Privacy Policy
Last updated July 6, 2026
This policy explains, in plain language and in line with the EU General Data Protection Regulation (GDPR) and the Dutch implementing law (UAVG), how A Plus Apps handles personal data when you visit this website or contact us.
1. Who is responsible (Data Controller)
The controller responsible for personal data processed in connection with this website is:
A Plus AppsNetherlands
KVK: 42117052
Email: [email protected]
We are established in the European Union, so an Article 27 representative is not required. We have not appointed a Data Protection Officer, as the scale and nature of our processing does not require one under Article 37 GDPR. Our full company details are on the Legal Notice page.
2. What we do not do
- We do not sell or share your personal data for advertising or profiling.
- We do not run analytics or tracking cookies without your consent.
- We do not require an account to browse this website.
3. Personal data we process
| Context | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Contact form | Name, email, project type, message contents | To respond to your enquiry and discuss a potential project | Legitimate interests, Art. 6(1)(f) - responding to enquiries; or pre-contractual steps, Art. 6(1)(b) | Until resolved, then deleted within 24 months |
| Direct email | Your email address and message contents | To communicate about projects, support, or partnerships | Legitimate interests, Art. 6(1)(f) | Until resolved, then deleted within 24 months unless a business relationship continues |
| Website hosting | Standard server logs (IP address, browser/user-agent, timestamp, page requested) | To securely deliver the site and prevent abuse | Legitimate interests, Art. 6(1)(f) - security and delivery | Short-lived; rotated by Cloudflare and our host |
| Cookie consent | Your consent choice stored in localStorage | To record and honour your cookie preferences | Legitimate interests, Art. 6(1)(f) - compliance with ePrivacy rules | Until you clear browser storage |
4. Third-party processors
We use the following service providers who may process personal data on our behalf:
- Cloudflare - CDN, DDoS protection, tunnel, and email routing/sending for contact form delivery (may process IP addresses, request metadata, and message content). Privacy policy: cloudflare.com/privacypolicy
- Hostinger / VPS hosting - static file hosting, server logs, and the server-side contact form relay
We have assessed these providers and require appropriate safeguards for data processing. Data processing agreements are in place where required.
5. International transfers
Our website is hosted within the EU/EEA. Cloudflare may process data globally; they participate in the EU-US Data Privacy Framework and offer Standard Contractual Clauses where applicable.
6. Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten") where applicable
- Restrict or object to processing
- Data portability where processing is based on consent or contract
- Withdraw consent at any time (without affecting prior lawful processing)
To exercise any of these rights, email [email protected]. We will respond within 30 days.
7. Complaints
You have the right to lodge a complaint with the Dutch supervisory authority:
Autoriteit Persoonsgegevens (AP)autoriteitpersoonsgegevens.nl
8. Security
We use HTTPS everywhere, minimal data collection, and access controls on our infrastructure. No system is perfectly secure, but we take reasonable measures to protect your data.
9. Children
This website is not directed at children, and we do not knowingly collect personal data from children under 16 (the digital-consent age in the Netherlands). If you believe a child has provided us personal data, contact us and we will delete it.
10. Regional disclosures (US, India & elsewhere)
United States: if you are a resident of California (CCPA/CPRA) or another US state with a comprehensive privacy law, you have the right to know what personal information we collect, to access, correct, and delete it, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined under US state laws, and we will not discriminate against you for exercising these rights.
India: we handle personal data of individuals in India in line with the Digital Personal Data Protection Act, 2023 (DPDP Act). You have the right to access, correct, and erase your personal data and to grievance redressal. To raise a grievance, email us with "DPDP grievance" in the subject; if you are not satisfied with our response, you may escalate to the Data Protection Board of India.
Everywhere else: we apply the GDPR-level protections described in this policy to all visitors, wherever you are. To exercise any right, email [email protected].
11. Cookies
See our dedicated Cookie Policy for details on cookies and similar technologies used on this site.
12. Changes
We may update this policy when our practices change. The "Last updated" date at the top reflects the most recent revision.