Your Data Protection Rights

Last updated: March 2026

At Tatoma B.V., we respect your privacy and are committed to protecting your personal data. Under the General Data Protection Regulation (GDPR), you have specific rights regarding the personal data we hold about you.

This page explains your rights and how to exercise them.


Your Rights Under GDPR

Right to Access

You have the right to request a copy of the personal data we hold about you. This includes information about:

  • What data we collect
  • How we use it
  • Who we share it with
  • How long we retain it

Right to Rectification

You have the right to request correction of any inaccurate personal data we hold about you. You also have the right to have incomplete data completed.

Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal data in certain circumstances, including when:

  • The data is no longer necessary for its original purpose
  • You withdraw consent (where consent was the legal basis)
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

Self-service option: You can delete your account directly from your Manage Data page using the "Delete My Account" feature. Account deletion includes a 14-day grace period during which you can cancel the request.

Note: Some data may be retained for legal or compliance purposes even after an erasure request.

Right to Restrict Processing

You have the right to request that we limit how we use your data in certain circumstances, such as:

  • While we verify the accuracy of your data
  • If processing is unlawful but you prefer restriction over erasure
  • If we no longer need the data but you need it for legal claims

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format. You can also request that we transfer this data directly to another organization where technically feasible.

Self-service option: You can export all your data directly from your Manage Data page using the "Export My Data" feature. This generates a downloadable ZIP file containing your personal data in structured JSON format, organised by category.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests. This includes:

  • Direct marketing (you can opt out at any time)
  • Profiling related to direct marketing
  • Processing for research or statistical purposes

Right to Withdraw Consent

Where we process your data based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects. You can request human intervention in such decisions.


How to Exercise Your Rights

Self-Service Options

You can exercise the following rights directly from your account, without needing to contact us:

  • Delete My Account (Right to Erasure): Visit your Manage Data page to request account deletion. Your request includes a 14-day grace period during which you can cancel it.
  • Export My Data (Right to Data Portability): Visit your Manage Data page to download all your personal data as a structured ZIP file.

For General Requests

For all other rights (access, rectification, restriction, objection, consent withdrawal), contact our Data Protection team:

Email: gdpr@tatoma.eu

Postal Address: Tatoma B.V. Willemstraat 1 5611 HA, Eindhoven The Netherlands

For Manual Erasure Requests

If you prefer not to use the self-service option, or need to request erasure of data not covered by the "Delete My Account" feature, you can submit our Data Erasure Request Form:

Download Data Erasure Request Form (PDF)

Send the completed form to gdpr@tatoma.eu.


What to Expect

Response Time

We will respond to your request within one month of receipt. If your request is complex or we receive many requests, we may extend this period by up to two additional months. We will inform you of any extension within the first month.

Identity Verification

To protect your privacy, we may need to verify your identity before processing your request. This helps ensure that personal data is not disclosed to unauthorized persons.

No Fee (Usually)

You will not have to pay a fee to exercise your rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. In such cases, we may also refuse to comply with your request.

What We Need From You

To help us process your request efficiently, please provide:

  • Your full name
  • Email address associated with your account
  • Organization name (if applicable)
  • Specific details about your request
  • Any information that helps us locate your data

Questions or Complaints

If you have questions about your data protection rights, please contact us at gdpr@tatoma.eu.

If you are not satisfied with how we handle your request, you have the right to lodge a complaint with a supervisory authority:

For the Netherlands: Autoriteit Persoonsgegevens (Dutch Data Protection Authority) Website: https://autoriteitpersoonsgegevens.nl

For other EU/EEA countries, you may contact your local data protection authority.


Related Documents