Legal

Privacy policy

We collect as little as we can, keep it in the EU, and never sell it. This page explains the details in plain language.

Last updated: 11 October 2026

Who we are

Penni (Tav IT, a sole proprietorship, Noordervesting 4, 1135 CL Edam, the Netherlands, registered with the Chamber of Commerce under 74592173) is the controller for the personal data described here. Questions or requests: [email protected].

This website

The pages of pennipay.eu set no cookies and load no third-party scripts, fonts or trackers; only the dashboard sets a session cookie once you log in (see below). Our web server keeps standard access logs (IP address, time, page, browser) for up to 14 days to keep the site secure and working. confirm log retention

The dashboard and facilitator

DataWhyLegal basis
Name and email address; passkey public keys; authenticator secret if you turn on 2FA (encrypted)Your account, sign-in, security emails and team invitationsContract
Signed-in devices: browser, IP address, sign-in and last-seen timeShowing your sessions and warning you about new devicesContract; legitimate interest
Billing details: company name, address, VAT number, billing emailInvoices and VAT (including checking VAT numbers with the EU VIES service)Contract; legal obligation
Refund bank account (IBAN and account holder), if you add one (encrypted)Paying out unused credits when you close your accountContract
Messages you send through the contact formAnswering your questions, token and network requests, kept 2 yearsContract; legitimate interest
Webhook delivery logs, including payer wallet addressesDelivering payment notifications to your own systems, kept 30 daysContract
Session cookieKeeping you logged in. Strictly necessary, so no consent bannerContract
Sites, wallet addresses, prices, API keys (as hashes)Running the service you configuredContract
Settlements: payer wallet address, amount, token, transaction hash, timeSettling payments, your statistics, our feeContract
Credit top-ups and invoicesBilling and bookkeepingContract; legal obligation
IP addresses of login attemptsRate limiting and abuse prevention, kept in memory onlyLegitimate interest

Wallet addresses and transactions are public on the blockchain by nature. We cannot change or delete data that is on-chain.

Who we share it with

Only with processors that help us run Penni, under a data processing agreement:

  • Hosting: Hetzner Online GmbH (Germany), servers in the EU.
  • Email delivery: Vimexx (part of team.blue, the Netherlands), for sign-in links, invoices and account emails.
  • Stripe, for card and iDEAL top-ups. Stripe receives your payment details directly; we never see card numbers. Stripe may process data outside the EU under the EU-US Data Privacy Framework and standard contractual clauses.

When we settle a payment, the signed transfer is sent to the blockchain of that payment (Base, Solana or Cardano), where it becomes public.

How long we keep it

  • Account data: as long as your account exists, and deleted within 30 days after you close it.
  • Settlement and billing records: 7 years, because tax law requires it.
  • Sessions: until 14 days without use (at most 90 days), or until you sign out.
  • Sign-in links: 15 minutes; invitations: 7 days; recognised devices (for new-device warnings): 400 days after last use.
  • Refund bank account: until the payout of your unused credits is done.
  • Contact messages: 2 years, or until you delete your user.
  • Database backups: 14 days, after which deleted data is gone from them too.

Your rights

You can ask us for access to your data, to correct or delete it, to restrict or object to its use, and for a copy in a portable format. Email [email protected]; we answer within one month. You can also complain to your data protection authority; in the Netherlands that is the Autoriteit Persoonsgegevens.

Changes

If we change this policy in a way that matters, we'll email account holders before it takes effect.