Privacy Policy — PrikKlokPlus
This is the privacy policy of Aevonix B.V., trading as PrikKlokPlus ("PrikKlokPlus", "we", "us", or "our"), provider of the PrikKlokPlus SaaS platform — software for time tracking, scrum planning, and invoicing. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Dutch implementing legislation (UAVG).
1. Controller contact details
| Company | Aevonix B.V., trading as PrikKlokPlus |
| Address | Heresstraat 1, 9665 NV Oude Pekela, Netherlands |
| Chamber of Commerce | 42123774 |
| VAT number | NL869834216B01 |
| Privacy email | privacy@prikklokplus.nl |
| Website | https://prikklokplus.nl |
We are not legally required to appoint a Data Protection Officer (DPO). For privacy questions, contact privacy@prikklokplus.nl.
2. Controller and processor roles
Controller — we are the controller for data related to our own service operations: account management, subscription billing, platform security, and communications from PrikKlokPlus.
Processor — when you as a tenant store data about your employees, clients, or projects inside PrikKlokPlus, we act as a processor on your behalf. A Data Processing Agreement (DPA) governs those data flows. The DPA is available at /legal/dpa.
3. What personal data we process
3.1 Account data
- Name (first and last), email address
- Hashed password (bcrypt — we never see the plaintext password)
- Registration timestamp and IP address
- Language and display preferences (locale, date format, dark mode)
- Two-factor authentication settings (TOTP secret key, recovery codes — encrypted)
- Passkey credentials (WebAuthn public key only)
3.2 Application usage data
- Hour entries: date, project, task, hours, description, approval status
- Tasks and sprints: title, priority, type, assignee, due date, progress
- Projects: name, description, start/end date, linked client relation
- CRM data: client relation names and contact details, invoices, quotes, line items
- Activity log: who performed which action and when (audit and security purposes)
3.3 Billing data
- Company name, billing address, VAT number, Chamber of Commerce number, IBAN
- Invoice history and payment status
- Payments processed via Mollie B.V. — we do not store full payment instrument details
3.4 Technical and security data
- IP addresses (at login, registration, and API requests)
- Session ID (cookie-based, linked to a server-side session record)
- Browser type and operating system (User-Agent header)
- Login/logout timestamps and failed login attempts
- Error messages and request traces (processed by our self-hosted Grafana/Loki/Tempo monitoring stack — see §6)
3.5 Email communications
- Email addresses for transactional messages: invitations, hour approvals, invoice notifications, security alerts
- Email preferences (opt-out per category, stored in
user_email_preferences)
4. Purposes and legal bases
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Account creation and management | Performance of contract (art. 6(1)(b)) |
| Delivery of SaaS service (hours, tasks, projects, CRM) | Performance of contract (art. 6(1)(b)) |
| Subscription billing | Performance of contract + legal obligation (art. 6(1)(b)(c)) |
| Statutory invoice retention (7 years) | Legal obligation — Dutch VAT Act (art. 6(1)(c)) |
| Platform security and fraud prevention | Legitimate interests (art. 6(1)(f)) |
| Error tracking and platform stability (self-hosted monitoring) | Legitimate interests (art. 6(1)(f)) |
| Product analytics (self-hosted, no cookies) | Legitimate interests (art. 6(1)(f)) |
| Transactional emails | Performance of contract (art. 6(1)(b)) |
| Opt-in product newsletter | Consent (art. 6(1)(a)) |
We never use your data for automated individual decision-making or profiling (GDPR art. 22) without human review.
5. Retention periods
| Data type | Retention | Reason |
|---|---|---|
| Account data (name, email) | Until account deletion + 2 years | Business correspondence; GDPR art. 17(3) |
| Hashed password, 2FA secret | Until account deleted | Security requirement |
| Hour entries | 7 years | Dutch accounting obligation (art. 52 AWR) |
| Invoices and payment data | 7 years | Statutory tax retention (Dutch VAT Act) |
| Activity log | 90 days | Security monitoring; auto-deleted thereafter |
| IP addresses in logs | 30 days | Security monitoring; auto-deleted thereafter |
| Session data | 2 hours of inactivity | Technical necessity; auto-expired |
| Monitoring traces and logs | 90 days | Debugging; auto-deleted thereafter |
6. Sub-processors and third parties
| Sub-processor | Service | Data location | Transfer outside EEA |
|---|---|---|---|
| Contabo GmbH | Server hosting (application and database); self-hosted transactional email (own SMTP server); self-hosted analytics (Plausible); self-hosted monitoring and error tracking (Grafana, Loki, Tempo, Prometheus); self-hosted source code and CI/CD (Forgejo) — all on our own infrastructure | Germany (EU) | No |
| Hetzner Online GmbH | Backup storage | Germany / Netherlands (EU) | No |
| Mollie B.V. | Payment processing | Netherlands (EU) | No |
We never sell your personal data to third parties. Transactional email, analytics (Plausible) and monitoring/error tracking (Grafana/Loki/Tempo/Prometheus) are self-hosted on our own infrastructure in the EU — no personal data leaves the EEA.
