Privacy statement (privacyverklaring). This explains what Ridoco does with personal data, under the General Data Protection Regulation (AVG). It describes what this website and this business actually do, and it names nothing that is not in use. Last revised 11 August 2026.
1. Who is responsible
The controller (verwerkingsverantwoordelijke) is:
- Ridoco, a Dutch sole proprietorship (eenmanszaak)
- De Nieuwe Erven 3-12572, 5431 NV Cuijk, Netherlands
- Chamber of Commerce (KvK) 95439609, VAT identification number (btw-identificatienummer) NL005153257B49
- Email: contact@ridoco.com
- Phone: 06 49154776, from outside the Netherlands +31 6 49154776
There is no data protection officer, and none is required. Art. 37 AVG requires a DPO for public authorities, for organisations whose core activity is large-scale regular and systematic monitoring of people, and for large-scale processing of special categories of data. Ridoco is a one-person business that builds websites and does IT and security work, and none of those conditions apply. Questions go to contact@ridoco.com and are answered by the person who runs the company.
2. What is processed, why, and for how long
2.1 Your account
Data: username, display name, email address, a one-way hash of your password (never the password itself), and anything optional you choose to fill in such as an avatar, a short description, social links or a date of birth. Date of birth is private by default.
Why and on what basis: to give you the account you asked for and to let you sign in, art. 6(1)(b) AVG, performance of a contract with you.
How long: while the account exists. Deleting it is covered in section 7.
2.2 Support tickets, and their attachments
Data: the subject and body of your ticket, the category and any tags, every reply on the thread, and any files you attach, up to three per message. Attachments often contain more than people expect: screenshots of a desktop, an exported configuration, a log file, an invoice. Whatever you send is what is stored.
Where the files live: attachments are written to a private area of the server that sits outside the public web root. They have no public URL. They can only be reached through a route that first checks the request belongs to the person the ticket belongs to. They are not sent to any third party.
Why and on what basis: to answer you and to carry out the work, art. 6(1)(b). Where the ticket is not about a contract, art. 6(1)(f), the legitimate interest in running a support channel at all.
How long: kept with your account so the history of a job stays readable. A ticket that evidences a paid job forms part of the record of that transaction and follows the seven year rule in 2.5. You can ask for a specific attachment to be deleted at any time and it is deleted.
2.3 Bookings
Data: the name and email address you enter, your time zone, any notes you add, the slot you chose, and a random token that is part of your management link so you can change or cancel the appointment without an account. For a visit to your address the booking also records the street and number, the postcode, the town, a telephone number, and the province you pick for the travel charge.
Why and on what basis: art. 6(1)(b), a step taken at your request before a contract.
How long: for as long as the appointment and any follow-up are relevant, and removed on request. A booking that turned into a paid job becomes part of the record of that job.
2.4 The contact form, and WhatsApp
Data: your name, email address, subject and message, plus the company name and telephone number when you fill those in.
Why and on what basis: to answer you, art. 6(1)(f) and, where you are asking about work, art. 6(1)(b).
How long: what you send is recorded as a support ticket on this site and emailed to the operator. The ticket is kept as long as the correspondence is relevant and is removed on request. The email in the mailbox is kept on the same footing.
WhatsApp: the footer of every page offers WhatsApp as a way to make contact. If you use it, the conversation runs over a service operated by WhatsApp Ireland Ltd, part of Meta, and their terms and privacy statement apply to it alongside this one. What is processed there is your phone number, which is how the service identifies you, and whatever you send. The message content is end-to-end encrypted between the two devices; the fact that you made contact, when, and from which number is not. The chat stays on both phones until it is deleted at either end. Same legal bases as above. If a question involves documents, account details or anything you would rather not put through a third party's messenger, use email or a support ticket instead: 2.2 explains where ticket attachments are stored, which is on this server and not with anybody else.
2.5 Orders, invoices, and withdrawal statements
Data: what you bought, amounts, currency, VAT treatment and rate, the capacity you declared (consumer or business) and for a business the company name and the KvK and VAT numbers, the payment status and a payment reference, the IP address recorded at the time of the order, and the timestamps that decide a withdrawal deadline. Where the site asks you to confirm a statement before buying, the exact wording you agreed to is stored together with a hash of it, the time, your IP address and your browser user agent. That record exists to prove later what you were shown.
If you withdraw from a contract, the withdrawal statement is stored: your name, which contract, the contact address you gave, the text of your statement, the time it arrived and whether it was inside the deadline.
Why and on what basis: art. 6(1)(b) to perform the contract, and art. 6(1)(c) because Dutch tax law requires the administration to be kept. The consent and withdrawal records exist to meet obligations under consumer law, art. 6(1)(c).
