Last updated: 3 May 2026 · Version 3.0
Holdy, a product of Basepay B.V.
Registered office: Le Mairekade 77, 1013 CB Amsterdam, The Netherlands
Chamber of Commerce (KvK): 42081353
Privacy & data protection: privacy@getholdy.com
Data Subject Request portal: in-product "Privacy" settings or by email
Plain-language summary. We collect the minimum we need to run Holdy and keep you safe: your account details, the transactions you create, evidence you upload in disputes, and technical logs. We never sell your data. We keep transaction records as long as tax and anti-money-laundering law requires (up to 7 years), and we delete the rest when we no longer need it. You have the right to see, correct, or delete your data; contact us at privacy@getholdy.com. This summary is for convenience; the binding text is below.
1.1. This Privacy Policy explains how Basepay B.V., trading as Holdy ("Holdy", "we", "us", "our"), registered in the Netherlands under Chamber of Commerce number 42081353, collects, uses, stores, shares, and protects your personal data in connection with the Services at www.getholdy.com, app.getholdy.com, and related apps and APIs.
1.2. Holdy is the controller of your personal data for most processing activities described below. Where we act as a processor (for example, when you submit Content for a specific counterparty), we do so on your instructions.
1.3. This Policy should be read together with our Terms of Service, which define capitalised terms used here ("Services", "Platform", "User", "Buyer", "Seller", "Deal", "Content", "Payment Processor", etc.).
1.4. This Policy is provided in English. Translations may be made available for convenience; the English version prevails in the event of conflict, except where mandatory local law requires the local-language version to prevail.
1.5. Business-only Service. Holdy is currently offered to Business Users only (see Clause 5.2 of the Terms). However, the personal data of individuals associated with a Business User — founders, employees, sole traders, beneficial owners — remains personal data under the GDPR and UK GDPR; the rights described in this Policy apply to those individuals in full.
We do not intentionally collect special-category data under Article 9 GDPR (e.g. health, religious, political data) or similar categories under other laws. Please do not submit such data in Deal descriptions, messages, or evidence. If you do, you are doing so under Article 9(2)(e) GDPR (manifestly made public by you) or Article 9(2)(f) GDPR (establishment, exercise, or defence of legal claims).
Some features of the Services use third-party large language models to help with non-decisional tasks: (a) Deliverable suggestion — when you ask for help structuring your Deliverables list, your project brief (capped at 2,000 characters) is sent to Anthropic via OpenRouter and the suggested deliverables are returned. (b) Abuse-review pre-classification — when a rejection or upload is flagged as potentially abusive, the relevant text and metadata are sent to Anthropic via OpenRouter to pre-classify the signal for our human reviewer. The Anthropic / OpenRouter contracts include zero-data-retention terms; inputs and outputs are not used to train the providers' models. We rate-limit AI calls to 10 requests per hour per User. Logs of AI requests (input length, timestamp, decision token count) are retained for 90 days for cost and abuse auditing. AI never makes final decisions affecting you; see Clause 4.
| Purpose | Legal basis (EU/UK GDPR) |
|---|---|
| Create and operate your account; authenticate you; deliver the Services | Contract | Art. 6(1)(b) |
| Process Deals, payments, payouts, disputes, and refunds | Contract | Art. 6(1)(b) |
| Send transactional emails and in-product notifications | Contract | Art. 6(1)(b) |
| Generate and issue invoices and VAT records | Legal obligation | Art. 6(1)(c) |
| Anti-money-laundering, sanctions screening, counter-terrorist-financing checks (NL Wwft / AMLD6 / OFAC equivalents) | Legal obligation | Art. 6(1)(c) |
| Platform tax reporting under DAC7 (NL) and equivalent regimes | Legal obligation | Art. 6(1)(c) |
| Fraud prevention, platform security, rate limiting, abuse detection | Legitimate interests | Art. 6(1)(f) |
| Content moderation and notice-and-action under the Digital Services Act | Legal obligation | Art. 6(1)(c) and legitimate interests | Art. 6(1)(f) |
| Display your display name, avatar, trust metrics, and reviews to counterparties | Contract | Art. 6(1)(b) and legitimate interests | Art. 6(1)(f) |
| Respond to your support, DSA, or data-subject requests | Contract | Art. 6(1)(b) and legal obligation | Art. 6(1)(c) |
| Defend, exercise, or establish legal claims | Legitimate interests | Art. 6(1)(f) |
| Improve and develop the Services (aggregated analytics) | Legitimate interests | Art. 6(1)(f) |
| Send marketing email (if you have opted in) | Consent | Art. 6(1)(a) |
| Comply with court orders, subpoenas, and regulator requests | Legal obligation | Art. 6(1)(c) |
For processing based on legitimate interests, we have carried out a balancing test and can share the outcome on request.
