Terug naar de app

Privacybeleid

Versie: 4.1  |  Ingangsdatum: Juni 2026
Bedrijf: Amani Deen (eenmanszaak)  |  KVK: 93369093  |  BTW: NL005018794B44
Adres: Bedrijvenpark Twente 147-F, 7602 KE Almelo, Nederland  |  E-mail: info@amanideen.com

1. Inleiding

Amani Deen hecht grote waarde aan de bescherming van uw persoonsgegevens. Dit Privacybeleid legt uit welke gegevens wij verzamelen, waarom, hoe wij deze verwerken en welke rechten u heeft. Dit beleid is opgesteld in overeenstemming met de Algemene Verordening Gegevensbescherming (AVG / GDPR) en bevat aanvullende bepalingen voor gebruikers buiten de EU, waaronder Californië (CCPA). Dit Privacybeleid is te allen tijde raadpleegbaar via de Web-App.

2. Verwerkingsverantwoordelijke

Amani Deen  |  Bedrijvenpark Twente 147-F, 7602 KE Almelo, Nederland

E-mail: info@amanideen.com  |  KVK: 93369093

3. Welke persoonsgegevens verzamelen wij?

3.1 Accountgegevens

  • E-mailadres (verplicht)
  • Gebruikersnaam (optioneel)
  • Wachtwoord (versleuteld via bcrypt-hashing; niet leesbaar voor Amani Deen)

3.2 Door de gebruiker ingevoerde content

  • Dagboekinvoeren (ochtend- en avondsessies)
  • Shukr Meter beoordelingen
  • Gebedstracker-gegevens
  • Checklist-voortgang en 30-dagentracker gegevens
  • Niyah, dhikr en persoonlijke reflecties

Bijzondere categorieën persoonsgegevens: een deel van bovenstaande gegevens kan informatie bevatten over uw geloofsovertuiging, welke valt onder de bijzondere categorieën als bedoeld in art. 9 AVG. Wij verwerken deze gegevens uitsluitend op basis van uw uitdrukkelijke toestemming, verleend bij het aanmaken van uw account. Verwerking van religieuze gegevens is noodzakelijk voor de levering van de door u gevraagde functionaliteiten van de Web-App; zonder deze verwerking kan de kernfunctionaliteit van de dienst niet worden geleverd.

Overige bijzondere categorieën: dagboekentries kunnen naar eigen keuze van de Gebruiker informatie bevatten over gezondheid, mentale toestand, etniciteit of andere bijzondere persoonsgegevens in de zin van art. 9 AVG. Dergelijke gegevens worden door Amani Deen uitsluitend verwerkt voor de levering van de dienst en worden nooit gebruikt voor profilering, targeting of enig ander doel.

3.3 Betalingsgegevens

Betalingen worden volledig verwerkt via Paddle als Merchant of Record. Amani Deen heeft geen toegang tot betaalkaartgegevens en slaat deze niet op. Wij ontvangen uitsluitend een betalingsstatus en een abonnements-ID. Paddle kan voor bepaalde betalings-, fiscale, fraudepreventie- en wettelijke nalevingsdoeleinden optreden als zelfstandig verwerkingsverantwoordelijke voor de persoonsgegevens die zij verwerkt. Op deze verwerkingen zijn de voorwaarden en het privacybeleid van Paddle van toepassing. Zie paddle.com/legal/privacy voor het privacybeleid van Paddle.

