
Our Approach
At Easy2Name, we believe it is important that customers can shop safely and that personal data is handled with care. On this page, we explain how we approach security, privacy, payments, AI, cookies, third-party service providers and vulnerability reporting. This page provides an overview of our security and data policy. For the full legal details, please also refer to our Privacy Policy, Cookie Policy, Terms & Conditions and Returns Policy.
At a Glance
Goedgemerkt follows these key principles: we only process personal data that is necessary for providing our services, meeting legal obligations, ensuring security, delivering customer support, or where permitted for analytics and marketing purposes. We use personal data only for clear and legitimate purposes. We do not store payment card details in our own systems. Payments are processed through Stripe’s secure external payment platform. Access to customer data is restricted to employees and service providers who require it to perform their duties. We implement appropriate technical and organisational security measures. Our systems are monitored, tested and assessed for vulnerabilities. We use AI only as a support tool within customer service. Personal data is not used to train external AI models. Customers can exercise their privacy rights in accordance with the GDPR.
Goedgemerkt does not claim independent ISO 27001 certification unless this is explicitly stated on this page.
Who Is Responsible for Your Data
Easy2Name.com is operated by Goedgemerkt B.V., registered at Cobolweg 3, 3821 BJ Amersfoort, the Netherlands.
Our Chamber of Commerce (KvK) registration number is 32119030 and our VAT number is NL817123015B01. For general enquiries, please contact customerservice@easy2name.com. For privacy-related enquiries, you can contact Desanne Valkenberg at desanne@goedgemerkt.nl. For security-related enquiries or to report security issues, please contact Bas Koesveld at bas@goedgemerkt.nl.
For the processing activities described on this page, Goedgemerkt is the data controller within the meaning of the General Data Protection Regulation (GDPR).
If you have any questions about privacy, security or personal data, you can contact us via customerservice@easy2name.com, by telephone on +01635 298326, or via our website: Easy2Name.com.
Organisation and Security Governance
Easy2Name is part of CCL Industries, a publicly listed international company. Across the wider CCL Group, security governance, controls and processes are in place to support secure and reliable business operations.
Personal data is not shared more widely within the Group than is necessary for purposes such as hosting, security, system management, compliance, administration or service delivery.
Within Easy2Name, we have internal responsibilities for privacy, security and data protection. Access to personal data is restricted to employees and service providers who require it to carry out their work.
What Personal Data We Process
We process the personal data that is necessary to provide our products and services.
This may include your name and address, email address, telephone number, order details, billing information, personalisation details such as names, text or other content printed on labels, communications with our customer service team, technical information such as your IP address, browser information, cookie data and website usage, as well as marketing preferences, for example when you subscribe to our newsletter.
As our products are often ordered for children, personalisation details may also include names or text relating to children. We use this information solely for production, delivery, customer service and, where applicable, repeat orders.
We ask customers not to enter unnecessary sensitive personal data into personalisation fields, such as medical information, religious beliefs or other special category personal data, unless this is genuinely required for the selected product.
Purposes of Processing and GDPR Legal Bases
We process personal data only where there is a valid legal basis under the GDPR.
| Purpose | Examples | GDPR Legal Basis |
|---|---|---|
| Order fulfilment | Production, personalisation, delivery and order communications | Performance of a contract |
| Customer service | Responding to enquiries, handling complaints and providing support | Performance of a contract or legitimate interests |
| Administration | Invoicing, accounting and statutory tax retention requirements | Legal obligation |
| Website security | Logging, fraud prevention, abuse prevention and security investigations | Legitimate interests |
| Marketing communications | Newsletters and promotional emails | Consent, or legitimate interests where legally permitted for existing customers and similar products or services |
| Cookies and tracking | Analytics, advertising measurement and personalisation | Consent where required |
| Service improvement | Analysis of website usage, customer interactions and ordering processes | Legitimate interests or consent, depending on the data and technology used |
We do not use personal data for purposes other than those for which it was collected, unless this is permitted or required by law.
Data Minimisation
Easy2Name does not process more personal data than is necessary for the purpose for which it was provided.
This means, among other things, that we only request the information required to process your order, arrange delivery, handle payments, provide customer support or meet administrative obligations. We also restrict access to customer data, do not retain personal data for longer than necessary, and only share it with third parties where this is required to deliver our services, maintain security or comply with legal obligations.
Security Measures
We implement appropriate technical and organisational measures to protect personal data and our systems against loss, misuse, unauthorised access, alteration and disclosure.
