Privacy
Policy

How Elioud handles your data, in plain language.

Legal

Last updated: 7 May 2026

This Privacy Policy explains what personal data we collect when you use the Elioud website, why we collect it, who we share it with, and the rights you have over it. We have kept the language plain on purpose so you do not need a lawyer to read it.

Company details

The data controller for personal data collected through this site is:

  • Elioud B.V.
  • Pieter Braaijweg 105
  • 1114 AJ Amsterdam
  • The Netherlands
  • KvK: 73942448
  • VAT (BTW): NL859718542B01

Who is responsible for your data

Elioud B.V. is part of the Spades Holding group, based in Amsterdam, the Netherlands. Spades Holding owns and runs the data systems used across the group and supervises strict compliance with Dutch and European law, including the GDPR. The data controller for personal data collected through this site is Elioud B.V., acting under that group-wide oversight. When we say "we", "us" or "our", we mean Elioud B.V. within the Spades Holding group. When we say "you", we mean the person visiting the site, subscribing to the newsletter, or contacting us. For any question about your personal data, reach us through the contact page.

What we collect and why

Newsletter signup. When you subscribe to our newsletter we collect your email address and, optionally, your first and last name. We use this only to send you the newsletter, occasional product updates, and related communications you have signed up for. The legal basis is your consent, which you can withdraw at any time.

Contact form. When you send us a message through the contact page we receive your name, email address, the contents of your message, and, if you choose to share it, the company you work for. We use this to read your enquiry and reply to it. The legal basis is our legitimate interest in responding to people who get in touch with us, and, where relevant, taking steps at your request before entering into a contract.

Technical logs. Like most websites, our hosting provider keeps short-lived technical logs (such as IP address and request information) to keep the site running and secure. We do not use these logs to build profiles of visitors.

Private dinner registrations. When an invited guest requests a seat at one of our private dinners, we collect their name, email address, selected dinner and submission time. We use these details only to review the request, manage the invitation and contact the guest about that dinner. The legal basis is our legitimate interest in organizing the event and responding to the guest's request.

How long we keep it

We keep newsletter details for as long as you remain subscribed. If you unsubscribe, we remove your address from active mailing lists and retain only what we need to honour your unsubscribe request. We keep contact-form messages for as long as needed to handle your enquiry and any follow-up conversation, and then archive or delete them. Technical logs are kept for a short period and then rotated out.

We keep private dinner registration details until the event and any necessary follow-up are complete, then delete or anonymize them unless a longer period is required for a legal obligation.

Subprocessors

We use a small number of trusted providers to run the site and our communications. These act as processors on our behalf, are bound by data-processing agreements under GDPR Art. 28, and are selected because they comply with applicable EU data-protection rules:

  • Brevo; newsletter delivery and storage of your subscription details so we can send the emails you signed up for, and delivery of internal notifications about private dinner registration requests.
  • Our hosting and platform provider; serves the website, runs the application and database, and keeps the short-lived technical logs described above.
  • Our payments provider; processes payments and handles related fraud, billing and tax compliance for paid plans.
  • Our scheduling provider; runs the booking flow when you schedule a call with us.
  • Other tools; additional processors that comply with applicable regulations may be used from time to time (for example, future analytics) and will be reflected here.

We do not sell your data and we do not share it with third parties for their own marketing.

Cookies and tracking

This site does not set marketing or advertising cookies and does not use cross-site tracking. We may use a small number of strictly necessary cookies to keep the site working (for example, to remember a form submission). If we ever add analytics or other non-essential cookies in the future, we will update this page and ask for your consent first where required.

Your rights under the GDPR

Because we operate from the European Union, your personal data is protected by the General Data Protection Regulation. You have the right to:

  • access the personal data we hold about you;
  • have inaccurate or incomplete data corrected;
  • have your data deleted when we no longer need it;
  • receive your data in a portable format, or have it sent to another provider where technically possible;
  • object to processing based on our legitimate interest;
  • withdraw your consent at any time (this does not affect processing we did before you withdrew it);
  • lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), if you believe we have not handled your data properly.

To exercise any of these rights, send us a message through the contact page. You can also unsubscribe from the newsletter at any time using the link at the bottom of every email we send.

Changes to this policy

We may update this Privacy Policy from time to time, for example when we add new features or change a provider. The "last updated" date at the top of this page will always reflect the most recent version. For the wider terms that govern your use of the site, see our Terms of Use.