3.4 Technische gegevens

  • IP-adres (gepseudonimiseerd: laatste octet afgekapt — uitsluitend voor beveiligings- en foutopsporingsdoeleinden)
  • Browsertype en apparaattype
  • Tijdstip van gebruik (voor beveiliging en foutopsporing)
  • Bewaard voor maximaal 90 dagen, daarna permanent verwijderd

3.5 Juridische toestemmingsregistratie

Ten behoeve van het vastleggen van toestemming en contractsluiting worden bij registratie de volgende gegevens afzonderlijk geregistreerd en bewaard:

  • Volledig IP-adres (niet gepseudonimiseerd)
  • Datum en tijdstip van acceptatie (UTC)
  • Taalomgeving (NL of EN)
  • Versienummer van de geaccepteerde Algemene Voorwaarden
  • Versienummer van het geaccepteerde Privacybeleid
  • Status van alle toestemmingscheckboxes

Deze registratie vindt plaats op grond van gerechtvaardigd belang (art. 6 lid 1 sub f AVG) en wordt bewaard zolang het account actief is, met een minimum van 5 jaar na de datum van toestemming of contractsluiting, conform de wettelijke verjaringstermijn voor contractuele vorderingen (art. 3:307 BW). Intrekking van toestemming doet geen afbreuk aan deze bewaartermijn, aangezien de registratie uitsluitend dient als juridisch bewijs. Deze gegevens zijn strikt gescheiden van de technische beveiligingslogs in sectie 3.4.

4. Doeleinden en grondslagen

DoelGrondslag (AVG)
Accountbeheer en inloggenUitvoering overeenkomst (Art. 6 lid 1 sub b)
Verlenen van de dienst (opslaan dagboekdata)Uitvoering overeenkomst (Art. 6 lid 1 sub b)
Verwerking geloofsgebonden gegevens (art. 9 AVG)Uitdrukkelijke toestemming (Art. 9 lid 2 sub a)
Verwerking overige bijzondere categoriegegevensUitdrukkelijke toestemming (Art. 9 lid 2 sub a)
Betalingsverwerking via PaddleUitvoering overeenkomst (Art. 6 lid 1 sub b)
Juridische toestemmingsregistratieGerechtvaardigd belang (Art. 6 lid 1 sub f)
Verzenden van marketing e-mails met tips en aanbiedingenToestemming (Art. 6 lid 1 sub a) — alleen na expliciete opt-in; intrekbaar via Instellingen → Notificaties → Marketing e-mails
Niet-transactionele berichten (nieuwsbrief, updates)Toestemming (Art. 6 lid 1 sub a) — alleen na expliciete opt-in
Wettelijke verplichtingenWettelijke verplichting (Art. 6 lid 1 sub c)
Geanonimiseerde statistieken voor dienstverbeteringGerechtvaardigd belang (Art. 6 lid 1 sub f)

5. Bewaartermijnen

GegevenstypeBewaartermijn
AccountgegevensActieve periode + 12 maanden na verwijdering
Dagboek- en trackergegevensActieve periode; bij accountverwijdering binnen 30 dagen permanent gewist
BetalingsgegevensConform wettelijke bewaartermijnen via Paddle (doorgaans 7 jaar)
Technische loggegevensMaximaal 90 dagen
Marketing toestemming en e-mailgegevensZolang het account actief is of totdat de toestemming wordt ingetrokken, waarna de gegevens binnen 30 dagen worden verwijderd uit de marketinglijsten
Juridische toestemmingsregistratieZolang het account actief is, met een minimum van 5 jaar na de datum van toestemming of contractsluiting (art. 3:307 BW)

6. Beveiliging

  • Supabase Row Level Security (RLS): gebruikers hebben uitsluitend toegang tot eigen data
  • HTTPS/TLS-encryptie: alle communicatie versleuteld
  • Bcrypt-hashing: wachtwoorden onleesbaar opgeslagen
  • Toegangsbeperking: need-to-know principe voor medewerkers Amani Deen
  • Risicoanalyse (DPIA): Amani Deen heeft een Data Protection Impact Assessment uitgevoerd en gedocumenteerd voor de verwerking van bijzondere categoriepersoonsgegevens

7. Datalekken

Bij een datalek met waarschijnlijk hoog risico voor uw rechten en vrijheden zal Amani Deen:

  1. De Autoriteit Persoonsgegevens binnen 72 uur informeren (art. 33 AVG)
  2. U rechtstreeks informeren over aard, gevolgen en genomen maatregelen (art. 34 AVG)
  3. Een intern register bijhouden van alle incidenten

Verdachte incidenten kunt u melden via info@amanideen.com.

