Privacy Statement Mynta Law B.V. 

Version: 6 August 2026

1. Purpose of this privacy statement

1.1. The purpose of this privacy statement is to provide information regarding the way in which Mynta Law B.V. (hereinafter: ‘Mynta Law’) handles personal data and the way in which Mynta Law implements the rights of the owners of that personal data. This privacy statement explains which personal data we process, for which purposes and on what legal bases we do so, with whom we share personal data, how long we retain it and which rights data subjects have.

1.2. If you have specific questions about how Mynta Law handles personal data, or if this privacy statement is unclear, you can contact George Qiao via the contact details as mentioned in Article 1.3 of this Privacy Statement.

1.3. Mynta Law is located at Lange Voorhout 86 in The Hague, and registered in the Trade Register under number 61369667. You can reach Mynta Law by telephone on working days between 09:00-12:00 and 14:00-17:00 on +31702051160, or send an e-mail to info@mynta.nl.

2. Types of personal data

The personal data that Mynta Law processes may be the following:

2.1. Data from internet visitors, such as IP addresses of computers and mobile devices that visit Mynta Law’s websites, social media pages, online advertisements, banners, articles and the like, as well as data that Mynta Law derives from these IP addresses, such as location data, behavioral data (how long does one visit a certain page and the like), interaction data including company names and the like;

2.2. Data from potential clients, such as the names and contact details of persons with whom Mynta Law maintains general contact or who generally emails, calls, contacts Mynta Law via social media, registers for events, meetings, webinars and the like, as well as the personal data that is provided to Mynta Law in the context of such contacts;

2.3. Data of those who seek advice from Mynta Law on a one-off basis, for example the names, contact details, case descriptions, and any other personal information of persons who have an (online) consultation with Mynta Law as well as the names, contact details, and any other personal information of persons who accompany them, of their family members, (ex-)partners, relatives, or other persons involved;

2.4. Data of clients, for example the names, contact details and any other personal information of those who assign a case for the provision of legal services to Mynta Law;

2.5. Data of third parties involved in cases whose identity Mynta Law does not establish, for example the names, contact details, and any other personal information of persons who are directly or indirectly involved in the execution of Mynta Law’s legal assignment, such as decision-makers, accountants, clerks, lawyers, notaries, interpreters and translators, friends and acquaintances, referrers, intermediaries and the like;

2.6. Data of third parties involved in cases whose identity Mynta Law does establish, for example the names, contact details and any other personal information (including photos, copies of identity documents and the like) of persons who are not clients themselves, but whose identification contributes substantially to the adequate execution of Mynta Law’s legal assignments, such as certain employees, family members or other natural persons directly involved in a case;

2.7. Data that serves as evidence, for example personal data that clients or others provide to Mynta Law for the purpose of providing evidence, such as birth certificates, marriage certificates, death certificates, declarations of unmarried status, employment contracts, salary details, financial data (such as bank statements), correspondence, photos, videos, CVs, diplomas, references, location data and the like;

2.8. Mynta Law’s data, for example the names, contact and identity details of (former) employees, interns, volunteers and the like who work or have worked for Mynta Law;

2.9. Job applicant data, such as the names and contact details of applicants, as well as personal data such as CVs, application letters, references, and the like, which are provided to Mynta Law in the context of the application process;

2.10. Other data, such as personal data that reaches Mynta Law, such as names and contact details of persons who contact Mynta Law for whatever reason, or whom Mynta Law wishes to contact.

2.11. Under the Money Laundering and Terrorist Financing Prevention Act (Wet ter voorkoming van witwassen en financieren van terrorisme, ‘Wwft’), Mynta Law is legally obliged to identify its clients and, in some cases, to carry out client due diligence. To this end, Mynta Law collects personal data, such as nationality, the country where the client resides or is established, a copy of an identity document, the names of the ultimate beneficial owner (‘UBO’) and whether that person or a close associate is a politically exposed person (‘PEP’). Mynta Law is also obliged, under sanctions legislation and regulations, to verify whether the client or – in short – a UBO, appears on national, international or European sanctions lists. To this end, Mynta Law also collects personal data, such as the names of the aforementioned persons, their date of birth and the country in which they reside. Mynta Law collects and processes this personal data only if and to the extent that Mynta Law is legally obliged to do so. Clients are obliged to provide this personal data to Mynta Law. If the client does not provide Mynta Law with the personal data, Mynta Law cannot and is not permitted to provide its services.

