Privacy Statement

Version 2.0 · last updated 13 augustus 2026 · van kracht voor bestaande klanten vanaf 13 september 2026

This statement explains how Studio Primary, trading as Bravik, handles personal data in providing the Bravik bookkeeping and invoicing service. It is written from what the software actually does, not from what is customary.

In short

We do not sell your data and do not use it for advertising. We retain your administration by default for as long as your statutory retention obligation runs — seven years — because you must be able to produce it. If you ask for deletion, we erase what we are allowed to erase and explain per category what must legally remain. See article 6 and article 7.

This is a courtesy translation. The binding text is the Dutch Privacyverklaring; where the two differ, the Dutch version prevails.

Article 1 — Who is responsible, and for what

Using Bravik involves processing personal data in two distinct roles. That distinction determines who you need to address with which question, so it comes first.

We are the controllerWe are the processor
Which dataYour account, your subscription and billing, your use of the service, security logs and your contact with our support.Everything you record in Bravik: your clients and suppliers, their contact details, your invoices, quotes, receipts, hours and projects.
Who determines purpose and meansWe do.You do. We process that data solely on your behalf and on your instructions.
Where it is governedThis privacy statement.The Data Processing Agreement, which satisfies art. 28(3) GDPR and forms part of our agreement.
Who should a data subject addressUs.You. If a client of a Bravik user asks us for access or deletion, we refer them to that user and help the user handle the request.

Our details: Studio Primary (Eenmanszaak, a Dutch sole proprietorship), Eindhoven, Nederland, Chamber of Commerce 82701237, VAT number NL003719360B48. For privacy questions: info@studioprimary.com.

We are not required to appoint a data protection officer: we are not a public authority, our core activity is not large-scale systematic monitoring, and we do not process special categories of personal data on a large scale (art. 37(1) GDPR). Privacy questions arrive at the address above and are handled by us directly.

Article 2 — What data we process

  • Account data — first and last name, email address, encrypted password, language preference, registration and last-login times, and your email verification status.
  • Business data — company name, legal form, address, Chamber of Commerce number, VAT number, IBAN, logo, branding and the details of any partners in a general partnership.
  • Subscription and payment data — chosen plan, our invoices to you, payment status and the payment reference at our payment service provider. Your full card or account details never reach us; the payment service provider processes those.
  • Administration data — invoices, quotes, contacts, expenses and receipts, hours, projects, mileage records, bank transactions and the resulting overviews. For this data we are the processor (article 1).
  • Usage and technical data — IP address, browser and device data, login times, failed login attempts and application error reports.
  • Communications — your messages to our support and the email we send you, with its delivery status.

We do not ask for special categories of personal data and do not need them for the service. If you record them yourself in a description or on a receipt, we process them as part of your administration, on your instructions and under your responsibility.

Article 3 — Purposes and legal bases

Every processing operation has a purpose and a legal basis under art. 6(1) GDPR. They are set out side by side below.

PurposeDataLegal basis
Providing the service: creating an account, logging in, creating and sending invoices and quotes, keeping the administrationAccount, business and administration dataPerformance of the contract — art. 6(1)(b)
Billing, collection and receivables management for your subscriptionAccount, business and payment dataPerformance of the contract — art. 6(1)(b)
Meeting our own statutory retention obligation and responding to requests from competent authoritiesOur invoices to you and the associated dataLegal obligation — art. 6(1)(c)
Security: preventing abuse and fraud, limiting login attempts, investigating an incidentIP address, device data, login data and logsLegitimate interest — art. 6(1)(f) (a secure service for all customers)
Support and resolving faultsCommunications, error reports and, where necessary, limited access to your environmentPerformance of the contract — art. 6(1)(b)
Improving the service using anonymised and aggregated usage statisticsUsage data, not traceable to an individualLegitimate interest — art. 6(1)(f)
Service and product email about changes, incidents and new featuresName and email addressLegitimate interest — art. 6(1)(f), with an unsubscribe option in every message
Visitor statistics for the public websiteIP address, device and visit dataConsent — art. 6(1)(a), via the cookie banner
Reading receipts and answering questions through the AI assistantThe contents of the receipt or your question with limited business contextPerformance of the contract — art. 6(1)(b), only when you use the feature
Establishing or defending a legal claimThe data required for that purposeLegitimate interest — art. 6(1)(f)

Where we rely on a legitimate interest, we have weighed that interest against your privacy. You may object; see article 12. Where we ask for consent, you may withdraw it at any time — that does not affect the lawfulness of processing before withdrawal.

