Go Back
Legal & Privacy
EN NL
Jump To Section
01Data Controller 02Data I Collect 03How I Use It 04Legal Basis 05Security Measures 06Data Retention 07Third Parties 08Your Rights 09Cookies & Sessions 10Policy Changes 11Contact Me
Privacy Questions?

For any questions about your personal data, data access requests, or deletion requests, contact me directly.

ricardo@exploremyspace.eu
Legal

Privacy Policy

Last updated: August 26, 2026 GDPR / AVG Compliant 11 Sections

I am committed to protecting your personal data. This Privacy Policy explains what personal data I collect, why I collect it, how I use and store it, and what rights you have under the General Data Protection Regulation (GDPR) and the Dutch implementation thereof (Algemene Verordening Gegevensbescherming, AVG).

By creating an account or using my Services, you acknowledge that you have read and understood this Privacy Policy. If you have any questions or wish to exercise your rights, please contact me at ricardo@exploremyspace.eu.

On This Page
  • Data Controller
  • Data I Collect
  • How I Use Your Data
  • Legal Basis For Processing
  • Security Measures
  • Data Retention
  • Third-Party Services
  • Your Rights Under GDPR
  • Cookies & Sessions
  • Changes To This Policy
  • Contact Me
01

Data Controller

I am responsible for your personal data, reachable at ricardo@exploremyspace.eu. As the data controller, I determine the purposes and means of processing your personal data and am fully responsible for ensuring that my processing activities comply with the GDPR and AVG.

If you have questions, concerns, or requests regarding your personal data, you may contact me at any time using the email address above. I will respond to all data subject requests within the timeframes required by law.

02

Data I Collect

I only collect personal data that is strictly necessary to deliver my Services to you. Below is a clear overview of the categories of personal data I store and why each category is needed.

Account Identity

Your full name, email address, and company name (if applicable). Required to create and manage your account.

Billing Address

Street address, city, postal code, state/province, and country. Required for invoicing and tax compliance.

Phone Number

Your phone number and associated country code, where you choose to provide them. This information is optional and may be used for account-related communication or support when needed.

VAT Number

Business VAT identification number where applicable. Used for EU VAT compliance on invoices.

Payment Information

Payment method type, card brand, and the last 4 digits only. Full card numbers are never stored by me and are handled exclusively by Stripe.

Subscription & Invoice Records

Details of your active and past subscriptions, payments, and invoices. Required for billing history and legal financial record-keeping.

Session & Login Data

IP address, browser user agent, login timestamps, and session identifiers. Used to manage authenticated sessions and detect unauthorized access.

Authentication Credentials

Password data, two-factor authentication (2FA) credentials, passkey credentials, and related account security information needed to protect your account and support secure login features.

Email Address

Used for account notifications, invoices, service updates, and responding to your requests. I do not send unsolicited marketing emails.

I do not sell, trade, or rent your personal data to any third party. All data collected is used solely for the purpose of delivering and improving my Services.
03

How I Use Your Data

I use the personal data I collect only for the following specific purposes. I do not process your data for any purpose that is incompatible with the reason it was originally collected.

  • 1

    Account management — to create and maintain your account, verify your identity, and provide access to my Services.

  • 2

    Billing and invoicing — to process payments, generate invoices, apply VAT correctly, and maintain financial records required by law.

  • 3

    Service delivery — to provide subscriptions and deliver the Services you have signed up for.

  • 4

    Security and fraud prevention — to detect and prevent unauthorized access, account takeovers, and fraudulent activity using login and session data.

  • 5

    Communication — to send transactional emails such as payment confirmations, subscription updates, and responses to your support requests.

  • 6

    Legal compliance — to meet my obligations under applicable Dutch and EU law, including financial record-keeping requirements.

04

Legal Basis For Processing

Under the GDPR and AVG, I am required to have a lawful basis for each type of personal data processing. The legal bases I rely on are listed below.

  • Contract

    Performance of a contract (Article 6(1)(b) GDPR) — Processing your account identity, billing address, payment details, and subscription data is necessary to provide the Services you have agreed to receive.

  • Legal Obligation

    Compliance with a legal obligation (Article 6(1)(c) GDPR) — Retaining invoices and financial records is required under Dutch tax and accounting law.

  • Legitimate Interest

    Legitimate interests (Article 6(1)(f) GDPR) — Storing session data, IP addresses, and login history is necessary to protect the security of my platform and your account from unauthorized access and fraud.

05

Security Measures

I take the security of your personal data seriously. I implement technical and organizational measures appropriate to the risk level of the data I process.

Password Hashing

Passwords are stored using strong one-way cryptographic hashing. Plain-text passwords are never stored or logged.

2FA Protection

Two-factor authentication data and recovery-related account security data are handled as restricted account security information and are not displayed publicly.

Address Protection

Billing addresses are stored only where needed for invoicing and account administration.

Card Data Truncation

Only the last 4 digits and card brand are stored. Full card numbers are never held by me, and payment processing is handled by Stripe.

IP Address Handling

IP addresses are stored only in session and audit records for security purposes and are not shared with third parties for tracking.

Passkey Credential Security

WebAuthn and passkey-related account security data is used only for secure authentication and account access control.

