Privacy statement
English translation. This page translates our Dutch privacy statement for readers who prefer English. The Dutch text is the binding version: if the two ever differ, the Dutch privacy statement prevails.
When you use our services and our SaaS platform, or visit our website(s) (together: the "Platform"), your personal data may be processed. In this privacy statement we explain what we do with that information, why we do it and what rights you have. We always handle your data with care and store it securely. If you have questions, or want to know what information we hold about you, please get in touch.
We may amend this privacy statement where necessary, for example following changes in legislation or in our services. We therefore recommend reviewing it from time to time so you stay aware of any changes. This privacy statement was last amended on 25 August 2026.
Contents
- When does this privacy statement apply?
- Who uses your data?
- Whose data do we use?
- How do we obtain your data?
- What data do we use?
- What do we use your data for?
- How long do we keep your data?
- Who do we share your data with?
- Where do we store your data?
- How secure is your data with us?
- What can you ask of us?
- What rules apply to this privacy statement?
- Which cookies do we use?
- What do we do with data about minors?
- Google Calendar integration and Google user data
- Do you have a question about this privacy statement?
1. When does this privacy statement apply?
This privacy statement applies to all personal data that Flixer processes through its websites, widgets, the online SaaS platform and in the course of providing its services. It covers the personal data of everyone who has been in contact with us or uses our services: visitors to our website, (prospective) customers, business contacts, users of the Platform (such as our customers' employees) and, where our customers use the Platform towards their own customers, the personal data processed through the Platform on those customers' behalf.
Personal data is any data that can be traced back to you as an individual, such as your name, telephone number, IP address, customer number or browsing behaviour. If you would like to know more about personal data, see the website of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
2. Who uses your data?
In most cases Flixer is responsible for the use of your personal data as described in this privacy statement. Our full details are:
Flixer B.V. Raadhuisstraat 20 1016 DE Amsterdam The Netherlands Chamber of Commerce (KvK): 98298232 Email: info@flixerpro.nl
Where we process personal data on behalf of a business customer using our Platform (for example a construction or installation company entering data about its own customers), we act as processor and that customer is the controller. Section 6 explains this further.
3. Whose data do we use?
We process the personal data of everyone who has been in contact with us, has visited our website or uses our Platform. This includes:
- Visitors to our website(s).
- Contacts at (prospective) customers and partners.
- Users of the Platform (such as employees, contractors or other users designated by our customers).
- End customers of our business customers, whose data is processed through the Platform (for example consumers for whom our customers carry out work).
4. How do we obtain your data?
We receive your data in a number of ways:
- Directly from you, for example when you create an account, complete a form on our website, contact us by email or telephone, or use the Platform.
- From our business customers, when they enter data about their own customers and users into the Platform.
- Through your use of the Platform, for example from log and usage data.
- Through cookies and similar techniques on our website(s), to the extent you have consented or this is otherwise permitted.
- Through partner websites on which our widgets or web modules are embedded.
- Through third-party integrations you connect to the Platform yourself, such as Google Calendar (see section 15).
5. What data do we use?
Depending on your relationship with us and how you use the Platform, we may process the following data:
- Identification and contact details, such as first name, surname, (company) name, address, email address and telephone number.
- Business details, such as job title, company name and Chamber of Commerce number.
- Account and usage data, such as username, login times, roles and permissions within the Platform, and settings.
- Communication data, such as messages you send us, support tickets, feedback and conversation notes.
- Data about end customers entered by our business customers, such as name, address, contact details, appointment and project information, invoicing details and any further information needed to carry out their work.
- Technical data, such as IP address, device and browser information, and log files.
- AI-related data, such as transcripts or summaries of conversations, to the extent these may contain personal data.
- Data from connected third-party services, such as Google Calendar data when you activate that integration (see section 15 for the full explanation).
