Legal
Privacy Policy
Last updated: 27 July 2026
This policy explains how AppCustomCraft ("we", "us") collects, uses and protects personal data when you visit our website, request a discovery call, subscribe to our newsletter, or use our client portal. We process personal data in line with the EU General Data Protection Regulation (GDPR / AVG).
1. Who is the controller?
The data controller is AppCustomCraft, registered in Utrecht, The Netherlands. KVK: 42124410. VAT: Aanvraag in behandeling. For any privacy question you can contact us at privacy@appcustomcraft.com.
2. What data we collect
- Contact & lead data — name, email, company, phone, message you provide via the discovery call form, project brief, or support widget.
- Newsletter data — email address and subscription source.
- Account & portal data — email, hashed password (managed by our auth provider), role, profile info, tasks, files and messages you create inside the portal.
- Usage data — anonymous analytics on pages visited, device, referrer, and interaction events used to improve the site.
- Technical data — IP address, browser, timestamps, security logs.
3. Why we process it (legal bases)
- Performing a contract — to answer your request, deliver our services, host your portal and provide support.
- Legitimate interest — to secure our site, prevent abuse, measure aggregate traffic and improve the product.
- Consent — for the newsletter and non-essential cookies. You can withdraw consent at any time.
- Legal obligation — accounting, tax and applicable Dutch/EU law.
4. How long we keep it
- Leads & discovery requests: up to 24 months from last contact.
- Newsletter: until you unsubscribe.
- Portal accounts: while active + 12 months after deactivation.
- Invoicing & contracts: 7 years (Dutch tax law).
- Security & server logs: up to 12 months.
5. Who we share it with (subprocessors)
We only share data with vetted processors that support GDPR compliance. Current subprocessors:
- Supabase — authentication, database and file storage (EU region).
- Microsoft Azure — infrastructure for Enterprise Cloud Native customers (EU region).
- Cloudflare — CDN, DNS and DDoS protection.
- Brevo — transactional and marketing email delivery (EU).
- Resend — transactional email delivery fallback.
- Google — Search Console and privacy-friendly analytics.
An up-to-date list is available on request at privacy@appcustomcraft.com.
6. International transfers
We prioritise EU-hosted services. Where a subprocessor operates outside the EU/EEA, transfers rely on Standard Contractual Clauses and supplementary safeguards.
7. Your rights (GDPR)
You have the right to access, rectify, erase, restrict, port or object to the processing of your personal data, and to withdraw consent at any time. Requests: privacy@appcustomcraft.com. You can also file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
8. Security
We apply appropriate technical and organisational measures: TLS in transit, encryption at rest, least-privilege access, role-based access control in the portal, audit logs, and regular backups.
9. Changes
We may update this policy to reflect changes in our services or the law. Material changes will be announced on this page.
