Are you an activity provider? List your activities on Huppels →

GDPR Compliance

Your privacy matters. Learn about your rights under the General Data Protection Regulation and how Huppels protects your personal data.

Your Data Rights

Right of Access

You have the right to request a copy of the personal data we hold about you.

Right to Rectification

You can request that we correct any inaccurate or incomplete personal data.

Right to Erasure

You can request that we delete your personal data under certain circumstances.

Right to Restrict Processing

You can request that we limit how we use your personal data.

Right to Data Portability

You can request your data in a machine-readable format to transfer elsewhere.

Exercise Your Rights

To exercise any of your GDPR rights, you can:

  • 1
    Account Settings: Access and manage most of your data directly through your account dashboard
  • 2
    Email Request: Send a request to privacy@huppels.com with your specific request
  • 3
    Written Request: Mail your request to our Data Protection Officer at the address below

We will respond to your request within 30 days. In some cases, we may need to verify your identity before processing your request.

How We Protect Your Data

Data Security Measures

We implement robust security measures to protect your personal data:

  • Encryption of data in transit and at rest (TLS/SSL, AES-256)
  • Regular security audits and penetration testing
  • Access controls and authentication mechanisms
  • Employee training on data protection
  • Incident response and breach notification procedures

Data Processing

We process your personal data based on the following legal bases:

  • Contract: Processing necessary to fulfill our services to you
  • Consent: For marketing communications and optional features
  • Legitimate Interest: For improving our services and fraud prevention
  • Legal Obligation: When required by law

Data Retention

We retain your personal data only for as long as necessary:

  • Account data: While your account is active, plus 3 years
  • Booking records: 7 years for legal and tax purposes
  • Marketing preferences: Until you withdraw consent
  • Support tickets: 2 years after resolution

International Data Transfers

Your data is primarily processed within the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission
  • Data processing agreements with our service providers

Third-Party Processors

We work with trusted third-party processors who help us provide our services:

  • Stripe: Payment processing (PCI-DSS compliant)
  • AWS: Cloud hosting (EU data centers)
  • Sendgrid: Email communications
  • Intercom: Customer support

All processors are contractually bound to protect your data and process it only as instructed.

Children's Data

We take special care with children's data:

  • Children's profiles are managed by parents/guardians
  • We collect only necessary information (name, age)
  • No direct marketing to children
  • Parents can request deletion of their children's data

Data Protection Officer

For any questions about our data practices or to exercise your rights, contact our DPO:

Email: dpo@huppels.com

Address: Herengracht 123, 1015 Amsterdam, Netherlands

You also have the right to lodge a complaint with a supervisory authority, such as the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Huppels

Discover the best kids' activities, camps, and courses near you.

© 2026 Huppels. All rights reserved.