How long: seven years from the end of the financial year, the retention period for business records under Dutch tax law. These records are not deleted on request during that period. The obligation to keep them overrides the request. Everything else about you still is.
2.6 Care plans and other subscriptions
Data: the plan, the billing interval and amount, VAT rate and country, a VAT number for reverse charge where it applies, the start date, the current billing period, and the dates of any cancellation, payment failure or suspension.
Why and on what basis: art. 6(1)(b) and art. 6(1)(c) for the invoicing part.
How long: while the plan runs, then under the seven year rule in 2.5 for the parts that are invoicing records.
2.7 The newsletter
Data: your email address, where you signed up, a one-time confirmation token, and the dates you subscribed, confirmed and unsubscribed.
Why and on what basis: art. 6(1)(a), your consent. Sign-up is double opt-in: nothing is sent until you click the link in the confirmation email. An address entered by someone else never receives anything.
How long: until you unsubscribe. Every mailing carries an unsubscribe link. The record that you consented, and when, is kept afterwards because that is the proof that the mailings were lawful.
2.8 Comments and anything else you post
Data: what you wrote, when, and the account it was posted from.
Why and on what basis: art. 6(1)(b): publishing what you posted is what you asked for. Art. 6(1)(f) covers moderation.
How long: while it is published. Removed on request, or by moderation.
2.9 Server and application logs
Data: the web server records requests with an IP address, a timestamp, the page requested and your browser user agent. A signed-in session is stored server side with the IP address and user agent it was created from. Application error logs may contain a URL, an account id and a technical stack trace. Automated calls to outside services made on your behalf are logged with the endpoint and the result.
Why and on what basis: art. 6(1)(f). The interest is keeping the site working, finding faults, and dealing with abuse such as brute force login attempts and spam. Logs are not used to build a profile of you and are not used for marketing.
How long: a signed-in session expires after 120 minutes of inactivity. Server and error logs are kept for as long as they are useful for diagnosis and security, in the order of months, and are then rotated away.
2.10 Cookies
Covered in section 3, and in full in the Cookie Policy.
3. Cookies
This site sets a small number of first-party cookies and nothing else.
| Cookie | What it does | How long |
|---|---|---|
ridoco_session | Keeps you signed in during a visit. Required. | Session, 120 minutes of inactivity |
XSRF-TOKEN | Stops another site from submitting forms as you. Required. | Session |
remember_web_* | Set only if you tick "remember me" when signing in. | Long lived, cleared when you sign out |
cookie_consent | Remembers the choice you made in the cookie banner. You are not asked again. | 1 year |
All four are strictly necessary or are a direct record of your own choice. No analytics cookie is set and no analytics script is loaded. No analytics measurement id is configured on this installation. The software supports Google Analytics behind the consent banner; it is switched off, so nothing is sent anywhere. If that ever changes, the analytics cookies would only be set after you accept them in the banner, and this section and the Cookie Policy would be updated before it happened.
Blocking the first two cookies in your browser will stop you from signing in.
4. Who else handles your data
- Hosting. The site and its database run on a virtual private server rented from a hosting provider inside the European Union, which acts as a processor under a data processing agreement. The provider's name is given on request.
- Email. Messages the site sends you, confirmations, ticket notifications, invoices and newsletter mailings, go out through an SMTP mail provider for the ridoco.com domain, which acts as a processor. Email you send to contact@ridoco.com arrives in that same mailbox.
- Payments. Work is quoted and then invoiced, and an invoice is paid by bank transfer, which involves your bank and Ridoco's bank and nobody else. This site cannot take an online payment at all right now. No payment provider is configured on it, so there is no checkout to reach and no payment data leaves this site to anyone. If online payment is switched on, the provider handling it is named in this section before the first payment is taken, not after.
- Error monitoring. When the software on this site fails, a report of the failure goes to Sentry (Functional Software, Inc., San Francisco, United States), which acts as a processor. The report is sent to Sentry's European region and stored in Frankfurt, Germany. It holds the error, the stack trace, the address of the page with any token in it removed, and the shape of the database statement without the values in it. Your name, your email address, your IP address, your cookies and anything you typed into a form are not part of it. Sentry runs on the server and not in your browser. Opening a page here sends nothing to it.
Present in the software, and not in use. This site is built on a general purpose platform that also ships optional integrations: two further payment providers, Stripe and PayPal, a set of social sign-in buttons, and an analytics tag. None of them has credentials configured here. With no keys there is no connection to make, so those integrations are unreachable and receive no data at all.
