Legal
Privacy policy
Which personal data Legate collects when you use our website and platform, what we do with it, who else sees it and how you control it. We process your data under the GDPR and store it within the EU.
Last updated 30 September 2026
1Who we are
Legate runs a curated marketplace for management, technology and AI consulting in the Netherlands. We connect companies that need consulting capacity with independent consultants and consulting firms, and we run the engagements that follow.
[Legate B.V.] is the controller for the personal data this policy describes, registered with the Dutch Chamber of Commerce (KvK) under number [KvK number]. Our address is [Street and number], [postcode] Amsterdam, the Netherlands. Send any question about your data to [privacy@asklegate.co].
This policy covers our website, the platform behind your account, and the emails and calls you have with us. Clients and firms you meet through Legate handle the data you share with them under their own policies.
2What we collect
What we hold depends on how you use Legate. You give us most of it yourself.
If you are an independent consultant
- Identity and business details: your name, contact details, Chamber of Commerce registration, VAT number and the legal form you work through.
- Your record: your CV, project lists, past references, a LinkedIn export and anything else you upload, plus the profile our system builds from it and the edits you make before you approve it.
- Vetting: notes from your interview with the Legate team, what your referees tell us, and proof of registration and professional insurance.
- Your terms: rate, availability, the engagement lengths and topics you accept, how you like to work and what you want to learn.
- Engagement history: the matches we send you, what you accept or decline, client feedback and the references we verify after each engagement.
- How you work: details such as your other clients and how an engagement runs, so we can check a construction against the Dutch rules on self-employment before contracting.
If you buy consulting for a company
- Contact details of the people who work with us: name, role, business email and phone number.
- Company details: name, Chamber of Commerce number, billing address and VAT number.
- Briefs and documents: what you enter into the AI intake, the brief we write with you, your budget and timing, and the files you share. These can name your own staff, so share what the brief needs and leave out the rest.
- Choices and feedback: the shortlists you receive, the candidate you pick, notes from check-ins and your feedback after the engagement.
If you run a consulting firm
- Contact details of the people who manage your account.
- Firm details: name, Chamber of Commerce number, services, sectors and team composition.
- Bench information: the consultants you flag as available, with their profiles, rate, duration, topics and notice period. Before you share their details, tell your people and point them to this policy.
- The ledger: who introduced which client relationship, so the credit stays with the firm that earned it.
If a consultant names you as a referee
We receive your name, role, contact details and how you know the consultant. We contact you to check the reference and record what you tell us. You can decline, and you can ask us to delete your details.
For every account holder
- Contracts: the framework agreements, statements of work and confidentiality terms you sign through Legate.
- Time and invoices: days or hours worked, rates, fees, VAT, invoice details, bank details for payment and payment status.
- Messages: what you send us or other users through the platform, and notes from calls with the Legate team.
When you visit the website or use the platform
- Device and log data: IP address, browser, operating system, the pages you open, the time of your visit and the site you came from. Our hosting provider records these to keep the site running and secure.
- Usage data: the platform features you use and the searches you run.
- Cookies: section 10 explains which ones we set. We load analytics after you accept them, and not before.
3Why we use it, and on what basis
The GDPR lets us use personal data when we have a legal basis for it. The list below pairs each use with its basis.
Where we rely on legitimate interest, we have weighed your interests against ours. You can object to that use at any time; section 8 tells you how.
To contract with you we need your identity, business and payment details. Without them we cannot put you forward, contract an engagement or pay you.
4AI and matching
We use AI in three places.
- Profiles: our system reads your CV and other uploads and structures them into a profile. You check and approve that profile before anyone outside Legate sees it.
- Intake: the AI intake reads the brief you enter and returns a first cut at the scope. The Legate team then works through it with you.
- Matching: we score consultants against a brief on sector context, comparable engagements, confirmed references, working style, availability and rate.