6. What do we use your data for?
We only use your personal data where there is a legitimate reason (a legal basis) to do so. Depending on the situation, we use your data for the following purposes.
a) To provide our services and the Platform
We process your data to make the Platform available, to create and manage accounts, to deliver functionality (such as planning, CRM, field management and invoicing) and to provide support. The legal basis is usually performance of the agreement with our customer, or our legitimate interest in being able to offer our services.
b) To stay in contact with you
When you contact us (for example for a demo, a support question or other information), we use your contact details and the subject of your message in order to answer your question. The legal basis is our legitimate interest in delivering our services and maintaining relationships or, if you ask us for a quote, taking steps at your request prior to entering into an agreement.
c) For marketing and communication
We may use your data to inform you about Platform updates, new functionality or other relevant information about our services. We do this on the basis of our legitimate interest in bringing our services to the attention of (prospective) customers. Where required we ask for your consent in advance, for example before sending certain newsletters or placing marketing cookies.
d) For security, analysis and product improvement
We use technical data, log data and aggregated information to keep the Platform secure and stable, to prevent misuse and to monitor performance. We may also use anonymised and/or aggregated data for statistical and analytical purposes and for product improvement. Such data cannot be traced back to individuals or to a specific customer. Data we receive through the Google Calendar integration is expressly not used for product improvement, AI model training or any other secondary purpose (see section 15).
e) Processing on behalf of our business customers (as processor)
Where a business customer uses our Platform to process personal data about its own customers, suppliers or employees, we process that data solely on behalf of and on the instructions of that customer. In that case the customer is the controller and Flixer acts as processor.
f) To comply with legal obligations
We may process your personal data in order to comply with legal obligations, for example under tax legislation or where competent authorities request it.
7. How long do we keep your data?
We keep your personal data for as long as the law requires and for as long as is necessary for the purpose for which we use it.
- Data about (prospective) customers and users is in principle kept for the term of the agreement and for up to seven (7) years afterwards, unless we are required to keep it longer for legal or tax reasons.
- Administrative data, such as invoicing and payment data, is kept for at least seven (7) years under the statutory tax retention obligation.
- Log and security data is kept for as long as necessary for security and analysis purposes, after which we delete or anonymise it.
- Data we process on behalf of our customers is kept for as long as agreed with the customer concerned in the data processing agreement. After the agreement ends we give our customer a reasonable period to export data. We then delete or anonymise it, unless we are legally required to keep it longer.
Specific retention periods apply to data processed through the Google Calendar integration; these are set out in section 15.
If you would like to know how long we keep specific data about you, please contact us.
8. Who do we share your data with?
We only share your personal data with others where this is necessary for the purposes described above, where we are legally required to do so, or where you have given your consent. This includes:
- IT service providers and hosting and cloud providers supporting our Platform and infrastructure.
- Suppliers of tools for email, customer communication, analytics and support.
- Business partners we work with in delivering our services.
We enter into data processing agreements with parties that process personal data on our instructions. Among other things, those agreements require them to take appropriate security measures and to process the personal data only on our instructions.
Data we receive through the Google Calendar integration is not sold or shared with third parties for advertising or other independent purposes. See section 15 for the full explanation.
9. Where do we store your data?
We process your data within the European Economic Area (EEA) as a matter of principle. In some cases we work with suppliers or service providers outside the EEA. The rules in those countries do not always offer the same protection as in the Netherlands. We have therefore made sure that your personal data is protected just as well there as it is here, for example by using model contracts approved by the European Commission (Standard Contractual Clauses) or other appropriate safeguards.
If you have questions about this, please get in touch.
10. How secure is your data with us?
We have gone to considerable lengths to secure your data as well as possible, both organisationally and technically. That includes access controls, logging, encryption where appropriate and the principle that only employees who need the data for their work are given access to it. We review our security measures regularly and adjust them where necessary.
When we share your data with others, they are equally obliged to handle it with the same care as we do. If you notice that this is not the case, please let us know. If you have questions about how we secure data specifically, please contact us.
11. What can you ask of us?
Because we use personal data about you, you have a number of rights under the GDPR. In some cases we may or must refuse a request in whole or in part, for example because we are legally required to retain certain data.
Right to information
We must explain, in clear and understandable terms, what we do with your data and what control you have over it. That is why this privacy statement sets out in detail what data we collect about you and how we handle it.
Right of access
You may always ask us to let you see the data we hold about you.
Right to rectification
You may ask us to correct your data if it is inaccurate or incomplete.
