Privacy Statement

Version 4 September 2026

In short

Your employees' data remains 100% the property of your organization. Hoeray uses it solely to send the gestures you set up — we never sell or share it for our own purposes. For that employee data, Hoeray is the processor and your organization is the controller; the arrangements governing this are set out in our data processing agreement at hoeray.com/dpa. For data of customers, prospects and website visitors, Hoeray is itself the controller — that is what most of this statement is about.

Who is Hoeray?

Hoeray (trade name of The Circle of 10 B.V.)

Danzigerbocht 45S, 1013 AM Amsterdam

KvK: 92475809

VAT ID: NL866064485B01

Email: hello@hoeray.com

1. Two roles: controller and processor

Hoeray processes personal data in two different roles. The role in which we process your data matters for your rights:

a) Hoeray as controller. For data of customers (account holders and users), prospects (for example via our forms) and visitors to our website, Hoeray itself determines the purposes and means of the processing. Parts 2 through 6 of this statement apply to these processing activities.

b) Hoeray as processor. The data of our customers' employees (names, dates of birth, home addresses and other HR data) is processed by us solely on the instructions of the employer. The employer is the controller; Hoeray is the processor. The data processing agreement at hoeray.com/dpa applies to this processing. Part 7 of this statement explains what this means and how employees exercise their rights.

One exception: when Hoeray sends a gesture of its own (such as the free welcome card we send to new customers), Hoeray does so on its own account and is itself the controller for that sending.

2. What personal data we process as controller

Customer data (account holders and users)

  • Name
  • Business email address
  • Phone number
  • Address details of the organization
  • Chamber of Commerce (KvK) number (for sole proprietorships and partnerships, this is personal data)
  • VAT number
  • Login credentials (password stored encrypted) and, if enabled, two-factor authentication data
  • Payment and invoicing data (payments are processed via Stripe; Hoeray itself does not store card or bank account details)
  • Acceptance records (time and version of accepted terms)

Prospect data (forms and requests)

  • Name, email address and organization name that you enter yourself on our forms (for example a demo request or waitlist)

KvK verification and trial registration

  • Upon registration, we verify the provided KvK number in the Dutch Business Register (Handelsregister).
  • Because the free trial applies once per KvK number, for organizations that have used a trial we keep a record of the KvK number — even after the account has been deleted. This is how we prevent abuse of the trial. For sole proprietorships this is personal data; for this purpose we store only a hashed (irreversibly encrypted) form of the KvK number, for a maximum of five years (see part 4).

Website data (functional only)

  • IP address
  • Browser type
  • Campaign label (see part 6, cookies and local storage)

3. Purposes and legal bases

We process the data listed in part 2 for the following purposes, each with its corresponding legal basis:

  • Providing our service creating and managing your account, running approval rounds and sending gestures. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
  • Invoicing and administration. Legal basis: performance of the contract and legal obligation (Art. 6(1)(b) and (c) GDPR — statutory tax retention obligation).
  • Communication about the service service emails such as the monthly approval reminder and renewal reminders. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
  • Direct marketing about our own service see the separate paragraph below. Legal basis: legitimate interest (Art. 6(1)(f) GDPR), in conjunction with the existing-customer-relationship exception of Article 11.7(3) of the Dutch Telecommunications Act.
  • Improvement and security of the service including troubleshooting and preventing abuse (rate limiting, single-trial verification). Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
  • KvK verification upon registration verifying that we deliver exclusively to business customers. Legal basis: legitimate interest and performance of the contract.

Direct marketing and your separate right to object

On the basis of the customer relationship, every business contact person of a customer (account holders and users) and every prospect of Hoeray may receive marketing email about our own service — for example tips during onboarding, product news or an offer to expand your subscription — unless you have unsubscribed individually. Upon registration we also record through which marketing campaign your organization found us (see part 6), so we know which campaigns work.

  • You can unsubscribe per email address, via the one-click unsubscribe link included in every marketing message. Unsubscribing takes effect immediately and without logging in.
  • If you have unsubscribed, you will receive only functional messages from us: messages that are necessary for the service, such as approval rounds, reminders, invoices and security notifications. We will continue to send these for as long as your organization is a customer.
  • In addition, you have at all times the unconditional right to object to the use of your data for direct marketing (Art. 21(2) and (3) GDPR). If you object, we will stop this processing immediately and without any weighing of interests. You can object via the unsubscribe link or via hello@hoeray.com.

4. Retention periods

  • Customer data for the duration of the agreement. After termination of the agreement, we delete or anonymize customer data no later than two (2) years afterwards, with the exception of data subject to the statutory tax retention obligation.
  • Financial data (invoices, payment records, credit records) seven (7) years on the basis of the statutory tax retention obligation. When an account is deleted, only this financial data is retained; all other personal data is erased or anonymized immediately.
  • Prospect data up to two (2) years after the last contact, or earlier as soon as you unsubscribe or request it.
  • KvK number for the trial registration five (5) years, with the KvK number stored exclusively in hashed (irreversibly encrypted) form; solely to prevent the one-time free trial from being used more than once per KvK number.
  • Technical log files short-lived and cleaned up automatically; for example, rate-limiting records are deleted after two (2) days.
  • Employee data see part 7; as processor, we retain this data in accordance with the periods in the data processing agreement (no later than 90 days after the end of the customer relationship, subject to the tax exception).

