Privacy Policy

Privacy, trust and transparency

This policy explains how MyCompanyDesk protects your data, manages access and ensures that your business data stays secure.

Effective date: 1 June 2026

Our commitment

Privacy commitments

We design our platform around clear access controls, strong auditing and data minimisation.

Data minimisation

We collect only what we need to operate the platform. No unnecessary data collection.

Access controls

Role-based permissions keep sensitive data restricted to the people you invite.

Transparency

Clear documentation and export options at all times. You always know how your data is used.

Data controller

Data controller

The data controller for the processing of your personal data under the General Data Protection Regulation (GDPR) is:

Domain: MyCompanyDesk

Operated by: Sil van Rijnberk

Contact: [email protected] | +31 6 133 382 99

Supervisory authority: Autoriteit Persoonsgegevens (Dutch Data Protection Authority), www.autoriteitpersoonsgegevens.nl

TLS
Encrypted connections
2FA
Two-factor and passkeys
Daily
Backups of your data
GDPR
Compliant
Data collection

Information we collect

We only process personal data where there is a lawful basis to do so.

Account details

Name, username, email address and company information needed to provide the service.

Business data

Invoices, expenses, quotes, customer details, contracts and VAT data that you enter into the platform.

Usage data

Logins, device information and feature usage analytics to improve the service.

Payment details

Billing information, processed through our trusted payment providers.

Legal basis

Legal basis for processing

Under Article 6 of the GDPR, we process your personal data on the following legal bases.

Performance of a contract

Processing necessary to provide the MyCompanyDesk service you have signed up for (Art. 6(1)(b) GDPR), including account management, invoicing and data storage.

Legal obligation

Processing that is required by law (Art. 6(1)(c) GDPR), such as the statutory tax retention obligation (Art. 52 AWR, 7-year retention of financial records) and tax filing.

Legitimate interest

Processing based on our legitimate interest (Art. 6(1)(f) GDPR), such as platform security, fraud prevention and service improvement, balanced against your rights and freedoms.

Consent

Where we rely on your consent (Art. 6(1)(a) GDPR), such as for optional analytics cookies, you can withdraw your consent at any time without affecting the prior processing.

Data usage

How we use information

Service delivery

Providing, operating and improving the MyCompanyDesk services.

Security

Authenticating users and securing accounts.

Payments

Processing payments and issuing invoices or receipts.

Communications

Sending updates, service notices and support responses.

Compliance

Complying with legal and regulatory obligations.

Tracking features

Invoice and document tracking

To help our users understand how their customers interact with invoices and documents, MyCompanyDesk uses the following tracking techniques. These are applied on behalf of our users (who act as the data controller for their own customers).

Tracking of opened emails

Invoice emails may contain a small transparent image (tracking pixel). When the email is opened and the image is loaded, an "email opened" event is recorded, together with a privacy-preserving hash of the recipient's IP address, the date and time, and user agent information.

Tracking of opened PDFs

Downloaded PDF invoices may contain an embedded tracking image. When the PDF is opened in a viewer that loads external resources, a "PDF opened" event is recorded with the same privacy-preserving data as email tracking.

Tracking of portal interactions

When customers view invoices through the customer portal, actions such as viewing, downloading, copying payment details and confirming payment are logged, so that the invoice sender gains insight into delivery and engagement.

Privacy safeguards

All tracking data is stored with privacy-preserving measures: IP addresses are hashed (only the first 8 characters of a SHA-256 hash are retained), user agent strings are truncated, and events are accessible only to the invoice sender. Tracking data is subject to our standard retention policy.

Protection

Data protection and security

Security measures

Administrative, technical and physical safeguards protect your information. Access to production data is restricted.

Cookies and analytics

Essential cookies keep sessions secure. Analytics help us understand usage patterns and improve workflows.

Data processors

We work with vetted providers for hosting, email and payments, bound by confidentiality agreements.

International transfers

Standard contractual clauses ensure data protection when it is processed outside your region.

Sub-processors

Who we work with

For hosting, payments, email and AI we use carefully selected subprocessors. A data processing agreement is in place with each of them. Transfers outside the EU take place under Standard Contractual Clauses (SCC) or the EU-US Data Privacy Framework (DPF). You can verify the current DPF certification status of US processors at dataprivacyframework.gov/list. Business customers can consult our standard data processing agreement (DPA).

Hosting and infrastructure

Hetzner, application servers, Germany.
Neon, production database, Frankfurt.
Cloudflare, edge, security, R2 storage, Workers, EU plus global edge.
Amazon S3, backups and attachments, Stockholm (eu-north-1).

Email delivery

Resend, transactional email from mycompanydesk.com, EU.
Cloudflare Email Routing, receiving mail in your inbox on your own domain, global edge.

