Privacy policy
Version: 2026-01
This is a translation of the Dutch privacy policy. In the event of any difference between the two, the Dutch version is binding.
This Privacy Policy has been drawn up in accordance with the General Data Protection Regulation (GDPR) and describes how Fruitful processes personal data. Fruitful acts primarily as a Processor on behalf of its Clients, and as a Controller in respect of its own company data. This Policy sets out, for the Data Subject, the purposes, the legal bases and the relevant safeguards, including the principles of data minimisation and Privacy by Design.
1. Controller
Fruitful acts as:
Processor: on behalf of its clients (primarily).
Controller: in respect of its own company data.
2. Categories of personal data
The categories of personal data processed by Fruitful include, but are not limited to:
Identification data (such as name and email address)
Account data
Organisation and role data
Usage and interaction data
Analysis and progress data
Any feedback provided
3. Purposes of processing
Personal data is processed for the following explicit purposes:
Delivering and maintaining the platform.
Analysing collaboration and team dynamics.
Providing reports to the Client.
Product improvement, where data is processed in anonymised form.
Security and monitoring of systems.
4. Legal basis for processing
Processing takes place on the following legal bases, in accordance with the GDPR:
Necessity for the performance of a contract.
The pursuit of a legitimate interest.
Compliance with legal obligations.
Explicit consent of the data subject, where required.
5. Personal data of employees
This data is processed solely on the instructions of the employer (the Client).
Fruitful does not process this data for its own HR decision making.
Insights and results are presented at aggregated team level wherever the functionality allows.
6. Data minimisation and Privacy by Design
Only strictly necessary data is processed.
Privacy safeguards are built into the product by default (Privacy by Design).
7. Retention periods
Fruitful applies the following retention periods:
Account data: for as long as the account is active, and up to 12 months after termination.
Usage and log data: up to 30 days, unless required for security purposes.
Analysis data: up to 12 months, after which it is anonymised.
After these periods, data is deleted or anonymised.
8. Use of sub-processors
Fruitful uses sub-processors, including hosting providers and analytics tools. A full list is available on request or included in the Data Processing Agreement (DPA).
9. International transfers
Where data is transferred outside the EEA, this takes place only with appropriate safeguards such as Standard Contractual Clauses, with a preference for hosting within the EU.
10. Security measures
Fruitful implements appropriate technical and organisational measures, including:
Encryption of data.
Strict access control.
Logging and periodic monitoring of systems.
11. Rights of data subjects
Data subjects have the right to:
Access, rectification and erasure (the right to be forgotten).
Restriction of processing and the right to object.
Requests can be directed to the employer or to privacy@meetfruitful.com.
12. Data breach notification
Data breaches are reported to the supervisory authority without undue delay, and within 72 hours at the latest.
Where a breach concerns client data, the Client is informed without delay.
13. Artificial intelligence and profiling
No automated individual decision making with legal consequences takes place.
AI output is advisory in nature only.
Profiling is not applied outside the stated purposes.
14. Contact
For privacy questions: privacy@meetfruitful.com
Fruitful B.V., Luxemburgstraat 91, 1363 BK Almere, the Netherlands. Chamber of Commerce: 90010485