Last updated: 26 September 2026
This policy explains what happens to personal data on coworkings.nl: what we collect, why, who else sees it, how long we keep it, and what you can ask us to do about it. It covers the website at coworkings.nl and the enquiry forms on it. The rules we follow are the General Data Protection Regulation (Regulation (EU) 2016/679, in Dutch the Algemene verordening gegevensbescherming or AVG) and the Dutch implementing act, the Uitvoeringswet AVG.
coworkings.nl is a catalogue of flexible workspace in the Netherlands: coworking space, serviced offices, virtual offices and registered business addresses in Amsterdam and other Dutch cities. There are no accounts on this site, no sign-in and no personal area, so there is nothing to register for and no password for us to hold. The service is free for tenants, and we are not the operator, landlord or owner of any building listed.
We have written this in plain language rather than legal language. It is meant to be read, not filed.
Who is responsible for your data
The controller for this site is Fiato Trade Ltd. — "we", "us" and "our" throughout this policy.
- Country of registration: Saint Vincent and the Grenadines
- Company number: 25565 BC 2019
- Registered office: First Floor, St.Vincent Bank Ltd, James Street, Kingstown, Saint Vincent and the Grenadines
- Contact address in the Netherlands: Rokin 92-96, 1012 KX Amsterdam
- Telephone: +31 6 35247561
- E-mail for any privacy question or rights request: info@coworkings.nl
No Data Protection Officer has been appointed for this site. Privacy questions are handled through the e-mail address above. You are welcome to write to us first, but you may complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority, at any time, and you do not need to contact us before doing so.
What we collect
Information you type into a form
The site has an enquiry form, a building-page form and pop-up forms that help you shortlist space. They ask for:
- your name;
- your company, if you give one;
- your e-mail address;
- your phone number;
- the message you write.
Some forms ask for a little more, because they are meant to narrow a search rather than open a conversation: the type of space you are after, your budget, the size of your team and a preferred viewing date. In those forms every field except the company name is required, so that an enquiry arrives complete enough to answer without a round of clarifying questions.
Each submission also carries a small amount of context so a reply makes sense: the city and the address of the page you sent it from.
There is one more field you will never see — a hidden anti-bot trap ("honeypot"). A real visitor never fills it in, because a browser does not display it. If it arrives filled in, the submission is treated as automated and discarded without being delivered anywhere. We ask for a name and at least one way of replying — an e-mail address or a phone number; a submission without those is not accepted, because there would be no way to answer it.
You decide what goes in the message box. Please keep sensitive details out of it — bank or card numbers, health information, identity document numbers. None of that is needed to answer a question about office space, and we never ask for it.
Technical information handled by our hosting provider
The site is a static build served through Cloudflare, and the code that receives your enquiry runs on Cloudflare as well. No website can reach your browser without your IP address, and Cloudflare also sees your browser's user-agent string and the country your request comes from. It uses this to route traffic, cache pages and filter attacks, under its own logging rules.
We do not run our own web server for this domain and we do not keep our own visitor logs.
Your IP address is also used, at the moment you submit a form, to count how many enquiries have come from that address recently — see how your enquiry reaches us. It is used for that count and nothing else; we do not store the contents of your enquiry against it, and we do not build any profile from it.
What stays in your browser
The site sets no cookies of its own — none for sessions, none that identify you. Cloudflare may set its own technical cookies (such as __cf_bm and cf_clearance) for security and network delivery; those are set by Cloudflare, not by us. The analytics counter described in the next section sets cookies of its own once it loads.
The site does use two kinds of browser storage on your device, and they have very different lifespans.
localStorage — stays on your device until you clear your site data:
rot_favs— the buildings you have marked as favourites;rot_cookie_analytics— your choice in the Cookie Settings panel;rot_bridge_off— that you dismissed the language hint.
sessionStorage — erased as soon as you close the tab:
- pop-up timing keys (
promoShownAt,bdPromoShownAt,cwPromoShownAt,mcPromoShownAt,brandPromoShownAt,rotAnyPopupAt,rotPromoClosed,rotBdClosed,rotCwClosed,rotMcClosed) — so the same window does not keep reappearing during your visit.
All of this lives in your browser. It is written and read by the page's own code on your device, and it is never sent to our server or to anyone else. Clearing your site data removes it. There is more detail in our Cookie Policy.
