Doorst.app — Privacy Policy
Version: 1.1 — Last updated: 18 August 2026 — Effective date: 18 August 2026
This version replaces version 1.0 of 23 June 2026. It adds the recipients we send data to when validating a VAT number or looking up a Dutch address, describes our support access to workspaces, states our retention periods and breach process in detail, and sets out what we do not do with your data.
1. Who we are
Doorst.app is a subscription-management product for productized agencies, owned and operated by:
BTNG B.V. ("Doorst", "we", "us", "our") KvK (Dutch Chamber of Commerce) number: 91214777 RSIN: 865584047 VAT (BTW) number: NL865584047B01 Registered address: Willem Roelofsstraat 3, 7424 GD Deventer, The Netherlands Privacy contact: [email protected]
We are responsible for the processing of personal data as described in this policy. For some data we act as a controller; for other data we act as a processor on behalf of the agencies that use Doorst. Section 4 explains which is which, because it determines your rights and who you should contact.
We are not required to appoint a Data Protection Officer under Article 37 GDPR: we are a small company, and our core activity is not large-scale monitoring or large-scale processing of special-category data. Privacy questions are handled directly by us at [email protected].
2. Scope
This policy covers personal data we process through the Doorst.app website (doorst.app), the application (app.doorst.app and each agency's {agency}.doorst.app environment or custom domain), and related services. It does not cover the websites or services of the agencies who use Doorst, or of our sub-processors, which have their own policies.
3. What data we process, why, and on what legal basis
We process personal data only where we have a lawful basis under Article 6 GDPR (AVG).
Account and identity data — name, email address, hashed password, agency name, role, profile photo if you upload one. Purpose: to create and secure your account and provide the service. Legal basis: performance of a contract (Art. 6(1)(b)).
Agency workspace data — the content an agency creates in Doorst: client records, subscriptions, plans, tasks, comments, time entries, uploaded files (logos, avatars, task covers, attachments). Purpose: to provide the product the agency signed up for. Legal basis: performance of a contract with the agency (Art. 6(1)(b)). Where this content includes the agency's own clients' personal data, we act as a processor — see Section 4.
The agency's clients' data — names, email addresses, billing addresses, VAT numbers, portal login details and related details an agency enters about its own clients so it can bill and serve them. Purpose: to let the agency manage and invoice its clients through Doorst. Legal basis: we process this strictly on the documented instructions of the agency, as its processor. The agency is the controller and is responsible for having its own lawful basis.
Payment data — handled by our payment provider, Mollie. Card and bank details are entered with and stored by Mollie, not by Doorst. We receive only the transaction status and limited metadata needed to manage your subscription. Purpose: to take payment for the service. Legal basis: performance of a contract (Art. 6(1)(b)); compliance with tax-retention obligations for the resulting invoices (Art. 6(1)(c)).
VAT numbers you or your clients provide — we send the VAT number to the European Commission's VIES service to check whether it is valid, which decides whether reverse charge applies. Purpose: correct VAT treatment on invoices. Legal basis: legal obligation (Art. 6(1)(c)) and performance of a contract (Art. 6(1)(b)).
Dutch address lookups — when a Dutch postcode and house number are entered in a billing form, we send only that postcode and house number (never a name or any other detail) to the PDOK Locatieserver, the Dutch government's open address service, to fill in the street and city. Purpose: to save typing and keep billing addresses accurate. Legal basis: legitimate interest in a usable, accurate billing form (Art. 6(1)(f)).
Client agreement signatures — where an agency asks its clients to accept an agreement before a subscription starts, we record the signer's typed name, the date and time, the exact text they agreed to, and the IP address the signature came from. Purpose: to give both sides evidence of what was agreed and when. This is the whole point of the record, which is why it is kept rather than minimised. Legal basis: we process this as the agency's processor, on its instructions; the agency relies on its own legitimate interest in being able to evidence an agreement (Art. 6(1)(f)). Signature records are not altered or deleted by the application, and are removed when the client or the workspace they belong to is deleted.
Usage, technical and log data — IP address, browser/device information, timestamps, and security/audit logs (for example, failed sign-in attempts, administrative actions and deletion events). Purpose: to keep the service secure, prevent abuse and brute-force attacks, and diagnose problems. Legal basis: our legitimate interest in securing and running the service (Art. 6(1)(f)).
Service emails — we send emails that are part of the product: sign-in and email-verification links, invitations, invoice and payment notifications, dunning reminders, and a short onboarding sequence that explains how to set Doorst up. These are sent to agency users and, where the agency uses the portal, to its clients. Purpose: to deliver and administer the service. Legal basis: performance of a contract (Art. 6(1)(b)); for the onboarding sequence, our legitimate interest in helping new customers get the product working (Art. 6(1)(f)). You can ask us to stop the onboarding sequence at any time; transactional and billing emails cannot be switched off while your account is active.
