Privacy Notice for Reditus

Effective Date: 16 April 2025

At Reditus B.V. (“Reditus”), your privacy is a top priority, and we are fully committed to protecting your personal data. This Privacy Notice outlines how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

1. What Personal Data We Collect and For What Purpose

We process personal data for various purposes, in accordance with the principles of lawfulness, fairness, and transparency. The table below outlines the types of personal data we collect, the purposes of collection, the legal basis for processing, and how long we store your data:

PurposePersonal Data CollectedLegal BasisData Retention Period
Providing our servicesName, email address, password, company name, domain name, usage tracking data, Stripe account events, financial data, IP addressContractual necessityDuring the contract and 2 years after termination; certain data retained for 7 years for tax/legal obligations
Linking your Stripe accountStripe event data (e.g. subscriptions, payments, refunds)Contractual necessity (not needed when using the API)Referral-related events retained as long as necessary; other data deleted after 7 days
Linking your Google Analytics accountWebsite traffic, audience data, anonymized demographicsConsentData deleted within 7 days after account disconnection
Scheduling demo calls (via HubSpot)Name, email address, preferred date/time, optional messageConsentUntil meeting is completed + 1 year
Responding to inquiries & support requestsName, email, inquiry detailsLegitimate interestUntil inquiry is resolved + 1 year
Marketing & promotional communicationsName, email address, company nameConsentUntil you withdraw consent or unsubscribe
Social media interactionsIP address, browser type, social profile interactions via pluginsLegitimate interestAs long as necessary for analytics/engagement
Use of cookies and site analyticsIP address, usage data, device/browser infoConsentUp to 14 months (unless deleted sooner via browser settings)
Fraud prevention and platform securityIP address, usage logs, account activityLegitimate interest, legal obligationAs long as necessary for security/monitoring
Legal compliance (e.g., taxes, audits)Account and transaction data, billing informationLegal obligationUp to 7 years, per applicable Dutch tax law

2. How We Collect Your Personal Data

We use different methods to collect data from and about you, including through:

2.1 Direct Interactions:

You may provide us with personal information such as contact details, identifiers, financial data, and other categories when you:

  • Apply for our products or services.
  • Create an account with us.
  • Subscribe to publications.
  • Request marketing materials.
  • Provide feedback or contact us through forms, post, phone, email, our website, or other means.

2.2 Automated Technologies or Interactions:

As you use our website and services, we may automatically collect technical, profile, and usage data, such as details about your device, browsing behavior, and usage patterns.

2.3 Third Parties or Publicly Available Sources:

  • Online recruitment platforms or professional networks (e.g., work-related information).
  • Publicly available sources providing identity and contact data.

3. Who Has Access to Your Data?

Your personal data is accessed by authorized personnel at Reditus and, where necessary, trusted third-party service providers who assist us in fulfilling the purposes mentioned above. These third parties may include marketing platforms, payment processors, IT service providers, and others, all of whom operate under strict confidentiality agreements.

We may also share your personal data:

  • If required by law, regulation, or legal process;
  • To protect our legal rights, prevent fraud, or comply with lawful requests;
  • In connection with a merger, acquisition, or sale of all or a portion of our assets or in case of bankruptcy.

We ensure that access to your data is granted only on a need-to-know basis and is fully controlled and monitored.

3.1 Website and Hosting Services

ProviderCountryPurpose and NotesEncryption
CloudflareUSANetwork edge protection and performance. May process IPs for security.Encryption in transit, at rest
Google Tag ManagerUSAManages tracking scripts and may process IP's.Encryption in transit, at rest
Google AnalyticsUSAUsed for traffic insights.Encryption in transit, at rest
LeadfeederFinlandProvides company-level insights from known users. Integrated with HubSpot.Encryption in transit, at rest
HubSpotUSAMarketing landing pages, traffic insights and booking of demo's.Encryption in transit, at rest

3.2 Our Platform and Core Services

ProviderCountryPurpose and NotesEncryption
Reditus (own platform)NetherlandsAffiliate management tool. Processes client and affiliate data.Encryption in transit, at rest
StripeUSA/IrelandSubscription management and payment processing.Encryption in transit, at rest
Heroku / SalesforceUSAApplication infrastructure. Stores app and client data.Encryption in transit, at rest
AWS (via Heroku)USA/GermanyInfrastructure services. Hosts application databases and storage.Encryption in transit, at rest
ParagonUSAFor setting up client integrations.Encryption in transit, at rest

3.3 Internal Operations and Communication

ProviderCountryPurpose and NotesEncryption
HubSpotUSACRM, sales pipeline, and support chat. Stores client contact and activity data.Encryption in transit, at rest
SlackUSAInternal communications; includes system and client activity notifications.Encryption in transit, at rest
Google WorkspaceUSAEmail, Docs, Sheets, and internal communication. May include client info.Encryption in transit, at rest
GitLabUSADevelopment and version control. May contain user identifiers in logs or code.Encryption in transit, at rest
LinearUSAProduct and roadmap tracking. No client data stored.Encryption in transit, at rest
1PasswordCanadaInternal password manager. Stores internal credentials only.Encryption in transit, at rest

3.4 Integrations (Client-Enabled)

IntegrationCountryPurpose and NotesEncryption
Google AnalyticsUSAIf connected by clients, provides account and traffic insights.Encryption in transit, at rest
YouTubeUSAAffiliate integration. Provides account-level and channel data.Encryption in transit, at rest
LinkedInUSAAffiliate integration. Used to track engagement and referrals.Encryption in transit, at rest
CalendlyUSAUsed to log demo bookings via affiliates.Encryption in transit, at rest
HubSpot (via integration)USATracks demo bookings for affiliate tracking.Encryption in transit, at rest
PayPalUSAUsed for affiliate payouts via email.Encryption in transit, at rest

