DutchBSD B.V.
Privacy Notice
Version 1.01 · Effective 9 September 2026
Document versions: 1.00 · 1.01
This document is available in English.
DutchBSD B.V., Neuweg 2F, 1211 LW Hilversum, the Netherlands (KVK 76249956), is responsible for the controller processing described here. Contact privacy@dutchbsd.com.
1. Roles
DutchBSD B.V. is controller for account, billing, security, website, support and product-usage data. A customer is normally controller for personal data it places in Customer Content or collects through a Workspace product; DutchBSD B.V. is then processor under the DPA. Payment and integration providers may be independent controllers for parts of their services.
2. Data we process
- Account and workspace: name, email, authentication status, role, membership, language and settings.
- Billing: plan, order, invoice, VAT and payment status and provider references. DutchBSD B.V. does not intend to store complete payment-card numbers.
- Technical and security: IP address, device/browser data, timestamps, login and audit events, errors, security signals and abuse reports.
- Product use: features used, sites and projects, storage and traffic measurements, workspace actions and preferences.
- Support and communications: messages, attachments, complaints, privacy requests and service-email delivery records.
- Customer-controlled data: content, assets, domains, source history and any other data selected by the customer.
3. Purposes and legal bases
- Provide accounts, products, publication, billing and support: contract or requested pre-contract steps.
- Secure systems, prevent fraud and abuse, keep audit records and defend claims: legitimate interests and legal duties.
- Send verification, security, billing and support messages: contract, legal duty or legitimate interests.
- Keep invoices and tax records: legal duty.
- Measure reliability and improve usability: legitimate interests; consent where required for optional browser technology.
- Optional marketing: consent where required, withdrawable at any time.
4. Sources and recipients
We receive data from you, workspace owners, your use of the service, connected services, payment/email providers and security or abuse reporters. We disclose it only as needed to authorised workspace members; hosting, storage, content-delivery, DNS, email, source-repository, security and payment providers; professional advisers; and public authorities or other parties where law requires it. We do not sell personal data. Current provider information is on the Subprocessors and Service Providers page.
5. International transfers
We prefer EEA processing where practical. For processing outside the EEA, we rely on an adequacy decision, approved standard contractual clauses or another lawful safeguard and add supplementary measures where appropriate. Provider-specific locations and safeguards are described on the provider page and in the relevant provider documentation.
6. Retention
- Active account, workspace and Customer Content: while the contract is active.
- After termination: 30-day export period followed by active-copy deletion or irreversible anonymisation during the next 30 days, unless a legal hold or mandatory duty applies.
- Encrypted database backups, where created: rolling expiry within 35 days.
- Raw web and application logs: normally 30 days; incident-specific extracts may be held for up to 24 months after incident closure.
- Authentication and security audit events: normally 90 days, longer only for an incident, abuse case, dispute or legal claim.
- Invoices, orders and tax records: normally seven years where Dutch administration or tax law requires it.
- Support and complaint records: normally two years after closure, longer for an active dispute or legal duty.
- Agreement and consent evidence: for as long as reasonably needed to demonstrate the agreement and legal compliance.
Until automated customer lifecycle deletion is deployed, termination deadlines are operated manually and recorded. A legal hold pauses only the affected deletion and is documented.
7. Security
Application controls include server-side workspace and capability checks, mandatory TOTP for staff/administrative access, optional customer TOTP, HTTPS/HSTS production settings, secure session and CSRF cookies, login throttling, pinned runtime dependencies, non-root application execution, versioned source/release history and security/audit events. Backup, log and provider controls are enabled and evidenced separately by operations before they are treated as active guarantees. No online service is completely secure.
8. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests, and may withdraw consent without affecting earlier lawful processing. Email privacy@dutchbsd.com. We may verify identity and normally respond within one month. If a request concerns data controlled by a DutchBSD B.V. customer, contact that customer first; we assist the customer where required.
You may complain to the Autoriteit Persoonsgegevens or another competent EEA supervisory authority.
9. Automated decisions and children
We do not make solely automated decisions with legal or similarly significant effects on account users. Security controls may temporarily rate-limit or block suspicious activity, with human review where a restriction continues. Paid accounts are not intended for people under 18.
10. Changes
We show a version and effective date and provide clear notice of material changes. If a new purpose requires consent, we ask before using data for that purpose.