Our security measures include, among other things, secure connections using HTTPS and TLS, encrypted password storage, role-based access controls, application of the principle of least privilege, firewall rules, protection against brute-force attacks, a Web Application Firewall (WAF), protection against DDoS attacks through providers including Cloudflare, logging and monitoring of suspicious activity, vulnerability scanning, incident response processes, and regular security risk assessments.
We review our security measures on a regular basis and update them whenever risks, technologies or legal requirements change.
Monitoring, pentests and vulnerability management
To strengthen the security of our systems, we use multiple security assessment and monitoring mechanisms.
These include:
- Regular independent penetration testing at both application and network level;
- Periodic penetration testing by specialised external security partners, including Cyberlab;
- Vulnerability scanning of systems and infrastructure;
- Professional security tools for monitoring and vulnerability management;
- Active monitoring of suspicious activity and security risks;
- Internal processes for the detection, assessment and response to security incidents.
When a potential vulnerability is identified, we assess its risk and potential impact. We then determine the appropriate remediation measures and the timeframe within which they should be implemented.
Website and Account Security
We take measures to protect customer accounts and website data.
These measures include, among other things, HTTPS, TLS encryption, encrypted password storage, rate limiting, firewall rules, protection against unauthorised access, restricted employee access, and logging and monitoring where appropriate.
We also recommend that customers use a strong, unique password and never share their account credentials with others.
Payments
We use Stripe as our external payment provider. More information is available on Stripe.
This means that Easy2Name does not store full payment card details within its own systems. Payments are processed through Stripe's secure payment platform, which supports secure payment processing in accordance with the PCI DSS standard. Easy2Name only receives the information necessary to process payments, fulfil orders, manage administration and provide customer support.
PCI DSS is the international security standard for organisations that process payment card transactions. By using Stripe, we minimise the amount of payment data processed within our own environment.
Third-Party Service Providers, Data Processors and Other Recipients
For certain aspects of our services, we use third-party service providers. We only share the personal data that is necessary for the specific purpose. Where required, we enter into data processing agreements or other appropriate contractual arrangements with these parties. Below are the main providers with whom we directly work.
This list may change as our services, systems or suppliers evolve. We assess third-party service providers to ensure they offer appropriate safeguards for privacy and information security.
Some parties may act as independent data controllers for specific processing activities, for example where they are legally required to process personal data or determine their own processing purposes. Where applicable, we refer you to the relevant provider's own privacy information.
| Service Provider or Platform | Purpose | Personal Data That May Be Shared |
|---|---|---|
| Stripe | Payment processing | Payment transaction information |
| Analytics, advertising measurement and marketing | Cookie data, website usage data and technical information | |
| Meta/Facebook | Advertising and campaign analytics | Marketing data, cookie data and pseudonymised data where possible |
| Microsoft/Bing | Advertising and campaign analytics | Marketing data, cookie data and pseudonymised data where possible |
| CCL Industries Group | Infrastructure, security governance, system management and compliance | Only the data necessary for management, security or service delivery |
| AI customer service provider | Customer service support | Only the information and context required to assist with customer enquiries |
| Logistics providers | Shipping and delivery | Name, address, contact details and shipping information |
| Email service providers | Transactional emails and newsletters | Email address, name, order status and marketing preferences |
Use of AI in Customer Service
Within our customer service operations, we use AI to assist with answering specific customer enquiries and retrieving order information.
AI may help draft, structure or speed up responses to customer enquiries. However, AI does not make independent decisions regarding customers, orders, payments, returns or complaints.
The following safeguards apply:
- AI does not have independent access to complete customer profiles;
- Our employees remain responsible for all final decisions and customer communications;
- Sensitive personal data is not proactively shared with AI systems;
- Personal data is not used to train external AI models;
- AI is not used for automated decision-making that produces legal or similarly significant effects for customers;
- We only share the information necessary to respond appropriately to a customer's enquiry.
Where a customer enquiry contains personal or sensitive information, we carefully assess which data is required to handle the request appropriately.
Cookies and Tracking
We use cookies and similar technologies to ensure our website functions properly, to improve its performance and, where you have given your consent, to personalise marketing and advertising.
We use functional cookies, for example to support your shopping basket and login, analytical cookies to measure and improve website usage, and marketing cookies for advertising measurement and personalisation.
Consent is not always required for functional cookies or limited privacy-friendly analytical cookies. However, we obtain your consent before placing marketing cookies, tracking cookies and analytical cookies that have more than a minimal impact on privacy. You can change or withdraw your cookie preferences at any time through the cookie settings on our website.