8. Verwerkers en internationale doorgifte

Amani Deen verkoopt uw persoonsgegevens nooit aan derden.

PartnerDienstLocatieGrondslag
Supabase Inc.Database en authenticatieEU (Frankfurt)Verwerkersovereenkomst + SCCs
Paddle.com Market Limited (EU/VK) / Paddle.com Inc. (VS)Betalingsverwerking (Merchant of Record)VK / VSVerwerkersovereenkomst + SCCs (EU Module 2, Iers recht)
Netlify Inc.Hosting Web-AppVSVerwerkersovereenkomst + SCCs
Resend Inc.Transactionele e-mail en marketing e-mailVSVerwerkersovereenkomst + SCCs

Voor doorgifte naar landen buiten de EER zijn Standard Contractual Clauses (SCCs) van toepassing conform art. 46 AVG. Het Verenigd Koninkrijk beschikt over een adequaatheidsbesluit van de Europese Commissie. Paddle kan voor bepaalde verwerkingen optreden als zelfstandig verwerkingsverantwoordelijke. Verwerkersovereenkomsten werken door naar sub-verwerkers van bovengenoemde partijen.

9. Cookies

De Web-App gebruikt uitsluitend functionele cookies voor sessiebeheer. Geen tracking- of advertentiecookies. Paddle Checkout kan functionele en fraudepreventiecookies plaatsen (zie paddle.com/legal/privacy). Mocht gebruik worden gemaakt van niet-noodzakelijke cookies, dan wordt dit beleid vooraf bijgewerkt.

10. Uw rechten (AVG)

De meeste rechten kunt u direct uitoefenen via de accountinstellingen in de Web-App. E-mail naar info@amanideen.com (onderwerp: "AVG-verzoek") blijft beschikbaar als alternatief. Wij reageren binnen 30 dagen.

RechtGrondslagHoe uitoefenen
InzageArt. 15 AVGVia info@amanideen.com
RectificatieArt. 16 AVGVia info@amanideen.com
VerwijderingArt. 17 AVGInstellingen → Account verwijderen (automatisch, direct)
Beperking van verwerkingArt. 18 AVGVia info@amanideen.com
Gegevensoverdraagbaarheid (JSON)Art. 20 AVGInstellingen → Gegevens exporteren (automatisch, direct als JSON)
BezwaarArt. 21 AVGVia info@amanideen.com
Intrekking toestemmingArt. 7 lid 3 / Art. 9 AVGInstellingen → Toestemming intrekken
Abonnement annulerenArt. 5 AVInstellingen → Abonnement → Annuleren (automatisch, direct)

10.1 Accountverwijdering (art. 17 AVG): U kunt uw account en alle bijbehorende persoonsgegevens op elk moment verwijderen via Instellingen → Account verwijderen. Verwijdering wordt direct en automatisch uitgevoerd. Na verwijdering zijn alle door u ingevoerde gegevens binnen 30 dagen permanent gewist. De juridische toestemmingsregistratie wordt bewaard conform de termijnen in sectie 5.

10.2 Intrekking toestemming geloofsgebonden gegevens (art. 7/9 AVG): U kunt uw toestemming op elk moment intrekken via Instellingen → Toestemming intrekken. Intrekking is net zo eenvoudig als het verlenen van toestemming. Als u een actief Premium abonnement heeft, wordt u gewaarschuwd dat het abonnement automatisch wordt geannuleerd en dat er geen restitutie plaatsvindt. De intrekking wordt pas verwerkt na uw expliciete bevestiging.

10.3 Gegevensoverdraagbaarheid (art. 20 AVG): U kunt een volledige export van uw persoonsgegevens opvragen via Instellingen → Gegevens exporteren. De export wordt direct en automatisch gegenereerd als JSON-bestand.

