Privacy Policy
Global Staffing Support B.V. (“GSS”)
1. Who we are and what this policy covers
This Privacy Policy explains how Global Staffing Support B.V. (“GSS”, “we”, “us”), a private limited liability company incorporated under the laws of the Netherlands, registered with the Dutch Chamber of Commerce (Kamer van Koophandel) under number 09132165, VAT number NL811925225B01, with its registered office at Kraailandhof 63, 3828 JP Hoogland, the Netherlands, processes personal data.
This policy applies to:
- our public website at www.newsintel.eu and all of its subpages, including the pricing page, the contact form, the demo-booking flow and the free sample-article request flow (the “Website”);
- the NewsIntel customer application at app.newsintel.eu, together with the administrative console (the “Service”);
- our commercial communications, demo bookings, sample Articles and newsletters.
Download the Privacy Policy (PDF)
This policy does not apply to:
- the websites, applications or newsletters of our customers, even where these display Articles produced by the Service. Where a customer publishes an Article on its own channels, that customer determines the purposes and means of that publication and acts as controller in respect of it;
- third-party websites we link to.
Where we act as a processor on behalf of a business customer, the processing is governed by our Data Processing Agreement (DPA) with that customer and by that customer’s own privacy notice, not by this policy. Section 8 sets out the split of roles.
Contact for privacy matters
| Channel | Detail |
|---|---|
| privacy@newsintel.eu | |
| Postal | Global Staffing Support B.V., Kraailandhof 63, 3828 JP Hoogland, the Netherlands |
| Data Protection Officer | We have not appointed a Data Protection Officer. Privacy questions are handled by privacy@newsintel.eu. |
| EU/EEA establishment | GSS is established in the Netherlands; no Art. 27 GDPR representative is required. |
| UK representative | The Service is offered from the Netherlands. We have not appointed a UK GDPR Art. 27 representative. |
2. Summary table — what we process and why
The table below is a summary. The full detail is in Sections 3 to 7.
| Category of data subject | What we process | Why | Legal basis (Art. 6 GDPR) |
|---|---|---|---|
| Website visitors | Technical data, security data, consent records, consented analytics | Operate and secure the Website; measure use | Legitimate interests (f); consent (a) for analytics |
| Prospects, contact-form and demo enquiries | Name, work e-mail, company, role, message, appointment details | Answer enquiries, hold demos, pre-contractual steps | Contract / pre-contractual steps (b); legitimate interests (f) |
| Sample-article requesters | Name, work e-mail, company website, company LinkedIn URL, description of their work, up to 8 topic keywords | Produce and send one free sample Article; follow up commercially | Pre-contractual steps (b); legitimate interests (f) |
| Customer users (account holders) | Account, authentication, role, activity and support data | Provide, secure, support and bill the Service | Contract (b); legitimate interests (f) |
| Billing contacts | Billing name, address, VAT number, payment status | Invoicing, collection, accounting | Contract (b); legal obligation (c) |
| Newsletter recipients (our own list) | E-mail, name, subscription status | Send our own newsletter | Consent (a), or soft opt-in for existing business contacts |
| Newsletter recipients (customer lists) | E-mail, name, status, send events | Operate the mailing on the customer’s instructions | We act as processor; the customer’s basis applies |
| Individuals in a customer’s uploaded documents (Pro plan) | Whatever the customer’s documents contain | Index and answer questions on the customer’s instructions | We act as processor; the customer’s basis applies |
| Individuals mentioned in Articles | Name and publicly reported information appearing in source material | Produce and review news content | Legitimate interests (f), read with freedom of expression and the journalistic context |
| Applicants, partners, suppliers | Contact and contractual data | Recruitment, procurement, partnership administration | Contract (b); legitimate interests (f); consent (a) where applicable |
3. Website visitors
3.1 What we process
- Technical and connection data: IP address, user-agent string, device and browser type, operating system, language settings, referring URL, requested pages, date and time of request, HTTP status.
