Data controller
DLP Nederlands
The controller of personal data is DLP Nederlands, a Dutch sole proprietorship: De Vriendschap 48, 1188 GL Amstelveen, the Netherlands; KVK 42052238. Privacy questions and data subject requests can be sent to privacy@dlpnederlands.com.
We do not sell data and do not use advertising pixels, Google Analytics or cross-site profiling. DLP product analytics is first-party and does not store IP addresses, User-Agent strings, card text or selected answers. Cloudflare Web Analytics provides separate aggregate, cookie-free page and performance measurements.
1. Scope
This policy applies to dlpnederlands.com, its learning cards, accounts, progress synchronisation, Social Studio, restricted learning materials and email correspondence. YouTube, TikTok, Meta/Facebook and other external services determine independently how they process data on their platforms.
2. Data we process
- Technical logs: IP address, time, URL, request headers and security events required to deliver and protect the website.
- Catalogue abuse prevention: for rate limiting, the server derives a keyed, irreversible HMAC from an account ID or source IP address. The database stores only that HMAC, the request count and the beginning of the current time window, never the source IP address or User-Agent in this record.
- Product analytics: UTM source and campaign, normalised referrer hostname, a coarse browser/known-bot/unknown class, raw page opening, confirmed user interaction, start of learning, number of answers, reaching the useful-learning-session threshold and whether an anonymous browser returned on another day. The raw User-Agent is used transiently for classification and is not stored; the full Referer is not stored. Separate random tab and browser IDs are generated first-party; the server stores only domain-separated cryptographic HMAC values, never the raw IDs.
- Aggregate web performance: the public learning application loads the Cloudflare Web Analytics beacon to measure aggregate page views and real-user performance timings. It does not set cookies, use local storage or assign a persistent identifier, and is not used to recognise a person across visits.
- Local data: progress, active days, filters, theme and settings. Without signing in, they remain in the user's browser.
- Account data: email address, password hash, server session, acceptance of legal terms and synchronised progress.
- Social Studio content: original filename, MP4 file, size, duration, caption, selected platform settings, publication identifiers and status.
- Connected platforms: creator/channel identifier and name, granted scopes, encrypted access and refresh tokens, and the data required to complete an authorised publication.
- Telegram destinations: Telegram user ID used during connection, channel or group ID, title, public username, destination type, bot/user administrator status, message ID and publication status. The one-time Studio connection token is stored only as a hash and expires after ten minutes.
- Restricted materials: the technical fact that an authorised file request occurred may appear in an access log; restricted videos themselves are not published publicly.
- Email: sender address, message content and technical headers when a user contacts us.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Displaying the site and saving settings and learning progress | Providing the requested feature and legitimate interest in operating the learning service |
| Sign-in, synchronisation and protection of restricted materials | Providing the requested service and legitimate interest in security |
| Uploading creator content and publishing it to a platform explicitly connected by the creator | Performance of the requested service and the creator's explicit action |
| Attack prevention, diagnostics and availability | Legitimate interest in secure and reliable operation |
| Assessing the usefulness of publications and the product | Legitimate interest with data minimisation and pseudonymisation |
| Responding to requests and complying with law | Responding to a request, legitimate interest and legal obligation |
4. Recipients and international transfers
- Hetzner Online GmbH, Germany, EEA — application server, database and technical logs.
- Cloudflare, Inc. — DNS, incoming email forwarding and cookie-free Web Analytics for aggregate page and performance measurements. Website HTTP traffic is not currently proxied through Cloudflare; the learning application loads the analytics beacon directly from Cloudflare.
- Google — destination mailbox and, when authorised by a Social Studio creator, YouTube account connection and video upload.
- TikTok — when authorised by a Social Studio creator, TikTok account connection, creator settings and video transfer.
- Meta Platforms, Inc. — when authorised by a Social Studio creator, Meta account connection, a list of Pages the creator manages and linked Instagram professional accounts, the selected destination identifiers/names, encrypted Page access token, Reel transfer and Facebook/Instagram insights.
- Telegram Messenger Inc. — when a creator explicitly connects a channel or group, verification of administrator/member rights and transfer of the approved video, caption and optional link button through the Telegram Bot API.
For processing outside the EEA, providers use available legal mechanisms, including adequacy decisions, the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses. Data is not disclosed to advertising networks.
