Skip to main content
Privacy Policy
Taxsoar B.V.
Taxsoar B.V.
Financial Services

πŸ“œPrivacy Policy

How we collect, use, and protect your personal information when using our services.

Governing Law: Dutch law, jurisdiction in the Netherlands

Last updated: October 2025

Back to Legal

🏒Controller

Important information

β€’ Taxsoar, Rotterdam, The Netherlands
β€’ Contact: legal@taxsoar.com
β€’ We are the controller for the personal data described in this policy

πŸ“‹Information We Collect

Types of personal and service data we collect from users

Personal Information

We may collect the following categories of data (as applicable and when required):

β€’ Name, email address, phone number, BSN, RSIN, KVK, VAT and business details
β€’ Information you voluntarily provide when contacting us or using our services

Service Data

β€’ Documents and information necessary to perform bookkeeping services
β€’ Tax compliance and advisory service materials

Usage Data

β€’ Basic technical information automatically transmitted when you visit our site
β€’ IP address, browser type, device type, pages visited

Cookies

β€’ We use essential cookies for security, session management, and preferences (e.g., theme and navigation).
β€’ We use Zoho Analytics to collect statistical usage data to improve our website and services
β€’ We use Zoho SalesIQ to provide website chat and support
β€’ For details, see our Cookie Policy (including how to manage cookies and consent where required)

Electronic signing data

β€’ Signer identity (name, email)
β€’ Document content and signing status
β€’ Audit-trail data: timestamps, IP address, device/browser info
β€’ Cryptographic proofs/hashes generated by the e-signature provider

βš™οΈHow We Use Your Information

Ways we utilize collected information for service delivery

Service Provision

β€’ To provide and improve our professional services
β€’ To communicate with you regarding inquiries, contracts, or support

Legal Compliance

β€’ To comply with legal and regulatory obligations
β€’ Tax law, AML/KYC requirements
β€’ BSN/RSIN/VAT processing relies on legal obligation (Art. 6(1)(c) GDPR) and is restricted by Dutch law (UAVG Article 46 β€” only where a law permits use of the BSN)
β€’ To improve website functionality and security

Legal bases (GDPR)

β€’ Contract (Art. 6(1)(b)) β€” to provide services and execute documents
β€’ Legal obligation (Art. 6(1)(c)) β€” statutory retention, AML/KYC
β€’ Legitimate interests (Art. 6(1)(f)) β€” security, fraud prevention, evidencing transactions (incl. e-signature audit trail)

πŸ”’Data Sharing

How and when we might share your information with third parties

Our Policy

β€’ We do not sell or trade your personal data
β€’ Information shared only where necessary to deliver services
β€’ BSN/RSIN/VAT disclosure is limited to authorities and processors strictly necessary to meet legal obligations (e.g., tax authorities/accounting platforms). We do not use BSN as a general identifier or share it for marketing

Service Providers

β€’ Carefully selected service providers or professional partners
β€’ External tax specialists, IT/cloud service providers
β€’ Such parties are bound by confidentiality and data protection safeguards

Legal Requirements

β€’ We may disclose information if legally required to regulators or authorities when mandated by law

Processors

β€’ Hosting/CDN; EU database & storage
β€’ Accounting platforms
β€’ E-signature provider(s)
β€’ Email/SMS delivery; authentication/security
β€’ We sign Data Processing Agreements (DPAs) with all processors and use EU data residency where available

🌍International transfers

How we deal with international Transfers

Our storage

β€’ We primarily store personal data in the EU
β€’ If limited transfers occur (e.g., support/telemetry), we use Standard Contractual Clauses (SCCs) or equivalent safeguards

πŸ“…Data Retention

How long we keep your data and deletion policies

Retention Period

β€’ We retain client documents and service-related data only as long as necessary
β€’ To meet legal obligations (e.g., statutory retention requirements), signed PDFs, e-signature audit certificates, all legal documents and agreements are stored in our EU storage for the engagement term + 7 years after termination of said engagement
β€’ Where supported, we configure our e-signature provider to purge its copy shortly after completion.
β€’ BSN within statutory records is retained for the legal retention period (~ 7 years for business records). Outside those records we delete or mask the BSN

Data Minimization

β€’ Non-essential personal identifiers are minimized where possible
β€’ BSN, private addresses, phone numbers reduced when feasible

Secure Deletion

β€’ When retention is no longer required, data is securely deleted
β€’ Or anonymized according to data protection standards

πŸ›‘οΈData Security

Technical and organizational measures to protect your data

Protection Measures

β€’ Technical and organizational measures to protect your data
β€’ Against loss, unauthorized access, misuse, or disclosure
β€’ Webhooks: we verify signed webhook requests (e.g., HMAC) and process them securely
β€’ No PII in URLs: we do not include personal data in query strings or webhook URLs; we use opaque IDs
β€’ Minimisation & masking: BSN is also not shown in logs, URLs, or email subjects; UI shows redacted where possible
β€’ Access control: BSN is restricted to authorised roles; transmission only over TLS; never placed in webhook/query strings
β€’ Access is restricted to authorized personnel only

βš–οΈYour Rights

Your rights under GDPR and data protection laws

GDPR Rights

Contact legal@taxsoar.com

β€’ Access the personal data we hold about you
β€’ Correct inaccuracies in your data
β€’ Request deletion where legally permitted
β€’ Restrict or object to certain types of processing
β€’ Request portability of your data to another provider
β€’ We respond to requests within 1 month (may be extended by up to 2 months for complex requests; we will notify you)
β€’ To protect your data, we may ask you to verify your identity (email/account verification; only what’s necessary
)
β€’ You can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe we are not complying