For more information, please see our Cookie Policy.
International Data Transfers and Data Storage
Where possible, we store personal data within the European Union (EU) or the European Economic Area (EEA).
Where personal data is processed or accessed outside the European Economic Area, we do so only where appropriate safeguards are in place. These may include data processing agreements, the European Commission's Standard Contractual Clauses (SCCs), additional technical and organisational measures, or other legally recognised transfer mechanisms.
For each service provider, we assess what personal data is processed, where the processing takes place, and which privacy and security safeguards apply.
Data Retention Periods
We do not retain personal data for longer than is necessary for the purpose for which it was collected, unless we are legally required to keep it for a longer period.
| Type of Data | Retention Period |
|---|---|
| Order and invoice data | 7 years to comply with tax and accounting obligations |
| Account data | For as long as the account remains active, or earlier if deletion is requested and no legal retention obligation applies |
| Personalisation data | For as long as required for production, delivery, customer service and any repeat orders |
| Customer service communications | Up to 2 years after the last contact, unless a longer retention period is required for an ongoing enquiry, complaint or legal dispute |
| Marketing consent | Until consent is withdrawn |
| Newsletter data | Until you unsubscribe or withdraw your consent |
| Cookie data | In accordance with the retention periods set out in our Cookie Policy |
| Security logs | Generally up to 12 months, unless a longer retention period is required for security, fraud prevention, incident investigations or legal claims |
Once the applicable retention period has expired, we delete or anonymise personal data unless continued retention is required or permitted by law.
Data Breaches and Incident Response
We have internal processes in place to identify, assess and respond to security incidents and potential personal data breaches.
Where a potential data breach occurs, we investigate what happened, assess which personal data may have been affected and evaluate the potential risks to the individuals concerned. We also take appropriate measures to limit any potential impact, record the incident where required, notify the relevant supervisory authority where legally required, and inform affected individuals where required by applicable law.
Your Privacy Rights
Under the GDPR, you have the following rights, among others:
- The right to access your personal data;
- The right to rectify inaccurate personal data;
- The right to erasure;
- The right to restrict processing;
- The right to data portability;
- The right to object to processing;
- The right to withdraw your consent;
- The right to lodge a complaint with the Dutch Data Protection Authority (Dutch Data Protection Authority).
If you wish to exercise any of your rights, please contact us at: customerservice@easy2name.com
We will respond as soon as possible and no later than within the statutory time limits. In most cases, we aim to provide a substantive response within one week. For complex requests or where multiple requests are submitted at the same time, the legal response period may be extended. If this happens, we will inform you accordingly.
To help protect your personal data, we may ask you to provide additional information to verify your identity where necessary.
Report a Vulnerability
If you believe you have discovered a vulnerability in our website, systems or processes, we kindly ask you to report it responsibly.
You can report a vulnerability by emailing it@goedgemerkt.nl or by calling +01635 298326. Please use Security Report as the subject line.
When submitting a report, we ask that you provide sufficient information for us to investigate the issue, refrain from exploiting the vulnerability, do not access, modify, copy or delete data belonging to others, do not disrupt our systems, and do not disclose the vulnerability publicly until we have had the opportunity to investigate and, where necessary, resolve it.
We treat all security reports with care and, where possible, will provide you with feedback on the outcome.
Contact
Do you have any questions about privacy, security or how we use your personal data? Or would you like to exercise your privacy rights?
Please contact us:
Email: customerservice@easy2name.com
Telephone: +01635 298326
Website: Easy2Name.com
Related Documents
For more information, please refer to:
Key Facts
| Subject | Information |
|---|---|
| Website | Easy2Name.com |
| Organisation | Goedgemerkt B.V. |
| Address | Cobolweg 3, 3821 BJ Amersfoort, The Netherlands |
| Part of | CCL Industries |
| Payment Provider | Stripe |
| DDoS Protection | Cloudflare |
| Privacy Contact | customerservice@easy2name.com |
| Security Reports | security@goedgemerkt.nl |
| Applicable Privacy Law | GDPR |
| AI Training Using Customer Data | No |
| Payment Card Data Stored by Easy2Name | No |
| Easy2Name ISO 27001 Certification | Not independently claimed unless explicitly stated |
Security & Privacy FAQ
Last updated: 26 August 2026
Name Stickers
Clothes Labels
Value Packs
SOS Products
Bottles & Lunch Boxes
Baby Products
School




















