5. Retention
- browser data — until the user clears site data or resets the relevant setting;
- authenticated session — until sign-out or expiry, for a maximum of 30 days;
- account and synchronised progress — while the account exists or until justified deletion; backups are deleted within 30 days;
- Social Studio video file — seven days after upload; publication audit metadata may remain with the account until deletion;
- platform OAuth tokens — until the platform is disconnected, the grant expires or the account is deleted;
- Telegram destination and publication audit metadata — until disconnection or account deletion; short-lived connection requests expire after ten minutes and are removed during routine maintenance;
- first-party analytics containing a session HMAC — no more than 180 days; anonymous aggregates may be kept longer;
- catalogue rate-limit HMAC and counters — normally one active window and no more than 24 hours;
- technical logs — until automatic size-based rotation, or longer when required for incident investigation;
- correspondence — while needed to respond, fulfil a request or defend legal claims.
6. Data protection and security
We use technical and organisational safeguards appropriate to the data and the service:
- Encryption in transit: the production website, OAuth callbacks and media-transfer URLs use HTTPS.
- OAuth token protection: Google/YouTube and other platform access and refresh tokens are encrypted at application level using authenticated encryption before they are written to the database. Encryption keys are kept outside the source code and database in restricted server configuration.
- Account and session protection: passwords are stored only as one-way hashes. Authenticated sessions use Secure, HttpOnly and SameSite cookies, and state-changing requests are protected against cross-site request forgery.
- Access control and isolation: Social Studio requires authentication. Connected channels, uploaded files and publication records are selected by both record identifier and the current account owner; administrative functions require staff permissions.
- Data minimisation and expiry: DLP requests only the platform scopes needed for the chosen feature. Uploaded MP4 files expire after seven days and are removed by an automated maintenance task. Disconnecting YouTube deletes the stored DLP connection and its encrypted tokens; access can also be revoked in Google Account settings.
- Operational protection: access is limited to authorised operators, secrets are excluded from the source repository, technical logs and security controls are used to detect abuse, and software dependencies and safeguards are reviewed and updated as the service changes.
- Catalogue minimisation: the browser receives only a bounded learning selection and the matching audio references. The complete card and speech catalogues are kept outside the public web root; per-account or per-address request limits make systematic extraction materially harder.
No internet service can guarantee absolute security. If we become aware of a personal-data breach, we will investigate, contain it and notify affected users and authorities when required by applicable law.
7. Your rights
Where applicable, you may request access, correction, deletion, restriction or portability of your data, and object to processing based on legitimate interests. Send requests to privacy@dlpnederlands.com. We may ask for the minimum identification necessary and normally respond within one month.
You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
8. Children and automated decisions
Social Studio is limited to adults. A learning account for a minor may only be used under the supervision of a parent or legal guardian and may not use Social Studio. The website does not make solely automated decisions that produce legal or similarly significant effects and does not create advertising profiles.
9. YouTube API Services
When a creator connects YouTube, DLP uses YouTube API Services with the youtube.upload scope to upload only the video and metadata that the creator explicitly submits. We store the connected channel identifier/name and encrypted OAuth tokens until disconnection or account deletion. DLP's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google processes the upload under the Google Privacy Policy and YouTube Terms of Service. Access can be revoked at Google security settings; deletion can also be requested from DLP.
10. TikTok Login Kit and Content Posting API
When a creator connects TikTok, DLP retrieves the creator name and current publishing options and sends only a video and settings explicitly approved by that creator. OAuth tokens are stored encrypted. TikTok independently processes connected-account data and submitted content under its own terms and privacy policy. A creator can revoke DLP in TikTok settings or request deletion from DLP.
11. Meta Platform, Instagram accounts and Facebook Pages
When a creator connects Facebook or Instagram, DLP requests only the permissions required to list Pages managed by that creator and their linked Instagram professional accounts, publish a Reel to the destination explicitly selected by the creator, and display basic engagement insights. DLP stores the selected Page and/or Instagram account identifier/name, granted scopes and encrypted Page access token until disconnection, expiry or account deletion. Instagram and Facebook are separate destinations and DLP never publishes to either without a separate confirmation for the selected video. Meta processes the connection, destination data and submitted content under the Meta Privacy Policy and applicable platform terms. Access can be removed in Facebook's Business Integrations settings or by disconnecting Instagram or Facebook in DLP.
12. Telegram Bot API
When a creator connects Telegram, DLP opens the service bot and uses Telegram's native chat-selection flow. Before saving a destination, DLP verifies that the creator administers it and that the bot has the required membership or channel-posting right. DLP stores no creator Telegram access token. It sends only the video, caption and optional HTTPS button explicitly approved by the creator. Disconnecting Telegram disables future DLP publications but does not delete messages already published; those can be removed in Telegram by an authorised administrator.
13. Changes
We update this policy when processing changes—for example, before introducing payments, a new tracker or a third-party embedded player. The current revision date is always shown at the top of this page.