Chat met Jurre

Privacy statement

Laatst bijgewerkt: 22 augustus 2026 · Versie 2.3.0

Sectie A - In het kort

Het belangrijkste in mensentaal

Privacy isn't a box-ticking exercise for us; it's the foundation of Boldcaster. Here you'll read, in plain language, how we handle your data - and why you can feel at ease about it.

What you need to know in 30 seconds

  • Fully GDPR-compliant. No loose-ends approach.
  • All your data is stored in Frankfurt (Germany), on AWS servers. Nothing leaves Europe.
  • Our AI is European. The analysis of your company data runs on Mistral, a French company with servers in the EU. Training on your data is disabled.
  • Other clients technically cannot access your data - Row Level Security at the database level.
  • You can view, export or delete all your data at any time.

Questions?

Email [email protected] - we reply within five business days, often sooner.

Sectie B - De volledige tekst

Juridische uitwerking

1.Who we are and how to reach us

Boldcaster B.V., located at Pieter Baststraat 22-2, 1071 TX Amsterdam. Registered with the Dutch Chamber of Commerce under number 99064340.

Privacy officer: Jurre Roodenburg. Contact: [email protected] · +31 6 21 44 73 71.

2.Which data we process

Account data: name, email address, role within the organization, and optionally phone number and avatar.

Content data: everything you enter into the platform - KPIs, Rocks, strategy canvas, financial inputs, performance reviews, processes, notes.

Technical log data: IP address, browser/device type, timestamps, events (login, error messages) - solely for the purpose of security and stability.

Usage data: when you signed in, how long a session lasted and which modules you opened. No keystrokes, no mouse movements, no content of what you view. We use this to see whether an environment is actually being used and where the platform can improve; it is visible to Boldcaster, not to your colleagues or your employer.

3.Why we process this data

Performance of the contract (art. 6(1)(b) GDPR): to give you access to the platform and the features you use.

Legitimate interest (art. 6(1)(f)): product improvement, security, fraud prevention. We always weigh your interests.

Legal obligation (art. 6(1)(c)): accounting and tax retention obligations.

4.Where your data is stored

All data is stored and processed within the European Union: AWS region Frankfurt (eu-central-1) combined with Supabase (eu-central-1).

The AI that analyzes your company data is Mistral, based in France, with processing on European servers. There is no US party in between that gets to see your strategy, numbers or personnel data.

Meeting recordings and transcripts run through tl;dv, a German company that stores data in European data centers.

5.How long we retain data

Active accounts: for as long as the contract is in effect.

Closed accounts: 30-day recovery window, after which all content data is deleted.

Invoice and accounting data: 7 years, in line with the tax retention obligation.

Usage data: 12 months, then deleted automatically.

6.Who we share data with (sub-processors)

We only engage the parties necessary to run Boldcaster. We have a data processing agreement in place with each of them.

  • AWS - hosting & storage, Frankfurt region (eu-central-1).
  • Supabase - database & authentication, eu-central-1.
  • Mistral AI - AI analysis of your company data. French company, processing in the EU. Training on client data is disabled.
  • tl;dv - recording and transcription of meetings. German company, storage in European data centers. Only if you use this feature.
  • Cloudflare - DDoS protection, DNS, SSL/TLS.
  • TransIP - domain registration (Netherlands).
  • Resend - transactional emails.
  • Calendly - scheduling meetings. Receives your name, email address and the time, no content.
  • Stripe - payment processing (if applicable).

7.If you work through a partner

Some clients use Boldcaster through a partner: an advisory firm or coach who works with the platform while advising their clients. If you work through such a partner, that partner administers your environment and can see everything in it, including data about your team members. That is the same access an administrator within your own organization has. Please inform your team members about this; on request we provide wording you can use.

Your partner cannot access the environments of other clients, and other clients cannot access yours. Your partner cannot change your subscription, your billing details or the ownership of your account. If the collaboration with your partner ends, their access ends and you keep your environment and your data. We remain your point of contact for access, export and deletion.

8.How we secure data

TLS 1.3 in transit, AES-256 at rest. Row Level Security (RLS) at the database level - other clients technically cannot access your data.

Multi-factor authentication for admin access, audit logs on sensitive actions, encrypted backups, annual pentests, private GitHub repositories for the code, Coolify for controlled deployments.

9.Cookies and tracking

We only place functional and strictly necessary cookies. No marketing or analytics cookies without your explicit opt-in.

10.Your rights

You have the right to access, rectification, erasure, data portability, objection and restriction of processing.

You can exercise these in-app (Settings → Privacy) or via [email protected]. We respond within 30 days.

11.Complaints

Have a complaint? Email us first - we're happy to resolve it. If you can't work it out, you can turn to the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

12.Changes

We may update this statement. For material changes we will notify you by email and via an in-app banner, and we will ask for your explicit consent again.

13.Governing law

This privacy statement is governed by Dutch law. Disputes will be submitted to the Amsterdam District Court.