πPrivacy Policy
How we collect, use, and protect your personal information when using our services.
Governing Law: Dutch law, jurisdiction in the Netherlands
Last updated: October 2025
π’Controller
Important information
β’ Taxsoar, Rotterdam, The Netherlands
β’ Contact: legal@taxsoar.com
β’ We are the controller for the personal data described in this policy
πInformation We Collect
Types of personal and service data we collect from users
Personal Information
We may collect the following categories of data (as applicable and when required):
β’ Name, email address, phone number, BSN, RSIN, KVK, VAT and business details
β’ Information you voluntarily provide when contacting us or using our services
Service Data
β’ Documents and information necessary to perform bookkeeping services
β’ Tax compliance and advisory service materials
Usage Data
β’ Basic technical information automatically transmitted when you visit our site
β’ IP address, browser type, device type, pages visited
Cookies
β’ We use essential cookies for security, session management, and preferences (e.g., theme and navigation).
β’ We use Zoho Analytics to collect statistical usage data to improve our website and services
β’ We use Zoho SalesIQ to provide website chat and support
β’ For details, see our Cookie Policy (including how to manage cookies and consent where required)
β’ We use Zoho SalesIQ to provide website chat and support
β’ For details, see our Cookie Policy (including how to manage cookies and consent where required)
Electronic signing data
β’ Signer identity (name, email)
β’ Document content and signing status
β’ Audit-trail data: timestamps, IP address, device/browser info
β’ Cryptographic proofs/hashes generated by the e-signature provider
βοΈHow We Use Your Information
Ways we utilize collected information for service delivery
Service Provision
β’ To provide and improve our professional services
β’ To communicate with you regarding inquiries, contracts, or support
Legal Compliance
β’ To comply with legal and regulatory obligations
β’ Tax law, AML/KYC requirements
β’ BSN/RSIN/VAT processing relies on legal obligation (Art. 6(1)(c) GDPR) and is restricted by Dutch law (UAVG Article 46 β only where a law permits use of the BSN)
β’ To improve website functionality and security
Legal bases (GDPR)
β’ Contract (Art. 6(1)(b)) β to provide services and execute documents
β’ Legal obligation (Art. 6(1)(c)) β statutory retention, AML/KYC
β’ Legitimate interests (Art. 6(1)(f)) β security, fraud prevention, evidencing transactions (incl. e-signature audit trail)
πData Sharing
How and when we might share your information with third parties
Our Policy
β’ We do not sell or trade your personal data
β’ Information shared only where necessary to deliver services
β’ BSN/RSIN/VAT disclosure is limited to authorities and processors strictly necessary to meet legal obligations (e.g., tax authorities/accounting platforms). We do not use BSN as a general identifier or share it for marketing
Service Providers
β’ Carefully selected service providers or professional partners
β’ External tax specialists, IT/cloud service providers
β’ Such parties are bound by confidentiality and data protection safeguards
Legal Requirements
β’ We may disclose information if legally required to regulators or authorities when mandated by law
Processors
β’ Hosting/CDN; EU database & storage
β’ Accounting platforms
β’ E-signature provider(s)
β’ Email/SMS delivery; authentication/security
β’ We sign Data Processing Agreements (DPAs) with all processors and use EU data residency where available
πInternational transfers
How we deal with international Transfers
Our storage
β’ We primarily store personal data in the EU
β’ If limited transfers occur (e.g., support/telemetry), we use Standard Contractual Clauses (SCCs) or equivalent safeguards
π Data Retention
How long we keep your data and deletion policies
Retention Period
β’ We retain client documents and service-related data only as long as necessary
β’ To meet legal obligations (e.g., statutory retention requirements), signed PDFs, e-signature audit certificates, all legal documents and agreements are stored in our EU storage for the engagement term + 7 years after termination of said engagement
β’ Where supported, we configure our e-signature provider to purge its copy shortly after completion.
β’ BSN within statutory records is retained for the legal retention period (~ 7 years for business records). Outside those records we delete or mask the BSN
Data Minimization
β’ Non-essential personal identifiers are minimized where possible
β’ BSN, private addresses, phone numbers reduced when feasible
Secure Deletion
β’ When retention is no longer required, data is securely deleted
β’ Or anonymized according to data protection standards
π‘οΈData Security
Technical and organizational measures to protect your data
Protection Measures
β’ Technical and organizational measures to protect your data
β’ Against loss, unauthorized access, misuse, or disclosure
β’ Webhooks: we verify signed webhook requests (e.g., HMAC) and process them securely
β’ No PII in URLs: we do not include personal data in query strings or webhook URLs; we use opaque IDs
β’ Minimisation & masking: BSN is also not shown in logs, URLs, or email subjects; UI shows redacted where possible
β’ Access control: BSN is restricted to authorised roles; transmission only over TLS; never placed in webhook/query strings
β’ Access is restricted to authorized personnel only
βοΈYour Rights
Your rights under GDPR and data protection laws
GDPR Rights
Contact legal@taxsoar.com
β’ Access the personal data we hold about you
β’ Correct inaccuracies in your data
β’ Request deletion where legally permitted
β’ Restrict or object to certain types of processing
β’ Request portability of your data to another provider
β’ We respond to requests within 1 month (may be extended by up to 2 months for complex requests; we will notify you)
β’ To protect your data, we may ask you to verify your identity (email/account verification; only whatβs necessary
)
β’ You can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe we are not complying
