Privacy statement
This is a translation of the Dutch version. In the event of any differences, the Dutch version is binding: Privacyverklaring (Dutch).
Last updated: October 8, 2026
1. Introduction
Ledenboek attaches great importance to the protection of your personal data. In this privacy statement we explain which data we collect, why we do so, how we process this data and what rights you have. This statement applies to all services that we provide through Ledenboek to associations and their members.
2. Responsibility for data
Responsibility for the processing of personal data through Ledenboek is shared:
Controller
The association that uses Ledenboek is responsible for:
- deciding which data is collected
- the purposes of the data processing
- the lawfulness of the processing
If you have questions about how your association processes your data, please contact the board of your association.
Processor
Vuurpijl Beheer B.V.
Lagedijk 11A
2064 KV Spaarndam
Nederland
KVK: 34108141
Vuurpijl Beheer B.V. processes data solely on behalf of the association. The arrangements for this are set out in the data processing agreement, which forms part of the agreement with each association.
For questions about Ledenboek itself: info@ledenboek.nl
3. What data we collect
Personal data of members
- Name (first name, surname)
- Contact details (address, email address, telephone number)
- Date of birth
- Membership details (membership number, start date, status)
Account details
- Email address
- Encrypted password
- Two-factor authentication data (optional)
Payment details
- Payment status and history
- Billing details
- IBAN (for payouts, where applicable)
Please note: we do not store credit card numbers; they are processed directly by our payment provider Mollie.
Technical data
- IP address
- Browser type and version
- Device information
- Cookies (session and analytics)
4. Purposes of processing
We process your data for the following purposes:
Membership administration
Managing your membership and communicating about association activities.
Financial administration
Processing membership fees, payments and invoicing.
Communication
Sending invitations and newsletters, and answering questions.
Improving our services
Analysis of usage (anonymised) and technical optimisation.
Legal obligations
Tax records and legal proceedings where necessary.
5. Legal bases
We process your data on the basis of the following legal grounds under the General Data Protection Regulation (GDPR):
Performance of a contract (Art. 6(1)(b) GDPR)
Your membership of the association is a contract for which processing of data is necessary.
Legal obligation (Art. 6(1)(c) GDPR)
The statutory obligation to keep tax records and other legal obligations.
Legitimate interest (Art. 6(1)(f) GDPR)
Improving our services and keeping the application secure.
Consent (Art. 6(1)(a) GDPR)
For analytics cookies and marketing communication (where applicable). You can withdraw this consent at any time.
6. Third parties
We use the following service providers to deliver our service. We have data processing agreements with each of them, and all of their processing takes place within the European Economic Area. The full list is also included in the data processing agreement.
Mollie B.V.
Purpose: Processing online payments
Data: Invoice number, amount, payment status
Google Analytics
Purpose: Website statistics and usage analysis
Data: Anonymised usage data, page views
Hetzner Online GmbH
Purpose: Hosting of the application and the database
Data: All data stored in Ledenboek
Location: Germany (EU)
Euromailing
Purpose: Sending email to members on behalf of the association
Data: Name, email address and the content of the message
Location: Netherlands (EU)
Stripe Payments Europe Ltd.
Purpose: Billing for the association's own subscription
Data: Contact and payment details of the association, no member data
Location: Ireland (EU)
PostHog
Purpose: Usage statistics and error reports for the application
Data: Technical data and which screens are used
Location: European Union
7. Retention periods
We do not keep your data for longer than is necessary for the purposes for which it was collected:
| Type of data | Retention period |
|---|---|
| Membership details | For the duration of the membership + 2 years after it ends |
| Financial data | 7 years (statutory retention obligation) |
| Account details | Until the account is deleted |
| Analytics data | 26 months (anonymised) |
| Log data | 12 months |
After your membership ends, your data is anonymised or deleted, unless a statutory retention obligation applies.
8. Cookies
We use cookies to make the website work properly and to gain insight into how our service is used.
Necessary cookies (always active)
These cookies are essential for the website to work.
- Session cookie: For signing in and security (lifetime: session)
- CSRF token: Protection against cross-site request forgery (lifetime: session)
Analytics cookies (with consent)
These cookies help us improve the website.
- Google Analytics: Website statistics (lifetime: 26 months)
You can disable analytics cookies in your browser settings or via Google Analytics Opt-out.
We do not use third-party marketing or tracking cookies.
9. Your rights
Under the GDPR you have the following rights in relation to your personal data:
Right of access (Art. 15)
You can ask which data we hold about you.
Right to rectification (Art. 16)
You can have incorrect data corrected.
Right to erasure (Art. 17)
You can ask us to delete your data.
Right to restriction (Art. 18)
You can have processing stopped temporarily.
Right to data portability (Art. 20)
You can receive your data in a standard format.
Right to object (Art. 21)
You can object to certain types of processing.
How can you exercise your rights?
To exercise these rights, you can contact the board of your association or info@ledenboek.nl. We will respond to your request within 30 days.
10. Security
We take appropriate technical and organisational measures to protect your data against loss, unauthorised access and misuse:
- Encrypted connections (HTTPS/TLS) for all data transfer
- Encrypted storage of passwords (bcrypt)
- Two-factor authentication available for extra security
- Regular security updates and patches
- Access to data restricted to authorised persons
- Hosting within the European Union
11. Complaints
Do you have a complaint about the processing of your personal data? Please contact your association first, or us at info@ledenboek.nl. We will handle your complaint with care.
Autoriteit Persoonsgegevens
You also have the right to lodge a complaint with the supervisory authority:
Autoriteit Persoonsgegevens
Postbus 93374
2509 AJ Den Haag
12. Contact details
For questions about this privacy statement or about the processing of your personal data:
13. Changes
This privacy statement may be amended. If we make significant changes, we will inform you through the application. The most recent version is always available on this page.