2.12. Mynta Law retains a copy of the identity document for up to five (5) years after the end of the client’s engagement. Personal data processed by Mynta Law in accordance with the obligations under the Wwft is retained for up to five (5) years after the termination of the business relationship, the completion of the transaction or the reporting of a transaction.

3. Purposes of use

Mynta Law uses the personal data indicated above under section 2 for the following purposes:

3.1. Mynta Law uses data from website visitors (2.1) to operate, secure, analyse and improve its marketing and services, and, where applicable, for marketing purposes;

3.2. Mynta Law uses data from potential clients (2.2) to provide advice, maintain lists of participants for courses or events, maintain contact, provide or offer additional services and improve Mynta Law’s marketing and services;

3.3. Mynta Law uses data from those who seek advice from Mynta Law on a one-off basis (2.3) to provide advice, invoice, provide and offer additional services, provide evidence, request and publish online client reviews and maintain contact;

3.4. Mynta Law uses data from clients (2.4) to carry out the assignments given to us, communicate with clients, invoice, comply with legal obligations, and, where necessary, establish, exercise or defend legal claims;

3.5. Mynta Law uses data from third parties involved in cases whose identity it does not establish (2.5) to carry out the assignments given to Mynta Law, to offer additional services, to provide advice, to provide evidence, to request and publish online client reviews and to maintain contact;

3.6. Mynta law uses data from third parties involved in cases whose identity it establishes (2.6) to the extent necessary for the performance of the assignment, for communication, for evidentiary purposes, for compliance with legal obligations, to offer additional services, to provide advice, and to request and publish online client reviews ;

3.7. Mynta Law uses data that serves as evidence (2.7) to carry out the assignments given to Mynta Law, to provide advice, to provide and offer additional services, and to provide evidence;

3.8. Mynta Law uses its own data (2.8) to identify employees, to keep adequate records, to provide evidence and to maintain contact;

3.9. Mynta Law uses job applicants’ data (2.9) for recruitment and selection, to identify potential employees, interns, volunteers and the like, verify adequate access to the labor market in the Netherlands, provide evidence and maintain contact;

3.10. Mynta Law uses other data (2.10) to maintain contact.

4. Legal grounds for use

Mynta Law bases the use of personal data on the following legal grounds:

4.1. Mynta Law uses the data of internet visitors (2.1) on the basis of their consent where required, for example for non-essential cookies and marketing. Where processing is necessary for the operation and security of the website, Mynta Law relies on its legitimate interest;

4.2. Mynta Law uses the data of potential clients (2.2) on the basis of their consent where required, for example for non-essential cookies and marketing. Where processing is necessary for the aim of Mynta Law’s legitimate interests, it will do so to the extent that the legitimate interest justifies;

4.3. Mynta Law uses the data of recipients of one-off advice (2.3) on the basis of their consent where required, in order to provide advice, to comply with legal obligations or on the basis of Mynta Law’s legitimate interest;

4.4. Mynta Law uses the data of clients (2.4) on the basis of the performance of the agreement, legal obligations, its legitimate interests and, where applicable, Article 9 (2) (f) EU-AVG for the establishment, exercise or defence of legal claims;

4.5. Mynta Law uses the data of third parties involved in cases whose identity it does not establish (2.5) on the basis of their consent where required, in order to protect the vital interests of its clients, on the basis of its legitimate interest or that of its clients, or to comply with legal obligations;

4.6. Mynta Law uses the data of third parties involved in cases whose identity it establishes (2.6) on the basis of their consent where required, in order to protect the vital interests of its clients, on the basis of its legitimate interest or that of its clients, in order to comply with legal obligations or so that Mynta Law’s clients comply with their legal obligations;

4.7. Mynta Law uses data that serves as evidence (2.7) on the basis of the performance of the assignment, legal obligations and, where applicable, Article 9 (2) (f) EU-AVG;

4.8. Mynta Law uses its own data (2.8) to protect the vital interests of its employees, based on its legitimate interest or that of its employees, and/or in order to comply with legal obligations;

4.9. Mynta Law uses job applicant data (2.9) on the basis of their consent, based on its legitimate interest and/or in order to comply with legal obligations;

4.10. Mynta Law uses other data (2.10) on the basis of its legitimate interests and/or legal obligations, or on the basis of the consent of the owners of that data where required.

