Legal

Privacy statement

Last updated: [FILL IN]. Version 1.0.

Note: this is a working text based on standard conventions. Have it reviewed by a lawyer before launch or use a validated generator.

Who are we?

BilingualEpub is a trade name of [FILL IN — company name B.V.], based at [FILL IN — postal address Amsterdam], registered with the Dutch Chamber of Commerce (KvK) under number [FILL IN — KvK number], VAT number [FILL IN — NL...B01]. We are the data controller within the meaning of the GDPR. For questions about your personal data, reach us via the contact page.

Which data do we process?

  • On purchase: email address, optionally name and billing address, payment data (processed by Stripe; we never receive your full card number), order history and VAT-relevant invoice details.
  • On account use: email address, login session and authentication token (processed by Clerk).
  • On newsletter sign-up: email address, language preference and timestamp. You can unsubscribe from any email.
  • Technical: IP address, user-agent and server logs for security, fraud prevention and debugging.

Why (legal bases)?

  • Performance of contract (art. 6(1)(b) GDPR): delivering your order, providing account and download functionality.
  • Legal obligation (art. 6(1)(c) GDPR): tax retention duty and VAT filings (7 years).
  • Legitimate interest (art. 6(1)(f) GDPR): fraud prevention, security, technical diagnostics. Our balancing test is available on request.
  • Consent (art. 6(1)(a) GDPR): newsletter subscription. You can withdraw consent at any time.

Who do we share with?

  • Stripe Payments Europe Ltd. (Ireland) — payments, invoicing, fraud detection.
  • Clerk Inc. (United States) — authentication and session management.
  • Resend Inc. (United States) — sending transactional emails (order confirmation, download links).
  • Vercel Inc. (United States) and Neon (United States/EU) — hosting, database and file storage.
  • Technical service providers (United States): solely for processing book texts and producing cover illustrations. For books you upload yourself, the contents of your file are processed there. These parties receive no account or payment data and may not use the content for their own purposes.

We have signed a data processing agreement (DPA) with each of these parties documenting GDPR-compliant arrangements. We do not sell or rent your data.

Transfers outside the EEA

Several of our processors (Clerk, Resend, Vercel and our technical service providers) are based in the United States. Transfers occur on the basis of the EU-US Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023) and/or the European Commission's standard contractual clauses (SCCs), supplemented by appropriate technical and organisational measures. Stripe processes primarily within Ireland (EU).

Security

We protect your data with TLS encryption in transit, encrypted storage at our hosting and database providers, hashed password handling (by Clerk), strict access control and logging of administrative actions. We never see your password. In the event of a personal data breach with a risk to your rights and freedoms, we report it to the Dutch Data Protection Authority within 72 hours and to you where required by law.

Automated decision-making and profiling

We do not make decisions about you based solely on automated processing. We do not perform profiling for marketing purposes. Stripe does apply automated fraud detection to payments; you may request human review via the contact page.

How long do we keep data?

  • Order and invoice data: 7 years (fiscal retention duty, art. 52 Dutch General Tax Act).
  • Account data: until you delete your account; 30 days afterwards in backups.
  • Download tokens: 1 year after last use, deleted thereafter.
  • Server and security logs: 30 days max.
  • Newsletter subscriptions: until you unsubscribe; kept 6 months thereafter to prevent duplicate sign-ups.

Your rights

Under the GDPR you have the right of access (art. 15), rectification (art. 16), erasure (art. 17), restriction of processing (art. 18), objection (art. 21), data portability (art. 20) and withdrawal of consent. Email us via the contact page — we respond within one month. We may ask for additional information to verify your identity. If you have a complaint about how we handle your data, you may file it with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

Data Protection Officer

We have not appointed a Data Protection Officer (DPO) because our core activities do not involve large-scale or sensitive personal data processing (art. 37 GDPR). For privacy questions, please email our contact page.

Cookies

We use only strictly necessary / functional cookies: a Clerk session cookie for login, a Stripe cookie during checkout, and a NEXT_LOCALE cookie to remember your language preference. We use no tracking, analytics, or marketing cookies and place no third-party tracking pixels. Functional cookies do not require consent under art. 11.7a Dutch Telecommunications Act.

Changes

We may update this statement. The date at the top shows the most recent change. Material changes will be communicated by email to customers.