3.5 Email, Marketing, and Outreach

ProviderCountryPurpose and NotesEncryption
SendGridUSASends transactional and promotional emails. Stores recipient data.Encryption in transit, at rest
InstantlyUSAUsed for outbound email campaigns. Processes prospect emails and engagement.Encryption in transit, at rest
Social Media Platforms (LinkedIn, Twitter, Facebook)VariousUsed for communications, prospecting, and ads. May process profile data.Encryption in transit, at rest

3.6 Other Third Parties

ProviderCountryPurpose and NotesEncryption
Marketing AgencyNetherlandsHas access to HubSpot, website CMS, and analytics data to support campaigns.Encryption in transit, at rest
BookkeeperNetherlandsHandles invoices and financial reporting only. No access to personal data.Not applicable
CanvaAustraliaUsed to create visual content. No personal data processed.Encryption in transit, at rest
AppSignalNetherlandsApplication monitoring tool. No personal data is involved.Encryption in transit, at rest
BetterstackCzech RepublicUptime monitoring only. Does not process personal or client data.Encryption in transit, at rest

4. Is Data Transferred Outside the European Economic Area (EEA)?

Some of our external third parties are located outside the EEA, meaning your personal data may be transferred to countries outside the EEA. To ensure your data is protected, we implement at least one of the following safeguards:

  • The destination country has been recognized by the European Commission as providing an adequate level of data protection.
  • We use specific contracts approved by the European Commission that ensure your personal data receives the same level of protection as within the EEA, such as Standard Contractual Clauses.

5. What Technical and Organizational Security Measures Are in Place?

We take the security of your personal data very seriously and implement appropriate technical and organizational measures to safeguard your information. These measures include:

  • Data encryption (both in transit and at rest)
  • Secure access controls and authentication procedures
  • Regular security audits and vulnerability assessments
  • Monitoring and logging of system access
  • Employee training and awareness programs on data protection

In the event of a personal data breach, we will notify you and the relevant authorities as required by law.

6. What Are Your Data Subject Rights?

As a data subject, you have the following rights under the GDPR:

  • Right to Access: You can request access to the personal data we hold about you.
  • Right to Rectification: You can request that we correct any inaccuracies in your personal data.
  • Right to Erasure: You can request the deletion of your personal data under certain conditions.
  • Right to Restriction: You can request the restriction of processing your data under certain circumstances.
  • Right to Data Portability: You can request a copy of your personal data in a structured, commonly used, and machine-readable format when you have provided your personal data to us.
  • Right to Object: You have the right to object to the processing of your data for direct marketing or other purposes based on legitimate interest.
  • Right to Withdraw Consent: Where we rely on your consent, you can withdraw that consent at any time.

If you believe that we have not handled your data appropriately or you are unsatisfied with our response to your concerns, you have the right to lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens. You can contact them via their website at www.autoriteitpersoonsgegevens.nl.

For data subjects in other countries, you can contact your respective national data protection authority.

We may ask for specific information to verify your identity and confirm your right to access your personal data (or exercise any other rights). This is a security measure to prevent unauthorized access to your personal data.

7. How Long Do We Keep Your Data?

When determining the appropriate retention period, we consider:

  • The volume, nature, and sensitivity of the personal data.
  • The potential risk of harm from unauthorized use or disclosure.
  • The purposes for which we process your data and whether we can achieve those purposes through other means.
  • Any applicable legal, regulatory, tax, accounting, or other requirements.

Once the retention period has expired, we securely delete or anonymize your personal data so that it can no longer be associated with you.

8. Use of Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to improve your experience, analyze traffic, and provide personalized content. These may include:

  • Essential cookies – Necessary for the website to function properly.
  • Analytics cookies – Help us measure and understand how visitors interact with our site (e.g., via Google Analytics).
  • Marketing cookies – Help us deliver more relevant advertisements and track campaign effectiveness.

When you visit our website, you will be given the option to manage your cookie preferences. You can also control cookies through your browser settings. For more information, see our Cookie Policy.

9. Third-Party Websites

Our Site may include hyperlinks to third-party websites, such as LinkedIn or Instagram. These hyperlinks are provided for your reference and convenience only, and do not imply any endorsement of the activities of these third-party websites or any association with their operators. We are not responsible for the privacy practices or content of these third-party websites. You are encouraged to read their respective privacy notices for more information.

10. Privacy of Children

It is our policy to not collect personal data from any person under 18 because children are not permitted to use our services and our website and we request that children under the age of 18 not submit any personal data to us. If we learn that we have inadvertently gathered personal data from children under 18, we will promptly remove such information from our records. If you are a parent or guardian and believe we have collected personal information in violation of applicable data protection law, contact us at [email protected]. We will remove the personal information in accordance with applicable data protection law.

11. Updates to This Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our data practices, legal obligations, or operational requirements. If we make material changes, we will notify you via email (if we have your contact details) or via a prominent notice on our website prior to the change becoming effective.

The most recent version of this Privacy Notice will always be available on our website. We encourage you to review it regularly to stay informed about how we are protecting your data.

12. Contact Information

If you have any questions about this Privacy Notice or how we handle your personal data, please contact us:

Reditus B.V.

Reditus B.V.

Europalaan 100, Utrecht

KVK: 77814487

Email: [email protected]

Website: https://www.getreditus.com