Privacy Notice
Last updated: 28 September 2026.
Who we are
Headcore International B.V. runs a matching system for technical business-to-business work: a company describes what it needs, and the request reaches companies that do that kind of work. We are registered in Amsterdam, the Netherlands, under Chamber of Commerce number 42143330, with offices at Mussenstraat 9, 1223 RB Hilversum. For the personal information described here we decide how and why it is processed. Most privacy laws call that role the controller; South Africa's calls it the responsible party.
It is one notice for everyone we deal with, wherever you are. Rather than write a version per country, we hold ourselves to the same standard everywhere and give every right listed below to everyone, not only to the people whose national law happens to grant each one. The laws that apply to us include the General Data Protection Regulation in Europe, the Protection of Personal Information Act in South Africa and the Lei Geral de Proteção de Dados in Brazil, and this notice is written to satisfy all of them at once.
We may work with local partners in some countries. Where we do, they act on our instructions under a written agreement, and we remain responsible for your information. Tokens bought by South African companies are charged in rand.
For any question about your personal information, wherever you are, write to info@headcore.com or use the contact page on this site. That address is also our contact channel under Brazilian law.
Information we collect
- Identity and contact details: your name, work email address, telephone and WhatsApp number, and job role.
- Company details: name, registration number, website, location and the work your company does.
- The content you submit: requests, responses, messages and any files attached to them; if you speak a request instead of typing it, the recording is turned into text.
- Commercial records: token purchases, invoices and payment status.
- Technical data: sign-in sessions, IP address, browser and device information, and security logs.
- How you reached us: the advertisement or link you arrived through (its campaign tags and click identifier), the website that referred you, the first page you visited and when.
At a trade stand or event we collect the details you enter on the form, together with the exact wording of the consent you gave and when you gave it.
Most of this comes from you directly. There are two exceptions. When you ask us to build a profile of the work your company does, we read your company's public website. And when a request has not reached a company that could answer it, we, or a local partner where we have appointed one, may identify companies that could, using public business sources such as company websites, industry association member lists and public company registers, together with the business contact details published there.
Why we collect it
We use personal information for the purposes below, each on the ground named.
- To run the matching system, put a request in front of companies that do that kind of work, and put two companies in touch with each other: to perform our contract with you.
- To create, secure and support your account, and to send the notifications you have enabled: to perform our contract with you.
- To process token purchases and issue invoices: to perform our contract with you, and to meet our tax and accounting obligations.
- To help companies get started and follow up on their requests, including through a local partner where we have appointed one: our legitimate interest in a platform where requests get answered.
- To identify companies that could answer a request nobody has answered yet: the same legitimate interest, within the limits on contact described below.
- To detect and prevent fraud and abuse and to keep the platform secure: our legitimate interest in a safe platform, and where the law requires it, a legal obligation.
- To learn which of our advertising brings companies that join, post requests and buy tokens, and to tell the advertising services we use (Google, Meta, LinkedIn and Microsoft) when that happens, so they show our advertising to similar companies: our legitimate interest in knowing which advertising works.
- To improve the platform: our legitimate interest in making it work better for the companies that use it.
- To keep in touch with you after you leave your details at an event: your consent.
- To meet our legal obligations and respond to lawful requests from authorities: a legal obligation.
Whether you have to give it to us
Giving us your information is voluntary. Some of it is necessary rather than optional: without a name, a work email address and a company we cannot create an account, publish a request, or put you in touch with another company. If you choose not to provide those, we cannot give you that part of the service, and that is the only consequence. Fields marked optional can be left empty and nothing is withheld from you for leaving them empty. No law requires us to collect this information.
Our grounds for processing, and how we contact companies
The grounds above are the ones privacy law recognises: a contract with you, a legal obligation, our legitimate interests, and your consent. Where we rely on a legitimate interest, we have weighed it against your interests, and you can object at any time; we then stop, unless we have compelling grounds to continue. Where we rely on consent, you can withdraw it at any time; withdrawing it does not affect processing that already took place. We use personal information only for the purposes set out above, and not for an unrelated further purpose.
We do not send unsolicited marketing to companies or people who have not agreed to hear from us, by email, text message, WhatsApp, social media or telephone. A company that has not joined Headcore hears about a request only through someone it already knows, through an industry association it belongs to, or through a single message asking whether it wants to hear about such requests. If a company or person declines, we record that on a list that we, any local partner we appoint and anyone working with us check before any approach, and we do not contact them again.
Automated processing and AI
We use AI services to read the requests and company information you give us, so that a request reaches companies that do that kind of work. The providers we use for this may not use your information to train their models, and keep it no longer than they need to process it and keep their service secure. AI proposes; it does not decide. It makes no decision that has legal consequences for you or that affects you in a similarly significant way, and people check its work where it is uncertain. Wherever you are, you may ask us to explain how an automated outcome was reached and to have a person review it.
