1. General information
The protection of your privacy and personal data is important to us. We respect your privacy and we do what it takes to keep your personal data truly personal. On the basis of complete transparency, this privacy statement describes what personal data we process, on what legal basis we process it and for what purpose(s) we use your data. With this statement, we also inform you on how you can exercise your legal rights regarding privacy.
This privacy statement applies to all our services, the use of our website(s), application(s), contact form(s) and to other correspondence. In case you do not agree with this privacy statement, we advise you not to use our services. Please also take note of our Terms of Service(s), where definitions are given of words with capital letters used in this statement.
Moreover, we use cookies on our websites. For more information on what type of cookies we use and on how to delete or block them, please see our cookie statement.
If you require any additional information about the protection of your personal data, feel free to contact our Data Protection Officer via privacy@Sendsteps.com, or visit the website of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): www.autoriteitpersoonsgegevens.nl.
2. The data we gather
Sendsteps collects and processes personal data. We gather this data based on your input or by automated means. Not all data input is required to use our services, but some is. In the table below, we provide an overview of the data we gather, how and why we gather the data, and on what legal basis we do so.
We only collect personal data if and limited to what is necessary for the purposes listed below. In case we intend to further process your data, we will prior to that further processing provide you with information on what other purpose(s) we intend to process your data for. We do not use automated decision-making or personal-data processing techniques (such as profiling).
We are either Controller or Processor of the personal data we store, within the meaning of the EU General Data Protection Regulation. Regarding the types of data 'behaviour data', 'content data', 'purchase date', 'technical data' and 'contact data', we consider ourselves Controller of the personal data. This means it is Sendsteps that determines the purposes and means of the processing of personal data. Regarding 'content data', we consider our Customer the Controller of the personal data, which means Sendsteps merely processes the personal data on behalf of our Customer.
When our legitimate interests form the legal basis for the processing of your personal data, we use your data to improve the quality, stability and availability of our services. We make an explicit deliberation of the data we want to use for these purposes and we only use the data to the extent necessary. We also take specific security measures regarding this data: whenever we can pseudonymise or anonymise the relevant data, we will do so.
| Description of (personal) data | Data subject | Why do we gather this data and on what legal basis? |
|---|---|---|
| Content data (as Processor/Controller) | ||
| Data in the presentation of an End User and in answers to questions asked by End User on a Free Service. Depending on the settings selected by the Costumer or End User, this may also include nicknames. The data is non-required user input. | Audience member | To be able to provide the audience response services, to display the answers to your questions on screen, to make analysis on your answers. Legal basis: not required, because we are not the Controller. To use your answers for business development purposes. Legal basis: our legitimate interests. |
| Data in the presentation of an End User and in answers to questions asked by End User on a Paid Service (also including the Student Service). The data is non-required user input. In case the Paid Service / Student Service ends or is terminated, the relevant data will - until the end of the applicable storage period - be processed as if it was data under a Free Service. | Audience member | To be able to provide the audience response services, to display the answers to your questions on screen, to make analysis on your answers. Legal basis: not required, because we are not the Controller. |
| Behavioural data (as Controller) | ||
| Anonymised statistical data on how our products, services, websites and tooling are used. This includes data on what users click on, the type of questions used, times at which our products are used, etc. The data gathering is automated. | Audience member, End User, Customer | To make analysis that helps us improve our services. Legal basis: not required, because we are not the Controller. |
| Profile data (as Controller) | ||
| First name, last name, username and email address. The data is required user input. If this data is not provided we cannot render our services properly. | End User, Customer | To supply you with an account, recognize you as a user and send you messages regarding our services (including direct marketing). Legal basis: performance of a contract, our legitimate interests. |
| Company information and information provided by the Customer and/or End User regarding the intended and potential usage of our services. The data is non-required user input. | End User, Customer | To identify what services we may provide you, to be saved with your customer profile. Legal basis: performance of a contract, our legitimate interests. |
| Phone number. The data is non-required user input. | End User, Customer | To be able to contact you, to complete your customer profile, to provide the requested service. Legal basis: performance of a contract. |
| Technical data (as Controller) | ||
| Device data (e.g. hardware model, operating system version, unique device identifiers). The data gathering is automated. | Audience member, End User, Customer | To improve quality and availability of our products and services. Legal basis: our legitimate interests, performance of a contract. |
