DutchSpark CMS Privacy Statement
This statement describes how DutchSpark processes personal data within DutchSpark CMS, support, website connections, demos, subscriptions and related services.
Last updated: 2 July 2026
1. Data controller
DutchSpark is responsible for processing personal data within its own website, CMS accounts, support, commercial communication and administration. When managing customer websites, DutchSpark may also act as a processor on behalf of the customer. In that case, the customer and any reseller remain responsible for the content and personal data on the connected website.
2. Contact
For privacy questions, support and requests concerning personal data: the support form.
3. Which data is processed
- Account data, such as name, email address, role, organisation and login status.
- Technical data, such as IP address, browser, device, security logs and error messages.
- Website data, such as domain, preview URL, root path, pages, images, editable fields and publishing logs.
- SFTP or FTPS credentials when provided by a customer. Passwords are stored encrypted wherever possible.
- Support data, such as messages, screenshots, error descriptions and technical context.
- Billing and plan data, such as plan type, status, limits, upgrade or downgrade requests and payment status.
- AI input and AI output when AI functions are used for text, metadata or optimisation advice.
4. Purposes
Personal data is processed for account management, access control, website management, publishing, backups, rollback, support, security, optimisation advice, AI proposals, billing preparation, statutory administration and service improvement.
5. Legal bases
Processing is based on performance of a contract, legitimate interest, legal obligation or consent. Prior consent is requested for non-essential cookies and similar technologies.
6. AI processing
AI functions may analyse content or metadata to create proposals. Sensitive personal data, confidential information or special-category personal data should not be placed unnecessarily in AI prompts. AI output is shown as a proposal and must always be reviewed before use.
7. Retention periods
Data is not retained longer than necessary for the stated purposes. Account and plan data is retained while the service is active and afterwards for as long as necessary for administration, evidence, security or legal obligations. Backups and logs are retained according to the configured retention period or technical necessity.
8. Sharing with third parties
Data may be shared with hosting providers, email services, payment providers, security services, AI providers, support suppliers or other processors when required to deliver the service. Appropriate agreements are made with processors where required.
9. Security
DutchSpark uses appropriate measures such as access control, encryption where possible, backups, logging and security checks. The customer remains responsible for strong passwords, correct permissions and secure handling of accounts.
10. Rights
Data subjects may request access, correction, deletion, restriction, portability or object to processing. Requests can be sent to the support form. DutchSpark may request verification before handling a request.
11. Cookies
The cookie statement describes which cookies and similar technologies are used, which are necessary and which categories require consent.
12. Complaints
For complaints, contact can be made via the support form. You also have the right to file a complaint with the Dutch Data Protection Authority.