Privacy statement Tolar-app

Article 1 Controller and contact details

Tolar B.V., located at Vlotlaan 554, 2681 TX Monster, the Netherlands, is the controller for the processing of personal data via the Platform, except to the extent that Tolar acts as a processor on behalf of a business Customer pursuant to Part B.

Questions about this privacy statement or about Tolar’s processing of personal data can be directed to info@tolar.app. Tolar has not appointed a Data Protection Officer; the contact point above serves as the point of contact for privacy-related questions.

Article 2 What data Tolar collects

Upon registration and use of the Platform, Tolar collects the following categories of personal data:

  1. Contact and account data: first and last name, Chamber of Commerce (KvK) number, email address, phone number and address;
  2. Usage data: error codes and troubleshooting questions entered, feedback provided, requests made and other input on the Platform;
  3. Technical and security data: login times, IP address at login, and general user activity on the Platform.

Where an Admin creates an account on behalf of a User, the name and email address of that User are provided to Tolar by the Admin, not directly by the User. The User subsequently receives an email to log in and is made aware of this privacy statement at that time.

Article 3 Purposes and legal basis

Tolar processes the data referred to in Article 2 for the following purposes:

  1. Performance of the Agreement and providing access to the Platform (contact and account data)
    Legal basis: performance of a contract (Art. 6(1)(b) GDPR);
  2. Provision of the Service, including processing questions and generating AI Advice (usage data)
    Legal basis: performance of a contract;
  3. Security, fraud prevention and preventing misuse (login times, IP address, user activity)
    Legal basis: Tolar’s legitimate interest in a secure and reliable Platform;
  4. Improvement of the Platform, the knowledge base and the services (feedback, input, queries)
    Legal basis: Tolar’s legitimate interest in product improvement;
  5. Personalised email communication, marketing and telephone communication
    Legal basis: Tolar’s legitimate interest, or consent where legally required; opting out is possible at any time;
  6. Internal analysis and dashboarding for business operations purposes
    Legal basis: legitimate interest;
  7. Invoicing and financial administration
    Legal basis: legal obligation (statutory tax retention obligation) and performance of the contract.

In providing the Service, no automated decision-making takes place that produces legal effects concerning the User, or similarly significantly affects the User, without human intervention: the AI Advice is purely supportive in nature, and the User decides on any follow-up steps.

Article 4 AI processing and use of input

Tolar uses submitted queries, feedback and other input to (re)train the underlying AI model. This may happen either automatically, or this input is manually reviewed by Tolar’s team and used to expand the knowledge base and improve the Platform.

For its AI functionality, Tolar uses OpenRouter as its AI provider, which provides access to, among others, models from Anthropic (Claude) and OpenAI. These model providers have stated that data submitted via OpenRouter is not used to train their models; however, Tolar cannot guarantee that these third parties comply with this policy, and refers to the providers’ own policies for up-to-date information.

Article 5 Recipients and sub-processors

Tolar shares personal data only to the extent necessary for the performance of the Service: with team members and subcontractors/developers who play an essential role in the operation of the Platform, and with the sub-processors listed below. Personal data is never sold to third parties.

Tolar uses the following sub-processors:

  1. OpenRouter: AI provider that, among others, provides access to models from Anthropic and OpenAI; based in the United States (New York);
  2. Railway: hosting of the Platform, on an EU server;
  3. Supabase: data storage, in an EU region;
  4. Stripe: payment processing;
  5. ActiveCampaign and/or Mailchimp: sending of email campaigns.

To the extent data is transferred to sub-processors outside the European Economic Area (which in any event includes OpenRouter), Tolar ensures that an appropriate safeguard mechanism applies, such as Standard Contractual Clauses and/or, where applicable, certification under the EU-U.S. Data Privacy Framework. Further information can be requested via info@tolar.app.

Tolar is responsible for its own compliance with the GDPR, but is not liable for any failure by the platforms and sub-processors named above to comply with applicable laws and regulations themselves.

