Skip to main content

Privacy statement

Last updated: January 1, 2026

Offsoo B.V. ("Offsoo", "we", "us") attaches great importance to the protection of personal data. This privacy statement explains which personal data we process, for which purposes, on which legal bases, and which rights data subjects have.

This privacy statement is drawn up in accordance with the General Data Protection Regulation (GDPR).

Who is responsible?

Offsoo B.V.

  • Place of business: Utrecht, the Netherlands
  • Chamber of Commerce: 82696233
  • Email:

Offsoo may act as:

  • Controller (for the website, marketing, sales, administration and support outside the Offsoo app, for example);
  • Processor (for personal data Customers process within the Offsoo application).

When is Offsoo the controller?

Offsoo is the controller for personal data we process in connection with:

  • website visits and contact or demo forms;
  • marketing and communication (including email campaigns);
  • sales and relationship management;
  • invoicing and administration;
  • support requests (through Intercom or email, for example) insofar as Offsoo is itself the controller.

Which personal data do we process?

  • company name;
  • name;
  • email address and telephone number;
  • the content of communication (a message or chat, for example);
  • invoice and payment details (insofar as necessary);
  • technical data such as IP address, device and browser data (including through cookies).

Purposes

  • answering questions and scheduling demos;
  • entering into and performing agreements;
  • marketing and communication (only where permitted);
  • improving our website and services;
  • complying with legal obligations.

Legal bases

  • performance of an agreement or taking pre-contractual steps;
  • legal obligation (a tax retention obligation, for example);
  • legitimate interest (business operations, security, fraud prevention, for example);
  • consent (marketing cookies and certain marketing activities, for example).

When is Offsoo a processor?

Within the Offsoo application, Offsoo processes personal data on behalf of its Customers. In that case:

  • the Customer is the controller;
  • Offsoo is the processor;
  • the Customer determines which personal data is processed and for which purpose.

The arrangements are set out in the Data Processing Agreement (DPA) between Offsoo and the Customer.

Types of personal data in the Offsoo app

Depending on how the application is used, the following may be processed:

  • user and account data;
  • contact details of the Customer's clients and contacts;
  • planning, task and work notes;
  • time records and activities;
  • log and audit data;
  • content Users enter in free-text fields.

Sharing personal data and (sub)processors

Offsoo shares personal data with third parties only where this is necessary to provide our services or to comply with legal obligations. In doing so we use service providers such as hosting, support and monitoring tools. A current overview is on the Subprocessors page.

Transfers outside the European Economic Area (EEA)

Some service providers may process personal data outside the EEA (in the United States, for example). Where that is the case, Offsoo ensures a valid transfer mechanism, such as:

  • Standard Contractual Clauses (SCCs);
  • an adequacy decision;
  • the EU-US Data Privacy Framework (DPF), where applicable.

Retention periods

Offsoo does not keep personal data longer than necessary.

Offsoo as controller

  • Administration and invoice data: 7 years (statutory retention obligation).
  • Contact and sales communication: for as long as needed for follow-up, and after that a maximum of 24 months from the last contact, unless a longer period is necessary (in the event of a dispute, for example).
  • Support communication: for as long as the relationship lasts and after that a maximum of 24 months from closing the support request, unless a longer period is necessary (for evidence or security, for example).

Offsoo as processor (data in the Offsoo app)

  • After termination of the agreement, the Customer's Offsoo environment is no longer accessible to the Customer.
  • Offsoo retains Customer data until the Customer requests deletion, with a maximum retention period of one (1) year after termination.
  • Backups have a maximum retention of three (3) months. Deletion from backups takes place through expiry of that retention and/or through complete deletion of an environment.

Security

Offsoo takes appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access. More information is on the Security and Information Security page.

Cookies and similar techniques

Offsoo uses cookies and similar techniques on its website and, to a limited extent, in the application. Analytical and marketing cookies are placed only after consent, where required. More information is in the Cookie Policy.

Rights of data subjects

Under the GDPR, data subjects have the following rights, among others:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • data portability;
  • objection;
  • withdrawal of consent (where applicable).

Exercising these rights

Requests can be submitted through . Offsoo may ask for additional information to verify identity. In principle we verify through the email address known to us; we ask for additional verification only in case of doubt. We do not ask for copies of identity documents unless strictly necessary. Where Offsoo acts as a processor, we forward the request to the Customer concerned (the controller).

Complaints

If data subjects have complaints about the processing of personal data, they can contact us at . Data subjects also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Changes

Offsoo may amend this privacy statement. The most recent version is available on our website.

Contact

For questions about this page, contact us at .