Legal

Privacy Policy

Last updated: April 2026 · GDPR compliant · Governed by Dutch law

Daily Frozen BV is committed to protecting your personal data. This Privacy Policy explains which data we collect, on what legal basis, for what purpose, and how we protect it — in full compliance with the EU General Data Protection Regulation (GDPR) and the Dutch Uitvoeringswet AVG (UAVG).

A

Controller & Contact

The controller responsible for processing personal data on this platform is:

Daily Frozen BV

The Netherlands

VAT: NL[number]B01 · KvK: [number]

Privacy contact: privacy@dailyfrozen.nl

General: info@dailyfrozen.nl

For all privacy-related requests (access, correction, deletion, objection), contact us at privacy@dailyfrozen.nl. We respond within 30 days.

B

Data We Collect

We collect personal data only when strictly necessary for the operation of this platform. We never collect data speculatively.

1. Website Visitors (no account required)

IP address (truncated)Technical delivery of pages
Browser type & versionCompatibility & performance
Referring URLAnalytics & traffic attribution
Pages visited & timestampsStatistical improvement of our platform

IP addresses are anonymised before being stored. We retain them only for the duration of the session.

2. Company Registration

When a company registers as a partner producer or buyer, we collect:

  • Company name, legal address, country of registration
  • Chamber of Commerce number (KvK / company registration)
  • VAT number
  • Contact person: full name, job title, business email, phone number
  • Role on the platform: seller (producer), buyer, or both
  • Product categories and average trading volumes (for producers)
  • Preferred product categories and order frequency (for buyers)
  • Payment terms preference (30 / 60 / 90 days)

3. Purchase Requests (Buyers)

When a buyer submits a purchase request for a listed product, we collect:

  • Company name & registration number
  • Business email address and phone number
  • Quantity requested (in tonnes)
  • Optional message to Daily Frozen

4. Newsletter Subscribers

Email address, optional company name, preferred product categories, and language preference.

5. Credit Check Data (Buyers)

When a purchase request is approved for credit verification, the buyer's company details (name, registration number, trading volume) are submitted to Atradius Atrium for credit assessment. This is performed under our legitimate interest in protecting all parties in a transaction (Art. 6(1)(f) GDPR).

6. Deal & Transaction Data

Upon successful deal closure: deal value, product details, quantity, price per kg, commission amount, invoice reference (DF-YYYY-NNN format), and payment status. This data is processed and retained for statutory tax compliance.

D

How We Use Your Data

  1. 1
    Platform operation

    To display product listings, process purchase requests, and facilitate B2B introductions between partner producers and verified buyers.

  2. 2
    Onboarding & verification

    To verify company registrations, check certifications, and ensure all parties on the platform meet our quality standards.

  3. 3
    Credit assessment

    Before introducing a buyer to a producer, we run a credit check via Atradius Atrium to assess payment risk. This protects both parties. No credit decisions are made automatically — the operator reviews results and decides.

  4. 4
    Deal management & invoicing

    To track deal status, generate commission invoices (DF-YYYY-NNN format), record payments, and maintain audit logs for legal and tax purposes.

  5. 5
    Communication

    To notify registered companies about the status of their requests, deal progress, credit check results, and account updates. Email notifications are transactional and directly related to your activity on the platform.

  6. 6
    Newsletter (with consent)

    If you subscribe, we send periodic updates about new partner products, market availability, and platform news. You can unsubscribe at any time.

  7. 7
    Platform improvement

    Anonymised analytics data (Google Analytics 4 with IP anonymisation) helps us understand how users navigate the platform and where to improve. No personal data is used for this purpose.

  8. 8
    Security & fraud prevention

    Rate limiting (Upstash Redis) and error monitoring (Sentry) protect the platform against abuse. No personal data is shared with these providers beyond what is technically necessary.

E

Third-Party Processors

We work with carefully selected sub-processors, all bound by data processing agreements in accordance with Art. 28 GDPR. We only share data that is strictly necessary for each service.

Supabase (PostgreSQL + Auth + Storage)

Primary database, user authentication, and file storage

📍 EU — Frankfurt, Germany (GDPR region)

Privacy policy ↗

Vercel

Hosting and content delivery network for the platform

📍 EU edge nodes (data processed in Europe)

Privacy policy ↗

Google Analytics 4

Anonymised website usage statistics

📍 EU with IP anonymisation enabled — no personal data transmitted

Privacy policy ↗

Formspree

Email delivery for contact and quote request forms

📍 USA — Standard Contractual Clauses applied

Privacy policy ↗

Atradius Atrium

Credit risk assessment for buyers prior to deal introduction

📍 Netherlands (EU)

Privacy policy ↗

Upstash Redis

Rate limiting and API protection (no personal data stored)

📍 EU region

Privacy policy ↗

Sentry

Error monitoring and crash reporting — cookies and PII excluded

📍 USA — Standard Contractual Clauses applied

Privacy policy ↗

We never sell your data to third parties. We never use your data for advertising purposes beyond the platform itself.