4.1. We use automated systems to help operate the Platform, including: (a) fraud-score calculation to decide whether to hold a payout or require additional verification; (b) risk signals used to escalate disputes; (c) content filters that may hide or limit Content that looks abusive or illegal; (d) message-notification logic; and (e) AI-assisted pre-classification of abuse-review signals (see Clause 2.5).
4.2. We do not make solely automated decisions that produce legal or similarly significant effects on you (GDPR Article 22). Significant decisions affecting you — extended payout holds, abuse-review confirmations that remove or restore a strike, account suspensions, sanctions-related refusals, and any change to a Deal's outcome — are reviewed and signed off by a human Holdy team member before they take effect, even where AI assistance has been used to surface or pre-classify the signal. The rule-based outcome engine that decides Deal settlement and refunds (see Clause 10 of the Terms) is fully deterministic; no AI is involved in those decisions and they apply objective rules to recorded facts.
4.3. You have the right to: (a) request human review of automated decisions, (b) express your point of view, and (c) contest decisions by emailing privacy@getholdy.com.
5.1. We do not sell your personal data. We do not share or disclose personal data for cross-context behavioural advertising. We do not use your data for personalised advertising. California rights: see Clause 12.
5.2. We share personal data only as follows and only as necessary:
6.1. We engage the following sub-processors. A Data Processing Agreement (DPA) is in place with each.
| Provider | Purpose | Data location | Transfer mechanism (outside EEA) |
|---|---|---|---|
| Stripe Payments Europe, Ltd. / Stripe Payments UK, Ltd. / Stripe Payments Company | Payment processing, KYC/KYB, payouts, chargeback handling, fraud detection | Ireland / UK / US | EU–US Data Privacy Framework + SCCs |
| Supabase Inc. | Database, authentication, file storage | EU (AWS eu-central-1, Frankfurt) | EU residency; SCCs for ancillary US support |
| Vercel Inc. | Application hosting, edge network, log processing | Global edge; primary region EU | EU–US Data Privacy Framework + SCCs |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | US | SCCs |
| Upstash, Inc. | Rate limiting, ephemeral cache | EU (default) | EU residency; SCCs where applicable |
| Telegram FZ-LLC | Internal operational alerts to our admin team (no user data beyond pseudonymous Deal IDs and amounts; no free-form user content) | UAE / DE | SCCs / derogation under Art. 49(1)(b) GDPR |
| Google LLC (Fonts only) | Web-font delivery | Global edge | EU–US Data Privacy Framework |
| OpenRouter (operated by OpenRouter, Inc., routing to Anthropic, PBC) | AI-assisted Deliverable suggestion and abuse-review pre-classification (see Clause 2.5). Inputs capped at 2,000 chars. Zero-data-retention contract; no model training on User input. | US | SCCs + DPA + Transfer Impact Assessment |
6.2. Updates to this list. We keep this list current and republish it when we add or change a sub-processor. Material changes (new sub-processor with broader access to personal data) are announced at least 14 days before they take effect.
7.1. Our primary data storage is in the EU. However, some sub-processors (particularly Stripe, Vercel, Resend) process personal data in the United States or other countries outside the European Economic Area.
