Privacy statement
Last updated: 2 June 2026
This statement describes how stipt processes personal data and which third parties we work with. stipt provides a software platform to business customers; we act as a processor on behalf of those customers under a data processing agreement.
Who is responsible?
stipt acts as a processor (Article 28 GDPR) on behalf of its customers. The customer is the controller for data stored in stipt, including lead and CRM data. For our own processing, such as account data of customer staff and billing, stipt is the controller.
What data do we process?
On behalf of customers: lead and contact data (name, email, phone, address), CRM records and related communication. For our own service: customer staff account data, technical logs, IP addresses and billing data.
Purposes
Operating and securing the stipt platform, fraud prevention, debugging, billing and meeting legal obligations.
Legal basis
For processing on behalf of customers: the data processing agreement between stipt and the customer; the customer determines its own legal basis towards data subjects. For our own processing: contract performance, legitimate interest and legal obligation.
Retention
Customer data is retained for the duration of the active contract, unless otherwise agreed in writing. Technical logs are retained for 30 days. After contract termination, data is deleted within 30 days unless statutory retention rules require otherwise.
Data subject rights
Data subjects have the right to access, rectification, erasure, restriction, objection and data portability. For data we process on behalf of a customer, requests must be directed to the controller (our customer). For our own processing, requests can be sent to [email protected]. You have the right to lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).
International transfers
Some of our sub-processors (Anthropic, Resend, Supabase, Meta) are based in the United States or have a US parent company. Where a customer enables the WhatsApp channel, message content and contact identifiers are processed through the WhatsApp Business Platform (Meta Platforms Ireland Limited), which may transfer data to the United States. Transfers rely on the European Commission's Standard Contractual Clauses (SCCs). Where possible we select EU regions for storage and processing.
Security
Encryption in transit (TLS 1.2+) and at rest (AES-256). Integration credentials and the email addresses and phone numbers in the contact file are additionally encrypted at the application level, with a separate key per customer environment. Access is enforced through Row Level Security per organisation. Two-factor authentication is available on all customer accounts.
Data breaches
In the event of a breach affecting a customer's data, we will notify that customer without undue delay and no later than 24 hours after discovery, in line with our data processing agreement. The customer, as controller, then handles any notification to the Dutch Data Protection Authority.
Changes
We may update this statement. Changes will be published on this page; material changes will be actively communicated to customers.
Contact
Questions about privacy or security? Email [email protected].
Sub-processors
We engage the following sub-processors. We have a data processing agreement with each, providing protection at least equivalent to our agreement with the customer.
| Processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application hosting | EU (Germany) |
| Supabase Inc. | Database, authentication, secrets management | EU (Frankfurt), US parent company, SCCs |
| Resend Inc. | Transactional email | US, EU-US DPF / SCCs |
| Meta Platforms Ireland Limited | WhatsApp Business messaging | EU (Ireland), US transfers under SCCs |
| Anthropic PBC | AI models for classification and text generation | US, SCCs |
| Cohere Inc. | Making the knowledge base and documents searchable | US, SCCs |
| Sentry (Functional Software, Inc.) | Error monitoring | EU (Germany) |
| OpenAI LLC | AI models, only if selected by the customer | US, EU-US DPF / SCCs |
| Google LLC (Gemini) | AI models, only if selected by the customer | EU/US, EU-US DPF |
| Mistral AI SAS | AI models, only if selected by the customer | EU (France) |
Services you connect to stipt yourself, such as your own email provider (Microsoft 365, Google Workspace, IMAP) or integrations you configure in workflows, process on your own instructions and are not sub-processors of stipt. For geocoding addresses (planning, travel times, map display) we share only address and location data with Google Maps Platform and OpenStreetMap Nominatim, which act as independent controllers. Public government data services (PDOK, 3D BAG, PVGIS) queried only with address or location data are not sub-processors either.