| Log data (e.g. your search queries, details about your connection such as IP address, date, time, edge-location, ssl-protocol, ssl-cipher or time-taken to serve your requested site, device event information such as crashes, system activity, hardware settings, browser type, browser language, the date and time of your request and referral URL), browser local storage and application data caches. The data gathering is automated. | Audience member, End User, Customer | To improve quality and availability of our products and services. Legal basis: our legitimate interests, performance of a contract. |
| Location information (IP address), this may be personal data when used in conjunction with profile data but is not gathered as such. The data gathering is automated. | Audience member, End User, Customer | To safeguard and improve the quality and availability of our products and services. Legal basis: our legitimate interests, performance of a contract. |
| Contact data (as Controller) | ||
| Email address, messages. The data is non-required user input. | Anyone contacting Sendsteps through email or our contact form(s) | To be able to reply to you and provide the requested service. Legal basis: consent. |
| Biometric data (voice) (as Processor) | ||
| Voice recordings uploaded by the Customer or End User for use with the AI voice-over feature. Depending on the option selected, the recording may be used to (i) generate a voice-over in the uploader's own voice, or (ii) transcribe the recording into text (the original recording is also retained). For both options, the original voice recording itself is stored for as long as the underlying content is kept. Because a stored voice recording can be used to derive a unique voiceprint, this data qualifies as biometric data within the meaning of Article 4(14) GDPR. The data is non-required user input and is only processed when this specific feature is actively used. Note: the voice-over feature also offers the option to use a pre-existing, royalty-free AI voice instead of the user's own voice. This option does not involve any upload or processing of the user's voice and therefore does not involve biometric or other personal data. | End User, Customer (or the individual whose voice is uploaded) | To generate the requested AI voice-over and/or transcription, and to make it available within the presentation. Legal basis: not required, because we are not the Controller — the Customer/End User, as uploader, is responsible for obtaining the explicit consent of the individual whose voice is uploaded (Article 9(2)(a) GDPR), given the special category nature of biometric data. |
Please note: voice recordings uploaded for the own-voice and transcription options of the voice-over feature may constitute a special category of personal data (biometric data) under Article 9 of the GDPR, as the original recording is retained for as long as the underlying content is kept. We only process this data on the explicit instruction of the Customer, who as Controller of this content data is responsible for ensuring a valid legal basis — including, where applicable, the explicit consent of the individual whose voice is uploaded — is in place before the recording is uploaded to our Application. The option to use a pre-existing, royalty-free AI voice does not involve the upload or processing of any voice recording and therefore falls outside this note.
3. Period for which data will be stored
Sendsteps does not store your personal data longer than necessary for the purpose for which the data was collected. How long we store your data depends on the type of data and the purpose for which we use the data.
Profile and content data is stored as long as someone has an account/profile to access our services or applications. In case we store personal data relating to a contract with you, the data is erased within thirty days after termination of the contract, except for data that we are obliged by law to store for a longer period of time. Please also be referred to our Terms of Service(s). A storage period of one year also applies to contact data. Purchase data and certain profile data needs to be stored for a term up to seven years because of tax legislation. This data is deleted from our systems one year after the end of such a term, at the latest. Voice recordings uploaded for the own-voice and transcription options of the voice-over feature are stored as content data, for as long as the relevant presentation is kept in the Customer's or End User's account, and are erased within thirty days after termination of the Agreement in accordance with clause 10.14 of the Terms of Service(s). Lastly, technical and behavioural data (in anonymised form) is kept for an undetermined period of time.
4. Sharing of the data we gather
Sendsteps will only share personal data with others when we are legally permitted to do so. When we share data with others, we put contractual arrangements and security mechanisms in place as appropriate to protect the data and to comply with our data protection and security standards.
We render our services globally and use services from partners located all over the world. As a result, personal data may be transferred outside the country where we are located or where you live. This includes the transfer of data to countries outside the European Union and to countries that may not have laws that provide sufficient protection for personal data, such as the United States of America. However, we have taken steps to ensure all personal data is provided with appropriate safeguards and adequate protection.
5. Sub-processors/recipients of the data
The personal data stored by us may be disclosed to/shared with other organisations. These organisations include third-party organisations that provide IT, marketing and sales services to us. We use these parties' services to help us run and manage our internal and external IT systems, including cloud-based storage, software, website hosting, applications and security. We may also share personal data with our external auditor/accountant to the extent necessary for the audit(s) and to our insurance company regarding insurance claims. We use professional advisors, such as law firms, where necessary to establish, exercise or defend our legal rights and to obtain legal advice. Lastly, we may be obliged to provide personal data to law enforcement agencies or other government and regulatory agencies.
