Privacy Policy
Last updated: August 18, 2026
This Privacy Policy explains what personal data SuriWorld collects, why, and what rights you have. It applies to suriworld.com in both its Dutch and English versions.
Who we are
SuriWorld is published by MijnAIomgeving B.V. (Dutch Chamber of Commerce / KVK no. 92101550), registered at Duintopstraat 11, 1361BJ Almere, the Netherlands ('MijnAIomgeving', 'we', 'us', or 'SuriWorld'). We are the data controller for the personal data described in this policy.
Questions about this policy, about the data we hold on you, or want to exercise one of your rights? Contact us at info@suriworld.com.
Scope of this policy
This policy applies to suriworld.com and to every publicly accessible feature there: reading reels and dossiers, subscribing to our email digest, enabling push notifications, and reacting to reels or polls.
The internal editorial and admin platform (/studio, /dashboard, /planner) is accessible only to authorized MijnAIomgeving staff and partners and is covered separately under 'Staff and partner accounts' below.
Digest subscription
When you subscribe to our email digest, we process your email address, your language preference (Dutch or English), your chosen sending frequency (daily or weekly), and the IP address the signup form was submitted from. Signup uses double opt-in: you first receive a confirmation email, and only after confirming do you start receiving the digest.
Legal basis: your consent. Retention: until you unsubscribe or request deletion.
Every digest email includes a personal, time-limited link that lets you — without logging in — change your frequency, unsubscribe, request an export of your data, or delete your data outright. See 'Your rights' below for details.
Push notifications
If you enable push notifications, we store the push subscription your browser generates (an endpoint URL and encryption keys — not personal identifiers), together with your language preference and the IP address at the time. This data is used solely to deliver the notifications you opted into.
Legal basis: your consent. You can disable push notifications at any time via your browser or device settings, which removes the subscription on our end.
Reactions and polls
When you react to a reel or vote in a poll, we associate that with a pseudonymous session hash — a technical code that cannot be traced back to you — not with your email address, IP address, or an account. We use this solely to prevent duplicate votes and to show aggregate reaction/poll results.
reCAPTCHA
We use Google reCAPTCHA on forms to prevent automated abuse (spam, bots). reCAPTCHA analyses interaction data and sends it to Google, subject to Google's privacy policy. Legal basis: our legitimate interest in protecting the service from abuse.
Staff and partner accounts
Staff and partners with access to the editorial or admin platform (/studio, /dashboard, /planner) sign in via Microsoft Entra External ID. Google is offered as a federated identity option within Entra — choosing it redirects through Entra's identity layer; our application never receives tokens directly from Google's OAuth endpoint.
When a staff member or partner signs in using their Google account, SuriWorld receives (via Entra) their full name, email address, and a unique user identifier (the Google sub claim). This data is used exclusively to create or look up their operator account in our content management system (Umbraco) and to issue a session token that grants access to the admin platform. We do not use Google user data for advertising, profiling, or any purpose other than this internal authentication. Google user data is never shared with third parties beyond the Microsoft Entra infrastructure it transits through, and is never visible to or collected from public SuriWorld visitors.
Their session is recorded in a secure cookie valid across *.mijnaiomgeving.nl, so they don't need to sign in again when moving between Suri* domains.
Google user data — protection and access
The Google-derived name, email address, and user identifier that SuriWorld receives during admin sign-in are protected as follows:
— Encryption in transit: all data exchanged between Google, Microsoft Entra, and our servers travels exclusively over HTTPS/TLS. — Encryption at rest: session tokens are stored in an httpOnly, Secure, SameSite=Lax cookie that is inaccessible to JavaScript and scoped to *.mijnaiomgeving.nl. Umbraco member records (name, email address, role) are stored in a Microsoft Azure-hosted database within the European Union. — Access control: admin-platform routes (/studio, /dashboard, /planner) are protected by server-side session checks; unauthenticated requests are rejected. No Google user data is ever exposed to the browser, to front-end JavaScript, or to public visitors. — Minimal scope: we request only the openid, profile, email, and offline_access scopes — the minimum required for authentication and session refresh. We do not request access to Gmail, Google Calendar, Google Drive, Google Contacts, or any other Google service or user data beyond basic identity. — Retention: staff and partner account data (including any Google-derived fields) is retained for as long as that person is active at MijnAIomgeving, plus a reasonable administrative period afterward. Upon offboarding, their Umbraco member record is deactivated and their access is revoked. — YouTube channel OAuth: operators may optionally connect SuriWorld's own YouTube channel (not personal YouTube accounts) to the distribution dashboard. The resulting OAuth access and refresh tokens are stored server-side in Umbraco, encrypted at rest on Azure infrastructure within the EU, and used solely to publish SuriWorld's own content to its own YouTube channel and to retrieve aggregate channel statistics. These tokens are never exposed to the browser or to visitors.
Server logs and security
Like almost every website, our hosting and security systems keep technical logs (such as IP address, timestamp, and requested URL) to detect and prevent abuse, outages, and security incidents. These logs are not used for profiling and are automatically deleted after a maximum of 90 days, unless a longer period is necessary for an ongoing security investigation.
Facebook and Meta data deletion requests
SuriWorld does not offer 'Log in with Facebook' to visitors of suriworld.com. The only place a Facebook/Meta account is connected to SuriWorld is in our internal distribution dashboard, used by MijnAIomgeving staff and partners to publish content and measure reach on Facebook, Instagram, and Threads — that connection stores OAuth tokens and basic page/account identifiers for the connected Meta Page, not the personal data of visitors.
To request deletion of any personal data we hold about you — including a staff/partner Meta connection — email info@suriworld.com with the subject line 'Data deletion request' and the details we should search for (email address, phone number, or connected Page/account name). We confirm receipt within 5 business days and complete deletion within 30 days.
If you interact with SuriWorld content directly on Facebook, Instagram, or Threads (likes, comments, shares), that activity is Meta's data — request deletion from Meta directly, not from SuriWorld.
International data transfers
Some of the parties above (such as Google, Meta, and TikTok) may process data on servers outside the European Economic Area. In those cases, we and our partners rely on appropriate safeguards, such as the EU Standard Contractual Clauses or another transfer mechanism recognized by the European Commission.
Retention periods
We do not keep personal data longer than necessary for the purpose it was collected for: digest subscriptions until unsubscribe or deletion, push subscriptions until revoked, session hashes for reactions/polls for the duration of the session, and analytics data per Google Analytics 4's default retention (typically 14 months). Staff/partner account data is kept for as long as that person is active at MijnAIomgeving, plus a reasonable period afterward for administrative and security purposes.
Your rights
Under the GDPR, you have the right to access, rectify, or erase your data, restrict or object to processing, request data portability, and withdraw consent at any time.
For digest subscribers, this is self-service and requires no login: the personal link in every digest email takes you to a page where you can change your frequency, unsubscribe, request an export of your data, or delete your data outright.
No longer have that email, or is your request about push notifications, reactions/polls, or something else (for example, as staff or a partner)? Email info@suriworld.com; we respond within the statutory one-month period. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
Children
SuriWorld is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe we have inadvertently collected data from a minor, contact info@suriworld.com so we can remove it.
Changes to this policy
We may update this policy from time to time, for example when we add new functionality or when laws change. The date at the top of this page shows when it was last updated. For material changes, we will notify active digest subscribers by email.
Contact
MijnAIomgeving B.V. (KVK 92101550), Duintopstraat 11, 1361BJ Almere, the Netherlands. Email: info@suriworld.com.