| Wat | Waar | Bewaartermijn |
|---|
| What | Where | Retention |
| Het register (hashes, volgnummers, wortels, toestelkoppelingen) | Eigen server bij Hetzner, Nürnberg (DE) | Onbeperkt: het is de vertrouwensbasis. Persoonsnamen erin worden gewist bij opheffen; de naam van de organisatie blijft nog veertien dagen in de ingetrokken koppeling van een telefoon, alleen zichtbaar voor dat toestel. |
| The registry (hashes, sequence numbers, roots, device bindings) | Our own server at Hetzner, Nuremberg (DE) | Indefinite: it is the basis of trust. Personal names in it are erased on closure; the organisation’s name stays for another fourteen days in a phone’s revoked link, visible only to that device. |
| Organisaties, leden, opdrachten, verzoeken, auditlog | Register (Hetzner) en dashboarddatabase (Supabase, EU) | Zolang de organisatie bestaat; bij opheffen gewist, behalve de naam van de organisatie in de ingetrokken koppeling van een telefoon, die na veertien dagen weggaat; contactgegevens van gasten dertig dagen na afloop |
| Organisations, members, jobs, requests, audit log | Registry (Hetzner) and dashboard database (Supabase, EU) | For as long as the organisation exists; erased on closure, except the organisation’s name in a phone’s revoked link, which goes after fourteen days; guests’ contact details thirty days after the request ends |
| Gedeelde archieven, leveringen en bewaarde dossiers | Cloudflare R2, EU-jurisdictie, versleuteld; de sleutel van een levering of bewaring versleuteld in het register (Hetzner) | Zolang de link geldig is: standaard 30 dagen bij Basis en 30 bij Plus en Business, hooguit 30, 90 of 365 dagen; leveringen en bewaarde dossiers zolang het abonnement loopt, of een kortere termijn die u zelf instelt. Bij verlopen of intrekken gaan bestand en sleutel weg; een versleutelde regel zonder bestand blijft hooguit 17 dagen in een back-up |
| Shared archives, deliveries and kept files | Cloudflare R2, EU jurisdiction, encrypted; the key of a delivery or a kept file encrypted in the registry (Hetzner) | For as long as the link is valid: 30 days by default on Basis and 30 on Plus and Business, at most 30, 90 or 365 days; deliveries and kept files for as long as the subscription runs, or a shorter period you set yourself. On expiry or withdrawal the file and the key are removed; an encrypted row without a file stays in a backup for 17 days at most |
| Back-ups van het register | Op de server zelf, en versleuteld met age in Cloudflare R2 en de Hetzner Storage Box | Elke kopie is uiterlijk 17 dagen na het maken weg, op de server en versleuteld daarbuiten; het back-upscript rekent die grens zelf na, de kopieën van de hele server bij Hetzner meegeteld |
| Backups of the registry | On the server itself, and encrypted with age in Cloudflare R2 and the Hetzner Storage Box | Every copy is gone at most 17 days after it was made, on the server and encrypted off the server; the backup script checks that limit itself, counting the copies of the whole server at Hetzner |
| Kopieën van de hele server | Hetzner Backups | Volgens de instelling van ons abonnement daar (nu 7 dagen), meegeteld in de 17 dagen hierboven |
| Copies of the whole server | Hetzner Backups | Under the setting of our plan there (now 7 days), counted in the 17 days above |
| Back-ups van de dashboarddatabase | Supabase (EU) | De back-ups maakt Supabase, volgens de instelling van ons abonnement daar (nu 7 dagen) |
| Backups of the dashboard database | Supabase (EU) | Supabase makes the backups, under the setting of our plan there (now 7 days) |
| Betalingen en facturen | Dashboarddatabase (Supabase, EU) en Mollie | Tot zeven jaar na het einde van het jaar van de factuur, de fiscale bewaarplicht, ook na het opheffen van de organisatie |
| Payments and invoices | Dashboard database (Supabase, EU) and Mollie | Until seven years after the end of the year of the invoice, the statutory retention for tax records, also after the organisation is closed |