5. Recipients and transfers outside the EEA

We share personal data with the following service providers, only to the extent necessary for our services:

RecipientServiceLocation/regionCategories of dataTransfer mechanism
StripePayment processingIreland/USCustomer and payment dataDPF-certified (EU-US, including UK and Swiss extensions; certification active)
Print.one B.V.Printing and sending cardsThe NetherlandsEmployees' name, home address and card messagen/a (EEA)
Fleurop Interflora Nederland B.V.Flower deliveryThe NetherlandsEmployees' name and home addressn/a (EEA)
Neon Inc.Database hostingUS company, EU data regionAll platform dataNo DPF — SCCs with supplementary measures based on a Transfer Impact Assessment, via Neon's DPA; EU data region
Resend Inc.Email deliveryUSCustomer communications and — via the order email to Fleurop — employees' name and home addressDPF-certified (EU-US, including UK extension)
Vercel Inc.Application hostingUS company, EU edge networkAll platform trafficDPF-certified, with SCCs as contractual fallback

The transfer mechanisms in this table were verified on 27 August 2026.

Data processing agreements have been concluded with all processors in accordance with the GDPR. Where a transfer takes place outside the European Economic Area, it occurs exclusively on the basis of an adequacy decision of the European Commission (such as the EU-US Data Privacy Framework) or Standard Contractual Clauses with additional safeguards. You can request a copy of the safeguards used via hello@hoeray.com.

Source of employee data: we do not receive employee data from the employees themselves, but from their employer — via an HR system integration activated by the employer (including Nmbrs, Exact or Loket.nl) or via manual entry by the employer.

6. Security, cookies and local storage

Security. We take appropriate technical and organizational measures to protect personal data against loss, misuse and unauthorized access, including:

  • TLS encryption for all data transfers
  • Encrypted storage of sensitive data, including HR integration secrets (with a dedicated encryption key) and two-factor authentication secrets
  • Passwords stored exclusively as encrypted hashes
  • Two-factor authentication, which the account owner can make mandatory for the entire organization
  • Role-based access control and the least-privilege principle, with a separate database role for the application
  • Daily automated monitoring and regular backups

Cookies. Hoeray uses three kinds of techniques. (1) Functional cookies necessary for the proper functioning of the website — session cookies (for login functionality) and language preference cookies; no consent is required for these. (2) Cookieless statistics (Vercel Web Analytics): anonymised page statistics without cookies, without profiling and without identifying visitors. (3) Advertising cookies from Google, Meta and/or LinkedIn — the cookie banner names which of these parties are actually in use at that time, and they are only placed after you have accepted them via the cookie banner (legal basis: consent, Art. 6(1)(a) GDPR and Article 11.7a of the Dutch Telecommunications Act). These measure which campaigns lead to a visit or registration and may be used by those parties for audience building; data may be transferred to the United States under the EU-US Data Privacy Framework. If you decline, nothing from these parties is loaded. You can withdraw or change your choice at any time via "Cookie preferences" at the bottom of every page — as easy as accepting. We never place advertising cookies in the logged-in customer environment.

Campaign labels (local storage). If you arrive at our website via a campaign link (for example an advertisement), we store the name of that campaign in your own browser (localStorage) for at most 30 days. These are campaign labels we chose ourselves — no click IDs, no identifiers and no browsing behavior — and nothing is shared with third parties. If your organization registers an account, we record for that organization which campaign led to it; that way we know which campaigns work. If you do not register, the label simply expires.

7. Employee data: Hoeray as processor

Are you an employee of an organization that uses Hoeray? Then Hoeray processes a limited set of data about you, solely on the instructions of your employer, to have gestures (such as a birthday card or flowers) delivered to you.

What data: first name, last name, date of birth, address details, employment start and end dates, business email address, department, job title, language preference, and the delivery details of gestures sent (what, when and to which address).

Where it comes from: from your employer, via your employer's HR system or via manual entry by your employer. Hoeray does not collect this data from you directly.

Who is responsible: your employer is the controller and decides whether and which gestures are sent. Hoeray only carries this out, in accordance with the data processing agreement at hoeray.com/dpa.

How to exercise your rights: would you like access to, correction or deletion of your data, or do you no longer wish to receive gestures? Address your request to your employer — they can arrange it directly in the platform. If Hoeray receives such a request directly from you, we will forward it to your employer without delay and support its handling; as a processor, we are not permitted to decide about your data independently.

How long: for as long as your employer is a customer and does not delete your data. After the end of the customer relationship, employee data — including the delivery details in the sending history — is deleted or anonymized within 90 days at the latest, except where the statutory tax retention obligation (7 years, financial records only) requires longer retention.

8. Your rights as a data subject

Where Hoeray processes data about you as a customer, prospect or website visitor (the role of controller, parts 2 through 6), you have the following rights under the GDPR:

  • Right of access you can request which data we process about you.
  • Right to rectification you can have incorrect data corrected.
  • Right to erasure you can request the deletion of your data.
  • Right to restriction of processing you can request the restriction of processing.
  • Right to object you can object to processing based on legitimate interest; you can always and unconditionally object to direct marketing (see part 3).
  • Right to data portability you can request to receive your data in a structured, commonly used and machine-readable format.

You can submit your request via hello@hoeray.com. We will respond to your request within 30 days.

Are you an employee of a customer? Then address your request to your employer (see part 7).

9. Changes to this privacy statement

We reserve the right to modify this privacy statement. Changes will be published on this page, stating the date and version number of the latest update. In case of significant changes, we will inform customers by email. Previous versions can be requested via hello@hoeray.com.

10. Complaints

Do you have a complaint about the processing of your personal data? Please contact us first at hello@hoeray.com. You also always have the right to file a complaint with the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority), the supervisory authority for privacy protection: autoriteitpersoonsgegevens.nl.