- Security data: rate-limiting counters, bot-detection signals and blocked-request records generated by our own infrastructure.
- Cookie and consent data: the cookies described in our Cookie Policy, and a record of the choice you make in the cookie banner (which categories you accepted, and when).
- Analytics data (only with your consent): aggregated usage events such as pages viewed, elements clicked and session duration, together with a pseudonymous device or session identifier.
3.2 Why and on what basis
| Purpose | Legal basis |
|---|---|
| Deliver the Website and keep it functioning | Legitimate interests — Art. 6(1)(f) |
| Protect the Website against attack, abuse, scraping and fraud | Legitimate interests — Art. 6(1)(f) |
| Store and honour your cookie choice | Legal obligation — Art. 6(1)(c), read with Art. 11.7a Dutch Telecommunications Act |
| Measure and improve how the Website is used | Consent — Art. 6(1)(a) |
3.3 The cookie banner as it is actually deployed
The banner currently presented on the Website offers two choices — “Accept all” and “Essential only” — and states that only essential cookies are used to make the site work, with optional analytics running only with your consent. “Essential only” is a full rejection of every non-essential category: choosing it places no analytics cookie and loads no analytics script.
Details of each cookie are in the Cookie Policy.
3.4 Server logs
We keep web-server and CDN logs for 30 days and security-incident records for 12 months, after which they are deleted or irreversibly aggregated.
4. Prospects, contact forms, demo bookings and sample articles
4.1 The four entry points on the Website
The Website offers four distinct ways to get in touch, and they collect different data.
| Entry point | What we collect |
|---|---|
| Contact form (“a real person reads every message”) | Name, e-mail address, your question |
| Demo booking | Handled by Cal.com: your name, e-mail address, chosen slot, time zone and any notes you add |
| Free sample-article request | Your name, work e-mail address, your company website, your company LinkedIn URL (optional), one or two sentences describing what you do, and up to eight topic keywords |
| Newsletter subscription | E-mail address, and the fact and time of your subscription |
The Website states that a reply to the contact form usually arrives within one business day, and that a sample Article arrives within approximately 24 hours. We hold ourselves to those statements.
4.2 Why and on what basis
- To answer your question, prepare a proposal, produce your sample Article and take steps at your request before entering into a contract — Art. 6(1)(b). The keywords and the description of your work are used to brief the News Master who curates your sample.
- To hold and follow up on a demo, and to maintain our business-development records — Art. 6(1)(f), our legitimate interest in developing our business, balanced against your interest in not receiving unwanted contact. You can object at any time (Section 11).
- To send you our own newsletter or product updates — Art. 6(1)(a) consent, or, where you are an existing business contact and the communication concerns similar products and services, the soft opt-in permitted by Art. 11.7 of the Dutch Telecommunications Act. Every message contains a working one-click unsubscribe link.
- The sample-request flow says your details are “only used to prepare and send your sample” and “No spam, ever.” If we also keep the enquiry in a business-development record for a further period and follow up commercially, that sentence is narrower than the reality. Either the page changes to “used to prepare your sample and to follow up about NewsIntel”, or the follow-up stops. A privacy statement made in microcopy binds us exactly as much as this page does.
- The newsletter opt-in sits inside the sample-request flow. Consent must be separate from the sample request, presented unticked, and recorded with its own timestamp — a subscriber must be able to get the sample without joining the list.
4.3 Retention
Enquiry, demo and sample records are kept for 24 months from last contact, or until you object or withdraw consent, whichever is earlier. Where an enquiry leads to a contract, the data becomes part of the customer record (Section 5). The sample Article we produce for you, and the keywords you gave us, are retained on the same period as a record of what we sent.
5. Customer users of the Service
This section describes data we process as controller in order to run the Service: accounts, security, billing and the audit trail. Content and recipient data processed on a customer’s behalf is covered in Section 8 and in the DPA.
