PrivXS

PrivXS Privacy Statement

1. At a glance

EN-1.1 PrivXS is an online platform operated by Koowde B.V. It enables organisations such as artists, brands, venues and other businesses to manage public pages, registrations, audiences, events, sales and communications.

EN-1.2 Koowde B.V. is responsible for personal data needed to provide PrivXS as a platform, including accounts, subscriptions, security, support and invoicing. For our own online campaigns, we use optional browser measurement after consent and separate limited server measurement as explained in sections 6 and 8.

EN-1.3 When you join an organisation, register for a guest list, make a purchase or receive an organisation's communication, that organisation determines why it uses your data. The organisation is the controller and Koowde processes the data through PrivXS on its behalf. We do not use identifiable audience data to profile you across different organisations or for our own marketing.

EN-1.4 You can submit privacy questions and requests centrally to Koowde at info@koowde.nl. If possible, state the relevant organisation, account, registration or order. We handle the request for our own processing and assist the relevant organisation with its part.

EN-1.5 We use Meta Pixel, Meta cookies and campaign or matching IDs only after you have made a free, specific and informed choice. Without that consent, a limited server event without those IDs may be transmitted. Meta and Koowde then process technical request data such as IP address and user-agent. You can withdraw consent at any time and object to processing based on legitimate interests.

2. Who are we and how can you contact us?

EN-2.1 This privacy statement applies to PrivXS and the related websites, public organisation pages, registration, sales and event features, and platform accounts operated by Koowde B.V.

EN-2.2 Koowde's contact details are:

  • Koowde B.V., operating under the product name PrivXS
  • Dutch Chamber of Commerce number: 84704292
  • P.O. Box 37607, 1030 BB Amsterdam, the Netherlands
  • General contact and privacy requests: info@koowde.nl
  • Website: https://privxs.com/

EN-2.3 Koowde has a formally registered Data Protection Officer (DPO). You can contact the DPO confidentially at fg@koowde.nl. The DPO independently monitors and advises on data protection. For a standard access, deletion or correction request, please preferably use info@koowde.nl.

3. Who is responsible for what?

EN-3.1 Koowde as controller. Koowde determines the purposes and essential means for providing and securing PrivXS, managing accounts and SaaS subscriptions, invoicing and administration, platform support, legal compliance, abuse prevention, and our own communications and acquisition measurement.

EN-3.2 The organisation as controller. The organisation identified on the page, form, checkout or message determines the purposes for its audience building, promotions, guest lists, sales and campaigns. For example, it chooses the activity, the optional fields it requests and the people it contacts.

EN-3.3 Koowde as processor. For processing performed by an organisation through PrivXS, Koowde acts on the organisation's documented instructions. Koowde provides hosting, access, delivery, security, support, exports, deletion and central coordination of privacy requests. These duties are set out in an Article 28 data processing agreement that may be accepted as an identifiable addendum to the SaaS agreement.

EN-3.4 Payments. The selling organisation is responsible for the sale and necessary customer data. Koowde processes the data for the operation and security of PrivXS. A payment institution such as Mollie also processes data under its own legal responsibility. For Sentoo and underlying payment processors, the exact role depends on the selected payment method and contractual chain; their own privacy information applies to their processing.

EN-3.5 Central request route. You do not need to determine which technical party holds a data item. You may start with Koowde. If an organisation is responsible for the decision, we securely forward the request, help it respond and carry out approved actions in PrivXS.

4. Who and what data does this statement cover?

EN-4.1 This statement covers website visitors, account users, organisation owners and team members, subscribers, event visitors and participants, buyers, people contacting support and business contacts.