Right to object
You may object to the processing of your data, for example to processing based on our legitimate interest or for direct marketing. You can, for instance, tell us that you no longer wish to receive email from us.
Right to data portability
If you are a customer of ours or have given consent for the use of your data, you may ask us to provide the digital data we hold about you so that you can transfer it to another organisation.
Right to restriction
You may ask us to restrict the use of your data. In certain cases this means we may only store your data and not use it.
Right to be forgotten
You may ask us to delete all the data we hold about you. In some cases we cannot or may not yet delete your data: some records must be kept for 7 years for the Dutch tax authorities.
Right to lodge a complaint
You may lodge a complaint about the way we handle your data. Please contact us to do so. You may also take your complaint to the Dutch Data Protection Authority. As a last resort you may go to court, in which case the court in the district where Flixer is established will hear your complaint.
How do I submit a request or complaint?
Send your request or complaint to info@flixerpro.nl. We handle requests and complaints within 30 days. Where there are multiple or complex requests this may take longer, in which case we will contact you within 60 days at the latest. We may ask you to identify yourself.
For processing where we act as processor on behalf of a customer (see section 6 under e), we refer you in the first instance to that customer to exercise your rights. Where necessary, we assist the customer in handling your request.
12. What rules apply to this privacy statement?
Our privacy statement has to meet a number of requirements, set out mainly in the General Data Protection Regulation (GDPR). The general rules of Dutch law also apply. Our services are aimed primarily at business customers in the Netherlands and other countries within the EEA.
13. Which cookies do we use?
A cookie is a small text file placed on your device when you visit our website. We use the following types of cookie and similar techniques:
- Functional cookies, such as session and login cookies used to keep track of session and login information. These are needed to make our website and the Platform work properly and may be placed without consent.
- Cookieless statistics. We measure the use of our website, such as visitor numbers and popular pages, with Vercel Web Analytics. This places no cookies and stores no personal data.
- Google analytics and advertising cookies. Only if you give consent through our cookie banner, we place cookies from Google Analytics and Google Ads. These let us measure how visitors find and use our website, measure whether our advertising leads to sign-ups, and show advertising to previous visitors. They include the cookies
_gaand_ga_*(Google Analytics, up to 2 years) and_gcl_*(Google Ads, up to 3 months). Google also processes this data in the United States; Google LLC is certified under the EU-US Data Privacy Framework.
If you do not give consent, we do not place the Google cookies. We keep your choice in your browser for up to 12 months. You can change or withdraw your choice at any time through the "Cookie preferences" link at the bottom of every page; if you withdraw your consent, we delete the Google cookies. You can also set how cookies are handled, and delete cookies, in your browser.
14. What do we do with data about minors?
Neither our website nor our organisation is aimed specifically at minors. If you are under 18, you need permission from a parent or guardian to use our website. If you are a minor when you visit, we assume you obtained that permission beforehand.
15. Google Calendar integration and Google user data
Flixer Pro offers an optional Google Calendar integration that lets you synchronise your Flixer appointments with your personal or work Google Calendar. This section explains specifically how we handle data we receive through Google APIs ("Google user data"). It applies in addition to the other sections of this privacy statement and, where stricter, takes precedence over them.
Flixer's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
a) What data we use (Data Accessed)
When you activate the Google Calendar integration, Flixer Pro requests access to the following OAuth scopes:
https://www.googleapis.com/auth/calendar.events, to create, read, update and delete events in your Google Calendar.https://www.googleapis.com/auth/calendar.readonly, to read your calendars and existing events in order to determine conflicts and availability.
In concrete terms this means we may access the following data: event titles, descriptions, start and end times, event location and address details, attendees (name and email address), reminders, recurrence rules, calendar metadata (such as calendar IDs, time zones and calendar names) and the Google account profile needed to establish the connection (name, email address, Google account ID).
b) What we use this data for (Data Usage)
We use Google user data solely to provide two-way synchronisation between Flixer Pro and Google Calendar. That means:
- Appointments you create, update or delete in Flixer Pro are synchronised to the Google Calendar you selected.
