Privacy statement

Last updated: 2 June 2026

This statement describes how stipt processes personal data and which third parties we work with. stipt provides a software platform to business customers; we act as a processor on behalf of those customers under a data processing agreement.

Who is responsible?

stipt acts as a processor (Article 28 GDPR) on behalf of its customers. The customer is the controller for data stored in stipt, including lead and CRM data. For our own processing, such as account data of customer staff and billing, stipt is the controller.

What data do we process?

On behalf of customers: lead and contact data (name, email, phone, address), CRM records and related communication. For our own service: customer staff account data, technical logs, IP addresses and billing data.

Purposes

Operating and securing the stipt platform, fraud prevention, debugging, billing and meeting legal obligations.

Legal basis

For processing on behalf of customers: the data processing agreement between stipt and the customer; the customer determines its own legal basis towards data subjects. For our own processing: contract performance, legitimate interest and legal obligation.

Retention

Customer data is retained for the duration of the active contract, unless otherwise agreed in writing. Technical logs are retained for 30 days. After contract termination, data is deleted within 30 days unless statutory retention rules require otherwise.

Data subject rights

Data subjects have the right to access, rectification, erasure, restriction, objection and data portability. For data we process on behalf of a customer, requests must be directed to the controller (our customer). For our own processing, requests can be sent to [email protected]. You have the right to lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

International transfers

Some of our sub-processors (Anthropic, Resend, Supabase, Meta) are based in the United States or have a US parent company. Where a customer enables the WhatsApp channel, message content and contact identifiers are processed through the WhatsApp Business Platform (Meta Platforms Ireland Limited), which may transfer data to the United States. Transfers rely on the European Commission's Standard Contractual Clauses (SCCs). Where possible we select EU regions for storage and processing.

Security

Encryption in transit (TLS 1.2+) and at rest (AES-256). Integration credentials and the email addresses and phone numbers in the contact file are additionally encrypted at the application level, with a separate key per customer environment. Access is enforced through Row Level Security per organisation. Two-factor authentication is available on all customer accounts.

Data breaches

In the event of a breach affecting a customer's data, we will notify that customer without undue delay and no later than 24 hours after discovery, in line with our data processing agreement. The customer, as controller, then handles any notification to the Dutch Data Protection Authority.

Changes

We may update this statement. Changes will be published on this page; material changes will be actively communicated to customers.

Contact

Questions about privacy or security? Email [email protected].

Sub-processors

We engage the following sub-processors. We have a data processing agreement with each, providing protection at least equivalent to our agreement with the customer.

ProcessorPurposeLocation
Hetzner Online GmbHApplication hostingEU (Germany)
Supabase Inc.Database, authentication, secrets managementEU (Frankfurt), US parent company, SCCs
Resend Inc.Transactional emailUS, EU-US DPF / SCCs
Meta Platforms Ireland LimitedWhatsApp Business messagingEU (Ireland), US transfers under SCCs
Anthropic PBCAI models for classification and text generationUS, SCCs
Cohere Inc.Making the knowledge base and documents searchableUS, SCCs
Sentry (Functional Software, Inc.)Error monitoringEU (Germany)
OpenAI LLCAI models, only if selected by the customerUS, EU-US DPF / SCCs
Google LLC (Gemini)AI models, only if selected by the customerEU/US, EU-US DPF
Mistral AI SASAI models, only if selected by the customerEU (France)

Services you connect to stipt yourself, such as your own email provider (Microsoft 365, Google Workspace, IMAP) or integrations you configure in workflows, process on your own instructions and are not sub-processors of stipt. For geocoding addresses (planning, travel times, map display) we share only address and location data with Google Maps Platform and OpenStreetMap Nominatim, which act as independent controllers. Public government data services (PDOK, 3D BAG, PVGIS) queried only with address or location data are not sub-processors either.