This statement explains which personal data CleverPrism processes as a controller: when you visit this website, sign up, pay, contact us, or use your environment. For personal data that customers put into their own CleverPrism environment, the customer is the controller and we are the processor; see our data processing agreement.
1Who we are
CleverPrism B.V., Eindhoven, the Netherlands, registered with the Dutch Chamber of Commerce under number 42175200, is responsible for the processing described here. CleverPrism is part of the Clever group. You can reach us at [email protected] or +31 40 293 9003.
2Visiting this website
This website uses no cookies, no analytics and no tracking. We do not build visitor profiles.
To deliver the website and protect it against abuse, our hosting provider and Cloudflare, which protects and speeds up the website, process technical data such as your IP address, browser type and the time of your visit. They keep these server logs for a limited period for security and troubleshooting only. Legal basis: our legitimate interest in a secure, working website (Article 6(1)(f) GDPR).
3Signing up, billing and administration
When your organisation subscribes, we process:
- company name, address and VAT number;
- name and email address of the person who signs up, and of contacts for billing and support;
- subscription details, invoices and payment status;
- payment details. These are handled by our payment provider Stripe (Stripe Payments Europe, Ltd., Ireland). We do not see or store full card numbers; for direct debit we see the account holder and the last digits of the IBAN.
We use these data to conclude and perform the agreement, to invoice and collect payments, and to comply with our legal obligations, such as tax and accounting rules. Legal basis: performance of the agreement and legal obligation (Article 6(1)(b) and (c) GDPR).
Stripe also processes payment data under its own responsibility, for example to prevent fraud and to comply with financial regulations; see Stripe's privacy policy.
4Using your environment
To give your users access and keep the environment secure, we process the email addresses of users who may log in (login codes are sent to them), the email address of the password vault administrator, and technical logs of the environment such as IP addresses, timestamps and errors. We do not collect prompts or AI answers in these logs. Legal basis: performance of the agreement and our legitimate interest in a secure, reliable service (Article 6(1)(b) and (f) GDPR).
We send service emails, for example about invoices, failed payments, renewals, maintenance and security. We do not send newsletters or marketing email without your consent.
5When you contact us
If you call or email us, we use your name, contact details and message to answer you and to follow up on your question. Legal basis: our legitimate interest in handling your question, or taking steps at your request before entering into an agreement (Article 6(1)(f) and (b) GDPR).
6How long we keep your data
| Data | Retention |
|---|---|
| Invoices, payment and other administrative records | 7 years, as required by Dutch tax law |
| Customer and contact details | For the duration of the agreement and 60 days after it ends, unless they are part of the administrative records above |
| User accounts of the environment | For the duration of the agreement and 60 days after it ends |
| Technical logs of the environment | At most 90 days |
| Contact requests that do not lead to an agreement | As long as needed to handle the request, at most one year |
7Who receives your data
We do not sell personal data. We share it only with parties that help us provide our service, under an agreement that protects your data, or when the law requires us to:
- CleverIT B.V. (Clever group, Eindhoven): data centre, network, email and hosting of this website;
- Cloudflare: protection of this website and secure access to customer environments;
- Stripe: payments, invoices and the customer portal;
- our accountant, and authorities if we are legally obliged to provide data.
8Transfers outside the EEA
Our own systems and customer environments are in the Netherlands. Cloudflare and Stripe may process data outside the European Economic Area, including in the United States. They do so on the basis of the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses (Chapter V GDPR).
9Security
We protect personal data with appropriate technical and organisational measures, such as encrypted connections, a separate server per customer, strict access control and monitoring. If you believe your data is not secure or has been misused, please contact us right away.
10Your rights
You have the right to access, correct or delete your personal data, to restrict or object to its processing, and to receive your data in a portable format (Articles 15 to 21 GDPR). Send your request to [email protected]. We respond within one month. We may ask you to confirm your identity; we never ask for a copy of your passport or identity card.
If your request concerns data in a customer's environment, we forward it to that customer, because the customer is the controller for that data.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).
11Changes
We may update this privacy statement. The version and date at the top show when it was last changed. We inform customers by email of important changes.