| Kortingen | Dashboarddatabase (Supabase, EU); lezen alleen eigenaar en beheerder, schrijven alleen de dienstsleutel vanuit Beheer | Percentage, einddatum, wanneer gezet en door welke beheerder van EverStamp, tot de korting wordt weggehaald of de organisatie opgeheven; op de factuur een eigen regel (‘Korting 50%’), met de termijn van de factuur; de reden in het beheerlog |
| Discounts | Dashboard database (Supabase, EU); read by owner and administrator only, written only by the service key from Beheer | Percentage, end date, when set and by which EverStamp administrator, until the discount is removed or the organisation is closed; on the invoice its own line (‘Discount 50%’), with the term of the invoice; the reason in the management log |
| Supportvragen | Dashboarddatabase (Supabase, EU); de mails via Resend en in onze mailbox bij Google Workspace | Twee jaar nadat een vraag is gesloten gewist door de dagtaak; ook na het opheffen van de organisatie, dan zonder koppeling met de organisatie; de mails in onze mailbox bij Google Workspace zolang dat nodig is om de vraag af te handelen en op te volgen |
| Support questions | Dashboard database (Supabase, EU); the emails through Resend and in our mailbox at Google Workspace | Deleted by the daily job two years after a question is closed; also after the organisation is closed, then without the link to the organisation; the emails in our mailbox at Google Workspace for as long as needed to handle and follow up the question |
| Beheerlog (handelingen van de beheerder van EverStamp en mislukte betaalpogingen) | Dashboarddatabase (Supabase, EU), alleen voor de beheerder | 12 maanden, daarna gewist door de dagtaak; tijd, account, handeling, onderwerp (ook een account) en details (zoals een foutmelding, de reden bij een creditnota, de reden en identiteitscheck bij een reset van de tweede stap, of de reden bij een korting met percentage en einddatum van voor en na), waarin bij uitzondering een naam kan staan |
| Management log (actions of the EverStamp administrator and failed payment attempts) | Dashboard database (Supabase, EU), for the administrator only | 12 months, then deleted by the daily job; time, account, action, subject (also an account) and details (such as an error message, the reason for a credit note, the reason and identity check of a reset of the second step, or the reason for a discount with the percentage and end date before and after), which can exceptionally contain a name |
| Nieuws en productnieuws (wat een lid las, en de keuze voor productnieuws per e-mail) | Dashboarddatabase (Supabase, EU) | Zolang het account bestaat; bij verwijderen van het account gaan keuze, afmeldcode en leestijden mee. Geen e-mailadres; per melding alleen het tijdstip van mailen en het aantal ontvangers |
| News and product news (what a member read, and the choice for product news by email) | Dashboard database (Supabase, EU) | For as long as the account exists; when the account is deleted, the choice, the unsubscribe code and the read times go with it. No email address; per message only when it was mailed and the number of recipients |
| Cookies van het dashboard | In de browser, alleen op dashboard.everstamp.app, van het dashboard zelf | lang (taal), tz (tijdzone) en nav (menu open of ingeklapt) een jaar; de inlogcookies van Supabase: de sessie loopt af na 8 uur zonder activiteit en na hooguit 7 dagen (instellingen van ons Supabase-project), het cookie zelf blijft hooguit 400 dagen; de inlogpagina onthoudt in de browser (localStorage, geen cookie) het laatst gebruikte e-mailadres, alleen om het in te vullen als een link verlopen is; alleen functioneel, geen tracking. Vercel Web Analytics zet geen cookie, en everstamp.app zelf zet geen cookies |
| Cookies of the dashboard | In the browser, only on dashboard.everstamp.app, set by the dashboard itself | lang (language), tz (time zone) and nav (menu open or collapsed) one year; the Supabase sign-in cookies: the session ends after 8 hours without activity and after 7 days at most (settings of our Supabase project), the cookie itself stays at most 400 days; the sign-in page keeps the last used email address in the browser (localStorage, not a cookie), only to fill it in when a link has expired; only functional, no tracking. Vercel Web Analytics sets no cookie, and everstamp.app itself sets no cookies |
