[Privacy Policy]

> What we collect, why, and what you can do about it

privacy.txt

> Controller

Amsterdam Technologies B.V. is the controller for the processing described here.

Company:Amsterdam Technologies B.V.
Address:Overtoom 456-11054JW Amsterdam, Netherlands
VAT-ID: NL868682378B01KVK: 98875728

This policy covers amsterdam-technologies.com and the product websites we operate, including netcap.io, fastserve.nl, fasttap.nl, time-master.app and artist-connect.pro. Our products' hosted applications process data on behalf of the customers who use them; where we act as a processor rather than a controller, the agreement with that customer governs, not this policy.

────────────────────────────────────────

> Server Log Files

Our web servers record the following for each request, which your browser transmits automatically:

  • IP address
  • Browser type and version
  • Operating system
  • Referrer URL
  • Time of the request
  • Requested URL and response status

An IP address is personal data, and combined with the other fields above a request can in principle be linked to an individual. We process these logs on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in operating the service securely and diagnosing faults. They are not used for advertising or profiling, and are not combined with other data sources for that purpose.

Retention: server and reverse-proxy logs are kept for 30 days, then deleted.

────────────────────────────────────────

> Newsletter and Product Updates

If you subscribe to product updates, we process your email address, and any name you choose to give, to send you those updates.

Legal basis

Your consent (Art. 6(1)(a) GDPR). You give it by ticking a checkbox that is never pre-ticked, covering marketing email only. It is not bundled with any terms, nor with access to downloads.

Double opt-in

After you submit the form we send one email asking you to confirm. Your address stays unconfirmed and receives nothing else until you click that link. If you never confirm, no subscription is created.

What we store

Your email address, any name given, the product the signup came from, which form was used, the page you signed up on, and the time and wording version of your consent. We keep the consent record as evidence that consent was given, as Art. 7(1) requires.

Withdrawing consent

Every marketing email contains a working unsubscribe link. Unsubscribing takes effect immediately and costs nothing. You can also email support@amsterdam-technologies.com.

Subscriber data is held in our own mail system on our servers in Germany. It is not sold, rented or shared with advertisers.

────────────────────────────────────────

> Whitepaper Downloads

Whitepapers are downloadable without giving us any personal data. We do not require an email address to access them, and the optional newsletter signup next to them is genuinely optional.

────────────────────────────────────────

> Contact Forms

If you contact us through a form or by email, we process the details you send in order to answer you and handle any follow-up. The legal basis is our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR), or steps taken at your request prior to entering a contract (Art. 6(1)(b) GDPR) where that applies. We keep correspondence for as long as needed to deal with the matter and to meet our legal obligations.

────────────────────────────────────────

> Booking a Demo

If you book a demo through our booking page, we process your email address and — when you pick a time — any name you give and the product you say you are interested in.

We use this only to arrange the meeting. Your address is not added to any newsletter or marketing list — booking a demo does not sign you up for anything, and we will not send you marketing because you booked one.

How it works

You enter your email and we send you a one-time link to confirm the address is yours. If you never click it, no booking exists and nothing further happens. Once confirmed you choose a time, and we create a calendar entry with a video-meeting link and send you a confirmation. About an hour before the meeting we send you one reminder with the same joining link. There is no account and no separate database: the calendar entry and the emails are the only record.

Legal basis

Steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR), and our legitimate interest in responding to a demo request (Art. 6(1)(f) GDPR) where that does not apply.

Who receives it

The meeting is held in Google Workspace: Google receives your email address, any name you gave and the time of the meeting in order to send you the calendar invitation and host the video call (see Recipients and Processors). We also notify our own support inbox that a demo has been requested, so someone can prepare for it.

We keep the meeting and the related correspondence for as long as needed to deal with the matter and to meet our legal obligations. You can ask us to cancel a booking or delete the record at any time by emailing support@amsterdam-technologies.com.

────────────────────────────────────────

> Job Applications

If you apply to us — including speculatively, through the address given on our jobs page — we process what you send: your name and contact details, your CV, your work history and qualifications, any links or portfolio you include, and the content of our correspondence with you. We ask for nothing beyond that, and you should not send us special categories of data (Art. 9 GDPR) such as health, religion or ethnicity. There is no application form, no account, and no automated screening or profiling.

Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR), and our legitimate interest (Art. 6(1)(f) GDPR) in assessing whether there is a fit and in keeping a record of the process.

