Privacy Policy

Privacy, Trust, and Transparency

This policy explains how MyCompanyDesk protects data, keeps access controlled, and ensures that billing and rental records remain secure.

Effective date: 1 January 2024

Our Commitment

Privacy Commitments

We design our platform around clear access controls, strong auditing, and data minimization.

Data Minimization

We collect only what we need to operate the platform. No unnecessary data gathering.

Access Controls

Role-based permissions keep sensitive data restricted to authorized team members only.

Transparency

Clear documentation and export options at all times. You always know how your data is used.

Data Controller

Data Controller

The controller responsible for processing your personal data under the General Data Protection Regulation (GDPR) is:

Domain: MyCompanyDesk

Operated by: Sil van Rijnberk

Contact: support@mycompanydesk.com | +31 6 401 196 17

Supervisory authority: Autoriteit Persoonsgegevens (Dutch Data Protection Authority), www.autoriteitpersoonsgegevens.nl

24/7
Monitoring Coverage
100%
Audit Trail Coverage
99.9%
Availability Target
GDPR
Compliant
Data Collection

Information We Collect

We only process personal data when there is a lawful basis to do so.

Account Details

Name, username, email address, and company information needed to provide the service.

Business Data

Invoices, assets, rental contracts, and VAT data you input into the platform.

Usage Data

Logins, device information, and feature usage analytics to improve the service.

Payment Details

Billing information processed through our trusted payment providers.

Legal Basis

Legal Basis for Processing

Under Article 6 of the GDPR, we process your personal data based on the following legal grounds.

Contract Performance

Processing necessary for providing the MyCompanyDesk service you signed up for (Art. 6(1)(b) GDPR) — including account management, invoicing, and data storage.

Legal Obligation

Processing required by law (Art. 6(1)(c) GDPR), such as the Dutch fiscal retention obligation (Art. 52 AWR — 7-year retention of financial records) and tax reporting.

Legitimate Interest

Processing based on our legitimate interest (Art. 6(1)(f) GDPR), such as platform security, fraud prevention, and service improvement — balanced against your rights and freedoms.

Consent

Where we rely on your consent (Art. 6(1)(a) GDPR), such as for optional analytics cookies, you may withdraw consent at any time without affecting prior processing.

Data Usage

How We Use Information

Service Operation

Provide, operate, and improve the MyCompanyDesk services.

Security

Authenticate users and secure accounts.

Payments

Process payments and issue invoices or receipts.

Communications

Send updates, service notices, and support responses.

Compliance

Comply with legal and regulatory obligations.

Tracking

Invoice & Document Tracking

To help our users understand how their customers interact with invoices and documents, MyCompanyDesk uses the following tracking technologies. These are applied on behalf of our users (who act as data controllers for their own customers).

Email Open Tracking

Invoice emails may contain a small transparent image (tracking pixel). When the email is opened and the image is loaded, an “email opened” event is recorded, including a privacy-preserving hash of the recipient’s IP address, the date/time, and user-agent information.

PDF Open Tracking

Downloaded invoice PDFs may contain an embedded tracking image. When the PDF is opened in a viewer that loads remote resources, a “PDF opened” event is recorded with the same privacy-preserving data as email tracking.

Portal Interaction Tracking

When customers view invoices through the customer portal, actions such as viewing, downloading, copying payment details, and confirming payment are recorded to provide the invoice sender with delivery and engagement insights.

Privacy Safeguards

All tracking data is stored with privacy-preserving measures: IP addresses are hashed (only the first 8 characters of a SHA-256 hash are retained), user-agent strings are truncated, and events are only accessible to the invoice sender. Tracking data is subject to our standard data retention policies.

Protection

Data Protection & Security

Security Measures

Administrative, technical, and physical safeguards protect your information. Access to production data is restricted.

Cookies & Analytics

Essential cookies keep sessions secure. Analytics help us understand usage patterns and improve workflows.

Data Processors

We work with vetted providers for hosting, email, and payments, bound by confidentiality agreements.

International Transfers

Standard contractual clauses ensure data protection when processed outside your region.

Your Rights

Your Privacy Rights

You have control over your personal data.

Access

Access and receive a copy of your personal data.

Correction

Request correction of inaccurate or incomplete data.

Deletion

Request deletion of your data, subject to legal obligations.

Objection

Object to or restrict certain processing activities.

Portability

Data portability where applicable.

Withdraw Consent

Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing (Art. 7(3) GDPR).

Lodge a Complaint

You have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Dutch Data Protection Authority) at autoriteitpersoonsgegevens.nl.

Policies

Retention & Response

Data Retention

We retain personal data only as long as necessary to provide the service, meet legal requirements, resolve disputes, and enforce agreements. You can request deletion at any time.

  • Financial records (invoices, expenses, VAT): 7 years after the end of the relevant fiscal year, as required by Dutch tax law (Art. 52 Algemene wet inzake rijksbelastingen).
  • Account data: Retained while your account is active and deleted upon account deletion request, unless retention is required by law.
  • Audit and security logs: Retained for up to 12 months for security and fraud prevention purposes.
  • Analytics data: Aggregated and anonymised; raw data deleted within 90 days.

Incident Response

If a personal data breach occurs, we will notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware (Art. 33 GDPR). If the breach is likely to result in a high risk to your rights, we will also notify you without undue delay (Art. 34 GDPR). Our response plan includes containment, investigation, remediation, and communication.

Additional Information

Additional Disclosures

Children's Data

MyCompanyDesk is a business tool and is not intended for use by individuals under the age of 16 (in accordance with Article 8 GDPR and the Dutch UAVG). We do not knowingly collect personal data from children. If we become aware that a child under 16 has provided us with personal data, we will delete it promptly.

Automated Decision-Making

MyCompanyDesk does not use automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22 GDPR). Any analytics we perform are for service improvement only and do not affect your rights or access to the platform.

Questions About Privacy?

Contact us at support@mycompanydesk.com for any privacy-related questions. We may update this Privacy Policy from time to time — the latest version will always be available here.