EN-4.2 Depending on your use, we may process:

  • identity and contact data, such as name, email address, phone number, postal code, address and social-media URL;
  • account and authentication data, such as password hash, role, session, two-factor status, one-time codes and login history;
  • Google identity data when you deliberately choose Google sign-in;
  • organisation, team, profile and subscription data;
  • subscriber, consent, guest-list and unsubscribe data;
  • order, product option, delivery, ticket, payment, refund and transaction data;
  • campaign, sending, delivery, error and suppression data;
  • text, images, files, audio and video published or uploaded by organisations;
  • technical and security data, such as IP address, user-agent, URL, time, device/browser information and security events;
  • without optional consent for limited server measurement: event ID and name, time, canonical page, IP address, user-agent and relevant transaction or product context;
  • only after consent: cookie IDs, Meta and UTM campaign IDs, click IDs, referrer and hashed matching data;
  • correspondence, support content and other information you choose to provide;
  • for SaaS contracts and the Data Processing Agreement: legal organisation name, Chamber or registration number, country of registration, correspondence address, representative's position, document version/hash, acceptance time and linked organisation, account and subscription references.

EN-4.3 PrivXS does not ask for special-category data such as medical information, political opinions, religion, biometric identification or sexual orientation. Do not enter this data in forms, free text, support messages or uploads. If we receive it unintentionally, we restrict access and delete it under our procedure unless a specific legal obligation temporarily prevents deletion.

5. Where does the data come from?

EN-5.1 We usually receive data directly from you when you create an account, complete a form, sign in, make a purchase, contact us or choose cookie preferences.

EN-5.2 We may receive data from the organisation you are associated with, for example when it imports an existing list under a valid legal basis or corrects a registration on your behalf. The organisation must inform you and be able to demonstrate that it may lawfully use the data.

EN-5.3 If you choose Google sign-in, we receive a Google-signed identity result and the profile data configured for the sign-in flow after your action. For payments, we receive status, references and limited transaction details from the selected payment party. We do not receive full card or online-banking credentials where those are entered only in the payment environment.

EN-5.4 Technical data arise when systems are used. Without optional consent, limited server measurement uses only the event and request context listed in section 6. Meta Pixel, browser IDs, campaign/click IDs, referrer and matching data arise or are used after consent. An explicit ambassador or referral code may be recorded during your sign-up to honour the requested introduction or business referral without collecting other tracking data when you reject tracking.

