Privacy policy

Version: 2026-01

This is a translation of the Dutch privacy policy. In the event of any difference between the two, the Dutch version is binding.

This Privacy Policy has been drawn up in accordance with the General Data Protection Regulation (GDPR) and describes how Fruitful processes personal data. Fruitful acts primarily as a Processor on behalf of its Clients, and as a Controller in respect of its own company data. This Policy sets out, for the Data Subject, the purposes, the legal bases and the relevant safeguards, including the principles of data minimisation and Privacy by Design.

1. Controller

Fruitful acts as:

  • Processor: on behalf of its clients (primarily).

  • Controller: in respect of its own company data.

2. Categories of personal data

The categories of personal data processed by Fruitful include, but are not limited to:

  • Identification data (such as name and email address)

  • Account data

  • Organisation and role data

  • Usage and interaction data

  • Analysis and progress data

  • Any feedback provided

3. Purposes of processing

Personal data is processed for the following explicit purposes:

  • Delivering and maintaining the platform.

  • Analysing collaboration and team dynamics.

  • Providing reports to the Client.

  • Product improvement, where data is processed in anonymised form.

  • Security and monitoring of systems.

4. Legal basis for processing

Processing takes place on the following legal bases, in accordance with the GDPR:

  • Necessity for the performance of a contract.

  • The pursuit of a legitimate interest.

  • Compliance with legal obligations.

  • Explicit consent of the data subject, where required.

5. Personal data of employees

  • This data is processed solely on the instructions of the employer (the Client).

  • Fruitful does not process this data for its own HR decision making.

  • Insights and results are presented at aggregated team level wherever the functionality allows.

6. Data minimisation and Privacy by Design

  • Only strictly necessary data is processed.

  • Privacy safeguards are built into the product by default (Privacy by Design).

7. Retention periods

Fruitful applies the following retention periods:

  • Account data: for as long as the account is active, and up to 12 months after termination.

  • Usage and log data: up to 30 days, unless required for security purposes.

  • Analysis data: up to 12 months, after which it is anonymised.

  • After these periods, data is deleted or anonymised.

8. Use of sub-processors

Fruitful uses sub-processors, including hosting providers and analytics tools. A full list is available on request or included in the Data Processing Agreement (DPA).

9. International transfers

Where data is transferred outside the EEA, this takes place only with appropriate safeguards such as Standard Contractual Clauses, with a preference for hosting within the EU.

10. Security measures

Fruitful implements appropriate technical and organisational measures, including:

  • Encryption of data.

  • Strict access control.

  • Logging and periodic monitoring of systems.

11. Rights of data subjects

Data subjects have the right to:

  • Access, rectification and erasure (the right to be forgotten).

  • Restriction of processing and the right to object.

  • Requests can be directed to the employer or to privacy@meetfruitful.com.

12. Data breach notification

  • Data breaches are reported to the supervisory authority without undue delay, and within 72 hours at the latest.

  • Where a breach concerns client data, the Client is informed without delay.

13. Artificial intelligence and profiling

  • No automated individual decision making with legal consequences takes place.

  • AI output is advisory in nature only.

  • Profiling is not applied outside the stated purposes.

14. Contact

For privacy questions: privacy@meetfruitful.com

Fruitful B.V., Luxemburgstraat 91, 1363 BK Almere, the Netherlands. Chamber of Commerce: 90010485