Legal
Written to be read rather than to be complied with. If anything here is unclear or wrong, say so and I will fix it.
This site sets no cookies, runs no analytics, and loads nothing from anyone else. The fonts are served from this domain rather than from Google, so opening a page tells no third party you were here.
Two pages are different, and both only when you use them. The booking page loads a calendar from Cal.com. The contact form opens your own email programme; nothing is submitted anywhere.
I do not sell anything to anyone, and there is nothing to sell. That is the whole of it.
Hugo van de Haar, a sole trader registered in the Netherlands, is the controller for the personal data described here. Full details are on the terms page. For anything on this page, write to hugo@vandehaar.com.
No cookies are set. There is no analytics, no tag manager, no advertising pixel and no session tracking. The free scorecard works entirely inside your browser: the six answers are never sent anywhere and are gone when you close the tab. The research pages read from a file served with the site and record nothing about who read what.
Hosting. The site is served by Netlify, which keeps standard server logs for security and operation: IP address, the page requested, the time, and the browser's user-agent string. I do not read those logs as a matter of course and do not connect them to anything else. The basis for this is legitimate interest, in keeping a website online and defended. Netlify is a United States company and acts as a processor.
Fonts. The typefaces are stored on this domain. They used to load from Google's servers, which would have sent your IP address to Google before you had agreed to anything. That was worth removing and has been removed.
The booking page loads a calendar from Cal.eu, the European instance of Cal.com. Opening the page makes a request to them, and booking a slot gives them what you type: your name, your email address, your time zone and any note you add. They pass it to me and to my calendar, and they set their own cookies in your browser.
The basis is the steps you take before entering into a contract, at your own request. Cal.eu acts as a processor and runs on European infrastructure, so booking data stays inside the EU and nothing here depends on a transfer mechanism to a third country. Their own policy governs what they do with it.
This is the only page on the site that loads anything from anyone else. If you would rather not involve them at all, email me instead and we will find a time by hand. That route has exactly the same outcome and one fewer party.
The contact form does not submit anything to a server. It opens a message in your own email programme with the fields filled in, and nothing leaves your machine until you press send. Once you do, your message sits in my mailbox like any other email.
I keep correspondence for as long as the conversation is live and for a reasonable period afterwards, in case it resumes. Where an email becomes part of an engagement, invoices and the records behind them are kept for seven years, which Dutch tax law requires. Everything else I delete when it stops being useful.
The subscribe form on the publication pages posts your email address to Netlify Forms, which stores it and notifies me. That is the only field asked for, and the only one submitted. From there it goes into the list I send the publication from, and nowhere else.
The basis is your consent, given by submitting the form. It is used for that publication and for nothing else, it is never passed on or sold, and one line back from you removes it for good. There is no tracking in what I send: no open pixels, no click tracking, and no way for me to know whether you read it.
Netlify is a United States company and acts as a processor, so the transfer relies on the European Commission's standard contractual clauses or an adequacy decision, whichever applies at the time. The form uses a hidden field to catch automated submissions; it collects nothing about you.
The published research covers companies: what their websites say, what roles they advertise, and what their public filings and announcements show. It is compiled from sources anyone can reach, on dates that are printed alongside the figures.
Individual people are not the subject and are not profiled. Where a person appears in a public source, such as a founder quoted in a funding announcement, they appear as part of the company's public record. Aggregate reporting is the rule, and companies are named individually only where the finding is favourable.
If you work at a company covered by the research and something is wrong, write to me. Corrections are published alongside the figures rather than folded in quietly, which is the same standard the research files hold internally.
Under the General Data Protection Regulation you can ask for a copy of what I hold about you, ask for it to be corrected or deleted, object to my processing it, ask me to restrict it, or ask for it in a portable form. Where I rely on consent you can withdraw it at any time, and withdrawing does not affect what happened before.
One email to hugo@vandehaar.com is enough, and I will answer within a month. If you are not satisfied, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority where you live.
The site is static and served over HTTPS, so there is no database to breach and no login to compromise. Email and calendar sit behind two-factor authentication. This is a one-person business, so treat that as the level of assurance it is: proportionate to a mailbox and a diary, not to a bank.
If this statement changes in a way that matters, the date below changes with it. Last updated 25 July 2026.
Written in English because the work is. A Dutch version is available on request, and Dutch law applies either way.