Legal

Privacy Policy

Last updated: 3 May 2026 · Version 3.0

Holdy, a product of Basepay B.V.
Registered office: Le Mairekade 77, 1013 CB Amsterdam, The Netherlands
Chamber of Commerce (KvK): 42081353
Privacy & data protection: privacy@getholdy.com
Data Subject Request portal: in-product "Privacy" settings or by email

Plain-language summary. We collect the minimum we need to run Holdy and keep you safe: your account details, the transactions you create, evidence you upload in disputes, and technical logs. We never sell your data. We keep transaction records as long as tax and anti-money-laundering law requires (up to 7 years), and we delete the rest when we no longer need it. You have the right to see, correct, or delete your data; contact us at privacy@getholdy.com. This summary is for convenience; the binding text is below.

1. About this Policy

1.1. This Privacy Policy explains how Basepay B.V., trading as Holdy ("Holdy", "we", "us", "our"), registered in the Netherlands under Chamber of Commerce number 42081353, collects, uses, stores, shares, and protects your personal data in connection with the Services at www.getholdy.com, app.getholdy.com, and related apps and APIs.

1.2. Holdy is the controller of your personal data for most processing activities described below. Where we act as a processor (for example, when you submit Content for a specific counterparty), we do so on your instructions.

1.3. This Policy should be read together with our Terms of Service, which define capitalised terms used here ("Services", "Platform", "User", "Buyer", "Seller", "Deal", "Content", "Payment Processor", etc.).

1.4. This Policy is provided in English. Translations may be made available for convenience; the English version prevails in the event of conflict, except where mandatory local law requires the local-language version to prevail.

1.5. Business-only Service. Holdy is currently offered to Business Users only (see Clause 5.2 of the Terms). However, the personal data of individuals associated with a Business User — founders, employees, sole traders, beneficial owners — remains personal data under the GDPR and UK GDPR; the rights described in this Policy apply to those individuals in full.

2. The personal data we collect

2.1 Data you provide to us

2.2 Data we collect automatically

2.3 Data from third parties

2.4 Sensitive personal data

We do not intentionally collect special-category data under Article 9 GDPR (e.g. health, religious, political data) or similar categories under other laws. Please do not submit such data in Deal descriptions, messages, or evidence. If you do, you are doing so under Article 9(2)(e) GDPR (manifestly made public by you) or Article 9(2)(f) GDPR (establishment, exercise, or defence of legal claims).

2.5 AI-assisted features

Some features of the Services use third-party large language models to help with non-decisional tasks: (a) Deliverable suggestion — when you ask for help structuring your Deliverables list, your project brief (capped at 2,000 characters) is sent to Anthropic via OpenRouter and the suggested deliverables are returned. (b) Abuse-review pre-classification — when a rejection or upload is flagged as potentially abusive, the relevant text and metadata are sent to Anthropic via OpenRouter to pre-classify the signal for our human reviewer. The Anthropic / OpenRouter contracts include zero-data-retention terms; inputs and outputs are not used to train the providers' models. We rate-limit AI calls to 10 requests per hour per User. Logs of AI requests (input length, timestamp, decision token count) are retained for 90 days for cost and abuse auditing. AI never makes final decisions affecting you; see Clause 4.

3. How we use your data, and why (legal bases)

Purpose Legal basis (EU/UK GDPR)
Create and operate your account; authenticate you; deliver the ServicesContract | Art. 6(1)(b)
Process Deals, payments, payouts, disputes, and refundsContract | Art. 6(1)(b)
Send transactional emails and in-product notificationsContract | Art. 6(1)(b)
Generate and issue invoices and VAT recordsLegal obligation | Art. 6(1)(c)
Anti-money-laundering, sanctions screening, counter-terrorist-financing checks (NL Wwft / AMLD6 / OFAC equivalents)Legal obligation | Art. 6(1)(c)
Platform tax reporting under DAC7 (NL) and equivalent regimesLegal obligation | Art. 6(1)(c)
Fraud prevention, platform security, rate limiting, abuse detectionLegitimate interests | Art. 6(1)(f)
Content moderation and notice-and-action under the Digital Services ActLegal obligation | Art. 6(1)(c) and legitimate interests | Art. 6(1)(f)
Display your display name, avatar, trust metrics, and reviews to counterpartiesContract | Art. 6(1)(b) and legitimate interests | Art. 6(1)(f)
Respond to your support, DSA, or data-subject requestsContract | Art. 6(1)(b) and legal obligation | Art. 6(1)(c)
Defend, exercise, or establish legal claimsLegitimate interests | Art. 6(1)(f)
Improve and develop the Services (aggregated analytics)Legitimate interests | Art. 6(1)(f)
Send marketing email (if you have opted in)Consent | Art. 6(1)(a)
Comply with court orders, subpoenas, and regulator requestsLegal obligation | Art. 6(1)(c)

For processing based on legitimate interests, we have carried out a balancing test and can share the outcome on request.