In the event of a data breach that is likely to result in a risk to your rights and freedoms, I will notify you and the relevant supervisory authority (Dutch Data Protection Authority) within 72 hours of becoming aware of it, as required by Article 33 and 34 of the GDPR.
06

Data Retention

I retain personal data for as long as it is needed to provide and operate your account, comply with legal obligations, and support the Services you use. Specific retention periods may differ depending on the type of data and whether your account remains active or has been deleted.

  • 1

    Account data — retained for as long as your account exists. If your account is deleted, some related data may also be removed, while certain records may be retained where required for legal, billing, fraud prevention, or administrative purposes.

  • 2

    Invoices and financial records — retained for 7 years as required by Dutch tax law.

  • 3

    Session data and login records — retained for up to 1 year for security, account access control, and fraud prevention purposes.

  • 4

    Deleted accounts — if your account is deleted, some personal data may be removed or no longer actively used, but certain records may remain where retention is required for legal, billing, fraud prevention, dispute handling, or other legitimate business purposes.

07

Third-Party Services

I work with a limited number of trusted third-party processors and service providers to deliver my Services. Each party only receives the data necessary to perform its specific role. Where a third party processes personal data on my behalf, I take appropriate steps to ensure that such processing is carried out in accordance with the GDPR and applicable data protection requirements.

For transparency, I list below the providers that have direct influence over my domain, network, and security, or that receive customer data from me. I do not list every tool I use to build and maintain my Services (for example, source code hosting or package registries used during development) if that tool has no influence over my domain and does not receive personal data such as your IP address or email address.

Stripe (Payment Processing)

Stripe handles payment processing for my Services. I may share your name, email address, billing address, VAT information, and limited payment-related information with Stripe where necessary to create customer records, process payments, and issue invoices. Full payment card details are processed directly by Stripe and are not stored by me. See stripe.com.

Cloudflare (DNS & Security)

Cloudflare provides DNS resolution and network security features for my domain, including protection against malicious traffic and bot/CAPTCHA challenges. As a result, Cloudflare may process technical data such as your IP address as part of routing and securing traffic to my Services. See cloudflare.com.

Hosting Infrastructure

My servers are hosted within the EU. Personal data is stored and processed on infrastructure selected to support secure service delivery. I do not transfer personal data outside the EEA without an appropriate legal basis and, where required, appropriate safeguards.

CookiePal (Cookie Consent)

I use CookiePal to run the cookie consent banner on my website and to record your cookie preferences. CookiePal does not receive your customer account data from me. See cookiepal.io.

Instatus (Status Page)

I use Instatus to host my public status page, which reports the operational status of my Services. Instatus does not receive your customer account data from me. See instatus.com.

I do not sell, trade, or rent your personal data. I also do not share personal data with advertising networks or unrelated third parties for marketing purposes.
08

Your Rights Under GDPR

As a data subject under the GDPR and AVG, you have the following rights regarding your personal data. To exercise any of these rights, contact me at ricardo@exploremyspace.eu. I will respond within one month of receiving your request.

  • 1

    Right of access (Article 15) — You may request a copy of all personal data I hold about you, along with information about how and why it is processed.

  • 2

    Right to rectification (Article 16) — You may request that I correct any inaccurate or incomplete personal data I hold about you. Most account data can also be updated directly in your account settings.

  • 3

    Right to erasure (Article 17) — You may request that I delete your personal data where it is no longer necessary for the purpose it was collected, subject to any overriding legal retention obligations.

  • 4

    Right to restriction of processing (Article 18) — You may request that I limit the processing of your personal data in certain circumstances, such as while a dispute about accuracy is being resolved.

  • 5

    Right to data portability (Article 20) — You may request a machine-readable copy of the personal data you provided to me, where processing is based on your consent or a contract.

  • 6

    Right to object (Article 21) — You may object to the processing of your personal data where I rely on legitimate interests as my legal basis.

  • 7

    Right to lodge a complaint — If you believe your data is being processed unlawfully, you have the right to file a complaint with the Dutch data protection authority: Dutch Data Protection Authority.

09

Cookies & Sessions

I use strictly necessary session cookies to maintain your authenticated session after you log in. I also use CookiePal to display a cookie consent banner and record your cookie preferences. These cookies do not track you across other websites and are not used for advertising or analytics.

Session Cookie

A secure, HTTP-only session identifier stored in a cookie. This is required to keep you logged in while you navigate my portal. It expires when your session ends or at the configured session timeout.

Cookie Consent Cookie

A cookie set by CookiePal to remember your cookie consent choices, so that you are not asked again on every visit.

No Tracking Cookies

I do not use Google Analytics, Meta Pixel, or any other third-party tracking cookies. Your browsing behaviour on my platform is not profiled or shared with advertisers.

Because I only use strictly necessary cookies, I am not required to display a cookie consent banner under the Dutch Telecommunications Act. I choose to display one via CookiePal regardless, for transparency. You may block cookies in your browser settings, which will prevent you from logging in to my Services.

10

Changes To This Policy

I may update this Privacy Policy from time to time to reflect changes in my Services or applicable law. When I make material changes, I will notify you by email to your registered address and update the "Last updated" date at the top of this page.

I encourage you to review this policy periodically. Continued use of my Services after a policy update constitutes your acknowledgment of the revised policy.

11

Contact Me

If you have any questions about this Privacy Policy, wish to exercise your data rights, or want to report a privacy concern, please contact me directly. I aim to respond to all requests within 30 days.

ricardo@exploremyspace.eu