Retention: we delete an application no later than 4 weeks after we finish considering it, in line with Dutch Data Protection Authority guidance. If we would like to keep it on file for a future opening, we will ask you, and only keep it — for up to 1 year — if you agree. You can withdraw that agreement at any time and we will delete it.

Applications arrive by email and are stored in our self-hosted mail service (see Recipients and Processors). They are not added to any newsletter or marketing list, and are read only by the people involved in hiring.

────────────────────────────────────────

> Consultant Database

Separately from hiring, we keep a database of independent consultants and contractors we can approach for client work of the kind described on our consulting page. If you ask to be added — through the address on our jobs page — we keep what you send: your name and contact details, your CV, the skills and tools you work with, your rate and how you invoice, and your availability.

Legal basis: your consent (Art. 6(1)(a) GDPR). You ask to be added; we do not add anyone who has not asked. Applying for a job does not put you in the database, and being in the database is not an application.

Retention: we keep your entry for 1 year. Before that runs out we will ask whether you want to stay in; if you do not reply, we delete it. You can ask to be removed at any time — one email is enough — and withdrawing does not affect anything we did beforehand (Art. 7(3)).

We use the database for one thing: contacting you when a project matches what you do. It is not a newsletter and not a marketing list, and there is no automated scoring or profiling behind it. If an engagement means showing your profile to a client, we ask you first.

────────────────────────────────────────

> Analytics

We run our own self-hosted analytics at analytics.amsterdam-technologies.com to understand how our sites are used. It runs on our own infrastructure in the EU; no analytics data is sent to third-party advertising networks.

No cookie is set and your IP address is not stored. The IP address is used only to derive an approximate country and a short-lived visit identifier, and is then discarded. What we keep is the page visited, the referring URL, and coarse browser, device and country information. We do not record what you type, and session recording is not enabled.

We also record a small number of named actions so we can tell which pages lead anywhere: submitting the newsletter form, downloading a whitepaper, starting a trial download, and clicking through to the checkout. Each is stored as the name of the action plus the page it happened on and, where relevant, which product or plan the link pointed at. These records contain no email address, no name and no order or payment identifier.

Finally, your browser reports anonymous page-speed measurements — how quickly the page rendered and responded. These describe the page, not you.

Addresses of pages you visit are stored without their query string, apart from campaign labels (utm_*) and a marker recording that a visit came from an advertisement. Anything else in a link — including an email address or a one-time token that happened to be in it — is discarded before the measurement is recorded, and again daily on our side.

Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in understanding aggregate usage of our sites. You can object to this processing at any time under Art. 21 — write to us at the address above and we will stop measuring your visits. You can also block the script; nothing on our sites depends on it.

────────────────────────────────────────

> Purchases, Licences and Invoices

If you buy a product or licence, our payments platform processes the data needed to complete the order: your billing details, the items purchased, and payment status. You pay through either Stripe or PayPal, whichever you pick at checkout. Card and account details are entered with them directly; we do not receive or store full card numbers.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and, for invoices, our legal obligation (Art. 6(1)(c) GDPR).

Retention: Dutch tax law requires invoices and the underlying administration to be kept for 7 years. This is also why we cannot delete an invoice on request, even though you may ask us to erase other data.

────────────────────────────────────────

> Desktop Apps: Licences, Trials and Device Activation

Our desktop applications — Noted, ImageSieve, VidMaker, AudioVault, WiFiSpoof, WiFi Analyzer, Bluetooth Analyzer and Timemaster — check their licence with our licensing server. This happens when a trial or licence is first activated, and then periodically while the app is running.

What is sent

A device fingerprint, the platform, and the product. The fingerprint is a one-way SHA-256 hash of a hardware identifier; we never receive the underlying hardware ID, and the hash cannot be reversed into one. The platform is a device class such as “Mac” or “Windows PC”.

What is not sent

We do not send or store the name of your computer. Earlier versions of these apps sent the machine's hostname, which on a personal computer is often the owner's name. That was removed in August 2026, and the values already recorded were deleted from our systems at the same time.

When it happens

Most of these apps start a free trial automatically the first time you open them, which means the activation request above is sent on first launch.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR) — the licence is what entitles you to run the software, and it can only be checked against something. We also have a legitimate interest (Art. 6(1)(f) GDPR) in enforcing the number of devices a licence covers.

Retention: an activation record is deleted after 18 months without the device being seen.

