Direct naar inhoud
wiekomt.nl
InloggenMaak gratis

Privacy Policy / Privacyverklaring

Last updated / Laatst gewijzigd: September 5, 2026

English Nederlands

Privacy Statement (English)

wiekomt.nl is designed to be minimal, privacy-friendly, and fully compliant with the General Data Protection Regulation (GDPR / AVG). We collect only what is strictly necessary to make event RSVPs work smoothly.

1. Who We Are & Contact

wiekomt.nl is an independent event invitation and RSVP platform operated in the Netherlands.

  • Contact email: privacy@wiekomt.nl
  • Data Controller: wiekomt.nl acts as the Data Controller for host user accounts, session data, and platform security logs.
  • Data Processor: For guest lists and guest RSVPs, the event host acts as the Data Controller (deciding who to invite and managing the guest list), and wiekomt.nl acts as a Data Processor on the host's behalf.

2. What Data We Collect

Data Subject Information Collected Purpose & Storage
Host Email address, salted & hashed password (bcrypt). Account authentication and event management. Display name is derived from email and never stored separately.
Guest Name (required, max 70 characters), RSVP status (accepted/declined), party size (1–10). Recorded for the host's event headcount. No guest email is collected at launch; an optional email for event updates returns with reminders (M3).
Personal Invites Guest label (name entered by host), 128-bit unguessable random token. Allows hosts to share individualized invite links (?t=token) with prefilled names.
Technical & Security Client IP address (in-memory rate limiters only), session cookie IDs, CSRF tokens. In-memory rate limiting and brute-force protection. IP addresses are never written to disk or database logs.

What we never collect: We never collect phone numbers, physical addresses, dates of birth, tracking pixels, or third-party marketing profiles. Full guest lists and guest email addresses are never made public.

3. Legal Bases for Processing (GDPR Art. 6)

  • Guest RSVP (Name, Status, Party Size): Consent (Art. 6(1)(a) GDPR). Given affirmatively when tapping Accept or Decline and submitting the form. No guest email is collected at launch.
  • Host Account & Management: Contract Performance (Art. 6(1)(b) GDPR). Necessary to create and administer events.
  • Displaying Guest List to Host: Legitimate Interest (Art. 6(1)(f) GDPR). The host has a legitimate need to see the guest headcount and attendee list to organize their event.
  • Security, CSRF & Rate Limiting: Legitimate Interest (Art. 6(1)(f) GDPR). Strictly necessary to protect the platform against automated abuse and attacks.

4. Data Retention & Deletion

  • Automatic 13-Month Purge: All event data, including RSVPs, invite tokens, and event details, is automatically deleted from our database 13 months after the event date.
  • Host Self-Deletion: Hosts can delete individual RSVP entries, remove events, or delete their entire account at any time via their dashboard with immediate effect.
  • Backups & Snapshots: Automated database snapshots (stored in Cloudflare R2) rotate and expire within a maximum retention window of 30 days.
  • Sessions: Inactive host sessions automatically expire after 30 days.

5. Who Sees Your Data & Sub-Processors

Only the event host can see their own event's guest list and attendee names. Other guests and the public cannot see the full guest list or other guests' email addresses.

We use reputable infrastructure providers located within the European Union:

  • Fly.io, Inc.: Application hosting and TLS termination, strictly pinned to the ams (Amsterdam, Netherlands) region. Compliance & DPA: fly.io/compliance (signed DPA gated at fly.io/documents after sign-in, or on request via the Fly dashboard).
  • Cloudflare, Inc.: DNS, privacy-friendly cookieless Web Analytics planned for host pages only (M1); no beacon deployed today, and encrypted backup storage in the EU (WEUR) jurisdiction. Customer DPA: cloudflare-customer-dpa.
  • Resend, Inc.: Transactional email delivery and event reminders (EU-region sending when enabled; until verified, transfers covered by Resend DPA + SCCs). DPA: resend.com/legal/dpa.
  • BetterStack, Inc.: Uptime monitoring (GET /healthz only, no personal data processed; minimal health pings, no PII).

Data transfer notice: We do not store or process personal data on servers in the United States or outside the EEA without appropriate Standard Contractual Clauses (SCCs) and explicit notification. No US-region storage/processing without updating GDPR.md + /privacy first. Guest invite pages (/e/*) set no analytics cookies and load no third-party analytics beacons; guest Content-Security-Policy stays script-src 'self'; connect-src 'self'.

6. Cookie Policy (No Cookie Banner Required)

We use strictly necessary functional cookies only:

  • session / __Host-session: Authenticates logged-in hosts (30 days, HttpOnly, SameSite=Lax, Secure on HTTPS).
  • csrf / __Host-csrf: Prevents cross-site request forgery attacks (HttpOnly, SameSite=Lax).
  • lang: Stores interface language preference (nl / en) — planned with M2 i18n, not set today.

We do not use advertising, marketing, or tracking cookies. Cloudflare Web Analytics (cookieless) is planned for host pages only (M1); no beacon is deployed today, guest /e/* pages are excluded and their Content-Security-Policy is unchanged. In accordance with Article 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet) and European ePrivacy guidelines, purely functional and strictly necessary cookies do not require a cookie consent banner.