6. Processing activities, purposes, legal bases and periods

Activity Data and purpose Role and legal basis Main period
Website and necessary operation Request/device data, language, theme and cookie choice to deliver pages, remember choices and prevent failures. Koowde is controller. Requested service and legitimate interest in availability and security. Preferences up to 12 months; security logs normally 12 months.
Account and sign-in Name, email, password hash or Google identity, role, 2FA, session and login logs for access and abuse prevention. Koowde is controller. Contract and legitimate security interest. Account life plus up to 90 days; logs 12 months; legal/dispute evidence where needed.
Organisation and SaaS Organisation, team, plan, subscription, configuration and invoice data, legal party details and acceptance evidence for the SaaS and processing terms, to provide PrivXS, perform the contract and demonstrate the agreement. Koowde is controller for the platform contract. Contract, legal obligation and legitimate interest in contractual evidence. Operational SaaS data: contract life plus 90 days; core tax records 7 years; minimised contract/acceptance evidence under applicable limitation and statutory periods.
Subscriber Email, selected optional fields, organisation, consent evidence and unsubscribe data for benefits and promotional messages from the organisation. Organisation is controller; Koowde is processor. Explicit marketing consent. Until withdrawal or 24 months without relevant activity; active profile deleted within 30 days after withdrawal.
Guest-list or event registration Contact data, event and status to provide the requested registration, confirmation and practical service messages. Registration itself is not consent to promotional email. Organisation is controller; Koowde is processor. Requested registration/contract; marketing only under a separate optional consent checkbox. Guest-list data 3 months after the event unless financial/legal retention applies.
Order, ticket, course or merchandise Buyer, product, options, price, delivery address, ticket and status to fulfil, support and keep records. Selling organisation is controller; Koowde is processor and separate security controller. Contract and legal obligation. Fulfilment/support data 2 years; fiscal transaction data 7 years.
Payment and refund Amount, currency, provider, status, time and reference to initiate, verify, settle and refund. Organisation/Koowde according to the transaction; payment provider often independent controller. Contract and legal obligation. Koowde follows fiscal retention; provider applies its own legal periods.
Campaign delivery Recipient, campaign, message ID, time, delivery, error, unsubscribe and suppression to send allowed messages and prevent abuse. Organisation is controller; Koowde and email provider are processors. Consent for promotional delivery. Campaign diagnostics 24 months; minimal consent/suppression evidence 5 years.
Support and business contacts Contact data, correspondence and issue details to handle questions, contracts and complaints. Koowde is controller. Contract or legitimate service/administration interest. Normally 2 years after closure; relevant contract/dispute evidence up to 5 years or legal period.
Security and incidents IP, user-agent, time, route, account, action, status and incident data to detect and investigate attacks, fraud and unauthorised access. Koowde is controller. Legitimate interest and, where applicable, legal obligation. Routine logs 12 months; restricted incident evidence while an investigation or claim requires it.
Limited server measurement Without optional cookies: event ID and name, time, canonical page, IP address, user-agent and, where relevant, plan, organisation, subscription, sale, value and currency context. No Meta cookie, campaign/click or hashed contact IDs. Koowde is controller for platform acquisition. For measurement to a customer organisation's dataset, that organisation is controller and Koowde is processor; Meta's role follows the applicable Business Tools terms. Legitimate interest in limited campaign and conversion measurement, supported by a documented balancing assessment and a permanent technical stop control. Outbox 30 days after sent/skipped delivery; unresolved needs_attention up to 90 days. Minimized PrivXS funnel data up to 24 months.
Optional acquisition and Meta After consent: Meta Pixel, UTM/Meta campaign and click IDs, _fbp, _fbc, page, referrer, user-agent, event, value, currency and hashed matching data. Hashing is pseudonymisation and does not make data anonymous. Koowde is controller for platform acquisition. For a customer organisation's campaign, that organisation is controller and Koowde is processor. Meta may be processor, joint or independent controller according to purpose. Consent. Outbox 30/90 days as above; minimized PrivXS funnel data up to 24 months; Meta applies its own contractual periods.
Privacy and consent evidence Request, identity check, decision, policy version, source, consent and withdrawal time for rights and accountability. Koowde and/or organisation is controller. Legal obligation and legitimate evidential interest. Minimized evidence normally 5 years after closure or withdrawal.

EN-6.1 We rely on legitimate interests only after a balancing assessment covering purpose, necessity, effect on you and safeguards such as restricted access, short periods, pseudonymisation and an easy objection route. The limited server measurement has additional safeguards: no Meta Pixel, Meta cookie, campaign/click or hashed contact IDs, a canonical URL without query parameters and short outbox retention. Legitimate interest is not used as a substitute for required cookie or marketing consent.

EN-6.2 If data are necessary for an account, registration, order, payment or statutory record, we cannot provide that function without them. Optional fields are marked as optional. Rejecting marketing or tracking does not prevent normal website use or a purchase.

7. Marketing, campaigns and audience data

EN-7.1 An organisation may send promotional email through PrivXS only where it has a valid legal basis. PrivXS policy is to base subscriber marketing on demonstrable consent. Consent is separate from a guest-list registration, purchase or other terms. A guest-list confirmation or practical service message is not promotional email.

EN-7.2 Consent is not pre-selected. The form identifies the organisation, communication type and unsubscribe option. We retain the form or notice version, source, organisation, time and any withdrawal to demonstrate consent.

EN-7.3 Every promotional email includes a working unsubscribe option. New promotional sends stop immediately after unsubscribe. The active marketing profile is deleted or irreversibly anonymised within 30 days, except for minimal suppression and consent evidence needed to respect the opt-out and demonstrate compliance.

EN-7.4 Koowde does not combine identifiable subscriber, guest-list or buyer data from different organisations into a PrivXS-wide marketing profile. Platform usage reports may be combined only where they can no longer reasonably be linked to a person.

8. Cookies and similar technologies

EN-8.1 PrivXS uses necessary storage for website operation and optional browser technology for advertising measurement. Necessary technology is not used to track you across other websites. Meta Pixel, Meta cookies and storage of campaign or matching IDs are activated only after consent. Limited server measurement can occur without a browser cookie and is therefore described separately in section 6.

