Privacy Policy

Last updated: 10/11/2025

This Privacy Policy explains how Thjis, trading as Collexion (“Collexion”, “we”, “us”, or “our”), collects, uses, and protects personal data when you use our website https://collexion.io and related services (the “Service”).

We operate in accordance with the EU General Data Protection Regulation (GDPR) and Dutch data-protection law.

1. Scope

This Policy applies to all personal data processed by Collexion in connection with its software-as-a-service platform for business (B2B) users.

Our Service is not intended for consumers or anyone under 18 years of age.

2. Data Controller

Thjis / Collexion

Registered in: The Netherlands

Email: legal@collexion.io

Website: https://collexion.io

3. Categories of Data Collected

TypeExamplesSource
Account DataName, business email, company name, password hashYou
Billing DataPayment method details (processed by Stripe), VAT number, transaction recordsYou / Stripe
Usage DataIP address, browser type, log files, pages visited, error reportsAutomatic
OAuth DataName, email address, OAuth provider ID (Gmail / Discord)Gmail / Discord
Marketing DataInteraction with ads via Facebook Pixel and analyticsAutomatic
Support DataMessages or tickets you submitYou

4. Purpose and Legal Basis for Processing

PurposeLegal Basis (GDPR Art. 6)
Providing and managing accountsContract (1)(b)
Processing payments through StripeContract (1)(b)
Sending transactional emails via ResendContract (1)(b)
Hosting and operating the Service (Vercel + Hetzner)Legitimate interest (1)(f)
Error monitoring (Sentry)Legitimate interest (1)(f)
OAuth authentication (Gmail, Discord)Contract (1)(b)
Marketing and analytics (Facebook Pixel)Consent (1)(a)
Compliance with legal obligationsLegal obligation (1)(c)

5. Service Providers and Data Processors

We rely on the following trusted third-party processors:

ProviderPurposeLocation / Safeguards
Stripe, Inc.Payment processingEEA / US – Standard Contractual Clauses
Resend, Inc.Transactional and notification emailsUS – SCCs
Hetzner Online GmbHBackend hosting and data storageGermany (EEA)
Vercel Inc.Frontend hosting and deploymentUS / EU – SCCs
Sentry (GmbH)Application error loggingGermany (EEA)
Google (Gmail OAuth)AuthenticationEEA / US – SCCs
Discord Inc.AuthenticationUS – SCCs
Meta Platforms (Facebook Pixel)Advertising and analyticsUS – SCCs

Each processor is bound by a Data-Processing Agreement ensuring GDPR-compliant safeguards.

6. Retention Period

We keep personal data only as long as necessary for the stated purposes or as required by law.

Account data is deleted or anonymised within 30 days after account closure unless legal retention (e.g. tax records) requires longer storage.

7. Right to Erasure (“Right to Be Forgotten”)

You may request deletion of your personal data at any time by emailing legal@collexion.io with the subject line “Data Deletion Request.”

After verifying your identity:

  • All personal data associated with your account will be permanently deleted within seven (7) days.
  • Legally required financial records (e.g. invoices) will be retained for the statutory 7-year period under Dutch law.

Once deletion is complete, it cannot be reversed.

We will confirm completion via email.

8. Your Other Data Protection Rights

Under GDPR you may request:

  • Access to your data
  • Correction of inaccuracies
  • Restriction of processing
  • Data portability
  • Objection to processing based on legitimate interest

To exercise any of these rights, contact us at the email address above. We respond within 30 days.

9. Security

We employ industry-standard security controls, including encryption in transit (HTTPS/TLS), firewalling, role-based access, and continuous monitoring.

While we take all reasonable precautions, no system is completely secure.

10. International Transfers

If personal data is transferred outside the EEA (e.g. to the United States by Stripe, Vercel, or Resend), such transfer is protected by EU Standard Contractual Clauses or other adequate safeguards approved by the European Commission.

11. Cookies and Tracking Technologies

We use:

  • Essential cookies for core site functionality;
  • Analytics cookies for usage statistics; and
  • Facebook Pixel for targeted advertising (where consent is given).

Full details are provided in our Cookie Policy.

12. Changes to This Policy

We may update this Privacy Policy periodically. The most recent version will be posted on our website and indicated by the “Last updated” date above. Continued use of the Service constitutes acceptance of the revised Policy.

13. Contact and Complaints

Questions or requests regarding this Policy may be sent to:

Thjis / Collexion

Email: legal@collexion.io

Website: https://collexion.io

If you believe your rights under GDPR have been violated, you may file a complaint with the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).