GDPR Compliance
Your privacy matters. Learn about your rights under the General Data Protection Regulation and how Huppels protects your personal data.
Your Data Rights
Right of Access
You have the right to request a copy of the personal data we hold about you.
Right to Rectification
You can request that we correct any inaccurate or incomplete personal data.
Right to Erasure
You can request that we delete your personal data under certain circumstances.
Right to Restrict Processing
You can request that we limit how we use your personal data.
Right to Data Portability
You can request your data in a machine-readable format to transfer elsewhere.
Exercise Your Rights
To exercise any of your GDPR rights, you can:
- 1Account Settings: Access and manage most of your data directly through your account dashboard
- 2Email Request: Send a request to privacy@huppels.com with your specific request
- 3Written Request: Mail your request to our Data Protection Officer at the address below
We will respond to your request within 30 days. In some cases, we may need to verify your identity before processing your request.
How We Protect Your Data
Data Security Measures
We implement robust security measures to protect your personal data:
- Encryption of data in transit and at rest (TLS/SSL, AES-256)
- Regular security audits and penetration testing
- Access controls and authentication mechanisms
- Employee training on data protection
- Incident response and breach notification procedures
Data Processing
We process your personal data based on the following legal bases:
- Contract: Processing necessary to fulfill our services to you
- Consent: For marketing communications and optional features
- Legitimate Interest: For improving our services and fraud prevention
- Legal Obligation: When required by law
Data Retention
We retain your personal data only for as long as necessary:
- Account data: While your account is active, plus 3 years
- Booking records: 7 years for legal and tax purposes
- Marketing preferences: Until you withdraw consent
- Support tickets: 2 years after resolution
International Data Transfers
Your data is primarily processed within the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions by the European Commission
- Data processing agreements with our service providers
Third-Party Processors
We work with trusted third-party processors who help us provide our services:
- Stripe: Payment processing (PCI-DSS compliant)
- AWS: Cloud hosting (EU data centers)
- Sendgrid: Email communications
- Intercom: Customer support
All processors are contractually bound to protect your data and process it only as instructed.
Children's Data
We take special care with children's data:
- Children's profiles are managed by parents/guardians
- We collect only necessary information (name, age)
- No direct marketing to children
- Parents can request deletion of their children's data
Data Protection Officer
For any questions about our data practices or to exercise your rights, contact our DPO:
Email: dpo@huppels.com
Address: Herengracht 123, 1015 Amsterdam, Netherlands
You also have the right to lodge a complaint with a supervisory authority, such as the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