4. Automated decision-making and profiling

4.1. We use automated systems to help operate the Platform, including: (a) fraud-score calculation to decide whether to hold a payout or require additional verification; (b) risk signals used to escalate disputes; (c) content filters that may hide or limit Content that looks abusive or illegal; (d) message-notification logic; and (e) AI-assisted pre-classification of abuse-review signals (see Clause 2.5).

4.2. We do not make solely automated decisions that produce legal or similarly significant effects on you (GDPR Article 22). Significant decisions affecting you — extended payout holds, abuse-review confirmations that remove or restore a strike, account suspensions, sanctions-related refusals, and any change to a Deal's outcome — are reviewed and signed off by a human Holdy team member before they take effect, even where AI assistance has been used to surface or pre-classify the signal. The rule-based outcome engine that decides Deal settlement and refunds (see Clause 10 of the Terms) is fully deterministic; no AI is involved in those decisions and they apply objective rules to recorded facts.

4.3. You have the right to: (a) request human review of automated decisions, (b) express your point of view, and (c) contest decisions by emailing privacy@getholdy.com.

5. Who we share your data with

5.1. We do not sell your personal data. We do not share or disclose personal data for cross-context behavioural advertising. We do not use your data for personalised advertising. California rights: see Clause 12.

5.2. We share personal data only as follows and only as necessary:

6. Sub-processors

6.1. We engage the following sub-processors. A Data Processing Agreement (DPA) is in place with each.

Provider Purpose Data location Transfer mechanism (outside EEA)
Stripe Payments Europe, Ltd. / Stripe Payments UK, Ltd. / Stripe Payments CompanyPayment processing, KYC/KYB, payouts, chargeback handling, fraud detectionIreland / UK / USEU–US Data Privacy Framework + SCCs
Supabase Inc.Database, authentication, file storageEU (AWS eu-central-1, Frankfurt)EU residency; SCCs for ancillary US support
Vercel Inc.Application hosting, edge network, log processingGlobal edge; primary region EUEU–US Data Privacy Framework + SCCs
Resend (Plus Five Five, Inc.)Transactional email deliveryUSSCCs
Upstash, Inc.Rate limiting, ephemeral cacheEU (default)EU residency; SCCs where applicable
Telegram FZ-LLCInternal operational alerts to our admin team (no user data beyond pseudonymous Deal IDs and amounts; no free-form user content)UAE / DESCCs / derogation under Art. 49(1)(b) GDPR
Google LLC (Fonts only)Web-font deliveryGlobal edgeEU–US Data Privacy Framework
OpenRouter (operated by OpenRouter, Inc., routing to Anthropic, PBC)AI-assisted Deliverable suggestion and abuse-review pre-classification (see Clause 2.5). Inputs capped at 2,000 chars. Zero-data-retention contract; no model training on User input.USSCCs + DPA + Transfer Impact Assessment

6.2. Updates to this list. We keep this list current and republish it when we add or change a sub-processor. Material changes (new sub-processor with broader access to personal data) are announced at least 14 days before they take effect.

7. International transfers of personal data

7.1. Our primary data storage is in the EU. However, some sub-processors (particularly Stripe, Vercel, Resend) process personal data in the United States or other countries outside the European Economic Area.

7.2. Safeguards. For transfers outside the EEA, we rely on one or more of the following:

7.3. You may request a copy of the relevant safeguards by emailing privacy@getholdy.com.

8. How long we keep your data

We retain personal data only as long as necessary for the purposes for which it was collected, to comply with our legal obligations, to resolve disputes, and to enforce our agreements.