Analytics: Yandex.Metrica
The site carries one analytics counter, Yandex.Metrica, with its session-replay feature (Webvisor) and click map switched on. It measures which pages are visited, where visitors come from, and how they move around a page — scrolling, clicks and mouse movement. To do that it sets its own cookies in your browser and sends the measurements to Yandex, which processes them on its own infrastructure, including outside the European Economic Area.
The counter is loaded about a second and a half after the page finishes loading, or at your first touch, scroll, key press or mouse movement, whichever comes first — unless you have switched analytics off in the Cookie Settings panel in the footer. When the switch is off, the counter's script is not requested at all and nothing is sent to Yandex. Your choice is recorded in rot_cookie_analytics and is read again on every page. Today the switch stands in the "on" position until you change it. The Cookie Policy lists the cookies the counter sets.
Google Analytics is not loaded on this site. The pages contain a prepared but disabled Google Analytics block; if it is ever switched on, it will follow the same switch in Cookie Settings, and we will update this policy and the Cookie Policy first.
Why we use your data, and our legal basis
The GDPR requires a legal basis for every purpose. Ours are set out below.
| What we do | Data used | Legal basis |
|---|---|---|
| Reply to your enquiry and help you find suitable space | Form fields and page context | Article 6(1)(f) GDPR — our legitimate interest, and yours, in answering an enquiry you chose to send us. We are not a party to any agreement you may enter into for a space, so we do not rely on Article 6(1)(b) |
| Pass your enquiry to the operator or owner of the building you asked about, so they can confirm availability and price | Form fields and page context | Article 6(1)(f) GDPR — legitimate interests: yours in getting a real quote, theirs in receiving the enquiry. This is the point of sending the form |
| Deliver the enquiry to the two channels we read — a Telegram chat and an e-mail mailbox — and tell you honestly if neither accepted it | Form fields and page context | Article 6(1)(f) GDPR — legitimate interest in not losing enquiries people have taken the trouble to send |
| Filter automated and abusive submissions | The hidden honeypot field, the web address the form was submitted from, and your IP address for a short-term rate count | Article 6(1)(f) GDPR — legitimate interest in keeping the enquiry channel usable and preventing our form from being abused |
| Keep the site online, fast and protected from attack | IP address, user-agent, country (through Cloudflare) | Article 6(1)(f) GDPR — legitimate interest in security and availability |
| Display the pages: fonts, building photographs, and the map when you interact with it | Your IP address, your browser's user-agent string and the address of the page requesting the file become visible to those providers | Article 6(1)(f) GDPR — legitimate interest in delivering a working website |
| Measure how the site is used (Yandex.Metrica) | Pages visited, referrer, device and browser data, page interaction; the counter's cookies | Consent — Article 6(1)(a) GDPR together with article 11.7a of the Dutch Telecommunicatiewet. You give or withhold it in Cookie Settings, and you can change it at any time |
Where we rely on legitimate interests, we have weighed what we want to do against your privacy, and limited ourselves to what an enquiry actually requires. You can object to any of it — see your rights below, or simply write to info@coworkings.nl.
How your enquiry actually reaches us
This is the part most privacy policies leave vague, so here it is in full.
One route, on this domain
When you submit a form, your browser sends the contents to /api/lead on coworkings.nl — an address on this same site. Nothing is posted to another website, and no mailbox address is written into the pages of this site. The request is handled by our own code running on Cloudflare, the provider that hosts the site.
From there the enquiry goes to two places, both belonging to Fiato Trade Ltd.:
- a Telegram chat that our managers monitor, delivered through the Telegram Bot API;
- an e-mail mailbox, sent by Cloudflare's own e-mail service from
leads@coworkings.nlto a single verified company address. There is no third-party mailing or forwarding service in this path: the message is handed to a confirmed destination address inside Cloudflare's infrastructure, and the sending configuration is locked to that one recipient, so the form cannot be made to send mail anywhere else.
We wait for both channels before answering you. If at least one accepted the enquiry, you are told it was sent. If neither did, you are told that it did not go through, with an invitation to try again or write to info@coworkings.nl — you will not be shown a false "sent" for an enquiry that went nowhere.
There is no third-party fallback
No form-forwarding service and no mailing platform is involved in delivering your enquiry, and enquiries are not routed through any other website of ours. The only parties that see the contents of your enquiry are set out in the table below.