5. Security of personal data

5.1. Mynta Law communicates general information through its social media channels. If Mynta Law is approached with questions as a result via the relevant channel, it provides general answers via the same social media channel. In doing so, it is possible that Mynta Law processes personal data, for example names, ages, nationality(ies). Mynta Law has no influence on the security of such information and does not know where this data is hosted, nor does it have influence on this. All this is solely the responsibility of the respective social media company. Mynta Law therefore advises against the use of social media when seeking substantive advice on a specific situation that requires the transfer of sensitive personal data.

5.2. Information entered on Mynta Law’s website is encrypted where appropriate. This data is hosted on server space in the European Union. Mynta Law has made appropriate agreements with the owner of this server about its security, which meets all current standards.

5.3. The e-mail traffic of Mynta Law is hosted on server space in the European Union. Mynta Law has made appropriate arrangements with the operator of this server about the security thereof, which meets all current standards.

5.4. Mynta Law works with electronic records. This data is hosted on server space in the European Union. Mynta Law has made agreements with the administrator of this server regarding its security. Access to Mynta Law’s file system is restricted to authorized employees of Mynta Law. The client themselves, and possibly other persons, has/have access to (parts of) their own file.

5.5. Mynta Law's own IT system is hosted on server space in the European Union. Mynta Law has made agreements with the administrator of this server about its security. Access to this system is reserved exclusively for employees of Mynta Law, and only via devices owned by Mynta Law.

5.6. Mynta Law uses appropriate technical and organizational measures, including encryption where appropriate, access controls, logging, backups and processor agreements, to protect personal data against loss and unlawful processing.

6. Identification of clients and others

6.1. Mynta Law does not generally need to identify a person seeking a one-off consultation, unless identification is required by law or necessary in view of the nature of the matter. A one-time consultation is only about determining a person's legal position, and which service is most appropriate for that purpose. Mynta Law still asks one-time visitors to bring proof of identity; there are two reasons for this. First, residence documents contain information (date of entry, alien number) that allows Mynta Law to provide more effective advice. Secondly, it often happens that during the interview people decide to assign a case immediately. The one-time visitor then becomes Mynta Law’s client, whom it is obliged to identify.

6.2. If a person decides to instruct Mynta Law (either before or after an interview), Mynta Law may ask for proof of identity and, where required, retain a copy of the identity document in the digital file.

6.3. The nature of Mynta Law’s services may require Mynta Law to retain copies of identity documents such as passports or residence permits, to the extent necessary for the performance of the assignment and compliance with legal obligations. After all, these must often be attached in migration procedures. This may involve data from a client, but it may also involve data from a family member, an employee, or anyone else whose identity must be established due to the nature of the assignment.

7. Retention of personal data

7.1. Files are archived after the completion of the matter, which means that these files are included as such in the Mynta Law file system. The employees who had access to the file will have access to the archived file. Seven years after archiving, the data in the file will be deleted, unless a longer retention period is required by law, professional rules or in connection with actual or reasonably anticipated claims. In cases in which Mynta Law is held liable or in which liability can reasonably be expected, Mynta Law will only proceed to delete the file data after the claim for liability has been settled or the claim for liability has expired.

7.2. E-mail messages sent to Mynta Law will be retained for a period consistent with Mynta Law’s document retention policy, seven years after the date of receipt, and then deleted, unless a longer retention period is required by law or in connection with actual or reasonably anticipated claims. The personal data of (former) employees of Mynta Law will be destroyed after seven years from the date of termination of employment, unless a longer retention period is required by law or in connection with actual or reasonably anticipated claims.

7.3. The personal data of job applicants will be retained for as long as the application procedure is ongoing and will then be deleted unless Mynta Law and the applicant agree otherwise. The deletion of the data will take place no longer than eight weeks after the procedure has ended.

8. Transfer of personal data to third parties

Mynta Law provides personal data to third parties because this is sometimes necessary for the performance of its services, compliance with legal obligations or the establishment, exercise or defence of legal claims.