Data category Retention period Reason
Account profileUntil account closure + 30 daysAccount recovery window
Transaction records (Deal, invoice, credit note, payment, dispute, refund)7 years from Deal completion (10 years for OSS-reported transactions and any other category subject to a longer statutory retention)NL tax law (Art. 52 AWR), Dutch commercial law, AMLD6, Wet OB OSS rules
AI-assisted feature logs (request length, timestamp, decision-token count; no full prompts retained)90 daysCost monitoring and abuse auditing
KYC/KYB documentation (via Stripe; snapshots we retain)5 years after account closure or last transactionNL Wwft, EU AMLD6
Delivery files1 year after Deal completionDispute resolution window
Dispute evidence files3 years after resolutionLimitation periods; secondary disputes
Chat messages and attachments2 years after last messageReasonable dispute / support reference
ReviewsUntil the reviewed account is closed, then 30 daysPlatform-trust integrity
Notifications (in-product)Read: 90 days; unread: 180 daysOperational
Technical and security logs12 monthsIncident investigation
Marketing consent records3 years after last contactProof of consent
Support correspondence2 years after resolutionQuality and escalation reference
DSA notices and internal-complaint records3 yearsDSA Art. 24 statement-of-reasons and transparency obligations

After retention periods expire, we delete or anonymise the relevant personal data. Where deletion is technically difficult (e.g., data in encrypted backups), we isolate the data until the backup is overwritten.

9. Cookies and similar technologies

9.1. We use the minimum cookies needed to run the Platform.

Cookie Purpose Duration Category
sb-access-token, sb-refresh-tokenKeep you logged inSession + refresh windowStrictly necessary
holdy_csrfCross-site request forgery protectionSessionStrictly necessary
holdy_prefsRemember language and interface preferences12 monthsFunctional
__stripe_mid, __stripe_sidStripe fraud detection on checkout pagesUp to 12 monthsStrictly necessary (payment security)
holdy_ref, holdy_ref_atAffiliate referral attribution. Set only on top-level navigation (Sec-Fetch-Dest=document) so a third-party page cannot drop a referral cookie via an embedded image or script. Records the referral code and the timestamp when it was set so we can apply the affiliate's configured attribution window.90 daysFunctional

9.2. We do not use analytics, tracking, or advertising cookies on the Platform. No cookie consent banner is presented for strictly necessary and functional cookies. If this changes in future, we will obtain your prior consent where required by the ePrivacy Directive, national implementation, and equivalent laws.

9.3. Most browsers allow you to control cookies through their settings.

10. Your rights

10.1. Subject to applicable law, you have the following rights:

10.2. How to exercise your rights. Use the in-product "Privacy" settings, or email privacy@getholdy.com. We may need to verify your identity before acting on a request. We will respond within 30 days (extendable by 2 months for complex requests, with notice).

10.3. Right to complain to a supervisory authority. You can complain to the data-protection authority in your country, including:

11. European Economic Area, United Kingdom, and Switzerland

11.1. Holdy is established in the European Union (Netherlands). Under Article 27 GDPR, we are not required to appoint an EU representative; you can reach us directly at the contacts in this Policy.

11.2. United Kingdom (UK GDPR). Holdy offers the Services to businesses in the United Kingdom. Processing of personal data of UK data subjects falls under UK GDPR; the rights described in this Policy apply on an equivalent basis. Holdy's processing of UK data subjects' personal data is occasional and limited to business contact information of representatives of UK-based customer entities, and is therefore covered by the "occasional processing" exemption under UK GDPR Article 27(2)(a). If and when our UK processing exceeds that exemption, we will designate and publish a UK Article 27 representative here. In the meantime, UK data subjects may contact us directly through the channels in Clause 23, and may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

11.2a. EEA → UK transfers. Personal data flowing from the EEA (including the Netherlands) to UK-based recipients is covered by the European Commission's adequacy decision in respect of the United Kingdom (renewed 19 December 2025, sunset 27 December 2031); Standard Contractual Clauses are not required for that route.

11.3. Swiss FADP. For users in Switzerland, this Policy applies with equivalent rights under the Swiss Federal Act on Data Protection (FADP) revised 2023. Complaints: Federal Data Protection and Information Commissioner (FDPIC) | edoeb.admin.ch.

12. California residents (CCPA / CPRA)

12.1. If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you specific rights. In the preceding 12 months we collected the categories of personal information described in Clause 2 for the purposes described in Clause 3, disclosed them to the recipients in Clauses 5–6, and retained them for the periods in Clause 8.

12.2. Your California rights are:

12.3. Submit requests via privacy@getholdy.com. We will verify your request consistent with CCPA regulations and respond within 45 days.

12.4. "Shine the Light" (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their direct marketing purposes.

13. Brazil (LGPD)

If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) applies. You have rights that are functionally equivalent to those in Clause 10 (confirmation of processing, access, correction, anonymisation/deletion, portability, information on data sharing, consent withdrawal, objection, and review of automated decisions). Our representative for LGPD purposes is the Privacy Officer at privacy@getholdy.com. You may lodge a complaint with ANPD.