7. Security
- Encryption in transit: TLS 1.2+ (HTTPS) for all connections
- Encryption at rest: database disks encrypted at server level
- Passwords: bcrypt hashing — never stored or transmitted in plaintext
- MFA: TOTP and passkeys available for all accounts
- Sessions: HTTP-only, Secure, SameSite=Lax cookies; expire after 2 hours of inactivity
- Rate limiting: login attempts limited (5 per minute per IP + email); registration limited (3 per 10 minutes per IP)
- Access control: staff access on need-to-know, least-privilege basis; secured with MFA
In the event of a personal data breach likely to result in a high risk to your rights, we will notify you promptly and report to the Dutch DPA (AP) within 72 hours (GDPR art. 33–34).
8. Cookies
| Cookie | Type | Purpose | Retention |
|---|---|---|---|
prikklokplus_session | Essential | Authentication and session management | 2 hours of inactivity |
XSRF-TOKEN | Essential | CSRF attack protection | Session |
appearance | Functional | Storing theme preference (light/dark) | 1 year |
locale | Functional | Storing language preference | 1 year |
We do not use tracking or marketing cookies. No third-party advertising cookies are placed.
9. Your rights
| Right | Description | How to exercise |
|---|---|---|
| Access (art. 15) | Request what data we hold about you | Settings → Data export or email us |
| Rectification (art. 16) | Have inaccurate data corrected | Via your profile settings or email |
| Erasure (art. 17) | Request deletion of your account and data | Settings → Delete account |
| Restriction (art. 18) | Have processing temporarily restricted | privacy@prikklokplus.nl |
| Portability (art. 20) | Receive your data in JSON/CSV format | Settings → Data export |
| Objection (art. 21) | Object to processing based on legitimate interests | privacy@prikklokplus.nl |
| Withdraw consent (art. 7(3)) | Withdraw consent (e.g. newsletter) | Unsubscribe link in emails or Settings → Notifications |
We respond within four weeks.
10. Complaints
If you are dissatisfied, please contact privacy@prikklokplus.nl first. You also have the right to lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens (AP)
P.O. Box 93374, 2509 AJ The Hague
autoriteitpersoonsgegevens.nl
11. Changes to this policy
We may update this policy when our services or applicable law require it. For material changes we will notify active users by email and/or in-app notification at least 30 days before the effective date.
Privacyverklaring PrikKlokPlus
Dit is de privacyverklaring van Aevonix B.V., handelend onder de naam PrikKlokPlus, aanbieder van het SaaS-platform PrikKlokPlus. Wij verwerken persoonsgegevens in overeenstemming met de AVG en de Nederlandse UAVG.
1. Contactgegevens
| Bedrijfsnaam | Aevonix B.V., handelend onder de naam PrikKlokPlus |
| Adres | Heresstraat 1, 9665 NV Oude Pekela |
| KvK-nummer | 42123774 |
| BTW-nummer | NL869834216B01 |
| E-mail privacy | privacy@prikklokplus.nl |
2. Welke gegevens verwerken wij?
- Naam en e-mailadres
- Gehasht wachtwoord, 2FA-geheim, passkey-credentials
- Urenregistraties, taken, projecten, CRM-gegevens, factuurgegevens
- IP-adressen (30 dagen), activiteitenlog (90 dagen), sessiedata (2 uur)
- Factuur- en bedrijfsgegevens voor het abonnement (bewaard 7 jaar — BTW-plicht)
3. Grondslagen (AVG art. 6)
- Uitvoering overeenkomst: accountbeheer, Dienst levering, transactionele e-mails
- Wettelijke verplichting: 7-jaar bewaarplicht facturen (BTW-wet)
- Gerechtvaardigd belang: beveiliging, foutopsporing (self-hosted monitoring), anti-fraude
- Toestemming: opt-in nieuwsbrief (intrekbaar via Instellingen → Notificaties)
4. Subverwerkers
Contabo GmbH (Duitsland, EU — hosting, database, self-hosted transactionele e-mail (eigen SMTP-server), self-hosted Plausible-analytics, self-hosted monitoring/ foutopsporing en self-hosted Forgejo broncode/CI, alles op eigen infrastructuur), Hetzner Online GmbH (EU — back-ups), Mollie B.V. (NL). Er verlaten geen persoonsgegevens de EER. Wij verkopen uw gegevens nooit aan derden.
5. Uw rechten
U heeft recht op inzage, rectificatie, vergetelheid, beperking, overdraagbaarheid en bezwaar (AVG art. 15–21). Verzoeken richten aan privacy@prikklokplus.nl of via Instellingen in de applicatie. Reactie binnen vier weken. Klachten: Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl.