Privacy statement

This is a translation of the Dutch version. In the event of any differences, the Dutch version is binding: Privacyverklaring (Dutch).

Last updated: October 8, 2026

1. Introduction

Ledenboek attaches great importance to the protection of your personal data. In this privacy statement we explain which data we collect, why we do so, how we process this data and what rights you have. This statement applies to all services that we provide through Ledenboek to associations and their members.

2. Responsibility for data

Responsibility for the processing of personal data through Ledenboek is shared:

Controller

The association that uses Ledenboek is responsible for:

  • deciding which data is collected
  • the purposes of the data processing
  • the lawfulness of the processing

If you have questions about how your association processes your data, please contact the board of your association.

Processor

Vuurpijl Beheer B.V.

Lagedijk 11A

2064 KV Spaarndam

Nederland

KVK: 34108141

Vuurpijl Beheer B.V. processes data solely on behalf of the association. The arrangements for this are set out in the data processing agreement, which forms part of the agreement with each association.

For questions about Ledenboek itself: info@ledenboek.nl

3. What data we collect

Personal data of members

  • Name (first name, surname)
  • Contact details (address, email address, telephone number)
  • Date of birth
  • Membership details (membership number, start date, status)

Account details

  • Email address
  • Encrypted password
  • Two-factor authentication data (optional)

Payment details

  • Payment status and history
  • Billing details
  • IBAN (for payouts, where applicable)

Please note: we do not store credit card numbers; they are processed directly by our payment provider Mollie.

Technical data

  • IP address
  • Browser type and version
  • Device information
  • Cookies (session and analytics)

4. Purposes of processing

We process your data for the following purposes:

Membership administration

Managing your membership and communicating about association activities.

Financial administration

Processing membership fees, payments and invoicing.

Communication

Sending invitations and newsletters, and answering questions.

Improving our services

Analysis of usage (anonymised) and technical optimisation.

Legal obligations

Tax records and legal proceedings where necessary.

5. Legal bases

We process your data on the basis of the following legal grounds under the General Data Protection Regulation (GDPR):

Performance of a contract (Art. 6(1)(b) GDPR)

Your membership of the association is a contract for which processing of data is necessary.

Legal obligation (Art. 6(1)(c) GDPR)

The statutory obligation to keep tax records and other legal obligations.

Legitimate interest (Art. 6(1)(f) GDPR)

Improving our services and keeping the application secure.

Consent (Art. 6(1)(a) GDPR)

For analytics cookies and marketing communication (where applicable). You can withdraw this consent at any time.

6. Third parties

We use the following service providers to deliver our service. We have data processing agreements with each of them, and all of their processing takes place within the European Economic Area. The full list is also included in the data processing agreement.

Mollie B.V.

Purpose: Processing online payments

Data: Invoice number, amount, payment status

Mollie privacy policy

Google Analytics

Purpose: Website statistics and usage analysis

Data: Anonymised usage data, page views

Google privacy policy

Hetzner Online GmbH

Purpose: Hosting of the application and the database

Data: All data stored in Ledenboek

Location: Germany (EU)

Hetzner privacy policy

Euromailing

Purpose: Sending email to members on behalf of the association

Data: Name, email address and the content of the message

Location: Netherlands (EU)

Stripe Payments Europe Ltd.

Purpose: Billing for the association's own subscription

Data: Contact and payment details of the association, no member data

Location: Ireland (EU)

Stripe privacy policy

PostHog

Purpose: Usage statistics and error reports for the application

Data: Technical data and which screens are used

Location: European Union

PostHog privacy policy

7. Retention periods

We do not keep your data for longer than is necessary for the purposes for which it was collected:

Type of data Retention period
Membership details For the duration of the membership + 2 years after it ends
Financial data 7 years (statutory retention obligation)
Account details Until the account is deleted
Analytics data 26 months (anonymised)
Log data 12 months

After your membership ends, your data is anonymised or deleted, unless a statutory retention obligation applies.

8. Cookies

We use cookies to make the website work properly and to gain insight into how our service is used.

Necessary cookies (always active)

These cookies are essential for the website to work.

  • Session cookie: For signing in and security (lifetime: session)
  • CSRF token: Protection against cross-site request forgery (lifetime: session)

Analytics cookies (with consent)

These cookies help us improve the website.

  • Google Analytics: Website statistics (lifetime: 26 months)

You can disable analytics cookies in your browser settings or via Google Analytics Opt-out.

We do not use third-party marketing or tracking cookies.

9. Your rights

Under the GDPR you have the following rights in relation to your personal data:

Right of access (Art. 15)

You can ask which data we hold about you.

Right to rectification (Art. 16)

You can have incorrect data corrected.

Right to erasure (Art. 17)

You can ask us to delete your data.

Right to restriction (Art. 18)

You can have processing stopped temporarily.

Right to data portability (Art. 20)

You can receive your data in a standard format.

Right to object (Art. 21)

You can object to certain types of processing.

How can you exercise your rights?

To exercise these rights, you can contact the board of your association or info@ledenboek.nl. We will respond to your request within 30 days.

10. Security

We take appropriate technical and organisational measures to protect your data against loss, unauthorised access and misuse:

  • Encrypted connections (HTTPS/TLS) for all data transfer
  • Encrypted storage of passwords (bcrypt)
  • Two-factor authentication available for extra security
  • Regular security updates and patches
  • Access to data restricted to authorised persons
  • Hosting within the European Union

11. Complaints

Do you have a complaint about the processing of your personal data? Please contact your association first, or us at info@ledenboek.nl. We will handle your complaint with care.

Autoriteit Persoonsgegevens

You also have the right to lodge a complaint with the supervisory authority:

Autoriteit Persoonsgegevens

Postbus 93374

2509 AJ Den Haag

www.autoriteitpersoonsgegevens.nl

12. Contact details

For questions about this privacy statement or about the processing of your personal data:

Email: info@ledenboek.nl

Vuurpijl Beheer B.V.

Lagedijk 11A

2064 KV Spaarndam

Nederland

13. Changes

This privacy statement may be amended. If we make significant changes, we will inform you through the application. The most recent version is always available on this page.