Data is disclosed to nobody else, and it is never sold. It can be disclosed to an authority where a legal obligation or a valid legal order requires it, and to an accountant or a lawyer bound by professional secrecy where that is necessary.
5. Third-party requests, and transfers outside the EEA
Opening a page on this site makes requests to this domain only. The fonts are self-hosted, not loaded from a font network. There is no analytics tag, no advertising pixel, no embedded tracker, no CDN and no chat widget. That means no third party learns your IP address, your browser or which page you were reading, simply because you visited.
That is a statement about what these web pages load. It says nothing about the network between you and the server, and it does not apply to what happens after you leave a link or send an email.
Transfers outside the EEA: the server is in the EU and the processors named in section 4 store your data in the EU. Sentry is the one exception worth spelling out: the error reports stay in its European region in Frankfurt, and the company behind it is established in the United States. Its staff can reach that region to support and administer the service. That access runs under the European Commission's standard contractual clauses, and Sentry is certified under the EU-U.S. Data Privacy Framework. Apart from that access, no routine transfer of personal data outside the EEA takes place through this website. If that ever changes, this section says so first, and names the transfer mechanism used.
6. Your rights
You have the right to see your data (art. 15), correct it (art. 16), have it erased (art. 17), restrict how it is used (art. 18), receive it in a portable format (art. 20), object to processing based on legitimate interest (art. 21), and withdraw consent at any time without that affecting what was done before.
Routes that exist on this site right now:
- See and take your data. Signed in, download a copy of your data as a JSON file. It contains your profile, linked accounts, orders, subscriptions and newsletter status.
- Correct it. Signed in, edit your profile under Account.
- Erase it. Signed in, delete your account from the profile edit screen. It asks for your password. What happens next is section 7.
- Withdraw marketing consent. Use the unsubscribe link in any mailing, or the revoke consents action in your account.
- Anything else, including access, restriction, objection or an erasure request without an account: email contact@ridoco.com.
A request is answered within one month (art. 12(3) AVG). If a request is complex, that can be extended by two months, and you are told inside the first month if it is. There is no charge. You may be asked to confirm who you are, and no more than that.
7. Deleting your account
- Immediately. Deleting your account signs you out, closes it, removes it from the site, and revokes any linked sign-in providers so the account cannot be re-linked.
- Then. The identifying fields on the record, the username, display name and email address, are overwritten so the record no longer points at a person. The row itself is kept. Orders, subscriptions, invoices and download history hang off it, and force-deleting it would take the accounting record with it. That record has to survive under 2.5.
- Who does that. An automatic sweep overwrites those fields 30 days after deletion, and it is switched on for this site. Ridoco also does it straight away if you email contact@ridoco.com and ask. Ask for written confirmation when it is done and you get it.
- What survives. Invoicing and order records under 2.5, for seven years, under Dutch tax law. Newsletter consent records, as proof that mailings were lawful. Anything you published that others replied to may be kept in anonymised form.
8. How the data is protected
- Traffic to the site is encrypted with TLS.
- Passwords are stored as one-way hashes and cannot be read back, by anyone, including Ridoco.
- Ticket attachments and other uploaded files sit outside the public web root with private visibility, behind an ownership check.
- Pages are served with a content security policy. It defaults to this site only, runs scripts from a per-response nonce, blocks plugins outright, and confines background connections to this domain. It is inherited from the platform Ridoco builds on and it still permits a short list of outside hosts that these pages do not use: a script CDN for an editor component, Google's font servers, video and audio embed frames, and the form targets of payment providers that carry no credentials here. The policy is a floor. Section 5 is a measurement of what these pages actually request, which is this domain and nothing else.
- Sign-in, password reset, ticket submission and other sensitive actions are rate limited against brute force and abuse.
- Access to the administration side is limited to the one person who runs the company.
If a data breach occurs that is likely to present a risk, it is reported to the Autoriteit Persoonsgegevens within 72 hours, and where the risk to you is high you are told directly.
9. Children
Ridoco sells services to adults and to businesses. This site is not aimed at children, and personal data is not knowingly collected from a child. If you believe a child has created an account here, write to contact@ridoco.com and it is removed.
10. Complaints
If you think your data is being handled wrongly, say so to contact@ridoco.com first.
You always have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens in The Hague (autoriteitpersoonsgegevens.nl), or with the supervisory authority in the EU country where you live or work.
11. Changes to this statement
This statement changes when what Ridoco does changes, and not otherwise. Revisions are recorded with a date. The version that applied at a given moment can be produced. A change that materially affects you is announced.
The terms that govern the work itself are at Terms of Service.