed carefully and in accordance with applicable laws and regulations. No decisions are made based solely on automated processing that produce legal effects for data subjects or otherwise significantly affect them, unless this is permitted under the GDPR and appropriate safeguards have been put in place.

If the provision of personal data is necessary for (part of) Paragin Group's services outside the agreement with the client, failure to provide this data or withdrawal of consent may result in (further) access to those parts not being possible.

3. Engagement of third parties (Processors)

Paragin Group may engage third parties (Processors) for the processing activities described in Article 2.2. In such cases, Paragin Group remains responsible for the processing of personal data, unless it acts as a Processor on behalf of the client.

Paragin Group enters into Data Processing Agreements with these third parties, which include appropriate safeguards for the protection of personal data, in accordance with the requirements of the GDPR.

Personal data may also be provided to competent authorities if Paragin Group is legally required to do so.

4. Retention periods

Paragin Group does not retain personal data for longer than necessary for the purposes for which it was collected and processed, unless a longer retention period is required or permitted under applicable laws and regulations.

5. Rights of data subjects

Data subjects have, to the extent applicable and within the limits of applicable laws and regulations, the following rights:

  • Right of access;
  • Right to rectification;
  • Right to erasure;
  • Right to restriction of processing;
  • Right to data portability;
  • Right to object;
  • The right not to be subject to a decision based solely on automated decision-making, except as permitted by law.

Requests can be submitted via support@paragin.com. Paragin Group will handle such requests within the statutory time limits.

If Paragin Group acts as a Processor on behalf of a client, it will forward requests to the relevant Controller, unless it is legally required to act independently.

6. Transfer of personal data outside the EEA

If personal data is, in exceptional cases, transferred to parties outside the European Economic Area (EEA), Paragin Group ensures that this transfer takes place in accordance with applicable laws and regulations.

Paragin Group takes appropriate safeguards, including the use of standard contractual clauses approved by the European Commission or transfers based on an adequacy decision.

7. Security of personal data

Paragin Group takes appropriate technical and organizational measures to protect personal data against loss, unauthorized access, or unlawful processing.

These measures include, among other things, access restrictions, logging and monitoring, security policies, and periodic evaluation of security measures, taking into account the state of the art, the nature of the data, and the risks of the processing.

In the event of a data breach, Paragin Group acts in accordance with the Data Processing Agreements, statutory notification obligations, and notification periods.

8. Dutch Data Protection Authority

If you believe that Paragin Group processes personal data in violation of applicable regulations and we are unable to resolve this together, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via www.autoriteitpersoonsgegevens.nl.