mvdm.io · legal
Privacy Notice
Effective . A later edit replaces this page in place.
This Privacy Notice explains how mvdm.io (sole proprietorship, KvK 86594737) processes personal data as a controller: for the public marketing site, for people who sign in to mvdmio applications, for billing, and for first-party request analytics. It does not replace the Data Processing Agreement, which covers personal data in a customer’s Compliance ISMS where mvdm.io acts as processor.
1. Who we are
Controller: mvdm.io, De Vierakkers 15, 7766 BL Nieuw-Schoonebeek, the Netherlands. Contact: michiel@mvdm.io. Further identification is on Company details.
2. What we process as controller
- Sign-in and account administration — name, email address, authentication identifiers, account membership, and related security logs needed to operate SSO and accounts.
- Billing — customer and payment details processed through our payment provider so we can charge for Compliance and related purchases.
- Request analytics — first-party request analytics through our Statistics product, so we can see how the applications are used at a technical level.
- Marketing site — ordinary server and access logs for mvdm.io, and whatever you send us by email or form contact.
3. Why we process it
We process this data to provide and secure the services, to bill for paid use, to understand and improve reliability and usage, and to respond to you. The legal bases are performance of a contract, our legitimate interests in operating and securing the service, and where required by law.
4. Cookies
The applications use a strictly necessary sign-in cookie so authenticated sessions work. That cookie is required for the service you ask for; there is no non-essential marketing cookie set by us for that purpose, and we do not show a cookie banner for a cookie you cannot refuse. The public marketing site does not rely on a consent banner for essential delivery.
5. Google Fonts
The public marketing site loads fonts from Google Fonts. Your browser may contact Google’s servers to fetch those fonts. See Google’s own documentation for how Google processes that connection.
6. Analytics
We use first-party request analytics (Statistics) in the applications. This is our own instrumentation, not a third-party advertising tracker.
7. Assistant conversations and operator access
When you use the Compliance assistant, conversation content is processed so the feature can run (see the Data Processing Agreement for the processor role). A Platform Administrator of mvdm.io can read Assistant conversations for support and quality. Import conversations used by the import feature are likewise visible to Platform Administrators for debugging.
8. Recipients and transfers
We use subprocessors listed on the Subprocessor list. Some of those providers are in the United States. Hosting for the applications is with Hetzner in the EEA.
9. Retention
Sign-in and billing records are kept while the account is active and for as long as needed for security, accounting, and legal obligations. Compliance ISMS content after a license ends follows closed-license retention (365 days from license end, then deletion of that account’s Compliance data), as described in the Terms and the Data Processing Agreement.
10. Your rights
Depending on where you live, you may have rights to access, rectify, erase, restrict, or object to certain processing, and to data portability. For controller data, contact michiel@mvdm.io. For personal data inside a customer’s ISMS, contact that customer organisation first; we act as their processor.
11. Changes
We may replace this notice by publishing an updated page with a new effective date.