11. Minderjarigen / COPPA

De Web-App is uitsluitend bestemd voor personen van 18 jaar of ouder. Amani Deen verzamelt niet bewust persoonsgegevens van personen jonger dan 13 jaar. Bij vaststelling hiervan wordt het account onmiddellijk verwijderd, conform de Children's Online Privacy Protection Act (COPPA, 15 U.S.C. § 6501 e.v.) voor zover van toepassing op gebruikers in de Verenigde Staten. Meldingen via info@amanideen.com — wij handelen dit binnen 5 werkdagen af.

12. California Privacy Rights — CCPA/CPRA

This section applies to residents of California pursuant to Cal. Civ. Code § 1798.100 et seq.

CategoryExamplesCollected
IdentifiersEmail address, username, pseudonymised IPYes
Personal contentJournal entries, prayer tracker, reflectionsYes
Sensitive personal informationReligious beliefs; other sensitive content voluntarily enteredYes
Internet/electronic activityBrowser type, access timestampsYes
Financial informationNone — handled solely by PaddleNo

No Sale or Sharing: Amani Deen does NOT sell or share personal information for cross-context behavioural advertising.

Submit requests to: info@amanideen.com | Subject: "CCPA Request" | Response within 45 days.

13. Wijzigingen

Wijzigingen worden minimaal 30 dagen van tevoren bekendgemaakt via e-mail en de Web-App.

14. Klacht indienen

Autoriteit Persoonsgegevens | Postbus 93374, 2509 AJ Den Haag | autoriteitpersoonsgegevens.nl

Wij stellen het op prijs als u ons eerst de gelegenheid geeft bezwaren te behandelen via info@amanideen.com.

15. Contact

Amani Deen  |  Bedrijvenpark Twente 147-F, 7602 KE Almelo, Nederland

E-mail: info@amanideen.com  |  KVK: 93369093

Privacy Policy

Version: 4.1  |  Effective Date: June 2026
Company: Amani Deen (sole proprietorship / eenmanszaak)  |  KVK: 93369093  |  VAT: NL005018794B44
Address: Bedrijvenpark Twente 147-F, 7602 KE Almelo, The Netherlands  |  Email: info@amanideen.com

1. Introduction

Amani Deen is committed to protecting your personal data. This Privacy Policy explains what data we collect, why, how we process it, and what rights you have. It is drafted in accordance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the CPRA, the Children's Online Privacy Protection Act (COPPA), and other applicable international privacy frameworks. This Privacy Policy is available at all times via the Web-App.

2. Data Controller

Amani Deen  |  Bedrijvenpark Twente 147-F, 7602 KE Almelo, The Netherlands

Email: info@amanideen.com  |  KVK: 93369093

3. Personal Data We Collect

3.1 Account Data

  • Email address (required)
  • Username (optional)
  • Password (stored encrypted via bcrypt-hashing; not readable by Amani Deen)

3.2 User-Generated Content

  • Journal entries (morning and evening sessions)
  • Shukr Meter ratings
  • Prayer tracker data
  • Checklist progress and 30-day tracker data
  • Niyah, dhikr, and personal reflections

Special category personal data: some of the above may contain information about your religious beliefs, which fall under the special categories referred to in Art. 9 GDPR. We process this data solely on the basis of your explicit consent, given when creating your account. Processing of religious data is necessary to deliver the core functionalities of the Web-App; without this processing, the core service cannot be provided.

Other special categories: journal entries may, at your own choice, contain information about health, mental state, ethnicity, or other special category personal data within the meaning of Art. 9 GDPR. Such data is processed by Amani Deen solely for the purpose of providing the service and is never used for profiling, targeting, or any other purpose.

3.3 Payment Data

Payments are processed entirely by Paddle as Merchant of Record. Amani Deen does not access or store full payment card details. We receive only a payment status confirmation and a subscription ID. Paddle may act as an independent controller for certain payment, tax, fraud prevention, and regulatory compliance activities involving personal data processed through its services. Such processing is governed by Paddle's own terms and privacy policy. See paddle.com/legal/privacy for Paddle's privacy policy.

