Draft — requires legal review before production use
LEGAL / 28 August 2026
Privacy Notice
This draft explains how NLTop intends to handle personal data connected with website enquiries, business contacts and client CRM operations. It must be reviewed against the confirmed legal entity, systems and processing activities before production reliance.
Controller and contracting-party details are incomplete. The confirmed legal entity, business address, registration details, governing law and dispute forum must be added before these terms are relied on.
1. Who is responsible
The intended controller is TODO — confirm legal entity name, trading as NLTOP, at TODO — confirm business address. Privacy questions and rights requests can currently be directed to dmitry@nltopconstruction.com.
2. Data covered by this notice
Depending on the interaction and agreed service, NLTop may process:
- website enquiry details, including name, company, work email, website, country and message content;
- commercial-fit details such as service scope, target market, indicative project value, contribution-margin range, capacity window, references and target-buyer information;
- business contact details such as name, role, employer, professional contact channels and location;
- account research, source references, relevance signals and contact-permission records;
- client CRM data, including activities, replies, opportunity stages, proposals, outcomes and next actions;
- service administration data such as instructions, meeting notes, billing records and support correspondence;
- limited technical data needed to operate and secure the website and its hosting.
3. Sources of data
Data may come directly from the person or client, from company websites and other business-facing public sources, from event or referral introductions, from correspondence, or from systems a client authorises NLTop to use. Sources and permission or objection status should be recorded where relevant.
4. Purposes and legal bases
Where NLTop relies on legitimate interests, the intended approach is to assess necessity, reasonable expectations and impact on the individual, and to use the least intrusive suitable method. Consent will be used where applicable law specifically requires it. Consent can be withdrawn without affecting prior lawful processing.
5. Client CRM roles
The contractual role depends on the activity. A client will normally determine why its own CRM and pipeline data is processed, while NLTop operates that data under the agreed service instructions. The contract should document the controller/processor roles, security measures, instructions, deletion or return, and any approved subprocessors.
6. Service providers and recipients
NLTop may use hosting, email, CRM, productivity, research, communications and workflow software providers. Only providers needed for the agreed service should receive relevant data, subject to appropriate contractual and security safeguards. A current provider list must be confirmed before production publication. Data may also be disclosed where required by law or to establish, exercise or defend legal claims.
7. International transfers
Some software providers may process data outside the European Economic Area. Where this occurs, NLTop intends to use a lawful transfer mechanism, assess the transfer and apply supplementary safeguards where required. The actual locations, mechanisms and providers must be recorded in the production version of this notice.
8. Retention
Data should be kept only for as long as needed for the stated purpose, the client instruction, an active business relationship, legal record-keeping or the handling of disputes. Enquiries that do not progress, inactive business contacts, opt-out records and client CRM exports require documented retention periods. Confirmed periods must replace this principle before production reliance.
9. Individual rights and objections
Subject to applicable law, individuals may have rights to information, access, correction, deletion, restriction, portability and objection, and rights concerning solely automated decisions. Requests can be sent to dmitry@nltopconstruction.com. Identity may need to be verified before a request is completed.
A person may object at any time to processing for direct marketing. That objection will be respected and a minimal suppression record may be retained so the person is not contacted again through the same process.
10. Complaints
Individuals may complain to the data-protection supervisory authority in the country where they live or work, or where they believe an infringement occurred. The competent lead authority cannot be confirmed until NLTop's legal establishment is verified.