Bugalou is fully compliant with the General Data Protection Regulation (GDPR). We take privacy and data protection seriously.
Our databases are hosted within the EU for maximum compliance
256-bit SSL/TLS encryption for all data transmission
Full support for all GDPR user rights
Clear privacy and cookie policies available
As data controller, we only collect and process data necessary for our service delivery.
You have full control over your personal data. We facilitate all your GDPR rights.
Download all your data in machine-readable format (JSON/CSV)
Within 30 daysModify or correct your personal data via your account
Immediately availableDelete your account and all associated data permanently
Within 48 hoursWe implement state-of-the-art security measures to protect your data.
256-bit SSL/TLS for transport, AES-256 for storage
Role-based access, 2FA authentication, API key rotation
Isolated databases, daily backups, disaster recovery
24/7 security monitoring, intrusion detection, audit logs
Annual security audits, penetration testing, compliance reviews
72-hour breach notification protocol per GDPR Art. 33
We only work with GDPR-compliant processors. All processors have signed a Data Processing Agreement (DPA).
| Service Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Neon (PostgreSQL) | Database Hosting | EU (Germany) | EU-based |
| Stripe | Payment Processing | US / EU | SCCs + PCI DSS |
| Vercel | Application Hosting | Global (Edge) | SCCs + DPA |
| Meta (WhatsApp) | WhatsApp Business API | Global | SCCs + DPA |
| OpenAI | AI Chatbot Processing | US | SCCs + DPA |
For questions about data protection or to exercise your GDPR rights, please contact our Data Protection Officer.
Within 30 days per GDPR Art. 12
File a complaint? You have the right to file a complaint with the Dutch Data Protection Authority (AP) via autoriteitpersoonsgegevens.nl