Privacy Policy
I am committed to protecting your personal data. This Privacy Policy explains what personal data I collect, why I collect it, how I use and store it, and what rights you have under the General Data Protection Regulation (GDPR) and the Dutch implementation thereof (Algemene Verordening Gegevensbescherming, AVG).
By creating an account or using my Services, you acknowledge that you have read and understood this Privacy Policy. If you have any questions or wish to exercise your rights, please contact me at ricardo@exploremyspace.eu.
Data Controller
I am responsible for your personal data, reachable at ricardo@exploremyspace.eu. As the data controller, I determine the purposes and means of processing your personal data and am fully responsible for ensuring that my processing activities comply with the GDPR and AVG.
If you have questions, concerns, or requests regarding your personal data, you may contact me at any time using the email address above. I will respond to all data subject requests within the timeframes required by law.
Data I Collect
I only collect personal data that is strictly necessary to deliver my Services to you. Below is a clear overview of the categories of personal data I store and why each category is needed.
Your full name, email address, and company name (if applicable). Required to create and manage your account.
Street address, city, postal code, state/province, and country. Required for invoicing and tax compliance.
Your phone number and associated country code, where you choose to provide them. This information is optional and may be used for account-related communication or support when needed.
Business VAT identification number where applicable. Used for EU VAT compliance on invoices.
Payment method type, card brand, and the last 4 digits only. Full card numbers are never stored by me and are handled exclusively by Stripe.
Details of your active and past subscriptions, payments, and invoices. Required for billing history and legal financial record-keeping.
IP address, browser user agent, login timestamps, and session identifiers. Used to manage authenticated sessions and detect unauthorized access.
Password data, two-factor authentication (2FA) credentials, passkey credentials, and related account security information needed to protect your account and support secure login features.
Used for account notifications, invoices, service updates, and responding to your requests. I do not send unsolicited marketing emails.
How I Use Your Data
I use the personal data I collect only for the following specific purposes. I do not process your data for any purpose that is incompatible with the reason it was originally collected.
- 1
Account management — to create and maintain your account, verify your identity, and provide access to my Services.
- 2
Billing and invoicing — to process payments, generate invoices, apply VAT correctly, and maintain financial records required by law.
- 3
Service delivery — to provide subscriptions and deliver the Services you have signed up for.
- 4
Security and fraud prevention — to detect and prevent unauthorized access, account takeovers, and fraudulent activity using login and session data.
- 5
Communication — to send transactional emails such as payment confirmations, subscription updates, and responses to your support requests.
- 6
Legal compliance — to meet my obligations under applicable Dutch and EU law, including financial record-keeping requirements.
Legal Basis For Processing
Under the GDPR and AVG, I am required to have a lawful basis for each type of personal data processing. The legal bases I rely on are listed below.
- Contract
Performance of a contract (Article 6(1)(b) GDPR) — Processing your account identity, billing address, payment details, and subscription data is necessary to provide the Services you have agreed to receive.
- Legal Obligation
Compliance with a legal obligation (Article 6(1)(c) GDPR) — Retaining invoices and financial records is required under Dutch tax and accounting law.
- Legitimate Interest
Legitimate interests (Article 6(1)(f) GDPR) — Storing session data, IP addresses, and login history is necessary to protect the security of my platform and your account from unauthorized access and fraud.
Security Measures
I take the security of your personal data seriously. I implement technical and organizational measures appropriate to the risk level of the data I process.
Passwords are stored using strong one-way cryptographic hashing. Plain-text passwords are never stored or logged.
Two-factor authentication data and recovery-related account security data are handled as restricted account security information and are not displayed publicly.
Billing addresses are stored only where needed for invoicing and account administration.
Only the last 4 digits and card brand are stored. Full card numbers are never held by me, and payment processing is handled by Stripe.
IP addresses are stored only in session and audit records for security purposes and are not shared with third parties for tracking.
WebAuthn and passkey-related account security data is used only for secure authentication and account access control.
Data Retention
I retain personal data for as long as it is needed to provide and operate your account, comply with legal obligations, and support the Services you use. Specific retention periods may differ depending on the type of data and whether your account remains active or has been deleted.
- 1
Account data — retained for as long as your account exists. If your account is deleted, some related data may also be removed, while certain records may be retained where required for legal, billing, fraud prevention, or administrative purposes.
- 2
Invoices and financial records — retained for 7 years as required by Dutch tax law.
