Data controller
Node Logic, registered with the Dutch Chamber of Commerce under number 42046427 and seated at Keurenplein 41, Box C3118, 1069 CD Amsterdam, The Netherlands, is the data controller for personal data processed through this website and for the accounts of platform administrators.
For the business records a customer’s staff enter into their own tenant — sales, customers, inventory, expenses, approvals and the reports built from them — the customer is the controller and Node Logic acts solely as a processor on that customer’s documented instructions. Those processing terms are set out in section 06 of our Terms of Service. If you are a member of staff at a business that uses the platform and you want to exercise a right over your own records, your employer is the right first point of contact; we will help them answer you.
Most of the businesses we serve are in the Philippines. For their own tenants they are personal information controllers under the Data Privacy Act of 2012 (Republic Act No. 10173) and we act as their personal information processor, which is the same division of responsibility the GDPR describes in different words. Duties that Act places on the controller — registering a data processing system with the National Privacy Commission, designating a Data Protection Officer, and notifying data subjects of a breach — remain the customer’s, and we give them what they need to meet them.
You can reach us on any data protection matter at legal@nodelogic.nl. Philippine rules require a controller or processor to designate a Data Protection Officer regardless of the scale of its processing; that designation is being put in place and the contact details will be published here.
Data we collect and why
We collect only what the service needs in order to work.
- Account and sign-in data. Your name, email address and authentication identifiers, together with the role granted to you. Used to authenticate you and to decide what you may open. Processed to perform our contract (Art. 6(1)(b) GDPR).
- Session data. A session cookie and the tokens issued by our authentication provider, so that you stay signed in between pages. Necessary to perform the contract and to keep accounts secure (Art. 6(1)(b) and 6(1)(f) GDPR).
- Subscription and billing data. Subscription status, billing period, invoices and the payment references returned by our payment processor. Card numbers are entered directly with the payment processor and never reach our servers. Processed to perform the contract and to comply with our tax obligations (Art. 6(1)(b) and 6(1)(c) GDPR).
- Platform audit records. Actions taken by platform administrators are written to an append-only audit trail with the administrator’s identity and a timestamp. Processed in our legitimate interest in the security and accountability of the platform (Art. 6(1)(f) GDPR).
- Support correspondence. Messages you send us and our replies, kept so we can follow a matter through. Legitimate interest (Art. 6(1)(f) GDPR).
- Server logs. Our hosting provider records request metadata, including IP address and user agent, for delivery, security and abuse prevention. Legitimate interest (Art. 6(1)(f) GDPR).
We do not sell personal data, we do not share it for advertising, and we do not use it to make automated decisions producing legal or similarly significant effects.
Cookies and local storage
This site sets no advertising cookies and no third-party analytics cookies. Nothing here tracks you across other websites, which is why you are not asked to consent to anything on arrival: strictly necessary cookies do not require consent under Art. 11.7a of the Dutch Telecommunications Act.
- Session cookie. Set only once you sign in. Identifies your session and expires when it does.
- Authentication token cookies. Set by our authentication provider on sign-in, refreshed while you keep working, and cleared on sign-out.
- Browser local storage. Small interface preferences, such as whether you have collapsed a sidebar or a dashboard panel. These stay in your browser, are never sent to us, and can be cleared from your browser at any time.
Sub-processors and service providers
We keep the list of parties who touch data deliberately short. Each is bound by a data processing agreement and may use the data only to provide its service to us.
- Supabase — database, authentication and file storage. Holds account data and customer business records.
- Vercel — application hosting and content delivery. Processes request metadata and server logs.
- Stripe — subscription billing and payment processing. Holds billing contact and payment instrument data as an independent controller for its own compliance purposes.
- Anthropic — the in-app help assistant. When a signed-in user asks the assistant a question, the question text and our own product manual are sent for answering. Customer trading records are not included in that request, and the content is not used to train models.
We will give customers notice before adding or replacing a sub-processor that handles their data, so that they have a fair opportunity to object.
International data transfers
Our database and application hosting are configured to keep data at rest within the European Union.
Stripe and Anthropic are established in the United States, so using them involves a transfer outside the EEA. Those transfers are covered by the European Commission’s Standard Contractual Clauses together with the supplementary measures described in each provider’s data processing agreement. You can request a copy of the transfer mechanism relied on for any given provider at legal@nodelogic.nl.
Data retention
We keep data only as long as the purpose it was collected for survives.
- Account data — for as long as the account is active. Deactivated accounts are removed when the customer’s subscription ends.
- Customer business records — for as long as the subscription runs. After termination they remain restorable for 30 days so a customer who leaves by accident or changes their mind is not left with nothing, and are then deleted.
- Invoices and accounting records — 7 years, as Dutch fiscal law requires. This obligation outlives a request for erasure.
- Platform audit records — 24 months. The trail is append-only by design, so entries are removed by age rather than edited.
- Support correspondence — 24 months after the matter is closed.
Your rights
Under the GDPR you may ask us to:
- confirm what personal data we hold about you, and give you a copy;
- correct data that is wrong or incomplete;
- erase data we no longer have grounds to keep;
- restrict processing while a dispute about accuracy or grounds is resolved;
- provide data you gave us in a structured, commonly used, machine-readable format, or send it to another provider;
- stop processing carried out on the basis of our legitimate interests, where your circumstances outweigh those interests.
Write to legal@nodelogic.nl. We answer within one month, and will tell you before that deadline if a request is complex enough to need longer. Exercising a right costs nothing and is never a reason for us to treat you differently.
If your data sits inside a customer’s tenant, we will forward your request to that customer, who is the controller for it, and support them in answering.
Children
The platform is business software sold to companies and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child’s data has reached us, write to legal@nodelogic.nl and we will delete it.
Supervisory authorities
If you believe we have handled your data unlawfully, we would rather hear from you first at legal@nodelogic.nl — but you never have to come to us first, and you are entitled to complain to a regulator directly.
- In the Philippines — the National Privacy Commission, which supervises the Data Privacy Act of 2012 (Republic Act No. 10173).
- In the Netherlands and the EEA — the Autoriteit Persoonsgegevens, or the authority where you live or work.
Changes to this policy
We may update this policy as the service changes. The effective date at the top of this page moves whenever the text does. For changes that materially affect how we handle your data we will give at least 30 days notice by email to account holders before the new version applies.