This policy explains how MyCompanyDesk protects your data, manages access and ensures that your business data stays secure.
We design our platform around clear access controls, strong auditing and data minimisation.
We collect only what we need to operate the platform. No unnecessary data collection.
Role-based permissions keep sensitive data restricted to the people you invite.
Clear documentation and export options at all times. You always know how your data is used.
The data controller for the processing of your personal data under the General Data Protection Regulation (GDPR) is:
Domain: MyCompanyDesk
Operated by: Sil van Rijnberk
Contact: [email protected] | +31 6 133 382 99
Supervisory authority: Autoriteit Persoonsgegevens (Dutch Data Protection Authority), www.autoriteitpersoonsgegevens.nl
We only process personal data where there is a lawful basis to do so.
Name, username, email address and company information needed to provide the service.
Invoices, expenses, quotes, customer details, contracts and VAT data that you enter into the platform.
Logins, device information and feature usage analytics to improve the service.
Billing information, processed through our trusted payment providers.
Under Article 6 of the GDPR, we process your personal data on the following legal bases.
Processing necessary to provide the MyCompanyDesk service you have signed up for (Art. 6(1)(b) GDPR), including account management, invoicing and data storage.
Processing that is required by law (Art. 6(1)(c) GDPR), such as the statutory tax retention obligation (Art. 52 AWR, 7-year retention of financial records) and tax filing.
Processing based on our legitimate interest (Art. 6(1)(f) GDPR), such as platform security, fraud prevention and service improvement, balanced against your rights and freedoms.
Where we rely on your consent (Art. 6(1)(a) GDPR), such as for optional analytics cookies, you can withdraw your consent at any time without affecting the prior processing.
Providing, operating and improving the MyCompanyDesk services.
Authenticating users and securing accounts.
Processing payments and issuing invoices or receipts.
Sending updates, service notices and support responses.
Complying with legal and regulatory obligations.
To help our users understand how their customers interact with invoices and documents, MyCompanyDesk uses the following tracking techniques. These are applied on behalf of our users (who act as the data controller for their own customers).
Invoice emails may contain a small transparent image (tracking pixel). When the email is opened and the image is loaded, an "email opened" event is recorded, together with a privacy-preserving hash of the recipient's IP address, the date and time, and user agent information.
Downloaded PDF invoices may contain an embedded tracking image. When the PDF is opened in a viewer that loads external resources, a "PDF opened" event is recorded with the same privacy-preserving data as email tracking.
When customers view invoices through the customer portal, actions such as viewing, downloading, copying payment details and confirming payment are logged, so that the invoice sender gains insight into delivery and engagement.
All tracking data is stored with privacy-preserving measures: IP addresses are hashed (only the first 8 characters of a SHA-256 hash are retained), user agent strings are truncated, and events are accessible only to the invoice sender. Tracking data is subject to our standard retention policy.
Administrative, technical and physical safeguards protect your information. Access to production data is restricted.
Essential cookies keep sessions secure. Analytics help us understand usage patterns and improve workflows.
We work with vetted providers for hosting, email and payments, bound by confidentiality agreements.
Standard contractual clauses ensure data protection when it is processed outside your region.
For hosting, payments, email and AI we use carefully selected subprocessors. A data processing agreement is in place with each of them. Transfers outside the EU take place under Standard Contractual Clauses (SCC) or the EU-US Data Privacy Framework (DPF). You can verify the current DPF certification status of US processors at dataprivacyframework.gov/list. Business customers can consult our standard data processing agreement (DPA).
Hetzner, application servers, Germany.
Neon, production database, Frankfurt.
Cloudflare, edge, security, R2 storage, Workers, EU plus global edge.
Amazon S3, backups and attachments, Stockholm (eu-north-1).
Resend, transactional email from mycompanydesk.com, EU.
Cloudflare Email Routing, receiving mail in your inbox on your own domain, global edge.
Mollie, online payments on invoices, the Netherlands.
Stripe, subscription payments, United States, DPF-certified.
Enable Banking, PSD2 bank connection, EU (Finland). Only active if you connect your bank.
Google Vertex AI (Gemini), contextual assistant, invoice and receipt suggestions, region europe-west1 (Frankfurt). No training on your data, no retention by the vendor.
Cloudflare Workers AI, fast classification of incoming email and receipts, embeddings for search, global edge. No training on your data; inference is transient and is not stored.
Google OAuth (Gmail), only if you connect your own Gmail account. MyCompanyDesk requests the gmail.send scope only: we send the emails you compose in MyCompanyDesk on your behalf. We do not read, import or store your Gmail messages or mailbox. We store only the OAuth token needed to send, and you can disconnect at any time. United States, DPF-certified.
Microsoft OAuth (Outlook), only if you connect your own Outlook account, EU plus United States, DPF-certified.
MyCompanyDesk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from your Gmail connection is used solely to send the emails you compose in MyCompanyDesk. We share it only with Google, to deliver your outgoing mail through the Gmail API; MyCompanyDesk does not share, transfer, or disclose Google user data to any other third party. It is never used for advertising, never sold, and never used to train AI or ML models.
Cloudflare Turnstile, bot and abuse detection at sign-up and sign-in, EU plus global edge.
KVK API and overheid.io, looking up trade register details during sign-up and when adding customers, the Netherlands.
MyCompanyDesk uses AI for the contextual assistant, invoice and receipt suggestions, classification of incoming email and summaries. In line with the transparency obligation of Article 50 of the EU AI Act (applicable from August 2026), we make this explicitly clear in the user interface at the places where AI is active. Answers from the assistant are AI-generated and may contain errors; always verify financial or tax conclusions yourself before acting on them. The AI calls run via Google Vertex AI (region europe-west1) and Cloudflare Workers AI; neither provider uses your data to train their models or retains conversations any longer than strictly necessary to deliver the answer.
You have control over your personal data.
Access and receive a copy of your personal data.
Request correction of inaccurate or incomplete data.
Request deletion of your data, subject to legal obligations.
Object to or restrict certain processing activities.
Data portability where applicable.
Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing (Art. 7(3) GDPR).
You have the right to lodge a complaint with the Autoriteit Persoonsgegevens via autoriteitpersoonsgegevens.nl.
We retain personal data only for as long as necessary to provide the service, comply with legal requirements, resolve disputes and enforce agreements. You can request deletion at any time.
In the event of a data breach, we report it to the Autoriteit Persoonsgegevens within 72 hours (Art. 33 GDPR). If the breach is likely to result in a high risk to your rights, we also notify you without undue delay (Art. 34 GDPR). Our response plan includes containment, investigation, remediation and communication.
MyCompanyDesk is a business tool and is not intended for use by persons under the age of 16 (in accordance with Article 8 GDPR and the Dutch UAVG). We do not knowingly collect personal data from children. If we discover that a child under the age of 16 has provided us with personal data, we delete it immediately.
MyCompanyDesk does not use automated decision-making or profiling that produces legal effects or similarly significant effects concerning you (Art. 22 GDPR). Any analyses we carry out are solely for service improvement and do not affect your rights or access to the platform.
For any privacy-related questions, please contact us at [email protected]. We may update this privacy policy from time to time; the latest version is always available here.