What we do to stop the form being abused
All of this happens without ever putting a puzzle or a CAPTCHA in front of you:
- the hidden honeypot field described above — if it is filled in, nothing is delivered;
- submissions are accepted only when they come from a page on coworkings.nl itself, so the form cannot be posted from someone else's site;
- a rate limit of six submissions per minute from one IP address. Go over it and you are told plainly to wait a minute and try again — the enquiry is not quietly dropped while you are shown a success message;
- a size limit on what a submission may contain, so an oversized payload is rejected rather than processed;
- technical fields of the kind used to redirect mail —
_cc,_bcc,_replytoand similar — are stripped and ignored, so the form cannot be turned into a relay for someone else's e-mail.
If you would rather not use the forms at all, write to info@coworkings.nl or call +31 6 35247561.
Who else receives your data
| Recipient | What they receive | Why |
|---|---|---|
| Cloudflare, Inc. (US) | Every request to the site: IP address, user-agent, country. Also the contents of your enquiry, both as the platform running the code that receives it and as the service that sends the e-mail copy | Hosting, content delivery, protection against attacks, and delivery of the enquiry e-mail to our verified mailbox |
| Telegram (Telegram Messenger Inc.) | The contents of your enquiry, as a chat message | How a manager sees new enquiries |
| The operator or owner of the building you asked about | Your contact details and what you asked for | Only they can confirm availability, terms and price for their building. We pass your details to that operator only, and only where your enquiry concerns their building — never to operators you did not ask about |
| Yandex (Yandex.Metrica) | Pages visited, referrer, device and browser data, how you move around a page, the counter's own cookies — only while analytics is switched on in Cookie Settings | Visitor statistics and session replay, so we can see how the site is used |
| Cloudflare (R2 storage at photos.rentofficetoday.com) and, for some original images, Amazon Web Services (S3) | Your IP address, your browser's user-agent string and the address of the page that requested the file | Building photographs are served straight from storage |
| Google Fonts (fonts.googleapis.com, fonts.gstatic.com) | Your IP address, your browser's user-agent string and the address of the page that requested the file | Typefaces used across the site |
| Mapbox | Your IP address, your browser's user-agent string and the address of the page that requested the file — only after you scroll, click or move the mouse | The map. It is not loaded when the page first opens |
| Nothing, unless you click our footer link | Our company page is an ordinary outbound link |
That is the whole list. No form-forwarding service, no mailing platform and no marketing tool receives what you send.
We may also disclose data where the law requires it, or to establish or defend a legal claim.
We do not sell personal data. We do not buy marketing lists or enrich what you send us with data bought from anyone else. We do not run a mailing list, so you will not be added to one by filling in a form.
Transfers outside the European Economic Area
Several of the providers listed above are established outside the European Economic Area. Cloudflare, Inc. is a United States company, and it both hosts the site and carries the e-mail copy of your enquiry. Amazon Web Services, Google and Mapbox serve photographs, fonts and maps from infrastructure that is partly outside the EEA, principally in the United States. Yandex, which receives the analytics data, processes it on its own infrastructure outside the EEA. Telegram Messenger Inc., which receives the full contents of every enquiry, states in its own privacy policy that it is established outside the EEA and has appointed a representative in the European Union. So some of your data — at minimum your IP address, and in the case of Cloudflare and Telegram the full contents of your enquiry — is processed abroad. We ourselves are established outside the EEA too, in Saint Vincent and the Grenadines.
Where a provider is covered by an adequacy decision of the European Commission under Article 45 GDPR — for United States providers, certification under the EU-US Data Privacy Framework — we rely on that decision. For the others we rely on the safeguards available under Article 46 GDPR, in practice the standard contractual clauses each provider offers its customers. We are reviewing the paperwork provider by provider and will name the mechanism here, against each provider, as that review completes. We will not claim a certification, standard contractual clauses or a transfer impact assessment for a provider before those documents have actually been checked. Write to info@coworkings.nl and we will tell you where a particular provider stands today.
How long we keep things
- Enquiries. We keep the message and your contact details for 24 months after our last contact with you, and remove them once that period has passed — or sooner if you ask. This covers both copies: the Telegram message and the e-mail.
- Technical and security logs. Held by Cloudflare under Cloudflare's own retention periods. We keep no separate copy, and the contents of an enquiry are deliberately kept out of our own diagnostic logging.