F

Data Retention

Data CategoryRetention PeriodReason
Company registration data7 years after last activityDutch tax law (Art. 52 AWR)
Purchase request data7 years after last activityDutch tax law
Deal & invoice records7 yearsMandatory financial recordkeeping
Audit logsIndefiniteLegal evidence for commission disputes
Credit check results7 yearsFinancial due diligence
Newsletter subscriptionsUntil unsubscription + 30 daysConsent-based — revocable
Analytics data (GA4)14 monthsGoogle Analytics default retention
Error logs (Sentry)90 daysSentry default
Session dataDuration of sessionTechnical necessity

Data subject to statutory retention periods is locked for further processing during that period and deleted automatically once the period expires.

G

International Data Transfers

Our primary infrastructure (Supabase database, Vercel hosting) is located within the European Economic Area (EEA), specifically in Frankfurt, Germany.

Where processors are located outside the EEA (Formspree, Sentry), we ensure adequate protection through:

  • EU Standard Contractual Clauses (SCCs) as approved by the European Commission (Art. 46(2)(c) GDPR)
  • EU–US Data Privacy Framework certification where applicable
  • Supplementary technical measures (encryption in transit and at rest)
H

Cookies & Tracking

We use a minimal number of cookies, categorised as follows:

Strictly Necessary Cookies

CookiePurposeDuration
sb-access-tokenSupabase authentication session (operator only)Session
sb-refresh-tokenSupabase session refresh (operator only)7 days

These cookies are essential for the operator dashboard to function. They are never set for public visitors.

Analytics Cookies

CookiePurposeDuration
_gaGoogle Analytics 4 — visitor identification (anonymised)2 years
_ga_*GA4 session tracking2 years

IP addresses are truncated before being sent to Google. No personal identifiers are included. We do not use Google Analytics for advertising purposes.

Managing Cookies

You can disable or delete cookies through your browser settings at any time. Disabling analytics cookies does not affect the functionality of this platform for public visitors. Disabling session cookies will prevent login to the operator dashboard.

We do not use marketing cookies, retargeting pixels, or social media tracking of any kind.

I

Your Rights under GDPR

As a data subject under GDPR, you have the following rights. To exercise any of them, contact privacy@dailyfrozen.nl. We respond within 30 days.

Art. 15Right of Access

Request a copy of all personal data we hold about you or your company.

Art. 16Right to Rectification

Request correction of inaccurate or incomplete personal data.

Art. 17Right to Erasure

Request deletion of your data, subject to legal retention obligations.

Art. 18Right to Restriction

Request that we limit processing of your data in certain circumstances.

Art. 20Right to Portability

Receive your data in a structured, machine-readable format (JSON/CSV).

Art. 21Right to Object

Object to processing based on legitimate interest, including profiling.

Art. 7(3)Right to Withdraw Consent

Withdraw newsletter consent at any time without affecting prior processing.

Art. 77Right to Lodge a Complaint

File a complaint with the Dutch DPA: Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

Where data is retained for legal obligations (tax records, audit logs), erasure requests cannot be fulfilled during the applicable retention period. We will notify you of any such limitation within 30 days of your request.

J

Security Measures

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction:

🔒

Encryption in transit

All data is transmitted over TLS 1.3. HTTPS enforced on all endpoints.

🗄

Encryption at rest

Supabase PostgreSQL database is encrypted at rest (AES-256).

🔑

Access control

Row-Level Security (RLS) on all database tables. Service role keys used only server-side, never exposed to the browser.

Rate limiting

All public API endpoints are rate-limited via Upstash Redis to prevent abuse (5 requests/minute per IP).

🛡

Audit logging

Every data modification is logged in an append-only audit table with actor, timestamp, IP address, and before/after values.

👁

Error monitoring

Sentry captures server errors with cookies and personal data stripped before transmission.

🏢

Operator access only

The operator dashboard is protected by Supabase Auth. No public access to any company or deal data.

🌍

EU infrastructure

Primary database and hosting located in Frankfurt, Germany — within the EU/EEA.

K

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing activities, applicable law, or best practices. Material changes will be announced via a prominent notice on our platform and, where applicable, via email to registered users.

The current version of this policy is always available at dailyfrozen.nl/privacy. The effective date is stated at the top of this page.

Continued use of the platform after a material change constitutes acceptance of the updated policy. If you do not agree with the changes, you may request deletion of your account at privacy@dailyfrozen.nl.

Questions about your data?

We take privacy seriously. Reach out and we will respond within 30 days.

✉ privacy@dailyfrozen.nl