Privacy Notice

Last updated: 7 September 2026

This Privacy Notice explains how FRISS | fraud, risk & compliance (“FRISS,” “we,” “us”) processes personal data collected through our website, marketing activities, and business communications. It applies to visitors to www.friss.com, prospective and existing business contacts, newsletter subscribers, and event attendees.

This notice does not cover personal data that FRISS processes on behalf of its customers as a data processor when providing its fraud, risk & compliance software (for example, data submitted by a customer’s own policyholders or claimants). That processing is governed by the data processing agreement between FRISS and the relevant customer.

For information about the cookies and similar technologies used on our website, see our separate Cookie Policy.

1. Who is responsible for your data

The data controller for the personal data described in this notice is:

FRISS Fraudebestrijding B.V.
Orteliuslaan 15, 3528 BA Utrecht, The Netherlands

2. How to contact us

For any question about this notice or about how we handle your personal data, or to exercise any of the rights described in Section 9, you can contact our Data Protection Officer:

  • Email: privacy@friss.com

  • Post: FRISS | fraud, risk & compliance, Attn. Data Protection Officer, Orteliuslaan 15, 3528 BA Utrecht, The Netherlands

3. Personal data we collect

Depending on how you interact with us, we may collect:

  • Contact details you provide, such as name, job title, business email address, company, country, and phone number (for example, through contact forms, demo requests, content downloads, event registrations, or newsletter sign-ups).

  • Communications data, including the content of messages you send us and records of our correspondence with you.

  • Website usage data, such as pages viewed, referring pages, approximate location derived from your IP address, and device or browser information. Details of the specific technologies used to collect this data, and your choices regarding them, are set out in our Cookie Policy.

We collect this data directly from you, and, for usage data, automatically as you interact with our website.

4. Why we use your data, and our legal basis

PurposeLegal basis (Art. 6 GDPR)
Responding to inquiries, providing requested information, and administering demo requestsSteps taken at your request prior to entering into a contract / performance of a contract
Managing our business relationship with existing customers and partnersPerformance of a contract
Sending marketing communications (newsletters, product updates, event invitations)Consent, or legitimate interest where permitted by applicable law for existing business contacts
Operating, securing, and improving our websiteLegitimate interest
Complying with legal and regulatory obligationsLegal obligation

Legitimate interests relied on: where we rely on legitimate interest, this is our interest in maintaining business relationships, keeping our website secure and functioning correctly, and understanding how our website is used so that we can improve it. Where required by law, we obtain your consent instead of, or in addition to, relying on legitimate interest — for instance for non-essential cookies and certain direct marketing.

5. Who we share your data with

We share personal data only where necessary, with:

  • Service providers that support our IT infrastructure, customer relationship management, marketing, and website hosting and analytics, acting on our instructions.

  • Professional advisers (such as legal or audit advisers), where necessary.

  • Public authorities, where required by law.

We do not sell personal data. A list of the specific service providers we currently use for website and marketing purposes is available on request, or set out in our Cookie Policy where they relate to cookies.

6. International data transfers

Where we or our service providers transfer personal data outside the European Economic Area (EEA), we ensure an adequate level of protection through recognized safeguards, such as the European Commission’s Standard Contractual Clauses. You can request further information about these safeguards using the contact details in Section 2.

7. How long we keep your data

We keep personal data only for as long as necessary for the purposes described in this notice. As a general rule, this is no longer than three years, or for the duration of our business relationship with you, whichever is shorter, unless a longer period is required to comply with a legal obligation or to establish, exercise, or defend legal claims.

8. Automated decision-making

We do not use automated decision-making or profiling, based on the personal data described in this notice, that produces legal or similarly significant effects on you.

9. Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you;

  • Rectify inaccurate or incomplete data;

  • Erase your data in certain circumstances;

  • Restrict our processing of your data in certain circumstances;

  • Object to processing based on legitimate interest, including for direct marketing;

  • Port your data to another provider, where technically feasible; and

  • Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, contact us using the details in Section 2. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority, or with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

10. Security

We maintain appropriate technical and organizational measures to protect personal data, consistent with our ISO/IEC 27001 certification.

11. Changes to this notice

We may update this notice from time to time. We will post the updated version on this page with a revised “last updated” date.