5.1 Account and identity data
Name, work e-mail address, company, job title, preferred language, a securely hashed password, e-mail-verification codes and their expiry, session tokens, and — where the customer uses single sign-on — the identifiers supplied by the identity provider (for example Google or Microsoft).
Basis: performance of the contract with the customer — Art. 6(1)(b) — and our legitimate interest in operating a secure, accountable multi-tenant platform — Art. 6(1)(f).
5.2 Authorisation and tenancy data
Workspace and project memberships, roles and permissions (Workspace Owner, Workspace Member, Project Admin, Project Member for the knowledge module, and News Master or Viewer for the news module), the active workspace or project, and API keys issued to the customer’s project — stored hashed with a pepper and displayed once, at creation.
Basis: Art. 6(1)(b) and Art. 6(1)(f).
5.3 Usage, audit and operational data
- Editorial and application events: who performed which action on which object and when — including creation, editing, approval, rejection, publication, unpublication and deletion of Articles, changes to sources, keywords, quotas and policies, key creation and revocation, and administrative actions.
- Technical telemetry: request timestamps, IP address, endpoint, response status, latency, error traces.
- AI-processing records: model used, token counts, latency, and — where a request is logged — the input text and derived vector representations. Our logging pipeline redacts passwords, tokens, API keys, authorisation headers and e-mail addresses before storage.
Basis: Art. 6(1)(f) — security, abuse prevention, service quality, cost accounting, demonstrating compliance with our own source and editorial policy, and handling disputes. For part of this data an additional basis is Art. 6(1)(c), where retention is required to demonstrate compliance.
Retention: editorial and generation audit logs 24 months; application and error logs 90 days; AI-processing records 12 months.
5.4 Support data
When you submit a support request from within the application we receive the subject, description, the URL of the page you were on, the timestamp, your user and workspace identifiers, your e-mail address, and any attachments you add.
Basis: Art. 6(1)(b) and Art. 6(1)(f). Retention: 24 months after closure.
5.5 Billing and payment data
Company name, billing address, VAT identification number, contact person, subscription plan, Article-usage counts for overage billing, invoice history, payment status and mandate references.
Card and direct-debit details are collected and processed directly by Stripe as our payment-services provider; GSS does not receive or store full card numbers or bank credentials.
Basis: performance of the contract — Art. 6(1)(b) — and compliance with statutory accounting and tax obligations — Art. 6(1)(c).
Retention: invoices and supporting records are kept for seven years from the end of the relevant financial year, as required by Dutch tax law (Art. 52 Algemene wet inzake rijksbelastingen).
6. Newsletter recipients
There are two distinct situations, and the roles differ.
6.1 Our own newsletter (GSS as controller)
If you subscribe to communications from GSS about NewsIntel, we process your e-mail address, name (optional), subscription and unsubscribe timestamps, and delivery and interaction events.
Basis: consent — Art. 6(1)(a) — or the soft opt-in for existing business contacts under Art. 11.7 of the Dutch Telecommunications Act. Withdrawal is possible at any time via the unsubscribe link in every message or by writing to us. Retention: until withdrawal, plus 12 months for a suppression record so that we do not contact you again by mistake.
6.2 A customer’s newsletter (GSS as processor)
Our customers can build recipient lists inside the Service — by adding addresses manually, importing a CSV file, or connecting a subscription form on their own website to our public API using a server-side key scoped to newsletter subscription — and the Service then composes and sends a digest of published Articles to those recipients.
In that scenario the customer decides who is on the list, on what basis, and what is sent. The customer is the controller; GSS is the processor and acts only on the customer’s documented instructions under the DPA. If you received such a newsletter and want your data removed, use the one-click unsubscribe link in the e-mail, which takes effect immediately, or contact the sender directly. You may also contact us and we will forward your request to the relevant customer without undue delay.