People make the calls that affect you. The Legate team validates each shortlist before it reaches a client, and the client chooses who to hire. We take no decision about you based solely on automated processing that has legal effects on you or affects you in a similar way, as Article 22 of the GDPR describes.
AI output can be wrong or out of date. You can ask us why we put you forward, and you can ask a person at Legate to review any outcome our systems produced about you.
The AI providers we use process your data on our instructions. Section 5 covers who they are, and section 6 covers data that leaves the EU.
5Who sees your data
Other users of Legate
- Clients see a consultant's profile once that consultant approves the specific match. Until then, no client sees it.
- Consultants and firms see a client's brief once the client approves sharing it with them.
- Both sides of an engagement see the full price, including what Legate earns on it.
- Firms see the ledger entries that concern their own relationships.
Service providers
We use outside providers to run Legate. They work on our instructions, under a data processing agreement, and may use your data for nothing but their service to us.
- Hosting, storage and databases
- AI models and search infrastructure
- Email and other communication
- Scheduling of calls, on servers in the EU
- Accounting, invoicing and payment
- Website analytics, for visitors who accept analytics cookies
Email [privacy@asklegate.co] and we send you the current list of providers.
Others
- The Dutch Tax Administration, courts and regulators, when the law requires it.
- Our lawyers, accountants and auditors, who owe us confidentiality.
- A buyer or investor, if we sell or merge all or part of Legate. They take over the commitments in this policy.
We do not sell your personal data.
6Data outside the EU
We store your data within the European Economic Area. Some of our providers, AI providers among them, may process data outside it.
When they do, we rely on an adequacy decision by the European Commission, such as the EU-US Data Privacy Framework, or we sign the Commission's Standard Contractual Clauses with the provider and add safeguards where the destination country calls for them. Ask us and we send you a copy of the safeguards that apply to your data.
7How long we keep it
We keep data for as long as we need it for the purpose we collected it for, and delete or anonymise it after that.
Search indexes and AI-derived records follow the data they came from. Deleted data can remain in our backups until the backup cycle overwrites it, and we do not restore it from there for any other use.
8Your rights
The GDPR gives you these rights over your data:
- Access: ask for a copy of the personal data we hold about you.
- Correction: have wrong or incomplete data fixed. You edit most of your profile yourself.
- Deletion: have your data deleted, apart from what the law obliges us to keep.
- Restriction: have us pause the use of your data while we sort out a dispute about it.
- Objection: object to any use based on our legitimate interest. When you object to marketing, we stop.
- Portability: receive the data you gave us in a common, machine-readable format. Your verified references also sit in a credential you own and can use away from Legate.
- Withdrawing consent: take back consent you gave, for example for analytics cookies. That does not undo what we did before.
- Human review: ask a person at Legate to review an outcome our systems produced about you.
Email [privacy@asklegate.co] to use any of these rights. We may ask you to confirm your identity first. We answer within one month, and if a request needs longer we tell you within that month and take at most two more.
If you think we mishandle your data, tell us, so we can put it right. You can also complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority, at autoriteitpersoonsgegevens.nl.
9Security and breaches
We protect your data with technical and organisational measures:
- We encrypt data in transit and at rest.
- Our team gets access to the data their work requires, behind multi-factor authentication.
- Our staff and providers are bound by confidentiality.
- We review our security measures and the providers we use.
No security measure rules out a breach altogether.
If a breach puts personal data at risk, we report it to the Autoriteit Persoonsgegevens within 72 hours of discovering it. If the breach is likely to put you at high risk, we tell you as well, with what happened and what you can do to protect yourself.
11Age
Legate is a platform for professionals. You need to be 18 or older to use it. If we learn that we hold data about someone younger, we delete it.
12Changes to this policy
We update this policy when the way we handle data changes. The date at the top of the page shows which version you are reading.
If a change affects how we use data you have already given us, we email you before it takes effect. Questions about this policy go to [privacy@asklegate.co].
