Privacy Policy

How RCMan handles personal data β€” in compliance with GDPR

1. Who we are

KlikBit, based in the Netherlands, is the data controller for account holders (club administrators). For member data that clubs process via RCMan, the club is the data controller and KlikBit is the data processor. See our Data Processing Agreement at /verwerkersovereenkomst.

2. What data we collect

We collect: account data (name, email address, organization name), payment data (via Stripe β€” we do not store payment details), usage data (login times, features used), and technical data (IP address, browser type) for security purposes.

3. Legal basis for processing

We process data based on: (a) performance of contract β€” to provide the service; (b) legitimate interest β€” for security and fraud prevention; (c) legal obligation β€” for tax record-keeping requirements; (d) consent β€” for marketing emails (optional and always revocable).

4. Use of data

Your data is used for: delivering and improving RCMan, billing and payment processing, sending service-related communications, security and fraud prevention, and legal compliance.

5. Sub-processors and third parties

We use: Stripe (payment processing, US β€” Privacy Shield), Vercel or equivalent hosting (EU servers), email provider for transactional emails. We have data processing agreements with all sub-processors. A current list is available via privacy@klikbit.nl.

6. International transfers

We store data preferably within the EU. Where data is processed outside the EU (e.g., Stripe in the US), this is done based on Standard Contractual Clauses (SCCs) approved by the European Commission or other appropriate safeguards.

7. Retention periods

Account data: until 30 days after cancellation. Invoice data: 7 years (legal obligation). Log files: 90 days. Member data entered by clubs: pursuant to the data processing agreement, at the club's instruction.

8. Security

We apply: encryption in transit (TLS) and at rest, role-based access control, regular security audits and monitoring. Discovered a vulnerability? Report it via security@klikbit.nl.

9. Cookies

We use: functional cookies (necessary for the service, no consent required) and analytics via Plausible Analytics (privacy-friendly, no personal tracking, no consent required). We do not use tracking or advertising cookies.

10. Rights of data subjects

You have the right to: access, rectification, erasure, restriction of processing, data portability, and objection. Submit requests via privacy@klikbit.nl. We respond within 30 days. We may request identity verification.

11. Complaints to the supervisory authority

If you believe we are not processing your data correctly, you can file a complaint with the Dutch Data Protection Authority (AP) at autoriteitpersoonsgegevens.nl. We encourage you to contact us first so we can resolve it together.

12. Minors

RCMan is not intended for direct use by persons under 16. Clubs entering data of minor members (e.g., junior members) are responsible for obtaining required parental or guardian consent.

13. Contact

For questions about this privacy policy or your rights: privacy@klikbit.nl. KlikBit, Netherlands.

Last updated: March 2025