7. Your Rights (GDPR Art. 15–22)

Under the GDPR, you have the following rights regarding your personal data:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete information.
  • Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
  • Right to Restriction of Processing (Art. 18): Restrict how your data is processed.
  • Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interest.
  • Right to Withdraw Consent: Withdraw consent at any time without affecting prior lawful processing.

To exercise your rights:

  • Guests with personal invite links (?t=) can change or withdraw their RSVP directly via their link.
  • Guests on open links can contact the host directly or email privacy@wiekomt.nl.
  • Hosts can manage and delete their data directly in their dashboard or contact us at privacy@wiekomt.nl.

You also have the right to lodge a complaint with the supervisory authority in the Netherlands:

Autoriteit Persoonsgegevens (AP)
Postbus 93374, 2509 AJ Den Haag, The Netherlands
Website: autoriteitpersoonsgegevens.nl

8. Changes

2026-09-05: Initial bilingual version. Future material changes will be listed here with date and summary.


Privacyverklaring (Nederlands)

wiekomt.nl is ontworpen om minimaal, privacyvriendelijk en volledig in overeenstemming met de Algemene Verordening Gegevensbescherming (AVG / GDPR) te zijn. Wij verzamelen alleen wat strikt noodzakelijk is om RSVP's soepel te laten verlopen.

1. Wie wij zijn & Contact

wiekomt.nl is een onafhankelijk platform voor evenementuitnodigingen en RSVP's, gevestigd in Nederland.

  • Contact e-mail: privacy@wiekomt.nl
  • Verwerkingsverantwoordelijke: wiekomt.nl is de verwerkingsverantwoordelijke voor host-accounts, sessiegegevens en beveiligingslogboeken van het platform.
  • Verwerker: Voor gastenlijsten en RSVP's van gasten is de organisator (host) de verwerkingsverantwoordelijke (die bepaalt wie wordt uitgenodigd en de gastenlijst beheert). wiekomt.nl treedt op als verwerker namens de organisator.

2. Welke gegevens wij verzamelen

Betrokkene Verzamelde gegevens Doel & Opslag
Organisator (Host) E-mailadres, gezouten & gehasht wachtwoord (bcrypt). Authenticatie van het account en beheer van evenementen. Weergavenaam wordt afgeleid van het e-mailadres en niet apart opgeslagen.
Gast Naam (verplicht, max. 70 tekens), RSVP-status (aanwezig/afwezig), aantal personen (1–10). Vastgelegd voor het aantal aanwezigen voor de organisator. E-mailadres van gasten wordt bij de lancering niet verzameld; een optioneel e-mailadres voor updates keert terug met herinneringen (M3).
Persoonlijke uitnodigingen Naamlabel (ingevoerd door host), niet-raadpleegbaar 128-bits willekeurig token. Stelt organisatoren in staat om persoonlijke uitnodigingslinks (?t=token) te delen met vooraf ingevulde namen.
Technisch & Beveiliging IP-adres van de bezoeker (alleen in tijdelijk geheugen voor rate limiting), sessie-cookies, CSRF-tokens. Beveiliging tegen geautomatiseerd misbruik en brute-force aanvallen. IP-adressen worden nooit opgeslagen in de database of op schijf.

Wat wij nooit verzamelen: Wij verzamelen geen telefoonnummers, fysieke adressen, geboortedata, tracking pixels of marketingprofielen van derden. Volledige gastenlijsten en e-mailadressen van gasten worden nooit openbaar gemaakt.

3. Rechtsgronden voor de verwerking (AVG art. 6)

  • RSVP van gast (naam, status, aantal personen): Toestemming (art. 6 lid 1 sub a AVG). Gegeven door actief op Aanwezig of Afwezig te klikken en het formulier te verzenden. E-mailadres van gasten wordt bij de lancering niet verzameld.
  • Host-account & Evenementbeheer: Uitvoering van de overeenkomst (art. 6 lid 1 sub b AVG). Noodzakelijk om het account en evenementen te beheren.
  • Weergave gastenlijst aan organisator: Gerechtvaardigd belang (art. 6 lid 1 sub f AVG). De organisator heeft een gerechtvaardigd belang om te weten wie er aanwezig is voor de organisatie van het evenement.
  • Beveiliging, CSRF & Rate limiting: Gerechtvaardigd belang (art. 6 lid 1 sub f AVG). Strikt noodzakelijk voor de beveiliging en integriteit van het platform.

4. Bewaartermijnen & Verwijdering

  • Automatische verwijdering na 13 maanden: Alle evenementgegevens, inclusief RSVP's, uitnodigingstokens en evenementdetails, worden 13 maanden na de datum van het evenement automatisch definitief verwijderd.
  • Zelfverwijdering door de host: Organisatoren kunnen te allen tijde individuele gasten, volledige evenementen of hun gehele account direct verwijderen via het dashboard.
  • Back-ups & Snapshots: Automatische databasesnapshots (in Cloudflare R2) worden geroteerd en binnen maximaal 30 dagen definitief gewist.
  • Sessies: Inactieve sessies van organisatoren verlopen automatisch na 30 dagen.