We process for these mailings: recipient e-mail address, optional name, active/inactive status, subscription and unsubscription timestamps, the unsubscribe token, and technical send outcomes. Re-subscription of a previously unsubscribed address restores the record rather than creating a duplicate.
7. Individuals mentioned in Articles
The Service monitors a curated pool of third-party publications and data sources and generates Articles grounded in that source material. An Article may therefore mention identifiable individuals — most commonly people acting in a public, professional or corporate capacity, as reported in the underlying source.
7.1 How we limit this processing
Controls that are in place today:
- Curated sources only. Articles are generated from a pool of sources selected and managed by GSS under a documented source-selection and compliance policy, which includes verifying lawful access and honouring machine-readable text-and-data-mining reservations (opt-outs) under Art. 4 of Directive (EU) 2019/790. The allowlist of permitted domains is enforced at discovery and before a page is fetched, not merely recorded as configuration.
- Human editorial gate. Every Article is reviewed by a human editor (a “News Master”) and must be approved before it is delivered to a customer. No Article reaches a customer channel without that review, and publication is blocked by policy if approval has not been given.
- Editorial guidelines. Our guidelines restrict the unnecessary use of personal data relating to non-public individuals, and prohibit the generation of content in the special categories of Art. 9 GDPR or relating to criminal offences under Art. 10 GDPR about identified individuals.
- Immutable revisions. Generation, regeneration and manual edits create a new revision rather than overwriting published content, so the editorial history of an Article can be reconstructed.
- Cover images. Cover images are produced by a model that generates illustration rather than photorealistic imagery of people, which materially reduces the risk of an image appearing to depict a real person.
Controls we are building, and which are not yet live:
- Automated detection of references to real, identified persons, with a blocking or confirmation step before approval.
- Claim-level verification. Grounding is currently applied at the prompt level, by supplying the actual content of the sources to the model. A mechanism that ties each individual claim to a specific source passage, and blocks approval where a claim cannot be tied, is in development.
- Bias and toxicity screening with quarantine. Not yet implemented.
- Recorded image provenance (model, prompt, timestamp) as an auditable record rather than a property of the model choice. Partial.
7.2 Legal basis and your rights
We rely on our legitimate interests — Art. 6(1)(f) — in producing and supplying news and information content, read together with the freedom of expression and information guaranteed by Art. 11 of the Charter of Fundamental Rights of the European Union and given effect in Dutch law. We perform and document a balancing test.
If you believe an Article processes your personal data unlawfully, or contains a factual inaccuracy about you, contact us at privacy@newsintel.eu or info@newsintel.eu. We will:
- acknowledge your request without undue delay;
- assess it against a documented balancing of interests, and record the outcome;
- where the request is justified, remove the Article from our own systems, prevent redelivery, and instruct every customer to whom the Article was delivered to remove or anonymise it from all of their channels — including website archives and scheduled future mailings — within 72 hours, reduced to 24 hours in urgent cases such as a court or regulatory order or manifest unlawfulness;
- inform you of the outcome, in any event within one month of receipt, extendable by two further months for complex requests.
Note that e-mails already sent cannot be recalled. In that case the Article is removed from web-accessible newsletter archives and excluded from all future distribution.
7.3 AI-generated content and transparency
Articles are generated using artificial intelligence and reviewed by a human editor. Cover images are generated entirely by artificial intelligence; no third-party photographic material is used under the Basic Plan. We supply metadata, including authorship and origin indicators, that enables the publishing customer to apply the transparency labelling required under Regulation (EU) 2024/1689 (the AI Act). The customer applies that labelling on its own channels and publishes each Article under its own editorial responsibility.
We do not use customer content, customer documents or the personal data described in this policy to train or fine-tune our own or third-party AI models.
7.4 No automated decision-making about you
We do not take decisions about you that are based solely on automated processing and that produce legal effects concerning you or similarly significantly affect you, within the meaning of Art. 22 GDPR. The generation of an Article is not such a decision: it is always followed by human editorial review before delivery.