Name/storage Provider Purpose and category Period
nuxt-cookie-control Koowde/PrivXS Necessary. Stores your cookie choice and preference version. Up to 12 months.
privXS-color-mode Koowde/PrivXS Necessary/functional. Remembers light or dark display. Up to 12 months.
i18n_redirected Koowde/PrivXS Necessary/functional. Remembers selected language. Up to 12 months.
privxs.saas.acquisition session storage Koowde/PrivXS Optional. After consent, retains campaign/UTM attribution for the browser session. Until session end or earlier withdrawal.
_fbp Meta Optional. Distinguishes browsers for advertising measurement and matching. Up to 90 days.
_fbc Meta Optional. Stores a Meta click reference for attribution. Up to 90 days.

EN-8.2 The first cookie-banner layer lets you accept or reject optional cookies and manage choices. No option is pre-selected and continuing to browse does not constitute consent.

EN-8.3 You can change your choice through "Privacy settings" in the footer. On withdrawal, we stop new optional storage and transmission and remove optional browser data where technically possible. Withdrawal does not affect earlier lawful processing. On the same page, you can directly stop or resume separate limited server measurement for this browser and device. You may also object through the contact route in section 14.

EN-8.4 Google sign-in, a payment environment or a deliberate click to Spotify or another external service may cause that service to receive data. Where possible, we load such services only after your deliberate action and provide information at the relevant point.

9. Who receives data?

EN-9.1 Only staff and engaged parties that need data for their work receive access. They are subject to confidentiality, role restrictions and appropriate security arrangements.

EN-9.2 Depending on the feature, data may be shared with:

  • the organisation you join, visit or purchase from;
  • Microsoft for Azure infrastructure, databases and platform services;
  • Team.blue/TransIP for object storage, email or infrastructure services;
  • Mailgun/Sinch for campaign email;
  • Google when you choose Google sign-in;
  • Meta for limited server measurement and, after consent, Pixel, interaction, campaign and conversion measurement;
  • Mollie, Sentoo and underlying financial institutions for payments;
  • GitLab where production backups or operational files are demonstrably stored in that service;
  • professional advisers, auditors and competent authorities where legally required;
  • a legal successor in a merger, acquisition or transfer, subject to confidentiality and appropriate notice.

EN-9.3 Koowde maintains a current, verified list of subprocessors, their functions, locations and transfer safeguards. The public version is available on the “Subprocessors” page. Contracts and assessment evidence remain in the internal supplier register; relevant additional information may be requested at info@koowde.nl.

10. Transfers outside the European Economic Area

EN-10.1 Some providers may process personal data outside the European Economic Area or allow access from another country. We do not make a general promise that all data remain exclusively in the Netherlands.

EN-10.2 We use an appropriate GDPR Chapter V mechanism, such as an adequacy decision, valid EU-U.S. Data Privacy Framework participation or European Commission Standard Contractual Clauses, supplemented by appropriate technical and organisational measures where necessary.

EN-10.3 Sentoo B.V. is established in Curaçao and acts in the payment chain under its own terms; it is not automatically Koowde's subprocessor. Before any transfer or access outside the EEA, we document the role, necessity, contractual safeguard and transfer assessment. For global providers such as Google, Meta, Microsoft and Mailgun/Sinch, we use the applicable entity, region and valid transfer basis. Under the current design GitLab contains source code and technical work files, not the production audience database.

EN-10.4 You may request information or, where available, a copy of the relevant transfer safeguard at info@koowde.nl. Commercial or security-sensitive parts may be redacted without withholding the substance of the protection.

11. Retention and deletion

EN-11.1 We retain personal data no longer than necessary for the purpose, a legal obligation or a specific legal claim. Main periods are stated here; the complete internal schedule is applied per data category and system.

EN-11.2 When an organisation account ends, access is terminated and the organisation normally has 30 days to request a permitted export. Operational personal data are deleted from active systems within 90 days, except for legally required records or a documented legal hold.

EN-11.3 Deleted data may remain in protected backups for up to 90 days. Backups are not used for ordinary business purposes. Applicable deletion instructions are reapplied after a restore.

