This policy explains what Platingoes B.V. (“Platingoes”, “we”) does with personal data collected through platingoes.app and the Platingoes app. We wrote it to be read, not to be survived. Short version: we ask for an email address, we measure the product with our own analytics, and we do not sell anything about you.
Who is responsible
Platingoes B.V., Van Diemenstraat 410, 1013 CR Amsterdam, Netherlands is the controller for the processing described here. Data protection questions go to [email protected] and are answered by a human within five working days.
What we collect, and why
| Data | Purpose | Legal basis | Kept for |
|---|---|---|---|
| Email address, kitchen type (home, professional, teaching) | Beta invitations and one launch announcement | Consent: Art. 6(1)(a) GDPR | Until you unsubscribe, then 30 days |
| Salted hash of your IP address at signup | Abuse and duplicate-signup protection | Legitimate interest: Art. 6(1)(f) | 12 months |
| Aggregate page and feature analytics (no cookies, no cross-site identifiers) | Understanding which parts of the app people actually use | Legitimate interest: Art. 6(1)(f) | 14 months, aggregated |
| Purchase records (order ID, amount, VAT country) | Fulfilling and accounting for a purchase | Contract: Art. 6(1)(b); tax law | 7 years (Dutch tax retention) |
| Support messages you send us | Answering you | Contract / legitimate interest | 24 months |
| Recipes, timers and notes you create in the app | Running the app for you | Contract: Art. 6(1)(b) | On your device; deleted with the app unless you sync |
What we deliberately do not do
- No advertising networks, no ad pixels, no retargeting.
- No sale or rental of personal data. Ever, to anyone.
- No third-party fonts, maps or embeds on this website. The typefaces you are reading are served from our own domain, so Google never sees your visit.
- No behavioural profiling and no automated decision-making with legal effect.
- No microphone access on the website. In-app voice control (“next”, “repeat that”) is recognised on the device and is never uploaded.
Who processes data for us
- Hosting: Hetzner Online GmbH, Falkenstein and Nuremberg, Germany (EU).
- Transactional email: Postmark (Wildbit LLC), used under the EU–US Data Privacy Framework and an SCC-backed data processing agreement.
- Payments: Mollie B.V., Amsterdam. Card data never touches our servers.
- App distribution: Apple Distribution International and Google Ireland, who process purchase data as independent controllers under their own policies.
Every processor works under a data processing agreement. Where data leaves the EEA, it is covered by Standard Contractual Clauses plus a transfer impact assessment we will happily send you.
Your rights
You may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interest. Withdrawing consent is one click in any email we send. Write to [email protected]; we do not require an account to honour a request. If you think we got it wrong, you can complain to the Autoriteit Persoonsgegevens (Dutch DPA) or your local supervisory authority.
Children
Platingoes is not directed at children under 16. We do not knowingly collect their data. If a parent or guardian tells us we have, we delete it.
Security
Transport encryption everywhere, encrypted backups, least-privilege access, and a short internal list of people who can read the waitlist. We keep an incident log and will notify affected users and the DPA within 72 hours of a qualifying breach.
Changes
If we change how we handle data in a way that affects you, we will update this page and, where consent is involved, ask again rather than assume.
Drafting note for the Platingoes team: this page ships with the theme as a complete starting point for a Dutch/EU launch. Have counsel review it and then delete this paragraph before go-live.