In the table below, the sub-processors and recipients of personal data we process are listed, as well as the purpose for disclosing data to them and the location in which the sub-processor or recipient (to our knowledge) processes the data. The mentioned locations indicate where your data is processed according to our agreement with the relevant sub-processor/recipient.
| Sub-processor / recipient | Purpose | Location of data processing |
|---|---|---|
| Microsoft Corporation | Office applications | European Union |
| Yukiworks | Accounting | Germany, Ireland |
| Zoho corporation | Sales and marketing CRM, analytics and email service | The Netherlands |
| ABN AMRO Bank | Banking | European Union |
| Adyen | Payment processing | The Netherlands |
| Amazon Web Services Inc. | IT infrastructure | Germany |
| CM.com | Telecom services | Several locations within the EU |
| Cookiebot, Cybot A/S | Cookie notifications on our website | The Netherlands |
| Hotjar Ltd | User behaviour analytics | Ireland |
| Lodewijk van Rijn Consultancy | IT Testing and customer service | The Netherlands |
| New Relic Inc. | IT Analytics | Germany |
| Vonage (Nexmo) | Telephony | European Union |
| World-Text | SMS services | United Kingdom |
| Calendly | Scheduling and appointment booking | United States |
| VOIP Studio | VOIP phone system | European Union |
| Zoho | Sales and marketing CRM, analytics and email service | The Netherlands |
| Rackspace | IT infrastructure / cloud hosting | European Union |
| New Relic | IT Analytics | Germany |
| Linktree | Marketing (link-in-bio tool) | Australia |
| Intercom R&D | Customer messaging and support | Ireland |
| Hotjar | User behaviour analytics | Ireland |
| Hostnet | Web hosting | The Netherlands |
| Google Analytics | Marketing / advertising | Ireland |
| Google Ads | Marketing / advertising | Ireland |
| Adyen | Payment processing | The Netherlands |
| Amazon Web Services | IT infrastructure | Germany |
6. Security
In order to keep your personal data truly personal, we process your data in manner that ensures appropriate security. That is why we have put in place appropriate safeguards and policies, and have taken appropriate technical and organisational measures. We regularly review these policies and measures.
Regarding the locations where we store your personal data, our systems are designed in a way that your data is never stored in one place in full. This limits the risk of exposure in the unfortunate event of a security breach, and limits the impact thereof.
Sendsteps employees are instructed regarding organisational measures, for example regarding: our data-breach protocol, the content of the present privacy statement, the need to obtain consent before processing of certain data, and the need to protect their passwords and devices.
For more information regarding the security measures we took, please see this page.
7. Your rights
You have certain legal rights with regard to the processing of your personal data. We are responsible for fulfilling these rights. To make use of any of these rights you can contact us via the contact details listed in this statement and any other form of communication specified. Our aim is to respond to any requests for information or to take action as soon as possible, but in any case within four weeks. Your rights include the following.
The right of free access to personal data
You have the right to know whether we process data concerning you and to receive a free copy of your personal data held by us.
The right to rectification of personal data
You have the right to request for your personal data to be changed, updated or rectified. This right is applicable where your personal data, for example, changes over time, is incomplete or is inaccurate. In addition to contacting us via e-mail, you can (if applicable) directly change your personal details via the website(s) or application(s) with which you registered. We will make sure your data is updated as appropriate based on your request and as far as we are able to do so.
The right to be forgotten
You have the right to ask us to erase your personal data when one of the following circumstances occur:
- when it is no longer necessary to store the data in relation to the purposes for which it was collected and processed;
- when you withdraw the consent you previously gave and we have no other legal basis for the processing;
- when you object to us processing your data based on certain legitimate interests pursued by us or a third party and we do not have overriding legitimate interests;
- when you object to us processing your data for direct marketing purposes;
- when your personal data has been unlawfully processed; or
- when your personal data must be erased to comply with a legal obligation to which we are subject.
The right to restrict processing of personal data
You have the right to demand the restriction of processing your personal data during the period in which we assess your objection to accuracy or the use of your personal data, when we have unlawfully processed your data, and in case you require us to retain your data in light of legal claims.
The right to object to processing of personal data
You have the right to object to us processing your personal data if the processing is based on our (or a third party's) legitimate interests or if we process your personal data for direct marketing purposes.
The right to data portability
You have the right to receive the personal data that we store of you. When requested, we will provide the information in a structured, commonly used and machine-readable format, that makes it is simple for you to transfer your data to another party.
The right to withdraw your consent
When you have given your consent to the processing of your personal data based, you can withdraw this consent at any time.
8. Contact & complaints
If you have any questions about this privacy statement or how and why we process personal data, please contact our Data Protection Officer via e-mail (privacy@Sendsteps.com.) or by regular mail: Sendsteps B.V., Haarlemmerweg 321B, 1051LG Amsterdam (the Netherlands). Sendsteps B.V. is registered with the Dutch Chamber of Commerce under number 34307436. More contact details can be found on www.sendsteps.com/en/contact/.
In the unfortunate situation you want to issue a complaint regarding our processing of your personal data, you may send your complaint to the abovementioned contact details. We will carefully investigate and respond to any complaints.
You also have the right to issue a complaint with the Data Protection Authority (DPA) in your country of residence, place of work or the country in which an alleged violation of your privacy took place. In the Netherlands, the Autoriteit Persoonsgegevens is the competent authority to issue your complaint to. For further information regarding your rights and how to issue a complaint with the DPA, we kindly refer you to the website of the Dutch DPA.
This privacy statement applies from 23 April 2020 on until further notice.