3.4 Technical Data

  • IP address (pseudonymised: last octet truncated — used solely for security and debugging purposes)
  • Browser type and device type
  • Timestamp of access (for security and debugging)
  • Retained for a maximum of 90 days, then permanently deleted

3.5 Legal Consent Records

For the purpose of recording consent and contract formation, the following data is separately recorded and retained at registration:

  • Full IP address (not pseudonymised)
  • Date and time of acceptance (UTC)
  • Language environment (NL or EN)
  • Version number of the Terms and Conditions accepted
  • Version number of the Privacy Policy accepted
  • Status of all consent checkboxes

This processing is based on legitimate interests (Art. 6(1)(f) GDPR) and is retained for the duration of the account, with a minimum of 5 years from the date of consent or contract formation, pursuant to the applicable statutory limitation period (Art. 3:307 Dutch Civil Code). Withdrawal of consent does not reduce this retention period, as the record serves solely as legal evidence of prior consent and contract formation. This data is strictly separate from the pseudonymised technical security logs in Section 3.4.

4. Purposes and Legal Bases

PurposeLegal Basis (GDPR)
Account management and authenticationPerformance of contract (Art. 6(1)(b))
Providing the service (storing journal/tracker data)Performance of contract (Art. 6(1)(b))
Processing religious beliefs (core service)Explicit consent (Art. 9(2)(a))
Processing other special category data voluntarily enteredExplicit consent (Art. 9(2)(a))
Payment processing via PaddlePerformance of contract (Art. 6(1)(b))
Legal consent records (full IP, version numbers, timestamp)Legitimate interests (Art. 6(1)(f))
Sending marketing emails with tips and offersConsent (Art. 6(1)(a)) — only where opted in; withdrawable via Settings → Notifications → Marketing emails
Non-transactional messages (newsletters, updates)Consent (Art. 6(1)(a)) — only where opted in
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))
Anonymised service improvement statisticsLegitimate interests (Art. 6(1)(f))

5. Retention Periods

Data TypeRetention Period
Account dataDuration of active account + 12 months after deletion
Journal and tracker dataActive period; permanently deleted within 30 days of account deletion
Payment dataRetained by Paddle per legal requirements (typically 7 years)
Technical log data (pseudonymised IP)Maximum 90 days
Marketing consent and email dataDuration of active account or until consent is withdrawn, after which data is removed from marketing lists within 30 days
Consent recordsActive account duration, with a minimum of 5 years from the date of consent or contract formation (Art. 3:307 Dutch Civil Code)

6. Security

  • Supabase Row Level Security (RLS): technical isolation ensures each user can only access their own data
  • HTTPS/TLS encryption: all data transmitted via encrypted connections
  • Bcrypt password hashing: passwords stored in unreadable encrypted format
  • Access restriction: need-to-know basis for Amani Deen personnel
  • Data Protection Impact Assessment (DPIA): Amani Deen has conducted and documented a DPIA covering the processing of special category personal data

7. Data Breaches

In the event of a personal data breach likely to result in high risk to your rights, Amani Deen will:

  1. Notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours (Art. 33 GDPR)
  2. Notify you directly without undue delay, describing the nature, likely consequences, and remedial measures taken (Art. 34 GDPR)
  3. Maintain an internal breach register regardless of severity

Report suspected security incidents to info@amanideen.com.

8. Third-Party Processors and International Transfers

Amani Deen does not sell your personal data to any third party.

PartnerServiceLocationBasis
Supabase Inc.Database and authenticationEU (Frankfurt)DPA + SCCs
Paddle.com Market Limited (EU/UK) / Paddle.com Inc. (US)Payment processing (Merchant of Record)UK / USDPA + SCCs (EU Module 2, Irish law)
Netlify Inc.Web-App hostingUSDPA + SCCs
Resend Inc.Transactional email and marketing emailUSDPA + SCCs

For transfers to countries outside the EEA, Standard Contractual Clauses (SCCs) are in place under Art. 46 GDPR. The United Kingdom benefits from an adequacy decision by the European Commission. Paddle may act as an independent controller for certain processing activities. Data processing agreements extend to sub-processors of the above parties.