5. Wie uw gegevens inzien & Subverwerkers

Alleen de organisator van het betreffende evenement kan de gastenlijst en namen van zijn of haar gasten inzien. Andere gasten en het algemene publiek kunnen de volledige gastenlijst of e-mailadressen van anderen niet bekijken.

Wij maken gebruik van betrouwbare infrastructuurpartners binnen de Europese Unie:

  • Fly.io, Inc.: Applicatiehosting en TLS-beveiliging, vastgezet op de regio ams (Amsterdam, Nederland). Compliance & DPA: fly.io/compliance (ondertekende DPA via fly.io/documents na inloggen, of op aanvraag via het Fly-dashboard).
  • Cloudflare, Inc.: DNS, cookieloze Web Analytics gepland voor hostpagina's alleen (M1); vandaag geen beacon actief en versleutelde back-upopslag binnen de EU (WEUR-jurisdictie). DPA: cloudflare-customer-dpa.
  • Resend, Inc.: Transactionele e-mailverzending en herinneringen (EU-regio verzending indien ingeschakeld; tot verificatie vallen overdrachten onder Resend DPA + SCC's). DPA: resend.com/legal/dpa.
  • BetterStack, Inc.: Uptime-monitoring (alleen GET /healthz, geen persoonsgegevens; minimale health-pings, geen PII).

Gegevensoverdracht: Wij slaan geen persoonsgegevens op buiten de Europese Economische Ruimte (EER) zonder passende modelcontractbepalingen (SCC's) en voorafgaande kennisgeving. Geen US-regio opslag/verwerking zonder eerst GDPR.md + /privacy bij te werken. Uitnodigingspagina's voor gasten (/e/*) plaatsen geen analytics-cookies en laden geen externe analytics-beacons; het Content-Security-Policy voor gasten blijft script-src 'self'; connect-src 'self'.

6. Cookiebeleid (Geen cookiebanner nodig)

Wij plaatsen uitsluitend strikt noodzakelijke functionele cookies:

  • session / __Host-session: Houdt ingelogde organisatoren aangemeld (30 dagen, HttpOnly, SameSite=Lax, Secure op HTTPS).
  • csrf / __Host-csrf: Bescherming tegen cross-site request forgery aanvallen (HttpOnly, SameSite=Lax).
  • lang: Bewaart de taalvoorkeur van de interface (nl / en) — gepland met M2 i18n, wordt vandaag niet geplaatst.

Wij gebruiken geen advertentie-, tracking- of marketingcookies. Cloudflare Web Analytics (cookieloos) is gepland voor hostpagina's alleen (M1); vandaag geen beacon actief, gastenpagina's /e/* zijn uitgesloten en hun Content-Security-Policy is ongewijzigd. Op grond van artikel 11.7a van de Telecommunicatiewet en de AVG is voor strikt noodzakelijke functionele cookies geen toestemming of cookiebanner vereist.

7. Uw rechten (AVG art. 15–22)

Op grond van de AVG heeft u de volgende rechten met betrekking tot uw persoonsgegevens:

  • Recht op inzage (art. 15): Inzage vragen in de persoonsgegevens die wij van u verwerken.
  • Recht op rectificatie (art. 16): Corrigeren van onjuiste of onvolledige gegevens.
  • Recht op gegevenswissing (art. 17): Verwijdering van uw persoonsgegevens ("recht op vergetelheid").
  • Recht op beperking van de verwerking (art. 18): Beperken van de gegevensverwerking.
  • Recht op overdraagbaarheid (art. 20): Uw gegevens ontvangen in een gestructureerd, gangbaar formaat.
  • Recht van bezwaar (art. 21): Bezwaar maken tegen de verwerking op basis van gerechtvaardigd belang.
  • Recht om toestemming in te trekken: U kunt eerder verleende toestemming te allen tijde intrekken.

Hoe u uw rechten uitoefent:

  • Gasten met een persoonlijke uitnodigingslink (?t=) kunnen hun antwoord direct wijzigen of intrekken via hun link.
  • Gasten op open links kunnen contact opnemen met de organisator of mailen naar privacy@wiekomt.nl.
  • Organisatoren kunnen hun gegevens direct in het dashboard beheren en verwijderen of contact opnemen via privacy@wiekomt.nl.

U heeft tevens het recht om een klacht in te dienen bij de toezichthouder:

Autoriteit Persoonsgegevens (AP)
Postbus 93374, 2509 AJ Den Haag
Website: autoriteitpersoonsgegevens.nl

8. Changes / Wijzigingen

2026-09-05: Initial bilingual skeleton per GDPR.md §8 (EN + NL). Future material changes will be listed here with date and summary. / Eerste tweetalige versie; toekomstige wijzigingen worden hier met datum vermeld.

Back to home / Terug naar home

Gratis · Geen app · Gasten loggen nooit in · Alleen naam-RSVP

Privacy · Voorwaarden · wiekomt.nl

Taal: NL · EN