Yanis De Maesschalck, trading as YDM Design, Roombaardstraat 40, 9810 Nazareth-De Pinte, Belgium. VAT BE0699694751. Contact: info@ydmdesign.be.
The dashboard uses a single session cookie to keep you signed in while it's embedded in your CRM. It's used only for authentication, is marked HTTP-only and secure, and carries no tracking or analytics purpose.
We process this data to perform the invoicing service you configured, on the basis of the contract formed when you install and use the app.
We keep your configuration and invoice logs for as long as the app stays installed, plus a reasonable period afterwards for bookkeeping and dispute-handling purposes. You can request earlier deletion by contacting us.
When we delete data, it remains present in the daily backups for up to 90 days, after which those expire on their own. Backups are not edited: doing so would destroy their value as a restore point.
Under GDPR, you can request access to, correction of, or deletion of your data, ask us to restrict or object to processing, and request a copy in a portable format. Contact info@ydmdesign.be for any of these requests.
Your data stays within the European Union: the application runs on Railway in Amsterdam (the Netherlands), the database is hosted by Neon in Frankfurt (Germany), and the backups sit with Cloudflare in storage under EU jurisdiction.
One processing step may leave the EU. The daily backup job runs on GitHub's infrastructure, which gives no geographic guarantee as to where that job is executed; the database passes through it temporarily before being written to storage in the EU. GitHub (Microsoft) participates in the EU-US Data Privacy Framework and additionally relies on standard contractual clauses. The same contractual safeguards apply to our other providers where they would process outside the European Economic Area.
Your Moneybird OAuth tokens and your CRM platform's access and refresh tokens are encrypted at rest with AES-256-GCM, all traffic is served over HTTPS, and access to the app's endpoints is rate-limited. The backups contain those same encrypted values — the key itself is never stored alongside them.
We may update this policy from time to time; the current version, with its update date, is always available at this page. Questions can be sent to info@ydmdesign.be.