01. Who we are
SoundSprout V.O.F., based at Krachtighuizerkern 18 in Putten, the Netherlands (KVK 99128829). We are the data controller for the data you provide through us. Privacy questions: privacy@soundsprout.nl. Our Data Protection Officer is reachable at the same address.
02. What data we process
We process: account data (name, email, password hash), billing data (address, VAT), platform data (Spotify, Meta), behavioural data (which pages you visit) and usage data (which features you use).
- Account: name, email, hashed password, language preference.
- Spotify integration: artist data only, no private listening history.
- Meta integration: ad-account ID and campaign data, no personal profiles.
- Usage data: anonymised via Plausible, no cookies.
03. What we use it for
Three goals: delivery (we can't run our service without it), improvement (understanding which features work), and communication (product updates, newsletter only after opt-in).
04. How long we keep it
Account data: as long as you have an active account plus 90 days after cancellation. Billing data: 7 years (legal retention period). Platform data: until you disconnect the integration plus 30 days. Marketing cookies: not applicable, we do not use third-party marketing cookies.
05. Your rights
You have the right to access, correct, export or delete your data. Send a request to privacy@soundsprout.nl. We respond within 30 days, in practice usually within 5 business days. You can file a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).
06. Sub-processors
We share your data with these parties, only what is strictly necessary: AWS (hosting, EU), Stripe (payments, EU), Postmark (transactional email, EU) and Sentry (error tracking, EU). The full list including DPA-status is at trust.soundsprout.nl/subprocessors.
07. Security
SOC 2 Type II achieved. AES-256 encryption at rest, TLS 1.3 in transit, multi-factor auth on all internal systems. Full technical details on the Trust & security page.
08. Changes
We announce significant changes by email, at least 30 days before they take effect. Minor changes (typos, clarifications) appear immediately here, with the date at the top.
Vragen?
Privacy questions or complaints? Email privacy@soundsprout.nl. Our DPO responds within 5 business days.