14. Canada (PIPEDA and Quebec Law 25)

14.1. If you are in Canada, PIPEDA applies to our processing in the course of commercial activities. You have the right to access and correct your personal information and to withdraw consent.

14.2. Quebec Law 25. If you are resident in Quebec, An Act to modernize legislative provisions as regards the protection of personal information applies. You additionally have the right to be informed of automated decision-making, the right to data portability (since 22 September 2024), and to receive information in French, first.

14.3. Our privacy officer for Canadian purposes: privacy@getholdy.com.

15. Australia (Privacy Act 1988)

If you are in Australia, the Australian Privacy Principles (APPs) and 2024–2025 amendments to the Privacy Act apply, including the new statutory tort for serious invasions of privacy. You have rights of access and correction. Complaints may be made to the Office of the Australian Information Commissioner.

16. Other jurisdictions

For users in other countries (including Japan APPI, Singapore PDPA, South Africa POPIA, and similar regimes), we comply with applicable local data-protection laws. Please contact privacy@getholdy.com for specific information about how local law applies to your data.

17. Security

We implement appropriate technical and organisational measures to protect personal data, including:

18. Data breach notification

18.1. If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware, as required by Article 33 GDPR and equivalent laws.

18.2. Where a breach is likely to result in a high risk to you, we will notify you directly without undue delay, with information about the nature of the breach, likely consequences, and steps you can take to protect yourself.

18.3. We maintain a breach register as required by Article 33(5) GDPR and equivalent laws.

19. Children

19.1. The Services are not intended for children under 18. We do not knowingly collect personal data from children under 13 (or the minimum age for digital consent in your country). If you believe we have inadvertently collected data from a child under 13, contact privacy@getholdy.com and we will delete it promptly.

19.2. This provision is provided for compliance with the US Children's Online Privacy Protection Act (COPPA), GDPR Article 8 (age of digital consent, 13–16 depending on Member State), the UK Age-Appropriate Design Code, and equivalent laws.

20. Direct marketing

20.1. We send transactional emails (Deal notifications, invoices, account security) as part of providing the Services; you cannot unsubscribe from these while you have an account.

20.2. We send marketing email only with your prior consent. You can withdraw consent at any time via the unsubscribe link in any marketing email or in your notification settings, without affecting the lawfulness of processing before withdrawal.

21. Links to other services

The Platform may contain links to third-party services (including Stripe's own pages, network partners, and our sub-processors). Those services have their own privacy policies. We are not responsible for their practices; please review their policies separately.

22. Changes to this Policy

22.1. We may update this Policy. Material changes (expansion of purposes, new categories of data, new recipients, reduction of your rights, changes to retention) take effect at least 30 days after we notify you by email and in-product notification. Non-material changes (clarifications, corrections, formatting) take effect on posting.

22.2. The "Last updated" date at the top of this Policy shows when it was most recently revised. Prior versions are archived and available on request.

23. Contact us

Version history

  • v3.0 | 3 May 2026 | B2B-only pivot — added Clause 1.5 noting the Service is offered to Business Users only while preserving full GDPR/UK GDPR rights for individuals associated with a Business User. Added Clause 2.5 disclosing AI-assisted features (Anthropic via OpenRouter, 2k char input cap, 10/hr per-user rate limit, 90-day log retention, zero-data-retention provider contracts). Strengthened Clause 4 to make explicit that AI never makes final decisions affecting users — every significant outcome is human-reviewed (Article 22 GDPR). Added OpenRouter to the sub-processor table (Clause 6) with SCCs + DPA + TIA. Bumped transaction-record retention from 7 to 10 years for OSS-reported transactions and added an AI-log retention row (Clause 8). Added the holdy_ref / holdy_ref_at affiliate cookies to the cookie table (Clause 9) with the Sec-Fetch-Dest top-level-navigation safeguard. Restated UK Article 27 representative obligation and added EU→UK adequacy decision reference (Clause 11.2 / 11.2a).
  • v2.0 | 18 April 2026 | Full rewrite: international coverage (CCPA/CPRA, LGPD, PIPEDA, Quebec Law 25, Swiss FADP, Australia Privacy Act, ePrivacy, UK GDPR), expanded sub-processor list (Stripe, Supabase, Vercel, Resend, Upstash, Telegram, Google Fonts) with transfer mechanisms, detailed retention schedule aligned to Wwft/AMLD6/NL tax law, legal bases table, automated decision-making disclosure, data breach notification process, California-specific rights, cookie table.
  • v1.0 | 15 April 2026 | Initial GDPR-focused policy.