Privacy policy
We collect as little as we can, keep it in the EU, and never sell it. This page explains the details in plain language.
Who we are
Penni (Tav IT, a sole proprietorship, Noordervesting 4, 1135 CL Edam, the Netherlands, registered with the Chamber of Commerce under 74592173) is the controller for the personal data described here. Questions or requests: [email protected].
This website
The pages of pennipay.eu set no cookies and load no third-party scripts, fonts or trackers; only the dashboard sets a session cookie once you log in (see below). Our web server keeps standard access logs (IP address, time, page, browser) for up to 14 days to keep the site secure and working. confirm log retention
The dashboard and facilitator
| Data | Why | Legal basis |
|---|---|---|
| Name and email address; passkey public keys; authenticator secret if you turn on 2FA (encrypted) | Your account, sign-in, security emails and team invitations | Contract |
| Signed-in devices: browser, IP address, sign-in and last-seen time | Showing your sessions and warning you about new devices | Contract; legitimate interest |
| Billing details: company name, address, VAT number, billing email | Invoices and VAT (including checking VAT numbers with the EU VIES service) | Contract; legal obligation |
| Refund bank account (IBAN and account holder), if you add one (encrypted) | Paying out unused credits when you close your account | Contract |
| Messages you send through the contact form | Answering your questions, token and network requests, kept 2 years | Contract; legitimate interest |
| Webhook delivery logs, including payer wallet addresses | Delivering payment notifications to your own systems, kept 30 days | Contract |
| Session cookie | Keeping you logged in. Strictly necessary, so no consent banner | Contract |
| Sites, wallet addresses, prices, API keys (as hashes) | Running the service you configured | Contract |
| Settlements: payer wallet address, amount, token, transaction hash, time | Settling payments, your statistics, our fee | Contract |
| Credit top-ups and invoices | Billing and bookkeeping | Contract; legal obligation |
| IP addresses of login attempts | Rate limiting and abuse prevention, kept in memory only | Legitimate interest |
Wallet addresses and transactions are public on the blockchain by nature. We cannot change or delete data that is on-chain.
Who we share it with
Only with processors that help us run Penni, under a data processing agreement:
- Hosting: Hetzner Online GmbH (Germany), servers in the EU.
- Email delivery: Vimexx (part of team.blue, the Netherlands), for sign-in links, invoices and account emails.
- Stripe, for card and iDEAL top-ups. Stripe receives your payment details directly; we never see card numbers. Stripe may process data outside the EU under the EU-US Data Privacy Framework and standard contractual clauses.
When we settle a payment, the signed transfer is sent to the blockchain of that payment (Base, Solana or Cardano), where it becomes public.
How long we keep it
- Account data: as long as your account exists, and deleted within 30 days after you close it.
- Settlement and billing records: 7 years, because tax law requires it.
- Sessions: until 14 days without use (at most 90 days), or until you sign out.
- Sign-in links: 15 minutes; invitations: 7 days; recognised devices (for new-device warnings): 400 days after last use.
- Refund bank account: until the payout of your unused credits is done.
- Contact messages: 2 years, or until you delete your user.
- Database backups: 14 days, after which deleted data is gone from them too.
Your rights
You can ask us for access to your data, to correct or delete it, to restrict or object to its use, and for a copy in a portable format. Email [email protected]; we answer within one month. You can also complain to your data protection authority; in the Netherlands that is the Autoriteit Persoonsgegevens.
Changes
If we change this policy in a way that matters, we'll email account holders before it takes effect.