| E-mail (inloggen, uitnodigingen, verzoeken, offerteaanvragen, contactberichten, betalingen, supportvragen, productnieuws, beveiliging) | Resend | Een inlog- of uitnodigingsmail: het adres en een link, bij een uitnodiging ook de naam van de organisatie. Een verzoekmail aan een gast: de naam van de organisatie, de titel, de einddatum, de notitie van kantoor en de link, geen dossierinhoud. Een offerteaanvraag: de naam, het e-mailadres, de organisatie en het bericht die de aanvrager invult. Een bericht via het contactformulier van de site: de naam, het e-mailadres, de organisatie als die is ingevuld, het onderwerp en het bericht. Een betaalmail aan elke eigenaar: het bedrag en waarvoor; bij een betaling of creditnota ook het nummer, met de factuur of creditnota als pdf-bijlage; na een mislukte incasso zonder bijlage. Een herinnering aan elke eigenaar, een keer, 30 dagen voordat een korting of gratis periode afloopt: de naam van de organisatie, het percentage en de einddatum; niet aan de mailbox voor facturen. Heeft de eigenaar een mailbox voor facturen opgegeven, dan krijgt die alleen de factuur of creditnota als pdf, in een neutrale mail zonder link. Een supportvraag: aan support@ de naam, het e-mailadres en de organisatie van wie de vraag stelt, het onderwerp en het bericht; aan de klant een bevestiging met het nummer en het onderwerp van de vraag, en elk antwoord van EverStamp. Een reset van de tweede stap: aan het lid een melding met een link om opnieuw in te loggen. Productnieuws, alleen aan leden die het zelf aanzetten: het e-mailadres, het onderwerp, de tekst in de taal van het account en een afmeldlink met een persoonlijke code, ook in de koppen List-Unsubscribe en List-Unsubscribe-Post. EverStamp bewaart geen kopie van de verstuurde mail, behalve wat in onze mailbox bij Google Workspace binnenkomt (offerteaanvragen, contactberichten en supportvragen): dat bewaren wij zolang dat nodig is om de vraag af te handelen en op te volgen; wat Resend bewaart staat bij de subverwerkers. |
| Email (sign-in, invitations, requests, quote requests, contact messages, payments, support questions, product news, security) | Resend | A sign-in or invitation email: the address and a link, for an invitation also the organisation’s name. A request email to a guest: the organisation’s name, the title, the end date, the office’s note and the link, no file content. A quote request: the name, email address, organisation and message the requester enters. A message through the site’s contact form: the name, the email address, the organisation if given, the subject and the message. A payment email to each owner: the amount and what it is for; for a payment or credit note also the number, with the invoice or credit note as a PDF attachment; after a failed direct debit without an attachment. A reminder to each owner, once, 30 days before a discount or free period ends: the organisation’s name, the percentage and the end date; not to the mailbox for invoices. If the owner set a mailbox for invoices, it gets only the invoice or credit note as a PDF, in a plain email without a link. A support question: to support@ the name, email address and organisation of the person asking, the subject and the message; to the customer a confirmation with the number and subject of the question, and each answer from EverStamp. A reset of the second step: to the member a notice with a link to sign in again. Product news, only to members who switched it on: the email address, the subject, the text in the language of the account and an unsubscribe link with a personal code, also in the List-Unsubscribe and List-Unsubscribe-Post headers. EverStamp keeps no copy of the email it sends, except what arrives in our mailbox at Google Workspace (quote requests, contact messages and support questions): we keep that for as long as needed to handle and follow up the question; what Resend keeps is listed with the subprocessors. |
| Toegangslog, systeemjournaal en de logs van de dienst op de servers | Hetzner | Hooguit 30 dagen |
| Server access logs, system journal and the service’s logs | Hetzner | At most 30 days |