// Privacy
Privacy Policy
Last updated · July 2026
Who we are
Division 9 (“Division 9”, “we”, “us”) builds and hands over automation systems that run inside our clients’ own infrastructure. We operate from the Netherlands and act in line with the EU General Data Protection Regulation (GDPR). For any question about this policy or your data, contact us at privacy@division9.agency [confirm address], or by post at [company legal name, KvK number, address].
What this policy covers
This policy explains how we handle personal data in two situations: people who visit this website or contact us, and clients we build systems for. These are deliberately different, because of how our builds are architected.
Website visitors and enquiries
When you submit the build-plan form or otherwise contact us, we process the details you provide — such as your name, email, company and message — to respond to you and to plan a possible engagement. The legal basis is our legitimate interest in answering enquiries and taking steps toward a contract at your request. We keep this information only as long as needed for that purpose and our normal business administration.
This site uses [essential cookies only / privacy-friendly analytics — confirm]. See our Cookie Policy for details.
Client and engagement data
A Division 9 build runs inside your own cloud account and connects to your own tools. Your customer records, orders, tickets and similar data stay in your systems, in the region you choose. They do not move into Division 9 infrastructure, because there is no Division 9 infrastructure in your build. Where we act as a processor for personal data during a build, we sign a Data Processing Agreement per engagement that sets out scope, purpose and safeguards.
The information Division 9 itself holds about a client is limited to your contact details and the build documentation.
Who else is involved
Our builds rely on a short list of providers: your own cloud account (AWS or GCP) for hosting and storage; the Anthropic API for model inference, under commercial terms that exclude training on inputs and outputs; and GitHub, in your organisation, for code. Your existing tools are connected with scoped credentials you issue. No additional processor holds your customer records.
International transfers
For EU clients, builds are architected to keep customer data in EU regions of your cloud account. Where any transfer outside the EEA occurs through a provider, it is covered by that provider’s safeguards (such as Standard Contractual Clauses).
Your rights
Under the GDPR you have the right to access, correct, delete, restrict or object to the processing of your personal data, and the right to data portability. To exercise any of these, contact us at the address above. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Security
How we protect the systems we build is part of every installation: scoped access, full logging, and reversibility.
Changes
We may update this policy. The date at the top reflects the most recent revision.