- Events you create, update or delete in Google Calendar are synchronised to Flixer Pro, so that planning, availability and conflict detection stay current.
- Existing events in Google Calendar are read in order to prevent double bookings and to show availability to planners and engineers.
We expressly do not use Google user data for advertising, profiling, training generalised AI or machine learning models, selling data, building marketing audiences, or any other purpose that is not directly necessary to deliver the calendar functionality you activated. Humans access Google user data only where legally required, where necessary for a security investigation or to prevent abuse, or where you explicitly ask us to (for example in a support request).
c) Who we share this data with (Data Sharing)
Flixer does not sell Google user data and does not share it with third parties for advertising, marketing or other independent purposes. Google user data is shared only with:
- Our cloud and infrastructure providers that make our Platform technically possible (currently Google Cloud Platform in region europe-west4 and comparable sub-processors), solely as necessary technical sub-processors under a data processing agreement.
- Google itself, to the extent inherent in how the Google Calendar API works.
- Competent authorities, where we are legally required to do so.
Within your own Flixer organisation, synchronised appointments are visible only to users with the relevant permissions (such as planners or engineers scheduled on the appointment), in line with the role permissions in the Platform.
d) How we store and protect this data (Data Storage & Protection)
We apply the following specific security measures to Google user data:
- OAuth access and refresh tokens are stored server-side, encrypted with AES-256-GCM. The encryption key is held as a secured server configuration secret, separate from the application code and the database, and is accessible only to the Flixer Pro production runtime.
- Synchronised calendar data and the connection records are stored in a PostgreSQL database with Row-Level Security (RLS), so that a user or organisation can only reach its own data.
- All traffic between Flixer Pro, our backend and the Google APIs runs exclusively over TLS (HTTPS).
- Access to production infrastructure is limited to a small number of authorised employees, requires multi-factor authentication, and is logged and monitored.
- Data is hosted primarily within the European Economic Area (EEA), on Google Cloud Platform region europe-west4 (the Netherlands).
- We apply the principle of data minimisation: we request only the OAuth scopes strictly necessary for the functionality offered, and store no more fields than the synchronisation requires.
e) How long we keep this data and how to request deletion (Data Retention & Deletion)
The following retention periods apply to Google user data:
- OAuth access and refresh tokens are kept for as long as the integration is active. As soon as you disconnect the integration (see below), the tokens are revoked with Google immediately and permanently removed from our systems within 30 days at the latest, including from back-ups in line with our regular back-up rotation.
- Links between Flixer appointments and Google Calendar event IDs (mapping data) are deleted within 30 days of the integration being disconnected.
- The appointment content itself (title, time, attendees) that reached Flixer through the synchronisation remains part of your Flixer records for as long as your Flixer account is active, because it is necessary for operational planning. You can delete this data using the normal delete functionality in the Platform or by submitting a deletion request (see below).
- Log files referencing Google API calls are kept for a maximum of 90 days for security and debugging purposes, after which they are deleted or anonymised automatically.
You can disconnect the Google Calendar integration, or have your data deleted, in two ways:
- In-app: in Flixer Pro, go to the Planning page, click the Google Calendar button at the top of the header and then "Disconnect" (or "Verbinding verbreken"). Flixer Pro then calls the Google OAuth revoke endpoint to revoke the access and refresh tokens with Google immediately, stops the active Google push notification channel registration, and starts the deletion procedure described above.
- By email: send a request to disconnect and/or fully delete Google user data to info@flixerpro.nl, with the subject "Deletion of Google Calendar data". We confirm receipt within 5 working days and complete the deletion within 30 days.
You can also revoke Flixer Pro's access to your Google account yourself at any time through your Google account settings at https://myaccount.google.com/permissions. If you do, we immediately lose the ability to synchronise your calendar. We delete our local copy of the associated tokens and mapping data within 30 days.
f) Questions about the Google integration
For questions specifically about the Google Calendar integration or about Google user data, please contact us at info@flixerpro.nl. We normally respond within 5 working days.
16. Do you have a question about this privacy statement?
Do you have a question about our privacy statement, or about the way we handle personal data? Please get in touch at info@flixerpro.nl. We are happy to help.