Who receives it
When a supplier responds to your request, or when you reveal yourself to a supplier, the two companies' business contact details are shared with each other so the work can proceed. You control when that happens: a request can be posted anonymously, and suppliers then see the job rather than who posted it. Anonymous means anonymous to suppliers: Headcore, and a local partner where we have appointed one, can always see which company posted a request.
Where we appoint a local partner, as described above, that partner can see the company details, contact details and requests of companies in its country. It uses them only on our instructions and only for Headcore's work there: to help companies get started, to support them, and to follow up on requests. It may not use them for its own business. If you contact such a partner about your information, it passes your request to us and we answer it.
When you register a company, post a request or buy tokens, we tell Google, Meta, LinkedIn and Microsoft that it happened (for a purchase, also its amount), together with the click identifier of the advertisement you came through and your email address and telephone number encoded (hashed). We do not do this where the law requires your prior consent for it, and we do not do it if you object: write to info@headcore.com and we stop for your company.
Otherwise we share personal information only with the companies that process it on our behalf under contract, and only as far as they need it: hosting and databases, AI processing, voice transcription, email delivery, text and WhatsApp messaging, payment processing, background processing, file storage and error monitoring, and sign-in with Google, LinkedIn or Microsoft where you choose to use it. Some of them, such as our payment provider and the sign-in services, also process information for purposes of their own, such as preventing fraud, and do so under their own privacy notices. Write to info@headcore.com and we will tell you which providers we use. We also disclose information where the law requires it. We do not sell personal information and we do not share it for anyone else's marketing.
Where your information is processed
Our systems are hosted in the European Union. Some of those companies process personal information in the United Kingdom or the United States, and a local partner, where we appoint one, reaches it from its own country, so information does cross borders. Wherever it goes, we move it only with the safeguards your law requires: an official finding that the destination protects personal information adequately; or a binding agreement holding the recipient to protection equivalent to what you have at home (in Europe, the European Commission's standard contractual clauses, which also cover any local partners we appoint); or because the transfer is necessary to perform the contract between you and us. Our agreements require recipients to protect the information, to process it only on our instructions, and not to transfer it onward without equivalent protection. You can ask us for a copy of the safeguards that apply to a transfer.
How we protect it
We take the security measures the law requires, appropriate to the risk: encryption, passwords stored only in a form that cannot be read back, access limited to the people who need it for their work, sessions that expire, logging of sensitive actions, separation between company accounts, and review of the providers and partners we rely on. Where we appoint a local partner, its staff use their own named accounts and reach your information through our systems, not through copies of their own. No system is perfectly secure. If personal information is accessed or acquired by an unauthorised person, we will notify the regulator and the people affected as soon as reasonably possible, as privacy law requires, and we will tell you what happened and what we are doing about it.
How long we keep it, and your rights
We keep personal information for as long as your company uses Headcore and we need it to provide the service. Invoices and payment records are kept for seven years, because Dutch tax law requires it. If you stop using Headcore, or you ask us to delete your information, we delete it or make it permanently anonymous, apart from anything the law requires us to keep or that we still need to settle a dispute, and we tell you what we kept and why. Details you leave at an event are kept for the purpose you agreed to, and we delete them whenever you ask or withdraw your consent. The same applies to the details of a company we identified from a public source: tell us and we remove them. If you ask us not to contact you again, we keep only what we need in order to respect that.
You may ask us
- to confirm what we hold about you and to give you a copy;
- to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained;
- to object to how we process it;
- to restrict our processing of it;
- and to receive your data in a portable form.
We give all of these to everyone, wherever you are, rather than only where a particular law grants them. Write to info@headcore.com or use the contact page. We answer within one month, and if a request is complex we tell you within that month that we need up to two months more. Asking is free; we refuse or charge only for a request that is clearly unfounded or excessive, and we explain why.
Complaints
If you are unhappy with how we handle your personal information, please tell us first at info@headcore.com so we can put it right. You are also entitled to complain to the privacy regulator where you live or work, and you do not have to come to us before you do.
In the European Union that is the data protection authority of your own country. In South Africa it is the Information Regulator, at JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001, by email to complaints.IR@justice.gov.za, or through inforegulator.org.za. In Brazil it is the Autoridade Nacional de Proteção de Dados, at gov.br/anpd. If you are somewhere else, your own national regulator can take a complaint about us, and we will help you find it if you ask.
Cookies and changes to this notice
We use strictly necessary cookies to sign you in and to keep your session secure; the platform does not work without them. We use Google Tag Manager on our public pages to measure how the site is used.
When you first arrive we store a cookie that remembers how you reached us: the advertisement or link and its campaign tags. It lasts 90 days and only we read it, when you join the waitlist or register. When you join the waitlist, the details you entered are also sent to Google from your browser so we can tell which advertising brought you here; when you register a company in South Africa or Brazil, your email address, name and country are. Your email address is encoded (hashed) before it leaves your browser. To object to any of this advertising measurement, write to info@headcore.com.
If a page offers an explainer video, nothing is requested from Google until you press play: the video then loads from YouTube in its no-cookie mode, and Google receives your IP address in order to deliver it.
We may update this notice as the platform grows, and the date above always says when it last changed.