Article 6 Retention periods

  1. Tolar does not retain personal data for longer than necessary, with a default maximum retention period of five (5) years after termination of the Subscription, unless otherwise provided below.
  2. If a deletion request is made within this period in accordance with Article 8, the contact and account data will be deleted. Query logs and feedback will in that case not be deleted, but anonymised, so that they can no longer be traced back to an individual Customer, Admin or User.
  3. If five years have passed after termination of the Subscription without a deletion request having been made, Tolar is entitled to anonymise all personal data. Once anonymised, data no longer qualifies as personal data within the meaning of the GDPR and may be retained and used by Tolar indefinitely.
  4. If the Customer, Admin or User enters into a new Agreement with Tolar after termination of a Subscription, a new five-year period begins upon any subsequent termination of that Agreement.
  5. Notwithstanding the above, invoicing and other financial administration data (including name, address and KvK number where included on invoices) will be retained for at least seven (7) years, in order to comply with the statutory tax retention obligation. A deletion request as referred to in Article 8 can never relate to this data.

Article 7 Security

Tolar takes appropriate technical and organisational measures to protect personal data against loss or unlawful processing. This includes:

  • encryption of data, both in transit and at rest;
  • role-based access control, with two-factor authentication (2FA) for accounts with elevated permissions;
  • a password policy in line with current security standards;
  • regular backups of stored data.

In addition, Tolar depends in part on the security measures of its sub-processors (including Railway and Supabase), which are themselves subject to their own statutory and contractual security obligations.

Article 8 Rights of data subjects

  1. A Customer, Admin or User has the right to request access, via info@tolar.app, to the personal data Tolar processes about them, and may request that this data be corrected or deleted.
  2. A deletion request relates to all personal data, with the exception of:
    1. feedback and input provided on the Platform, which will instead be anonymised in accordance with Article 6(2); and
    2. invoicing and financial administration data that Tolar is required to retain under statutory obligations, see Article 6(5).
  3. Tolar will handle a request as soon as possible and in any event within the statutory period of one month.
  4. In addition to the right of access and deletion, the data subject has the right to rectification, restriction of processing, objection to processing based on legitimate interest and, where applicable, data portability. A data subject also has the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Article 9 Data breaches

  1. If a data breach occurs that may affect the personal data of a Customer, Admin or User, Tolar will notify the Customer concerned and will provide assistance to the best of its ability in resolving the data breach.
  2. Tolar is not liable for a data breach and will not pay any damages in connection with a data breach, but will make best efforts to resolve a data breach and limit its consequences. This clause applies for as long as there is no deliberate act (i.e. intent) involved.
  3. To the extent Tolar acts as a processor within the meaning of Part B, it will notify the relevant Customer, as controller, without undue delay — and no later than forty-eight (48) hours after Tolar becomes aware of the data breach — so that the Customer can itself comply with any notification obligations towards the Dutch Data Protection Authority and data subjects.

Article 10 Confidentiality

All personal data is treated by Tolar as strictly confidential and is shared only with team members, subcontractors and developers who play an essential role in the operation of the Platform, and with the sub-processors listed in Article 5. Personal data is never sold to third parties.

Article 11 Changes

Tolar may amend this privacy statement and data processing agreement from time to time. The Customer, Admin and/or User will be notified of any changes. Continued use of the Platform after the effective date of a change constitutes acceptance of the amended version.

Part B — Data Processing Agreement

Applies in addition where the Customer is an organisation with an Admin and one or more Users, within the meaning of Article 28(3) GDPR.

Article 12 Applicability and status

  1. This Part B constitutes a data processing agreement within the meaning of Article 28(3) GDPR and applies whenever the Customer is an organisation acting as controller for the personal data of its own Admin(s) and Users on the Platform. To the extent the Customer is an individual sole trader who is themselves both Admin and User, Tolar acts directly as controller and only Part A applies.
  2. This data processing agreement forms an inseparable part of the Agreement between Tolar and the Customer, cannot be terminated separately, and terminates automatically upon termination of the Subscription.