The apps themselves work on your own machine. What you do inside them — the recordings and transcripts in Noted, the photos in ImageSieve, the captures in the network tools — stays on your computer and is not sent to us. Where an app can optionally use a third-party AI service, it says so at the point you enable it and you supply your own key for that service.

────────────────────────────────────────

> Cookies

Our marketing sites use no advertising or tracking cookies. Where a cookie is strictly necessary — for example to keep you signed in to an application — it is set only for that purpose. If we ever introduce cookies that require consent, we will ask for it before setting them and update this policy.

One exception is worth naming: the FastTap ordering page loads Stripe's payment library when you reach checkout, and Stripe sets its own cookies at that point to process the payment and detect fraud. These are set by Stripe, not by us, and only on the checkout step.

────────────────────────────────────────

> Recipients and Processors

We keep the number of parties who touch your data small. The current recipients are:

RecipientPurposeLocation
Hetzner Online GmbHServer hosting and backupsGermany (EU)
Cloudflare, Inc.Authoritative DNS, DDoS protection and content delivery for our sitesEU / US
Amsterdam Technologies mail service (self-hosted)Sending and storing email, newsletter listsGermany (EU)
Google Ireland Limited (Google Workspace)Calendar invitation and video-meeting link for a booked demoEU / US
StripeCard and wallet payments, subscriptions and licence billingEU
PayPalPayPal payments and subscriptionsEU

We do not sell personal data. Our own hosting and mail run on our own infrastructure inside the EU. Cloudflare, Google, Stripe and PayPal belong to groups headquartered in the United States: Cloudflare resolves DNS and routes traffic to our sites from its global network, and may see the IP address and requested hostname of a visit; Google contracts with us through its Irish entity under a data processing agreement, and processes demo bookings on its global infrastructure; Stripe and PayPal bill us through their European entities and may transfer payment data to the US. These transfers are made under the European Commission's standard contractual clauses and, for recipients certified under it, the EU–US Data Privacy Framework.

Additional processors used by individual applications

The table above covers this website and the processing we carry out for ourselves. Some of our hosted applications also send data to a third party in order to provide a feature, and those are listed separately here so it is clear which product involves which processor. If you do not use the product, the processor does not receive anything about you.

ApplicationProcessorWhat it receivesLocation
GuardianAnthropic, OpenAI, Google or OpenRouter — whichever the customer configuresSource code, dependency and finding data submitted for AI reviewUS
GuardianNVD, ZonecruncherPackage names and domains being checkedUS
LeadGenGoogle (Gemini)Prospect research and drafted message contentUS
LeadGenHunter.io, Foursquare, OpenCorporates, Companies House, GitHubSearch terms and prospect identifiers used to find and verify contactsUS / UK
LeadGenTwilioPhone number and message content, where SMS is usedUS
SocialBotGoogle (Gemini)Content being generated or analysedUS
SocialBotThe social platforms the customer connectsWhatever the customer instructs it to post or readVarious
PIMGoogle (Gemini)Product text and images submitted for enrichmentUS
FastServe, FastTapStripe, PayPalOrder amount and payment details at checkoutEU / US

Where a transfer outside the EU takes place it is made under the European Commission's standard contractual clauses, and for US recipients certified under it, the EU–US Data Privacy Framework.

Our desktop applications work on your own machine and do not send your content anywhere. Several of them can optionally use an AI service — you supply your own key for that service, the application tells you before the feature is enabled, and the arrangement is then between you and that provider.

────────────────────────────────────────

> Your Rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15)
  • rectify inaccurate data (Art. 16)
  • erase your data (Art. 17), subject to retention we are legally required to observe, such as the 7-year invoice rule above
  • restrict processing (Art. 18)
  • data portability (Art. 20)
  • object to processing based on legitimate interest (Art. 21), including our analytics and log processing
  • withdraw consent at any time where processing is based on consent (Art. 7(3)), without affecting processing carried out before withdrawal

To exercise any of these, email support@amsterdam-technologies.com. We respond within one month.

You also have the right to lodge a complaint with the Dutch supervisory authority:

Authority:Autoriteit Persoonsgegevens
Address:Postbus 93374, 2509 AJ Den Haag, Netherlands
────────────────────────────────────────

> Changes to This Policy

We update this policy when our processing changes. The date below shows when it was last revised. Where a change materially affects processing based on your consent, we will ask for consent again rather than rely on the old one.

Company details and other legal information are on our imprint page.