8.1. Where necessary for the performance of Mynta Law’s legal services, Mynta Law may share client data with third parties such as courts, public authorities, counterparties, experts, bailiffs, notaries, accountants or other advisers. This may also involve personal data of others, such as clients' employees, relations, family members or other parties involved.

8.2. When Mynta Law transfers a file to a lawyer or legal expert because a client wants to be assisted by another firm, this includes the transfer of personal data.

8.3. In exceptional cases, Mynta Law may transfer personal data outside the European Economic Area, where permitted by law and subject to appropriate safeguards, such as adequacy decisions or standard contractual clauses. This may involve employers outside the European Union, embassies of third countries and the like. The owners of the personal data concerned will be notified of this in writing.

9. Cookies and online tracking 

Mynta Law’s website uses cookies and similar technologies. Cookies may be used to ensure the proper functioning of the website, to analyse website usage and, where applicable, for marketing purposes.

Where cookies are not strictly necessary for the operation of the website, Mynta Law will ask for your consent before placing them. You may withdraw or change your consent at any time through the cookie settings on our website or your browser settings.

10. Owner’s rights

10.1. As a data subject you have a number of rights:

  • The right of access. This means that you may request access to the personal data that Mynta Law has collected about you. Please note that there may be circumstances in which Mynta Law is entitled, for example on the basis of professional privilege, not to comply with your request to provide copies of personal data;
  • The right to rectification or correction of your data if it is inaccurate or incomplete;
  • The right to erasure of your personal data. Please note that there may be circumstances in which Mynta Law is required to retain your data in order to comply with its legal and statutory obligations;
  • The right to object to, or request restriction of, the processing of your personal data. Again, there may be circumstances in which Mynta Law is legally entitled not to comply with your request;
  • The right to data portability. This means that you have the right to receive your data in a structured, commonly used and machine-readable format. You also have the right to transmit those data to another controller;
  • The right to object to profiling;
  • The right to lodge a complaint with a supervisory authority;
  • The right to withdraw your consent. Again, there may be circumstances in which Mynta Law is entitled to continue processing your data, in particular where such processing is necessary for compliance with its legal and statutory obligations. For this purpose, the person concerned can contact Mynta Law via e-mail (Article 1.3 of this Privacy Statement).

10.2. Data subjects may object at any time to direct marketing, including unsolicited advice, after the receipt of which objecting Mynta Law will stop such processing of data. This objection can be reported directly to the lawyer concerned. Mynta Law will note in the file system that the person concerned does not wish to receive unsolicited advice.

10.3. In exceptional situations, an objection can be made by a data subject to further processing of personal data, for example if, after an assignment has been issued, it becomes apparent that there is a close, personal relationship with an employee of Mynta Law. The decision to object means the end of Mynta Law’s services, as it cannot assist clients if it is not allowed to process their data.

10.4. If a data subject has requested the removal of all their personal data from the Mynta Law system, Mynta Law will assess whether it (still) bears interest in the storing of the said personal data. If this is not the case, Mynta Law will delete the personal data from the Mynta Law system.

10.5. The exercise of the rights listed above may be limited where necessary to protect legal professional privilege, the rights of others or our legal obligations.

10.6. Before responding to a request to exercise any of the above rights, Mynta Law will establish the identity of the requester. Mynta Law does this to prevent data from falling into the wrong hands, and guarantees that these rights are indeed exercised by the rightful owner.

11. Data protection officer

As a small firm, Mynta Law is not required to appoint a Data Protection Officer, and has chosen not to do so. Mynta Law does adequately guarantee the security of your data.  It takes appropriate technical and organisational measures to protect personal data against loss, unauthorised access, disclosure, alteration or destruction. These measures include: access restrictions, encryption where appropriate, secure hosting and backups, logging and monitoring,  confidentiality obligations for staff, processor agreements with third parties and internal procedures for handling security incidents.

Mynta Law handles individual requests and procedures, and the processing of personal data is in the vast majority of situations not a core activity, but ancillary to Mynta Law’s services.

If you have specific questions, complaints or requests regarding this privacy statement or the processing of personal data, please contact George Qiao via the contact details mentioned in Article 1.3 of this privacy statement.

12. Changes to the privacy statement(s)

This privacy statement was last amended on 6 August 2026. Mynta Law may amend this privacy statement from time to time by publishing the revised version on its Website.