7.2. Safeguards. For transfers outside the EEA, we rely on one or more of the following:
7.3. You may request a copy of the relevant safeguards by emailing privacy@getholdy.com.
We retain personal data only as long as necessary for the purposes for which it was collected, to comply with our legal obligations, to resolve disputes, and to enforce our agreements.
| Data category | Retention period | Reason |
|---|---|---|
| Account profile | Until account closure + 30 days | Account recovery window |
| Transaction records (Deal, invoice, credit note, payment, dispute, refund) | 7 years from Deal completion (10 years for OSS-reported transactions and any other category subject to a longer statutory retention) | NL tax law (Art. 52 AWR), Dutch commercial law, AMLD6, Wet OB OSS rules |
| AI-assisted feature logs (request length, timestamp, decision-token count; no full prompts retained) | 90 days | Cost monitoring and abuse auditing |
| KYC/KYB documentation (via Stripe; snapshots we retain) | 5 years after account closure or last transaction | NL Wwft, EU AMLD6 |
| Delivery files | 1 year after Deal completion | Dispute resolution window |
| Dispute evidence files | 3 years after resolution | Limitation periods; secondary disputes |
| Chat messages and attachments | 2 years after last message | Reasonable dispute / support reference |
| Reviews | Until the reviewed account is closed, then 30 days | Platform-trust integrity |
| Notifications (in-product) | Read: 90 days; unread: 180 days | Operational |
| Technical and security logs | 12 months | Incident investigation |
| Marketing consent records | 3 years after last contact | Proof of consent |
| Support correspondence | 2 years after resolution | Quality and escalation reference |
| DSA notices and internal-complaint records | 3 years | DSA Art. 24 statement-of-reasons and transparency obligations |
After retention periods expire, we delete or anonymise the relevant personal data. Where deletion is technically difficult (e.g., data in encrypted backups), we isolate the data until the backup is overwritten.
9.1. We use the minimum cookies needed to run the Platform.
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
| sb-access-token, sb-refresh-token | Keep you logged in | Session + refresh window | Strictly necessary |
| holdy_csrf | Cross-site request forgery protection | Session | Strictly necessary |
| holdy_prefs | Remember language and interface preferences | 12 months | Functional |
| __stripe_mid, __stripe_sid | Stripe fraud detection on checkout pages | Up to 12 months | Strictly necessary (payment security) |
| holdy_ref, holdy_ref_at | Affiliate referral attribution. Set only on top-level navigation (Sec-Fetch-Dest=document) so a third-party page cannot drop a referral cookie via an embedded image or script. Records the referral code and the timestamp when it was set so we can apply the affiliate's configured attribution window. | 90 days | Functional |
9.2. We do not use analytics, tracking, or advertising cookies on the Platform. No cookie consent banner is presented for strictly necessary and functional cookies. If this changes in future, we will obtain your prior consent where required by the ePrivacy Directive, national implementation, and equivalent laws.
9.3. Most browsers allow you to control cookies through their settings.
10.1. Subject to applicable law, you have the following rights:
10.2. How to exercise your rights. Use the in-product "Privacy" settings, or email privacy@getholdy.com. We may need to verify your identity before acting on a request. We will respond within 30 days (extendable by 2 months for complex requests, with notice).
10.3. Right to complain to a supervisory authority. You can complain to the data-protection authority in your country, including:
11.1. Holdy is established in the European Union (Netherlands). Under Article 27 GDPR, we are not required to appoint an EU representative; you can reach us directly at the contacts in this Policy.
11.2. United Kingdom (UK GDPR). Holdy offers the Services to businesses in the United Kingdom. Processing of personal data of UK data subjects falls under UK GDPR; the rights described in this Policy apply on an equivalent basis. Holdy's processing of UK data subjects' personal data is occasional and limited to business contact information of representatives of UK-based customer entities, and is therefore covered by the "occasional processing" exemption under UK GDPR Article 27(2)(a). If and when our UK processing exceeds that exemption, we will designate and publish a UK Article 27 representative here. In the meantime, UK data subjects may contact us directly through the channels in Clause 23, and may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
11.2a. EEA → UK transfers. Personal data flowing from the EEA (including the Netherlands) to UK-based recipients is covered by the European Commission's adequacy decision in respect of the United Kingdom (renewed 19 December 2025, sunset 27 December 2031); Standard Contractual Clauses are not required for that route.
