Privacy notice

Last updated 25 September 2026

This notice explains what personal data ExpatSuriname processes, why, on what legal basis and for how long. It is written to be read rather than dismissed: where something matters to you, it is said in plain language.

Who processes your data

Expat Suriname is a trade name of BlueOceanSolutions B.V., Chamber of Commerce 92101550, registered at Duintopstraat 11, 1361 BJ Almere, the Netherlands. BlueOceanSolutions B.V. is the controller for the data collected through this website: we decide what it is used for and how.

Questions about your data or about this notice: privacy@expatsuriname.com. You will get an answer within one month.

What we collect, and why

We do not collect more than a specific function needs. Part by part:

Reading articles — you need no account and we ask for nothing. Our server records the technical data any web server records, including your IP address, to keep the site working and secure.

Contact form — your name, email address and your message, so we can reply.

Sending an enquiry (the form inside an article) — your name, email address, phone number and your answers to the questions asked, so that the party we name before you consent can get in touch with you. See the separate chapter below; this is the only processing where we pass data to another company.

Account — if you create one: your name and email address, plus whatever you save yourself, such as bookmarked articles, calculations and the progress of your moving steps.

Calculators — your input is used to produce the result. We only keep a calculation if you deliberately save it to your account.

Chatbot — your question is sent to our search-and-answer service so it can answer. Please do not put anything in it you would rather not share; a chat box invites people to say more than is needed.

Country you are visiting from — we infer from your IP address whether you are in Suriname, the Netherlands or elsewhere, so we can show the right information. We store no IP address for this.

The enquiry form: exactly what happens

This is the processing where your data leaves our company, so we describe it in full.

You fill in two short steps. The second step contains a separate checkbox naming the party that will receive your details. That box is never pre-ticked. Without it nothing is sent and nothing is stored.

We pass your details only to the party named in that sentence. Not to “our partners”, not to a party we add later, not to someone else in the same category. If we want to pass an enquiry to a different party, you have to consent to that separately and afresh.

We and the recipient are each independent controllers. The recipient does not act on our instructions: once your details are with them, they decide how they handle them and they are responsible for that. Their own privacy notice governs what they do; we cannot answer for them.

For every consent we record: the exact sentence you read, its version and language, the recipient's name, the moment, the page you gave it on, your browser details and a truncated part of your IP address. That is not extra data collection but the evidence that consent was really given — without it we are not allowed to pass your details on at all.

We never charge you for an introduction, and it commits you to nothing.

Who we share data with

With the party you see named in the consent sentence — and with nobody else under that sentence.

Beyond that, with suppliers who work on our instructions and may not use your data for themselves: Microsoft Azure for hosting, storage and sending email; Google for Tag Manager, Analytics and reCAPTCHA; and the supplier behind our chatbot. There is a data processing agreement with each of them.

We do not sell your data and we do not use it for advertising.

Transfers outside the EEA

Our servers are in the European Union.

Some recipients and suppliers are outside the European Economic Area, for example in Suriname or the United States. Suriname has no adequacy decision from the European Commission. For those transfers we put Standard Contractual Clauses in place and assess whether they give sufficient protection in practice. Where that is not arranged, we do not transfer — that is enforced in our systems rather than left to a procedure.

We do not rely on your individual consent as a standing basis for transfers (Article 49(1)(a) GDPR). That exception is meant for occasional cases, and it would be unfair to use a checkbox as a substitute for real safeguards.

How long we keep it

An enquiry we did not pass on: 90 days, after which we delete the personal data.

An enquiry we did pass on: 24 months, after which we render it non-identifying. What remains cannot be traced back to you.

A refused enquiry (an automatically detected bot, for instance): 90 days.

Consent records are kept even after the data they relate to has been deleted. That sounds contradictory, but without them we could no longer show that a disclosure was lawful — it protects you as much as us.

Statistics about use of the form (how many people start and finish, with no name, email address or anything leading back to you): 13 months.

Account data: for as long as your account exists. Delete it and we delete them.

Automated assessment

Before we pass an enquiry on we run some automatic checks: whether the email domain exists, whether it is a disposable address, whether the form was filled in unrealistically fast, and whether the same enquiry has already arrived.

This is not automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR: nothing is decided about you, no profile is built, and the outcome is only whether an enquiry is passed on. If you disagree with an outcome you can always tell us.

Cookies and measurement

Functional cookies needed to make the site and your sign-in work are set without asking; without them the site does not work.

Analytics cookies via Google Tag Manager and Analytics are only set after you have consented to them. You can change your choice at any time through “Cookie preferences” at the bottom of every page; withdrawing is exactly as easy as giving.

To count how many people see and complete the enquiry form we also use our own counting. It stores nothing in your browser and contains no name, email address, session identifier or anything else leading back to you — only totals.

Security

The name, email address and phone number in an enquiry are stored encrypted (AES-256-GCM). We never store your IP address as such: for security purposes we keep an irreversible keyed hash of it, and in the consent record only a truncated part.

Traffic to this site runs over an encrypted connection. Access to the data is limited to those who need it.

Your rights

You have the right to: see your data; have it corrected; have it deleted; have processing restricted; object to processing based on legitimate interests; receive your data in a common file format; and withdraw consent you have given, without affecting what was lawfully done before.

Write to privacy@expatsuriname.com. We respond within one month. If we ask for extra details to identify you, that is to avoid handing your data to someone else.

If you are unhappy with how we handle your data you can complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We would appreciate hearing from you first, but that is not a condition.

Children

This site is not aimed at children under 16 and we do not knowingly collect their data. If you believe that has happened, tell us at privacy@expatsuriname.com and we will delete it.

Changes

If something material changes we will update this notice and change the date at the top.

The consent sentence you read when sending an enquiry never changes retroactively. If we revise that text it becomes a new version for new enquiries; your consent stays recorded exactly as it was shown to you.