9. Cookies

The Web-App uses only functional cookies strictly necessary for service operation (authentication session). No tracking or advertising cookies. Paddle Checkout may place functional and fraud-prevention cookies governed by Paddle's privacy policy. If non-essential cookies are introduced, this Policy will be updated in advance.

10. Your Rights Under GDPR

Most rights can be exercised directly via your account settings in the Web-App. Email to info@amanideen.com (subject: "Privacy Request") remains available as an alternative. We respond within 30 days.

RightLegal BasisHow to Exercise
Access (Art. 15)Art. 15 GDPRVia info@amanideen.com
Rectification (Art. 16)Art. 16 GDPRVia info@amanideen.com
Erasure (Art. 17)Art. 17 GDPRSettings → Delete Account (automatic, immediate)
Restriction (Art. 18)Art. 18 GDPRVia info@amanideen.com
Data portability (Art. 20)Art. 20 GDPRSettings → Export My Data (automatic, immediate as JSON)
Object (Art. 21)Art. 21 GDPRVia info@amanideen.com
Withdraw consent (Art. 7(3) / Art. 9)Art. 7(3) / Art. 9 GDPRSettings → Withdraw Consent
Cancel subscriptionSection 5 TermsSettings → Subscription → Cancel (automatic, immediate)

10.1 Account Deletion (Art. 17 GDPR): You may delete your account and all associated personal data at any time via Settings → Delete Account. Deletion is executed immediately and automatically. All data you have entered will be permanently removed from our systems within 30 days. The legal consent records are retained in accordance with the periods set out in Section 5.

10.2 Withdrawing Consent for Religious Data (Art. 7/9 GDPR): You may withdraw your consent at any time via Settings → Withdraw Consent. If you have an active Premium Subscription, you will be clearly warned that the subscription will be automatically cancelled and no refund will be issued. The withdrawal is only processed upon your explicit confirmation. Withdrawal does not affect the lawfulness of prior processing.

10.3 Data Portability (Art. 20 GDPR): You may request a full export of your personal data via Settings → Export My Data. The export is generated immediately and automatically, delivered as a JSON file.

11. Children — COPPA

The Web-App is intended solely for persons aged 18 years or older. Amani Deen does not knowingly collect personal information from children under the age of 13. If we become aware that a user is under 13, we will immediately delete the account and all associated data, in compliance with COPPA (15 U.S.C. § 6501 et seq.). Contact info@amanideen.com — we will act within 5 business days.

12. California Residents — CCPA/CPRA

CategoryExamplesCollected
IdentifiersEmail address, username, pseudonymised IPYes
Personal contentJournal entries, prayer tracker, reflectionsYes
Sensitive personal informationReligious beliefs; other sensitive content voluntarily enteredYes
Internet/electronic activityBrowser type, access timestampsYes
Financial informationNone — handled solely by PaddleNo

No Sale or Sharing: Amani Deen does not sell personal information and does not share it for cross-context behavioural advertising.

Submit a Verifiable Consumer Request: info@amanideen.com | Subject: "CCPA Request" | Response within 45 days.

13. Changes to This Policy

Material changes communicated at least 30 days before taking effect via email and the Web-App, with a clear summary of changes.

14. Supervisory Authorities

EU/EEA Users: Autoriteit Persoonsgegevens | Postbus 93374, 2509 AJ The Hague | autoriteitpersoonsgegevens.nl

California Residents: California Privacy Protection Agency | cppa.ca.gov

We encourage you to contact us first at info@amanideen.com.

15. Contact

Amani Deen  |  Bedrijvenpark Twente 147-F, 7602 KE Almelo, The Netherlands

Email: info@amanideen.com  |  KVK: 93369093