8. Roles: when we are controller, processor or joint controller
| Processing activity | GSS role | Customer role |
|---|---|---|
| Website, marketing, contact form, demo bookings, sample Articles | Controller | — |
| Customer accounts, security, audit logs, billing | Controller | — |
| Source monitoring, scraping, clustering and generation inside our own pipeline | Independent controller | — |
| Editorial approval of an Article containing personal data | Potentially joint controller (Art. 26 GDPR) | Potentially joint controller |
| Publication of a delivered Article on the customer’s channels | — | Controller |
| Newsletter recipient lists supplied or collected by the customer | Processor | Controller |
| Documents and sources the customer imports into the Service, including the knowledge module | Processor | Controller |
| Research of a customer’s own sources by our OSINT team (Pro) | Processor, on the customer’s instructions | Controller |
Where GSS and a customer jointly determine the purposes and means of a processing activity, the allocation of responsibilities is set out in the DPA, which prevails on this subject. The essence of that arrangement is made available to data subjects on request and is summarised in DPA Annex IV.
9. Recipients and sub-processors
We share personal data only where necessary, and only with parties bound by confidentiality and by a data-processing agreement or an equivalent legal instrument.
9.1 Categories of recipient
- Hosting, database and object storage: operated by us on our own infrastructure. No third-party hosting or content-delivery provider processes personal data for the Website or the Service.
- Payments: Stripe — subscription billing, direct debit and card payments, invoicing.
- E-mail delivery: TransIP — verification e-mails, notifications and newsletter sending.
- Scheduling: Cal.com — demo and appointment booking.
- Error monitoring and product analytics: Sentry (error and performance monitoring); Amplitude (product analytics in the Service, consent-gated); Google Analytics 4 on this Website (consent-gated via the cookie banner).
- AI model providers: OpenAI — text generation and cover-image generation.
- Search and discovery: DuckDuckGo — used to discover candidate source material.
- Customer-registered delivery targets: where a customer registers a Channel or other delivery target operated by a third party, Articles and the personal data they contain flow to that system on the customer’s instruction and under the customer’s own agreement with that provider.
- Professional advisers and authorities: accountants, auditors, lawyers, and competent authorities where we are legally required to disclose.
The current, itemised list of sub-processors, including each one’s role, processing location and transfer mechanism, is maintained at subprocessors.html and forms Annex III to the DPA. Customers can subscribe to change notifications there.
9.2 We do not sell personal data
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We show no third-party advertising on the Website or in the Service.
10. International transfers
Our application infrastructure is located in the European Union
Some of our sub-processors — in particular certain AI model providers, and our error-monitoring and analytics providers — process data on infrastructure located outside the EEA, including in the United States. Where that is the case, the transfer is made on one of the following bases:
- an adequacy decision of the European Commission under Art. 45 GDPR, including the EU–US Data Privacy Framework where the recipient is certified;
- the European Commission’s Standard Contractual Clauses under Art. 46(2)(c) GDPR, supplemented by a documented transfer impact assessment and additional technical and organisational measures (encryption in transit, access minimisation, and contractual challenge-and-notify commitments); or
- where applicable, a derogation under Art. 49 GDPR.
Where a customer is established outside the EEA, or where personal data originates in the United Kingdom or Switzerland, the corresponding transfer instrument applies — the UK International Data Transfer Addendum, or the Swiss addendum to the SCCs, as the case may be.
You may request a copy of the relevant safeguards, with commercially confidential terms redacted, by writing to privacy@newsintel.eu.
11. Your rights
Subject to the conditions and exceptions of the GDPR, you have the right to:
- access your personal data and receive a copy;
- rectify inaccurate data, and complete incomplete data;
- erase your data (“right to be forgotten”);
- restrict processing;
- data portability in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means;
- object to processing based on our legitimate interests, including profiling, and to object at any time to processing for direct-marketing purposes;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- not be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.