Marketing communications (only if you opt in) — email address. Purpose: to send product updates or other messages you asked to receive. Legal basis: consent (Art. 6(1)(a)), which you can withdraw at any time via the unsubscribe link or by emailing us.
Analytics — we use Plausible Analytics, which is privacy-friendly and cookieless. It sets no cookies and does not track you across sites. Your IP address and browser user-agent are sent to Plausible, which uses them only to generate a rotating daily hash so it can count a visit; neither the IP address nor the hash is stored in a way that identifies you, and we never see them. We also record a small number of product events (for example "invoice issued") as aggregate counts, with no personal identifiers attached. Legal basis: legitimate interest in understanding, in aggregate, how the site and app are used (Art. 6(1)(f)). Because the analytics is cookieless and anonymous, no consent banner is required.
In-app feedback (UserJot) — the agency dashboard embeds UserJot, where agency users send feedback, vote on the roadmap and read the changelog. We pass UserJot your user id, email address, name and avatar so your feedback is attributable. It is not present in the client portal, so your clients never encounter it. See the Cookie Statement for the local-storage detail. Legal basis: legitimate interest in collecting product feedback from our own users (Art. 6(1)(f)).
3a. What we do not do
- We do not sell personal data, and never have.
- We do not use your data, your clients' data, or your workspace content to train artificial-intelligence or machine-learning models, and we do not send it to an AI provider. Doorst contains no AI features.
- We do not run advertising, ad pixels or cross-site tracking, and we set no marketing cookies.
- We do not use personal data for automated decision-making that produces legal or similarly significant effects, and we do not profile you.
- We do not read your workspace content out of curiosity. See Section 6 for the limited support access that exists and how it is logged.
4. Controller vs. processor (important for B2B customers)
Doorst plays two different roles, depending on the data:
- For an agency's own account data (the agency's team members, login details, the agency's billing relationship with us), Doorst is the controller.
- For the agency's clients' personal data that the agency enters into Doorst, Doorst is a processor acting on the agency's behalf. The agency is the controller of that data.
Because we process your clients' personal data as your processor, we offer a Data Processing Agreement (verwerkersovereenkomst / DPA) governing that processing under Article 28 GDPR. Our standard DPA is at doorst.app/dpa and forms part of our agreement with you. If you are an agency handling personal data through Doorst, accept or sign the DPA before processing real client data.
5. Sub-processors
We use a small number of carefully chosen sub-processors to run the service. Where they process personal data on our behalf, they are bound by data-processing terms consistent with Article 28 GDPR.
| Sub-processor | Role | Location |
|---|---|---|
| Mollie | Payment processing (card, iDEAL, SEPA). Card/bank data is stored by Mollie, not Doorst. | Netherlands (EU) |
| Moneybird | Invoicing and accounting | Netherlands (EU) |
| Stripe | Invoicing and payment collection, where an agency connects its own Stripe account to bill its clients | Ireland (EU) / United States |
| UserJot | In-app feedback and feature requests submitted by agency users | United States |
| Hetzner | Application hosting and data storage | Germany (EU) |
| Cloudflare | DNS, transactional email delivery, and off-site backups (R2) | EU / global infrastructure |
| Plausible Analytics | Cookieless, privacy-friendly website analytics | EU |
Our hosting and primary data storage are in the EU (Hetzner, Germany). Where a sub-processor's infrastructure may involve transfers outside the EEA, that transfer is covered by an appropriate safeguard such as the European Commission's Standard Contractual Clauses (SCCs).
We keep this list current. Where we act as your processor, we will inform you of any intended change of sub-processors as set out in the DPA, so you can object.
Other recipients (not sub-processors). Two services receive data without processing it on our behalf: the European Commission's VIES system, which receives a VAT number when we validate it, and the Dutch government's PDOK Locatieserver, which receives a postcode and house number when a Dutch address is looked up. Both are public services in the EU. We also disclose data where the law requires it, for example to a tax authority or on a valid order from a competent authority — and we will tell you unless we are forbidden to.
6. Who inside Doorst can see your data
Access to production data is limited to the people who need it to run the service — today, that is the company's founder, and any future personnel bound by confidentiality.
Doorst has an administrative "view as agency" function that lets us open a workspace as its owner to diagnose a problem. Every use is written to an audit log with the administrator, the workspace and the time. We use it only to investigate a fault, respond to a support request, or meet a legal obligation. Where the issue allows, we will ask you first.
7. International data transfers
Our core processing takes place within the EU/EEA. Two sub-processors involve processing outside the EEA: Stripe (only if an agency connects Stripe as its invoicing provider) and UserJot (in-app feedback from agency users, never client data). Those transfers rely on a valid mechanism under Chapter V GDPR — Standard Contractual Clauses and, where applicable, certification under the EU-US Data Privacy Framework. Beyond that, we do not transfer personal data outside the EEA without an appropriate safeguard.