11.3. Swiss FADP. For users in Switzerland, this Policy applies with equivalent rights under the Swiss Federal Act on Data Protection (FADP) revised 2023. Complaints: Federal Data Protection and Information Commissioner (FDPIC) | edoeb.admin.ch.
12.1. If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you specific rights. In the preceding 12 months we collected the categories of personal information described in Clause 2 for the purposes described in Clause 3, disclosed them to the recipients in Clauses 5–6, and retained them for the periods in Clause 8.
12.2. Your California rights are:
12.3. Submit requests via privacy@getholdy.com. We will verify your request consistent with CCPA regulations and respond within 45 days.
12.4. "Shine the Light" (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their direct marketing purposes.
If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) applies. You have rights that are functionally equivalent to those in Clause 10 (confirmation of processing, access, correction, anonymisation/deletion, portability, information on data sharing, consent withdrawal, objection, and review of automated decisions). Our representative for LGPD purposes is the Privacy Officer at privacy@getholdy.com. You may lodge a complaint with ANPD.
14.1. If you are in Canada, PIPEDA applies to our processing in the course of commercial activities. You have the right to access and correct your personal information and to withdraw consent.
14.2. Quebec Law 25. If you are resident in Quebec, An Act to modernize legislative provisions as regards the protection of personal information applies. You additionally have the right to be informed of automated decision-making, the right to data portability (since 22 September 2024), and to receive information in French, first.
14.3. Our privacy officer for Canadian purposes: privacy@getholdy.com.
If you are in Australia, the Australian Privacy Principles (APPs) and 2024–2025 amendments to the Privacy Act apply, including the new statutory tort for serious invasions of privacy. You have rights of access and correction. Complaints may be made to the Office of the Australian Information Commissioner.
For users in other countries (including Japan APPI, Singapore PDPA, South Africa POPIA, and similar regimes), we comply with applicable local data-protection laws. Please contact privacy@getholdy.com for specific information about how local law applies to your data.
We implement appropriate technical and organisational measures to protect personal data, including:
18.1. If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware, as required by Article 33 GDPR and equivalent laws.
18.2. Where a breach is likely to result in a high risk to you, we will notify you directly without undue delay, with information about the nature of the breach, likely consequences, and steps you can take to protect yourself.
18.3. We maintain a breach register as required by Article 33(5) GDPR and equivalent laws.
19.1. The Services are not intended for children under 18. We do not knowingly collect personal data from children under 13 (or the minimum age for digital consent in your country). If you believe we have inadvertently collected data from a child under 13, contact privacy@getholdy.com and we will delete it promptly.
19.2. This provision is provided for compliance with the US Children's Online Privacy Protection Act (COPPA), GDPR Article 8 (age of digital consent, 13–16 depending on Member State), the UK Age-Appropriate Design Code, and equivalent laws.
20.1. We send transactional emails (Deal notifications, invoices, account security) as part of providing the Services; you cannot unsubscribe from these while you have an account.
20.2. We send marketing email only with your prior consent. You can withdraw consent at any time via the unsubscribe link in any marketing email or in your notification settings, without affecting the lawfulness of processing before withdrawal.
The Platform may contain links to third-party services (including Stripe's own pages, network partners, and our sub-processors). Those services have their own privacy policies. We are not responsible for their practices; please review their policies separately.
22.1. We may update this Policy. Material changes (expansion of purposes, new categories of data, new recipients, reduction of your rights, changes to retention) take effect at least 30 days after we notify you by email and in-product notification. Non-material changes (clarifications, corrections, formatting) take effect on posting.
22.2. The "Last updated" date at the top of this Policy shows when it was most recently revised. Prior versions are archived and available on request.
Version history