Payments

Mollie, online payments on invoices, the Netherlands.
Stripe, subscription payments, United States, DPF-certified.

Banking connection

Enable Banking, PSD2 bank connection, EU (Finland). Only active if you connect your bank.

AI and language models

Google Vertex AI (Gemini), contextual assistant, invoice and receipt suggestions, region europe-west1 (Frankfurt). No training on your data, no retention by the vendor.
Cloudflare Workers AI, fast classification of incoming email and receipts, embeddings for search, global edge. No training on your data; inference is transient and is not stored.

Optional integrations

Google OAuth (Gmail), only if you connect your own Gmail account. MyCompanyDesk requests the gmail.send scope only: we send the emails you compose in MyCompanyDesk on your behalf. We do not read, import or store your Gmail messages or mailbox. We store only the OAuth token needed to send, and you can disconnect at any time. United States, DPF-certified.
Microsoft OAuth (Outlook), only if you connect your own Outlook account, EU plus United States, DPF-certified.

Google API Limited Use

MyCompanyDesk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from your Gmail connection is used solely to send the emails you compose in MyCompanyDesk. We share it only with Google, to deliver your outgoing mail through the Gmail API; MyCompanyDesk does not share, transfer, or disclose Google user data to any other third party. It is never used for advertising, never sold, and never used to train AI or ML models.

Security

Cloudflare Turnstile, bot and abuse detection at sign-up and sign-in, EU plus global edge.

Company lookup

KVK API and overheid.io, looking up trade register details during sign-up and when adding customers, the Netherlands.

AI and transparency

AI-generated answers and suggestions

MyCompanyDesk uses AI for the contextual assistant, invoice and receipt suggestions, classification of incoming email and summaries. In line with the transparency obligation of Article 50 of the EU AI Act (applicable from August 2026), we make this explicitly clear in the user interface at the places where AI is active. Answers from the assistant are AI-generated and may contain errors; always verify financial or tax conclusions yourself before acting on them. The AI calls run via Google Vertex AI (region europe-west1) and Cloudflare Workers AI; neither provider uses your data to train their models or retains conversations any longer than strictly necessary to deliver the answer.

Your rights

Your privacy rights

You have control over your personal data.

Access

Access and receive a copy of your personal data.

Correction

Request correction of inaccurate or incomplete data.

Deletion

Request deletion of your data, subject to legal obligations.

Objection

Object to or restrict certain processing activities.

Portability

Data portability where applicable.

Withdraw consent

Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing (Art. 7(3) GDPR).

Lodge a complaint

You have the right to lodge a complaint with the Autoriteit Persoonsgegevens via autoriteitpersoonsgegevens.nl.

Policies

Retention and response

Data retention

We retain personal data only for as long as necessary to provide the service, comply with legal requirements, resolve disputes and enforce agreements. You can request deletion at any time.

  • Financial records (invoices, expenses, VAT): 7 years after the end of the relevant fiscal year, as required by Dutch tax law (Art. 52 Algemene wet inzake rijksbelastingen).
  • Account data: retained while your account is active and deleted upon an account deletion request, unless retention is required by law.
  • Audit and security logs: retained for up to 12 months for security and fraud prevention purposes.
  • Analytics data: aggregated and anonymised; raw data deleted within 90 days.
  • Free-domain fraud prevention list: when a workspace uses the included-free .nl perk that comes with an Office trial or Office subscription, we retain a minimal record (KVK number, SHA-256 hash of the claimed domain, claim date) for up to 5 years after the workspace is deleted. Legal basis: legitimate interest under Art. 6(1)(f) GDPR and the Art. 17(3)(e) exception to erasure for fraud prevention. The record contains no name, email, IP, or plaintext domain.

Incident response

In the event of a data breach, we report it to the Autoriteit Persoonsgegevens within 72 hours (Art. 33 GDPR). If the breach is likely to result in a high risk to your rights, we also notify you without undue delay (Art. 34 GDPR). Our response plan includes containment, investigation, remediation and communication.

Additional information

Additional statements

Children's data

MyCompanyDesk is a business tool and is not intended for use by persons under the age of 16 (in accordance with Article 8 GDPR and the Dutch UAVG). We do not knowingly collect personal data from children. If we discover that a child under the age of 16 has provided us with personal data, we delete it immediately.

Automated decision-making

MyCompanyDesk does not use automated decision-making or profiling that produces legal effects or similarly significant effects concerning you (Art. 22 GDPR). Any analyses we carry out are solely for service improvement and do not affect your rights or access to the platform.

Questions about privacy?

For any privacy-related questions, please contact us at [email protected]. We may update this privacy policy from time to time; the latest version is always available here.