8. How long we keep data
We keep personal data only as long as necessary for the purposes above.
| Data | Retention |
|---|---|
| Account and workspace data | While the account is active, and at least 30 days after a subscription ends so you can export or reactivate. Erased when you delete the workspace, or after that window. |
| Clients' data (processed as processor) | Per the agency's instructions and the DPA. Erased when the agency deletes the client, company or workspace, together with the associated uploaded files. |
| Invoices and accounting records | 7 years, as Dutch tax law requires. Retained after account deletion and not erased on request before that period ends. |
| Sign-in session | Cookie valid for 7 days (1 day during an administrative "view as" session). |
| Failed sign-in records | Kept for the 15-minute throttle window and pruned daily. |
| Administrative audit log | While the workspace exists; entries about a deleted workspace are kept for security-evidence purposes and then removed. |
| Web-server access logs | Rotated automatically; normally no longer than 14 days. |
| Backups | Daily snapshot; local copies rotate on a 7-daily / 4-weekly / 12-monthly schedule, off-site copies on the bucket lifecycle. Deleted data cycles out as backups are overwritten. |
9. Deletion and right to erasure
Doorst has a built-in right-to-erasure capability. An agency owner can delete their entire workspace from Settings → Account, which erases the workspace's records and its uploaded files, subject only to the statutory retention of invoices described above. Deletions of individual clients, companies and tasks also remove their associated files. Deletion is immediate and cannot be undone; take an export first if you need one.
10. Getting your data out (export and portability)
There is no self-service export button today. Email [email protected] or [email protected] and we will provide your workspace data in a structured, commonly used, machine-readable format (JSON and/or CSV) together with your uploaded files, normally within 10 working days and free of charge. Section 13 of our Terms sets out the same right in a switching and exit context, in line with the EU Data Act.
11. Your rights
If we are the controller of your data, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected (rectification);
- have your data erased, where the law allows;
- restrict or object to certain processing, including any processing based on our legitimate interest;
- data portability;
- withdraw consent at any time, where processing is based on consent, without affecting processing before you withdrew it.
To exercise these rights, contact us at [email protected]. We respond within the period required by law (normally one month, extendable by two months for complex requests, in which case we tell you). We may ask you for information to confirm who you are, and we do not charge for a request unless it is manifestly unfounded or excessive.
If your data was entered into Doorst by an agency (i.e. you are a client of one of our customers), the agency is the controller. Contact that agency directly to exercise your rights. We will support the agency in responding as required under the DPA, and we will forward a request we receive by mistake to the agency and tell you we have.
12. Right to complain
You have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (AP) — autoriteitpersoonsgegevens.nl — or with the supervisory authority in your EU country of residence. We would appreciate the chance to address your concern first, so please consider contacting us before you do.
13. Security
We take appropriate technical and organisational measures to protect personal data, in proportion to the risk:
- Tenant isolation — every query is scoped to one workspace, so one agency cannot read another's data; the isolation is covered by automated tests.
- Encryption in transit — HTTPS/TLS everywhere, including to our sub-processors.
- Credentials — passwords are stored hashed, never in plain text; session cookies are HttpOnly, Secure and SameSite.
- Brute-force protection — failed sign-ins are rate-limited per account and per IP address.
- Least privilege — administrative access is limited to authorised people and is audit-logged (Section 6). Backup-storage credentials are held separately from the application.
- Audited erasure — deletion paths for workspaces, companies, clients and tasks also remove the uploaded files they own, with an orphan-file sweep as a backstop.
- Backups — daily off-site copies to Cloudflare R2, transferred over TLS and encrypted at rest by the storage provider, with a fixed rotation.
No system is perfectly secure, but we work to keep risk low and to respond quickly if something goes wrong.
14. Data breaches
If a personal data breach occurs, we will assess it without delay. Where we are the controller and the breach is likely to result in a risk to people's rights and freedoms, we notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware, and we notify affected individuals without undue delay where the risk is high. Where we are your processor, we notify you without undue delay so that you can meet your own obligations — see Section 8 of the DPA.
15. Children
Doorst is a business-to-business service and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, tell us at [email protected] and we will delete it.
16. Cookies
See our separate Cookie Statement for detail. In short: Doorst uses one strictly-necessary cookie (login and session) and one functional cookie (light/dark preference), neither of which requires consent. Our analytics (Plausible) is cookieless, so Doorst does not use a cookie-consent banner.
17. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the version number and "last updated" date and notify account holders by email, normally at least 30 days in advance. The current version always lives at doorst.app/privacy, and we keep the previous version available on request.
18. Contact
Questions about this policy or your data: BTNG B.V. — [email protected] — Willem Roelofsstraat 3, 7424 GD Deventer, The Netherlands — KvK 91214777.