11.1 How to exercise them
Write to privacy@newsintel.eu. We respond within one month of receipt, extendable by up to two further months where the request is complex or numerous, in which case we tell you within the first month. We may ask for information reasonably necessary to verify your identity; we will not ask for more than is needed.
If your request concerns data we process as a processor on behalf of a customer — for example a newsletter list or imported documents — we will, without undue delay, refer you to that customer and forward your request to them. Neither party will unilaterally reject a request concerning an Article without consulting the other.
There is no charge for exercising your rights, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act, and will explain why.
11.2 Complaints
If you are unhappy with how we have handled your data, please tell us first so that we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority — in the Netherlands the Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl — or with the authority in your country of residence or workplace. You may also seek a judicial remedy.
12. Security
We apply technical and organisational measures appropriate to the risk.
In place
- encryption of data in transit using TLS, with HTTP redirected to HTTPS;
- role-based access control, membership-scoped authorisation, and enforcement of tenant scoping (workspace and project) in queries, endpoints and background jobs;
- password hashing with a salt and pepper; API keys stored hashed and displayed once at creation; production secrets held outside the source repository;
- centralised log sanitisation that redacts credentials, tokens, authorisation headers and e-mail addresses before logs are stored;
- input validation, output sanitisation and sanitised server-side Markdown rendering;
- rate limiting and scoped permissions on public API keys;
- least-privilege internal access and logging of administrative actions;
- error and performance monitoring;
- code review, automated tests and dependency monitoring.
No system can be guaranteed absolutely secure. If a personal-data breach occurs, we will notify the Autoriteit Persoonsgegevens within 72 hours where the breach is likely to result in a risk to individuals, notify affected individuals where the risk is high, and notify affected customers without undue delay in accordance with the DPA.
13. Retention — consolidated table
| Data | Retention | Basis for the period |
|---|---|---|
| Web server and CDN logs | Security necessity | |
| Security-incident records | Investigation and defence of claims | |
| Cookie consent records | , or until changed | Demonstrating consent |
| Analytics data (consented) | Measurement horizon | |
| Contact-form enquiries, demo bookings and sample requests | Business-development interest | |
| Marketing subscription (our own list) | Until withdrawal + suppression | Consent; suppression duty |
| Customer account data | Term of the agreement + | Contract; wind-down |
| Editorial and generation audit logs | Accountability; dispute resolution | |
| Application and error logs | Operations | |
| AI-processing records | Cost accounting; quality | |
| Scraped source records | from scraping | Pipeline necessity |
| Knowledge-module documents and embeddings (Pro) | Per the customer’s instruction and the DPA | Contract; customer instruction |
| Support tickets | Support history | |
| Invoices and accounting records | 7 years from end of financial year | Art. 52 AWR (Dutch tax law) |
| Content and Articles | As set out in the DPA and the customer’s project configuration | Contract; customer instruction |
| Records needed for legal claims | Until the claim is time-barred (in principle 5 years, Art. 3:307 DCC) | Establishment and defence of legal claims |
Where a shorter period is agreed with a customer in the DPA, that period prevails for the data processed on that customer’s behalf. Backups follow their own rotation cycle of 30 days, after which deleted data disappears from backups as well.
Every figure in this table is a target until the retention and purge mechanism referred to in Section 5.3 is implemented and verified.
14. Children
The Service is offered exclusively to business customers and is not directed at children. We do not knowingly collect personal data of persons under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to this policy and change log
We may amend this Privacy Policy to reflect changes in the Service, our sub-processors or the law. The current version and its effective date are always shown at the top of this page. Where a change materially affects how we process personal data relating to you, we will notify you — by e-mail to account holders, or by a prominent notice on the Website — at least 30 days before it takes effect. Previous versions are available on request.