Privacy statement

Version 2.0, effective date 18 September 2026

This statement covers the personal data for which Eclarion B.V. is itself responsible: that of visitors to this website, of anyone who contacts us, and of customers and users of Eclarion as far as the relationship with us is concerned (account, contract, billing, support). For each situation it says which data we record, what we use it for, on which legal basis and for how long we keep it.

For the data your organisation itself puts into Eclarion (recipes, specifications, your colleagues' accounts, supplier contact details) we are the processor and your organisation the controller. That is governed by our data processing agreement, not by this statement.

Who is responsible?

Eclarion B.V., registered with the Dutch Chamber of Commerce under number 62087282, Nieuwstad 70 C, 6811 BM Arnhem, the Netherlands. Questions about this statement, and requests about your data, go to team@eclarion.com.

When you visit our website

We record which pages are visited, from which country, with which browser and device, and the IP address. That shows us how the site is used, keeps it secure and which companies visit us. The latter works at company level, without a profile of you as a person. If you do not want that, you can object, see your rights below. The statistics work without cookies and cannot be traced to a person.

Legal basis: our legitimate interest in a working and secure website and in knowing which companies are interested in Eclarion.

We only use cookies that are needed to make the site work. We show no advertising and use no third-party tracking cookies, which is why you see no cookie banner here.

When you contact us

Through the contact form, by email or through the chat in Eclarion we record your name, email address and the content of the conversation. With it we answer your question, and we find the conversation again if you contact us later. Legal basis: the performance of the agreement if you are a customer, and otherwise our legitimate interest in answering your question.

When your organisation is a customer

Of the contact persons at a customer we record name, business email address, company details and billing details, and the phone number if you provide one. With these we deliver the subscription, invoice, provide support and inform you about changes to the service, such as a new version of the terms or of the sub-processor list. Legal basis: the performance of the agreement, and for the administration our legal obligation.

Every user of Eclarion has a personal account with name, business email address, password (stored as a hash, we cannot read it either), role and language preference, possibly supplemented with data for two-factor authentication. We record when and from which IP address someone signs in. That is needed to deliver the service securely.

We make no decisions about you based on automated processing.

How long do we keep your data?

  • Visitor statistics: indefinitely, because they are aggregated and cannot be traced to a person.
  • Contact and support conversations: seven years after the last contact, so that in a later conversation we know what was discussed before. After that we remove the name and contact details from the conversation. We keep the content to improve the product, but it can then no longer be traced to you.
  • Contract and invoice data: at least seven years, the statutory retention period for the administration. After that we remove the details of contact persons. The invoices and company details themselves stay in our administration.
  • Account data: for as long as the subscription runs. After cancellation the environment stays available for three months to export data. After that we delete everything, and copies in backups disappear within 45 days.

Who do we share data with?

Only with parties we need to deliver the service, and only what is needed for that:

  • Hosting and security of the website and the platform: Cloudflare and Hetzner.
  • Support: Plain. For summarising and sorting questions we use AI assistance via Amazon Web Services in the EU. The content is not retained and not used for training.
  • Visitor statistics without cookies: Fathom and Ahrefs. Company recognition by IP address: Leadinfo.
  • Payments and invoicing: Stripe. Bookkeeping: our administration.
  • Email from the platform, such as invitations and password resets: Postmark.

With parties that process personal data on our behalf we conclude a data processing agreement. For the platform they are listed with function, data and location on our sub-processors page. We do not sell data and do not give it to third parties for their own purposes.

The platform, the database and the backups are in the European Union. Some of the parties above process data outside the European Economic Area, mostly in the United States. That happens only under a valid legal framework: the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

How do we protect your data?

What we do to protect data, from encryption to access and recovery, is set out concretely on our security page. If you suspect something is wrong with your data, email team@eclarion.com.

What are your rights?

You can access your data, have it corrected or deleted, object to a processing, withdraw a consent you gave and have your data transferred. Send your request to team@eclarion.com. We verify your identity through the email address we know you by, and you receive an answer within a month at the latest.

If you are unhappy with how we handle your data, you can lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.

Changes

We update this statement when our service or the law requires it. Every version gets its own number and effective date.

Version history

Version Date Change
2.0 18 September 2026 Rewritten: legal bases, retention periods and parties named, aligned with the data processing agreement
1.0 29 May 2026 First numbered version