Privacy policy
Last updated: 16 September 2026
This policy covers abram.systems and System, Abram’s software for organisations. It distinguishes website visits, enquiries and the newsletter from the use of System.
1. Who is responsible?
Abram, Zuidelijk Achterweg 24A, 3245 BR Sommelsdijk, the Netherlands. Dutch Chamber of Commerce number: 99874652. Contact: mail@abram.systems.
Abram is the controller for its own enquiries, newsletter and business administration. When an organisation uses System to process personal data for its own purposes, that organisation determines the purpose and lawful basis. Abram processes those data on its instructions. These responsibilities belong in the agreement and, where applicable, a data processing agreement.
2. Website, enquiries and newsletter
When you contact us, we process your contact details and message to answer your enquiry or discuss an engagement. Depending on the request, this is necessary to prepare or perform a contract, or serves our legitimate interest in answering business enquiries.
When you request the newsletter, we send a confirmation email with a link valid for 24 hours. Resend processes your email address to deliver that confirmation email. Only after confirmation do we add your email address and optional name to the newsletter segment at Resend, where we also process your subscription or unsubscribe status. Your confirmation provides consent. You may withdraw it by unsubscribing or emailing us. An unsubscribe record may be retained to prevent further mailings.
Vercel hosts the website. Loading a page involves processing technical connection data, such as your IP address and request information, to deliver and protect the website. Keeping the website available and secure is our legitimate interest. Records we must retain for statutory administration are processed to meet that legal obligation.
Booking an appointment takes you to an external Google Calendar link. Google’s privacy rules also apply when you open it. The same principle applies to other external platforms you visit through links.
3. Cookies, storage and measurement
The website uses local browser storage for its greeting and introduction. A visit counter and the date of the last counted visit remain on your device until your browser removes them or you clear the website data. Session storage remembers, among other things, whether the introduction or greeting has been shown or dismissed.
On your first visit, you choose separately for analytics, personalisation and marketing. Without permission, the site does not load Google Analytics or the LinkedIn Insight Tag. If you allow analytics and Abram activates a measurement ID, Google Analytics measures aggregate use of pages and buttons. If you allow marketing and Abram activates LinkedIn campaigns, the LinkedIn Insight Tag may load for conversion measurement and remarketing.
If you allow personalisation, the website stores a random browser code, the origin of a link such as UTM data or only the domain of a referrer, and a limited list of page and action events on your device. These data expire after no more than 90 days. They are not currently linked to your newsletter address or sent to a visitor database. You can change your choice through Cookie preferences in the footer or clear browser storage.
4. Personal data in System
The data processed by System depend on the features an organisation uses and the information it supplies. Data may come from users, their organisation and configured external services.
- Account and organisation information, such as name, email address, user role and organisation access.
- Organisation records, such as contact and membership details, schedules and communications.
- Messages, drafts, images, files and other content users enter or submit for processing.
- External service settings, technical identifiers and access credentials where required by a configured integration.
- Processing and delivery information, such as status, timestamps, errors and message identifiers.
These data support the selected features, access management, content storage and processing, delivery and troubleshooting. The organisation must have a valid lawful basis for the personal data it supplies, including data about other people. For data about children, health or religion, the organisation must also meet the applicable additional requirements. Only enter such data where necessary and permitted.
5. Facebook, Instagram and WhatsApp
System by Abram is the name of the Meta app Abram uses to develop channel integrations. Selecting Facebook, Instagram or WhatsApp in the app settings does not mean those channels are connected or available.
The current delivery route uses Make. Built-in Meta sign-in and account linking are not yet available. The direct Instagram integration is under development and WhatsApp is planned. There is therefore no generally available button in System for users to connect or disconnect a Meta account themselves.
A configured delivery route may process message content, media, channel or account identifiers and delivery results through Make and the relevant channel. The actual route determines which data are passed on. Contact us to review or stop an existing route. Stopping access does not automatically delete previously published posts or copies held by the external platform.
6. Service providers and AI
External services used for the website and System include Vercel for hosting and file storage through Vercel Blob, Neon for the database, Resend for email, Make for configured automation and delivery, and OpenAI for AI processing. Not every service receives data during every action.
Using an AI feature may send the text or other content supplied for that feature to OpenAI. Only enter data needed for that feature and which your organisation is entitled to have processed. AI output may be incorrect and requires human review.
When content is published or sent, the selected channel also receives it. Providers may process data outside the European Economic Area. The applicable locations, contractual arrangements and any transfer safeguards need to be established for each service and organisation; this policy does not guarantee exclusively European storage. Contact us for information about the processing relevant to your use.
7. Retention and security
Retention is determined by the processing purpose, the customer relationship, necessary follow-up, statutory retention duties and potential disputes. For organisation data, the organisation’s instructions and agreements also apply. Technical logs, backups and records with external providers may have different retention periods from data in the application.
There is no universal automatic deletion period for all data in System. Ending use or stopping a delivery route does not itself erase data. Deletion requests are assessed and carried out to the extent permitted and applicable.
System uses account access and roles to manage access. Some general uploads are stored with a publicly accessible file link; not every file requires a login to access. Only share or upload content appropriate for the storage feature concerned. Security also depends on the organisation’s configuration and use. Report suspected misuse or security problems to our contact address.
8. Your rights and deletion requests
Where the GDPR grants these rights in your circumstances, you may request access, correction, erasure, restriction or portability of your personal data. You may object to processing based on legitimate interests. You may withdraw consent without affecting the lawfulness of processing before withdrawal.
Email your request to our contact address. Identify the relevant organisation, account or channel and the data concerned. Do not send passwords or access tokens. We may request additional information where necessary to verify your identity.
We respond without undue delay and normally within one month. If the legal conditions for an extension apply, we explain the extension and its reason within that month. Where Abram acts as a processor, we help the organisation handle your request. To request deletion of data processed through a Meta-related route, use this contact address; automatic deletion through Meta is not available.
A request may not always be fulfilled in full, for example where statutory retention duties or the rights of others apply. We explain any restriction. You may complain to the Dutch Data Protection Authority or the competent supervisory authority in your country.
9. Changes
The date above shows when this policy was updated. When processing changes, we update the policy and provide additional information where necessary.