Privacy statement
Last updated: 28 juli 2026
Solven takes the protection of personal data seriously. This statement explains which data we process when you visit our website or use the Solven platform, for what purpose and on what legal basis, and what rights you have under the General Data Protection Regulation (GDPR).
Data controller
Solven Systems (“Solven”)
Gevestigd te Almere (Nederland) — volledig adres op aanvraag
Chamber of Commerce: 66754755 · VAT: NL195767081B03
Email: info@solvensystems.nl · Data Protection Officer: not appointed (not legally required for our size)
1. Who is responsible
The controller for data processed via our website and account/sales process is Solven Systems, established in Almere (the Netherlands), registered with the Dutch Chamber of Commerce under number 66754755.
For the data that customers (tenants) process in the platform, Solven acts as a processor; the data processing agreement applies to that.
2. Which personal data we process
- Account and contact data: name, email address, phone number, company name, role.
- Usage data: login data, logs, IP address, device and browser information.
- Billing data: company details, subscription, payment status (payments run via our payment provider).
- Communication: messages you send us via email, contact or demo forms.
3. Purposes and legal bases
We process personal data to provide and manage the service (performance of the contract), to invoice and prevent fraud (legal obligation and legitimate interest), to provide support and communication (performance of the contract and legitimate interest) and to secure and improve the service (legitimate interest).
4. Retention periods
We do not keep personal data longer than necessary; a daily automated retention job enforces this. Specifically: AI conversations are stripped after 90 days, sent e-mail bodies redacted after 12 months, and the personal data of deleted customers anonymised 30 days after deletion. Account and usage data are kept for the term of the contract and deleted within a reasonable period thereafter. Billing data and (append-only) audit logs are kept in line with the statutory retention obligation (7 years in the Netherlands).
5. Sharing with third parties and sub-processors
We do not sell personal data. We use service providers (sub-processors) for, among other things, hosting, email, payments and accounting integrations. We conclude a processing agreement with each sub-processor.
Current sub-processors include: our hosting provider (server and object storage), Mollie (payments), our e-mail delivery provider, and — only when the AI assistant is enabled — Anthropic (AI). Exact Online and Moneybird only when the customer activates the accounting integration. An up-to-date list is available on request.
6. Transfers outside the EEA
We aim to process data within the European Economic Area (EEA). If a transfer to a country outside the EEA takes place, this is done only with appropriate safeguards such as the European Commission’s standard contractual clauses.
7. Security
We take appropriate technical and organisational measures, including encryption of traffic, role-based access, strict separation between companies, two-factor authentication and logging. See also our security page.
8. Your rights
- The right to access, rectify and erase your data.
- The right to restriction of and objection to processing.
- The right to data portability.
- The right to withdraw consent you have given.
9. Cookies
Our website uses functional cookies only. See our cookie statement for details.
10. Contact and complaints
For questions or to exercise a right, email info@solvensystems.nl. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).