- Analytics. Yandex.Metrica keeps the measurements under Yandex's own retention periods; the lifetimes of its cookies are set by Yandex and listed in the Cookie Policy.
- Browser storage. localStorage entries — your favourites, your analytics choice and the dismissed language hint — stay on your device until you clear your site data. Everything in sessionStorage — the pop-up timing keys — disappears when you close the tab.
Your rights
Under the GDPR you can ask us to:
- Give you access — a copy of the personal data we hold about you, and an explanation of what we do with it.
- Correct it — if a name, number or address we hold is wrong or incomplete.
- Erase it — delete what we hold, where we have no continuing reason to keep it.
- Restrict use of it — pause our use of it while a dispute or an accuracy question is sorted out.
- Port it — receive what you gave us in a common machine-readable format, or have it sent to someone else, where that right applies.
- Object — to any use we base on legitimate interests, including passing enquiries on. Tell us and we stop, unless we have compelling grounds that override your objection.
- Withdraw consent — where we rely on consent, you can take it back at any time, without affecting anything done beforehand. Your analytics choice can be changed at any time in the Cookie Settings panel in the footer.
How to use these rights
Write to info@coworkings.nl and say what you want. There is no form to fill in and no charge. We reply within one month; if a request is complicated we may take longer and will tell you why. If we cannot tell who you are from what you send, we may ask for enough information to be sure we are not handing your data to someone else.
Because there are no accounts on this site, the fastest way to help us find your record is to tell us the e-mail address or phone number you used and roughly when you got in touch.
Complaining to the regulator
You have the right to lodge a complaint with the Dutch data protection authority at any time, whether or not you have raised the matter with us first:
Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl
If you live or work in another EU member state, you may also complain to the data protection authority there. We would like the chance to put things right, and most issues are quicker to fix directly — but that is an invitation, not a condition. Complaining to the Autoriteit Persoonsgegevens does not cost anything and does not stop you pursuing any other legal remedy.
No automated decision-making or profiling
We do not make decisions about you by automated means, and we do not profile you. Nothing on the site scores you, sorts you into segments, or decides anything with legal or similarly significant effect. Listings are ordered by the characteristics of the buildings, not by anything about the person looking at them. We also do not use your data for advertising or retargeting.
The only automated steps in the enquiry path are the anti-abuse checks described above: the hidden honeypot field, the check that the form was submitted from this site, a short-term count of submissions per IP address, and limits on the size and technical fields of a submission. They decide whether a submission is delivered, and they do nothing else with what you sent.
Children
This is a business site about renting office space. It is not designed for or directed at children, and we do not knowingly collect data about anyone under 18. If you believe a child has sent us their details through a form, write to info@coworkings.nl and we will delete them.
How we protect data
The site is served only over HTTPS, so what you type into a form is encrypted in transit, and it travels no further than this domain: the form posts to coworkings.nl itself. Because the site is a static build with no login and no visitor database, there is no store of user accounts on this domain to breach. The credentials used to deliver enquiries are held as server-side secrets and are never part of the code your browser downloads. We never collect card or payment details — there is nothing to pay for here.
Once an enquiry is delivered, it sits in a Telegram chat and a mailbox, handled by the managers who answer enquiries; we keep the number of people with access to those to the people who need it. No system is completely secure, and we cannot promise that a transmission over the internet is risk-free.
Changes to this policy
We update this page when the site changes — a new provider, a new delivery route, or a change to the analytics counter would each mean a revision. This version was written on 26 September 2026 for the launch of coworkings.nl. The date at the top always shows the current version, and material changes will be flagged on the page itself.
We have no mailing list and no way of contacting visitors individually, so we cannot notify you personally. If our handling of data matters to you, it is worth re-reading this page occasionally.
Related documents
- Terms and Conditions — the rules for using the site
- Cookie Policy — cookies and browser storage in detail
- Usage Policy — what is and is not allowed on the site
Contact
Any question about this policy, or about anything we hold: info@coworkings.nl, or +31 6 35247561. Post can be sent to Fiato Trade Ltd., Rokin 92-96, 1012 KX Amsterdam, Netherlands, or to the registered office at First Floor, St.Vincent Bank Ltd, James Street, Kingstown, Saint Vincent and the Grenadines.
This policy is governed by Dutch law. The Dutch version of this policy is the authoritative one; this English text is provided for convenience.