- 3
Session data and login records — retained for up to 1 year for security, account access control, and fraud prevention purposes.
- 4
Deleted accounts — if your account is deleted, some personal data may be removed or no longer actively used, but certain records may remain where retention is required for legal, billing, fraud prevention, dispute handling, or other legitimate business purposes.
Third-Party Services
I work with a limited number of trusted third-party processors and service providers to deliver my Services. Each party only receives the data necessary to perform its specific role. Where a third party processes personal data on my behalf, I take appropriate steps to ensure that such processing is carried out in accordance with the GDPR and applicable data protection requirements.
For transparency, I list below the providers that have direct influence over my domain, network, and security, or that receive customer data from me. I do not list every tool I use to build and maintain my Services (for example, source code hosting or package registries used during development) if that tool has no influence over my domain and does not receive personal data such as your IP address or email address.
Stripe handles payment processing for my Services. I may share your name, email address, billing address, VAT information, and limited payment-related information with Stripe where necessary to create customer records, process payments, and issue invoices. Full payment card details are processed directly by Stripe and are not stored by me. See stripe.com.
Cloudflare provides DNS resolution and network security features for my domain, including protection against malicious traffic and bot/CAPTCHA challenges. As a result, Cloudflare may process technical data such as your IP address as part of routing and securing traffic to my Services. See cloudflare.com.
My servers are hosted within the EU. Personal data is stored and processed on infrastructure selected to support secure service delivery. I do not transfer personal data outside the EEA without an appropriate legal basis and, where required, appropriate safeguards.
I use CookiePal to run the cookie consent banner on my website and to record your cookie preferences. CookiePal does not receive your customer account data from me. See cookiepal.io.
I use Instatus to host my public status page, which reports the operational status of my Services. Instatus does not receive your customer account data from me. See instatus.com.
Your Rights Under GDPR
As a data subject under the GDPR and AVG, you have the following rights regarding your personal data. To exercise any of these rights, contact me at ricardo@exploremyspace.eu. I will respond within one month of receiving your request.
- 1
Right of access (Article 15) — You may request a copy of all personal data I hold about you, along with information about how and why it is processed.
- 2
Right to rectification (Article 16) — You may request that I correct any inaccurate or incomplete personal data I hold about you. Most account data can also be updated directly in your account settings.
- 3
Right to erasure (Article 17) — You may request that I delete your personal data where it is no longer necessary for the purpose it was collected, subject to any overriding legal retention obligations.
- 4
Right to restriction of processing (Article 18) — You may request that I limit the processing of your personal data in certain circumstances, such as while a dispute about accuracy is being resolved.
- 5
Right to data portability (Article 20) — You may request a machine-readable copy of the personal data you provided to me, where processing is based on your consent or a contract.
- 6
Right to object (Article 21) — You may object to the processing of your personal data where I rely on legitimate interests as my legal basis.
- 7
Right to lodge a complaint — If you believe your data is being processed unlawfully, you have the right to file a complaint with the Dutch data protection authority: Dutch Data Protection Authority.
Cookies & Sessions
I use strictly necessary session cookies to maintain your authenticated session after you log in. I also use CookiePal to display a cookie consent banner and record your cookie preferences. These cookies do not track you across other websites and are not used for advertising or analytics.
A secure, HTTP-only session identifier stored in a cookie. This is required to keep you logged in while you navigate my portal. It expires when your session ends or at the configured session timeout.
A cookie set by CookiePal to remember your cookie consent choices, so that you are not asked again on every visit.
I do not use Google Analytics, Meta Pixel, or any other third-party tracking cookies. Your browsing behaviour on my platform is not profiled or shared with advertisers.
Because I only use strictly necessary cookies, I am not required to display a cookie consent banner under the Dutch Telecommunications Act. I choose to display one via CookiePal regardless, for transparency. You may block cookies in your browser settings, which will prevent you from logging in to my Services.
Changes To This Policy
I may update this Privacy Policy from time to time to reflect changes in my Services or applicable law. When I make material changes, I will notify you by email to your registered address and update the "Last updated" date at the top of this page.
I encourage you to review this policy periodically. Continued use of my Services after a policy update constitutes your acknowledgment of the revised policy.
Contact Me
If you have any questions about this Privacy Policy, wish to exercise your data rights, or want to report a privacy concern, please contact me directly. I aim to respond to all requests within 30 days.