Privacy Policy
This is an English translation of the legally binding Dutch version.
This policy explains how these sides UP handles personal data — information that can identify a real person. It's written to comply with the GDPR (the EU's General Data Protection Regulation), but we've tried to keep it in plain language.
1. Who is responsible for your data
- these sides UP
- De C. Rebecqueplein 20-B, 2518RA The Hague, The Netherlands
- Chamber of Commerce (KvK): 24375418
- Email: info@thesesidesup.nl
Under GDPR, we're the "controller" for your account data — that means we decide how and why it's processed. For personal data that might appear inside the files and records you upload (for example, a lender's name in a loan agreement), you or your organisation are the controller, and we act as a "processor" — we only handle that data to provide the service to you, on your instructions.
2. What personal data we process
- Account data: your name, email address, and phone number if you provide one.
- Usage data: basic activity logs (like who created or edited a record, and when), which help with security and support.
- Data inside your uploads: files you upload — contracts, agreements, condition reports, and similar documents — may contain personal data about other people (for example, a courier's name or an insurer's contact details). We only process this because you've asked us to store and manage it for you.
3. Why we process it, and on what legal basis
- To provide the service (account data, and the content of what you upload) — this is necessary to perform our contract with you.
- For security and support (usage/audit logs) — this is our legitimate interest in keeping these sides UP secure and working properly, balanced against your privacy.
- We don't use your data for marketing, profiling, or any purpose beyond running these sides UP for you.
4. Where your data is stored
Exclusively on a server located in the Netherlands. We don't transfer your data outside the Netherlands, and we don't use servers outside the EU.
We also don't use any third-party software services that can track, extract, or otherwise use your data.
5. Who can see your data
- People in your own organisation, according to the access levels your administrator sets.
- these sides UP staff, only when needed to provide support or keep the service running — never to browse or use your content for any other purpose.
- We never publish, distribute, or share your data — with the public or with any third party — without your prior agreement, except where we're legally required to.
6. Sub-processors
We use one sub-processor to host these sides UP's servers:
- Greenhost B.V. — hosting provider based at Science Park 400, 1098 XH Amsterdam, the Netherlands (KvK 62576593).
We only use sub-processors that keep your data within the Netherlands.
7. How long we keep your data
We keep your data for as long as your account or organisation is active with us. If you ask us to delete your data (see section 9), we'll do so completely.
Remember: these sides UP is not a backup or archive service. We keep your data as part of running the service, not as a long-term archive — please keep your own backups of anything important.
8. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct it, if it's wrong or incomplete.
- Delete it (see section 9).
- Restrict or object to certain processing.
- Receive a copy of your data in a portable format.
To use any of these rights, email us at info@thesesidesup.nl. If you're not happy with how we've handled a request, you can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
9. Getting a copy, or deleting everything
On request, we'll give you a full export of your (or your organisation's) data, or completely and permanently delete it from our servers. We aim to handle these requests within a reasonable time — usually within 30 days.
10. How we keep your data secure
We use reasonable technical and organisational measures to protect your data, including access controls and encrypted connections. No system is completely risk-free, but we take security seriously and keep our practices up to date.
11. If something goes wrong: our data breach procedure
A data breach is any incident where personal data is accidentally or unlawfully lost, altered, disclosed, or accessed without permission — for example, if an attacker gains unauthorised access to our systems.
If we discover a breach, here's what we do, in order:
- Contain it. We act immediately to stop the breach and limit any further exposure — for example, closing off the access point, revoking compromised credentials, or taking affected systems offline if needed.
- Assess it. We work out what happened, what data was involved, and who's affected.
- Notify the authority. Where the breach poses a risk to people's rights or freedoms, we report it to the Autoriteit Persoonsgegevens (the Dutch data protection authority) within 72 hours of becoming aware of it, as GDPR requires.
- Notify affected users as soon as possible. If the breach is likely to put your rights or freedoms at risk, we will tell you directly and without undue delay — we won't wait for the 72-hour authority deadline to also start telling the people affected. We'll explain what happened, what data was involved, what we're doing about it, and what you can do to protect yourself.
- Fix it. We investigate the root cause and take steps to stop it happening again.
We take this seriously: the sooner you know about a breach, the sooner you can protect yourself, so speed matters as much as thoroughness.
12. Do we need a Data Protection Officer?
GDPR only requires a formal Data Protection Officer (DPO) for organisations doing large-scale monitoring or handling large amounts of sensitive data. these sides UP doesn't currently meet that threshold, so we don't have a formal DPO — but you can always reach us directly at info@thesesidesup.nl with any privacy question or concern.
13. Changes to this policy
We may update this policy from time to time — for example, if the service changes or the law requires it. If we make a meaningful change, we'll let you know.
14. Contact us
Questions about this policy or your data? Reach us at info@thesesidesup.nl.