Last updated: 22 July 2026

Privacy policy

Kadova respects your privacy. This policy explains what personal data we process, in which role (controller or processor), why, how long we retain data, and your rights under the GDPR.

1. Who is responsible?

Kadova (trade name, sole proprietorship, Netherlands) is the data controller for platform users, website visitors and sign-ups. Contact: privacy@kadova.nl. For consumer data processed via the platform on behalf of customers, Kadova acts as processor — see also our DPA at /legal/dpa.

2. Roles under the GDPR

Depending on the situation:

  • Controller: Kadova for user account data, platform operations, billing, support and website visits
  • Processor: Kadova for personal data of consumers/end users that our customer (the organisation) processes via shop, gift card delivery or wallet — instructions follow from the customer account and DPA
  • Controller: the customer organisation for data of its staff, customers and gift card holders within their tenant

3. What data do we process?

Depending on how you use the platform, we may process:

  • Account data: name, email, role, organisation, MFA status, login logs
  • Gift card and transaction data: amounts, codes, store, date/time, wallet pass metadata
  • Shop and order data: name, email, address (if shipping), line items
  • Technical data: IP address, browser, device, user-agent, audit and security logs
  • Communication: email (and optional SMS) for gift cards, invoices, support
  • Payment data: processed by Stripe or Mollie; Kadova does not store full card numbers
  • Mobile app: device tokens (push), offline cache (limited), biometrics locally on device
  • Consent records: cookie and privacy preferences with timestamp

4. Why do we use your data?

We process data only for clear purposes:

  • Providing and managing your account and organisation
  • Issuing, redeeming and reporting on gift cards
  • Subscription and platform billing
  • Fraud prevention and platform security
  • Optional: website analytics (Google Analytics 4) and product improvement — only with consent via the cookie banner
  • Optional: marketing (with consent)

5. Legal bases (GDPR art. 6)

We rely on the following legal bases:

  • Contract — account management and gift card registration
  • Legitimate interest — security, fraud prevention and stability
  • Legal obligation — e.g. 7-year retention for invoices
  • Consent — analytics and marketing; withdrawable via My data

6. Cookies

We use cookies and similar technologies:

  • Essential: session, authentication and language — always active
  • Analytics (Google Analytics 4): measures visits to marketing pages (traffic, channels, conversions) — only after your consent; until then Consent Mode keeps analytics storage denied
  • You can change your choice later via My data (signed in) or by clearing browser cookies

7. Third parties and subprocessors

We do not sell your data. We share data only with processors required for the service. The current subprocessor list is at /legal/subprocessors.

  • Render — hosting, database and Redis (EU, Frankfurt)
  • Cloudflare R2 — object storage for documents and exports (EU)
  • Brevo — transactional email
  • Stripe and Mollie — payments
  • Sentry — error monitoring (with PII scrubbing, if enabled)
  • Google Analytics 4 — website analytics on marketing pages (consent required)
  • Apple / Google — push and wallet passes (mobile app)
  • Tenant isolation: customer A data is not visible to customer B

8. Retention periods

We do not keep data longer than necessary:

  • Account data: while the account is active; max. 2 years after last login
  • Deleted accounts: 30-day cooling-off, then anonymisation
  • Transactions and invoices: 7 years (legal requirement)
  • Audit logs: 3 years
  • Consent records: 5 years after withdrawal
  • Session cookies: up to 7 days

9. Security

We apply appropriate measures: TLS in transit, encryption of sensitive fields, role-based access, MFA for administrators, audit logging, tenant isolation, rate limiting and periodic security reviews. Report incidents to security@kadova.nl.

10. Transfers outside the EEA

Where possible we process data in the EU (e.g. Render Frankfurt, Cloudflare R2 EU). Some subprocessors (e.g. Sentry, Apple, Google, Google Analytics, Expo) may process data in the United States or via EU/US transfers. We use Standard Contractual Clauses (SCCs) or equivalent safeguards where required. Website analytics (GA4) runs only after consent (Consent Mode). See /legal/subprocessors for details per processor.

11. Kadova Winkel (mobile app)

The mobile app additionally processes:

  • Locally stored session and offline transactions (limited retention; synced to platform)
  • Biometric unlock via the OS — Kadova does not store fingerprint/face data
  • Camera for QR scan — images are not permanently stored
  • Push device tokens via Apple APNs or Firebase Cloud Messaging

12. Consumer data via customers

If you buy or receive a gift card through an organisation using Kadova, that organisation is usually the controller. Kadova processes this data as processor on the customer’s instructions. Direct privacy questions about gift card purchases should first go to that organisation; Kadova supports customers with GDPR requests via the platform.

13. Your rights

Under the GDPR you have rights including:

  • Access and a copy of your data (art. 15)
  • Rectification of inaccurate data (art. 16)
  • Erasure (art. 17) — via My data, with 30-day cooling-off
  • Data portability in a structured format (art. 20)
  • Withdraw consent (art. 7)
  • Lodge a complaint with your supervisory authority

14. Children

Our service is intended for organisations and their staff. We do not knowingly collect data from children under 16.

15. Changes

We may update this policy when law or our services change. The current version is always on this page. Material changes will be communicated by email or in-app notice.

16. Contact

Privacy questions or requests? privacy@kadova.nl (GDPR requests within 30 days). Support: support@kadova.nl. Security incidents: security@kadova.nl.

Your privacy settings

Signed in? Export your data, manage consents or request account deletion on the My data page.