Article 13 Subject matter, nature, duration and categories

  1. Tolar processes, on behalf of the Customer, the personal data of the Customer’s Admin(s) and Users, as described in Article 2, for the purpose of providing the Service as described in the general terms and conditions and this data processing agreement.
  2. Processing takes place for the duration of the Subscription and ends in accordance with the retention and anonymisation periods set out in Article 6.
  3. The categories of data subjects are the Admin(s) and Users that the Customer adds to the Platform. The categories of data are the contact, usage and technical data referred to in Article 2.

Article 14 Instructions

  1. Tolar processes personal data of the Customer’s Admin(s) and Users solely on the basis of this data processing agreement and any further written instructions from the Customer, unless a statutory obligation requires Tolar to process the data otherwise.
  2. Tolar will inform the Customer if, in its opinion, an instruction from the Customer infringes applicable data protection legislation.

Article 15 Confidentiality

Tolar ensures that every person acting under its authority who has access to the Customer’s personal data is bound by an appropriate confidentiality obligation.

Article 16 Sub-processors

  1. Upon entering into the Agreement, the Customer authorises Tolar to engage the sub-processors listed in Article 5.
  2. Tolar will inform the Customer in advance of any replacement of, or addition to, these sub-processors, so that the Customer may object on reasonable grounds.
  3. Tolar ensures that sub-processors are contractually bound to at least the same data protection obligations as set out in this data processing agreement.

Article 17 Assistance to the Customer

  1. Taking into account the nature of the processing, Tolar will provide the Customer with reasonable assistance in responding to requests from data subjects to exercise their rights as referred to in Article 8.
  2. Tolar will provide the Customer with reasonable assistance in complying with its obligations under Articles 32 to 36 GDPR, including security, data breach notification and, where applicable, a data protection impact assessment.

Article 18 Audit

Upon request, Tolar will provide the Customer with the information reasonably necessary to demonstrate that Tolar complies with its obligations as a processor, and will permit the Customer to have audits carried out, provided this is announced in writing in advance and takes place in a manner that is reasonable for Tolar.

Tolar is entitled to comply with an audit request by providing relevant certifications, independent third-party reports (such as ISO, SOC 2 or comparable audits) or other equivalent documentation, to the extent these reasonably cover the requested information. Only if such documentation is unavailable or provides insufficient insight is Tolar required to permit an on-site audit.

An audit will not take place until the Customer and the auditor engaged by the Customer have entered into a written agreement with Tolar, which shall at a minimum set out the following:

  • Confidentiality: the auditor and the Customer undertake to maintain full confidentiality regarding all information, data and business processes they become aware of in connection with the audit, and will not disclose this information to third parties or use it for any purpose other than assessing Tolar’s compliance with its obligations as a processor.
  • Non-competition: the auditor engaged by the Customer may not work for, or otherwise be affiliated with, a competitor of Tolar, and will not, during or after the audit, use any knowledge gained for the benefit of a competing service or business.

Without such a prior written agreement, Tolar is not obliged to cooperate with an audit.

All costs associated with an audit initiated by the Customer, including but not limited to the costs of employees, advisers or third parties engaged by Tolar, and any resulting business disruption reasonably arising therefrom, shall be borne entirely by the Customer.

Article 19 Return and deletion after termination

After termination of the Subscription, the personal data of the Customer’s Admin(s) and Users will be processed in accordance with the retention and anonymisation periods set out in Article 6. At the Customer’s request, made before the expiry of this period, Tolar will provide an export file of the relevant data.

Article 20 Liability

Tolar’s liability under this data processing agreement is subject to the same limitations as set out in Tolar B.V.’s general terms and conditions. These apply only to liability claims brought by the Customer against Tolar B.V.