Privacy policy

Softcrow Trusted Electronic Services B.V.

Version: 16 July 2026, replacing the previous version


1. Introduction

Softcrow Trusted Electronic Services B.V. (hereinafter: Softcrow) processes personal data in the context of its services. In this statement we explain which data we collect, why, how we store and secure it, and what rights you have.

This statement applies to all data that Softcrow processes in the context of its escrow services.

Softcrow Trusted Electronic Services B.V.
Monitorweg 11
1322 BJ Almere

KvK: 33251600
VAT: NL8023.94.620.B.02


2. Who is Softcrow?

Softcrow is an escrow service provider. We offer continuity arrangements that allow users of software to keep using that software, even if the supplier goes bankrupt or for another reason can no longer meet its obligations.

In the context of our services, we hold data for two reasons:

  • Contact details: data of our (prospective) customers, both users and suppliers of software
  • Deposit: data that a supplier deposits with us as part of a continuity arrangement

3. Which data do we process and why?

Contact details

This is data we receive from suppliers, beneficiaries or other parties involved in our services, such as name, e-mail address, telephone number and office address.

We use this data for:

  • Getting in touch: if you contact us via our website or otherwise, we record your details in order to answer your request
  • Business communication: to communicate about agreements, services, status and progress of our services
  • Sending documentation: if you request a model agreement via the website, we use your e-mail address to send it to you

Deposit

Suppliers can, as part of a continuity arrangement, place a data deposit with us. The contents of this deposit are determined by the supplier and usually contain data that users have entered into the supplier’s system.

A deposit may contain personal data within the meaning of the GDPR, but this is not necessarily the case. Softcrow cannot verify this itself.

Important: Softcrow has no access to the contents of a deposit. The supplier encrypts the deposit itself, before delivery. The encryption key is not shared with Softcrow, but solely with the beneficiary. Softcrow stores only encrypted files and has no access whatsoever to the contents. This is the core of our zero-knowledge architecture.

We store a deposit solely so that we can deliver it encrypted and unchanged to the beneficiaries named in the continuity arrangement. This only happens when the arrangement calls for it.


4. Storage and security

Contact details

Contact details are recorded in our contacts administration. Where necessary for carrying out our work, data is also included in physical documents such as agreements. All company documents are stored online; printed documents in our secured archive room.

Retention periods. We do not keep contact details longer than necessary. Data belonging to an agreement is kept for the duration of that agreement and for ten years afterwards, partly because of statutory retention obligations. Data from a contact request that does not lead to an agreement is deleted no later than one year after the last contact.

Deposit

For the storage of deposits we use the following approach:

  • Secure storage: deposits are stored in a secure storage environment in an ISO 27001 certified data centre within the EU
  • Daily back-up: a daily back-up is made in two independent ISO 27001 certified data centres within the EU
  • Encrypted by the supplier: the deposit is encrypted by the supplier before delivery. The encryption key is not shared with Softcrow. As a result, Softcrow has no access to the contents of the deposit, zero-knowledge
  • Append-only storage: delivered data cannot be changed, deleted or downloaded after storage. Delivering new versions is always possible. Download access is made available only on request
  • Integrity check: a SHA256 checksum is calculated for each deposit and verified weekly

5. Your rights

The rights below relate solely to contact details. With regard to data that may form part of a deposit, Softcrow cannot exercise these rights, because Softcrow itself has no access to that data. If a deposit may contain personal data about you, the supplier of the service in question is the controller for that data; please direct your request to that party.

RightWhat it means
AccessYou can request which data Softcrow has recorded about you
RectificationYou can have incorrect or outdated data corrected
PortabilityYou can request your data or have it transferred to another party
ErasureYou can request that your data be deleted
ObjectionYou can object to the use of your data
RestrictionYou can ask us to temporarily restrict the processing of your data, for example while an objection or correction request is being handled

To exercise one of these rights, we first verify that the request actually comes from you, for example by responding via the contact details we already have on record. Only if your identity cannot be established in another way do we ask for additional proof; a copy of an identity document is a last resort, in which case you should mask your photo and citizen service number (BSN).

If you are not satisfied with how we handle your personal data, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

When a beneficiary ends its participation in a continuity arrangement, or when the arrangement as a whole is ended, the associated deposits are destroyed via a secure wipe procedure.


6. Our obligations

Softcrow processes data on the following legal bases. Contact details needed to conclude or perform an agreement are processed on the basis of Article 6(1)(b) GDPR (performance of a contract, including pre-contractual contact). Where a statutory retention obligation applies, that obligation is the basis (Article 6(1)(c) GDPR). For answering other contact requests and for the website statistics and conversion measurement described in section 7, we rely on our legitimate interest (Article 6(1)(f) GDPR). We only request the data that is minimally necessary for carrying out our services.

Data is only shared with other parties involved in the same agreement, insofar as this is necessary for carrying out the services. If it is necessary to share data with parties outside the agreement in question, we always ask for consent in advance. The exception is the limited sharing of visit and conversion data as described in section 7.

Softcrow reserves the right to disclose data when this is legally required or when it is necessary to comply with a legal request. In doing so, we respect your right to privacy as much as possible.


7. Website statistics

Our website measures visitor statistics with Matomo, an open-source analytics tool that we host ourselves on our own infrastructure. All data stays with Softcrow; only for the Google Ads conversion measurement described below do we share one limited data point with Google.

Privacy-friendly and cookie-free. We have configured Matomo so that it:

  • places no cookies, which is why no consent banner is needed;
  • anonymises your IP address before it is stored;
  • respects your browser’s “Do Not Track” setting.

Which data. Matomo processes anonymised data about your visit, such as the pages you view, the duration of your visit, your approximate region (based on an anonymised IP address) and general information about your device and browser. We do not collect directly identifying data.

Purpose and basis. We use this data for website statistics, to improve the site and for the Google Ads conversion measurement described below. Because the processing is privacy-friendly and cookie-free, we rely on our legitimate interest (Article 6(1)(f) GDPR); your consent is not required for this.

Retention. Visit data is retained for a maximum of 14 months and is then automatically deleted.

Opting out. If you do not wish to be counted, enable the “Do Not Track” setting in your browser; we respect it.

Google Ads conversion measurement. If you arrive on our website via a Google Ads advertisement and then submit a contact request, we share the click ID of that advertisement (gclid) and the time of the request with Google Ads for campaign measurement. This happens without cookies and without your name, e-mail address or other directly identifying data; it only allows Google to establish that a specific ad click led to a contact request. Google may also process this data outside the EU, in the United States; Google is certified under the EU-US Data Privacy Framework for this purpose.

Marketing agency. For the management of our advertising campaigns, a marketing agency engaged by us can consult the visitor statistics from Matomo, solely for that purpose.

Map on the contact page. On the contact page we show a map from OpenStreetMap. When the map is loaded, your browser retrieves map tiles from the OpenStreetMap Foundation, which thereby receives your IP address.


8. Contact

For questions or comments regarding this privacy policy, you can reach us via:

E-mail: privacy@softcrow.com
Telephone: +31 (0)20 696 20 50

You can also write to us by post, using the address at the top of this policy.


9. Changes

This privacy policy may be amended as a result of changes in our work, new insights or changes in legislation. The current version, recognisable by the version date at the top, is always available on our website.