EN-11.4 Where an investigation, complaint or claim is pending, only relevant data may be held longer. Access is restricted and the ordinary period is resumed when the hold ends.

12. Security and personal data breaches

EN-12.1 Koowde applies technical and organisational measures appropriate to the nature and risks of the processing. Where appropriate, we use encrypted connections, role-based access, strong authentication, secrets management, logging and monitoring, backups, updates, vulnerability management, supplier review and incident and recovery procedures.

EN-12.2 No service can guarantee absolute security. We assess the measures periodically and after relevant changes or incidents and improve them where necessary. We refer to a security certification only when it is valid for Koowde, the relevant PrivXS services and the stated scope.

EN-12.3 We investigate, contain and document a suspected personal data breach. Where Koowde is the processor, we notify the controller organisation without undue delay and provide the information it needs for its assessment and notification.

EN-12.4 Where Koowde is the controller, we notify a reportable breach to the Dutch Data Protection Authority where feasible within 72 hours after becoming aware of it. We inform affected people without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

13. Children

EN-13.1 Public PrivXS platform registration and an account for a SaaS customer, organisation owner or team member are intended only for people aged 16 or over. In the SaaS signup, the 16+ confirmation is the first item in the information linked to the required checkbox. A customer organisation must not invite a team member under 16. We do not routinely request a full date of birth for this purpose.

EN-13.2 If we establish that a platform account was created by someone under 16, we block the account and assess which data must be deleted. An age confirmation does not remove our own legal responsibility.

EN-13.3 PrivXS public subscriber, guest-list and checkout forms are available only to people aged 16 or over. The form states this in the information linked to the required checkbox. PrivXS does not currently offer a parent or guardian flow, so a person under 16 cannot lawfully complete these forms.

EN-13.4 If we establish or reasonably suspect that a person under 16 registered through such a form, we block promotional communication and investigate with the controller organisation which data must be deleted. Report this at info@koowde.nl.

14. Your privacy rights

EN-14.1 Depending on the circumstances, you have rights of access, correction, deletion, restriction, portability and objection. You can withdraw consent at any time. You may object to direct marketing at any time, after which promotional processing stops.

EN-14.2 Send your request to info@koowde.nl and describe the relevant account, email address, organisation, event or order as clearly as possible. Contact the DPO at fg@koowde.nl.

EN-14.3 We verify identity proportionately to the risk. Do not send a full identity-document copy unless specifically and lawfully requested. If additional verification is needed, we explain the limited information required and why.

EN-14.4 We normally respond within one month. For a complex or numerous request, the period may legally be extended by two months; we notify you within the first month and explain why. Requests are normally free. If refused, we explain the reason and complaint options.

EN-14.5 Where an organisation is the controller, Koowde coordinates the request with it. You may also exercise your rights directly against that organisation.

EN-14.6 You may complain to the Dutch Data Protection Authority at https://autoriteitpersoonsgegevens.nl/. We appreciate the opportunity to investigate first, but this is not required.

15. Automated decisions

EN-15.1 Koowde does not use PrivXS to make solely automated decisions that produce legal or similarly significant effects for you within Article 22 GDPR.

EN-15.2 An independent payment provider may carry out its own automated fraud or statutory checks. Its privacy statement applies to that decision. Where we receive a rejection status, we help you find the appropriate contact route.

16. External links and organisation content

EN-16.1 Organisations may display links or content from external services. When you deliberately visit such a service, it processes data under its own terms. Review that service's privacy information.

EN-16.2 An organisation publishing or uploading another person's data to PrivXS must have a valid legal basis and necessary rights. Report potentially unlawful personal data to info@koowde.nl with the relevant page or organisation.

17. Changes to this statement

EN-17.1 We may update this statement when the platform, law or providers change. The current version and date appear at the top.

EN-17.2 For a material change, we provide active account users with appropriate notice. If a new purpose is not covered by the existing legal basis or consent, we first obtain new valid consent or do not use the data for that purpose.

EN-17.3 Previous versions remain internally available for accountability and to demonstrate the information that applied when consent was given or processing occurred.