Article 4 — We sell nothing and do not profile

  1. We do not sell, rent or trade your personal data.
  2. We do not use your administration for advertising and do not share it with advertisers or data brokers.
  3. We do not use your administration to train third-party AI models, and the sub-processor providing the AI features is contractually bound not to either.
  4. We do not build profiles of you for commercial purposes.

Article 5 — How long we retain data

Retention is the default here, and there is a reason

Under art. 52(4) of the Dutch State Taxes Act and art. 3:15i of the Civil Code you are required to retain your administration for seven years, and ten years for data relating to immovable property and under certain VAT schemes. If Bravik erased your administration sooner, we would put you in breach of that obligation. So we retain by default for the statutory period — and erase sooner as soon as you ask, subject to the exceptions in article 6.

DataRetention periodWhy
Administration: invoices, quotes, receipts, expenses, hours, projects, bank transactions and contacts7 years after the end of the financial year they relate to; 10 years for data on immovable property and when using the Union scheme (OSS)Your statutory retention obligation, art. 52(4) State Taxes Act and art. 3:15i Civil Code
Our invoices to you and the associated payment data7 years after the end of the financial yearOur own statutory retention obligation
Account and business dataFor as long as your account exists, and thereafter for as long as any of the above periods runs, because the administration cannot be interpreted without itPerformance of the contract and statutory retention obligation
Audit log: who created, changed or deleted which entryFor as long as the associated administration is retained, up to a maximum of 7 yearsAuditability of the administration and evidence in a dispute
Session and refresh tokensUp to 30 days, and revoked immediately on logout, password change or reuseSecurity
Security logs, login attempts and IP addresses12 months, or longer where a specific incident requires investigationLegitimate interest in a secure service
Email dispatch data: recipient, subject, time and status24 monthsEvidence that an invoice or reminder was sent
Receipts and questions sent to the AI providerWe retain nothing additional there; the provider processes the request and does not retain it for its own purposes. The receipt itself stays with us as part of your administrationPerformance of the contract
Support correspondence24 months after the question is closedLegitimate interest in proper follow-up
Website visitor statisticsUp to 14 months, and sooner on withdrawal of your consentConsent
Your cookie choice12 months, after which we ask againWe must be able to demonstrate what you chose

When a period expires we delete the data or make it irreversibly anonymous. If a dispute, complaint or audit is pending, we retain the relevant data until it is concluded.

Article 6 — Your deletion request

You may request deletion at any time, via info@studioprimary.com or from your account settings. This is how that works:

  1. We confirm within one month. If your request is complex we may extend that period by two months; we will tell you so with reasons within the first month (art. 12(3) GDPR).
  2. Your account is deactivated immediately. Logging in is no longer possible, active sessions are revoked, scheduled email and reminders are stopped, and nothing further is sent on your behalf.
  3. Whatever is not covered by a retention obligation, we erase. That includes in any event your profile and preference settings, your branding and logo, support correspondence, usage statistics and security logs unrelated to an ongoing incident.
  4. Whatever is covered by a retention obligation stays until that period expires. That is not our choice: art. 17(3)(b) GDPR expressly provides that the right to erasure does not apply to the extent processing is necessary for compliance with a legal obligation. For your administration, that is the period in article 5.
  5. In the meantime we lock that data down. It is no longer used for the service, no longer displayed, no longer included in overviews and no longer disclosed to third parties. It remains solely to comply with the law and to be produced in an audit or dispute. This is the restriction under art. 18 GDPR.
  6. If you expressly ask us to erase the administration sooner, we will do so. You are then instructing us as the controller of that data, and thereby assume responsibility for your own retention obligation. We confirm this in writing, and strongly recommend exporting first.
  7. Once the last retention period expires we erase everything, without you having to ask again.

Exporting is always possible and free of charge: CSV, UBL invoices and the XAF audit file that your bookkeeper or the Tax Administration can import. See also article 19 of the Terms of Service.

Article 7 — What happens if you stop without asking anything

  1. If you cancel your subscription, you retain access for ninety (90) days to export.
  2. After that we retain your administration for the remainder of your statutory retention obligation, and delete it thereafter. You need do nothing.
  3. If your account has been unused for twenty-four (24) months, we will warn you by email before closing it. The retention rule in paragraph 2 applies there too.

Article 8 — Who we share data with

We engage service providers who process data on our behalf. A data processing agreement is in place with each of them. This is the complete list; it is derived from the software itself rather than from a standard template.

RecipientPurposeWhich dataTransfer outside the EEA
Hetzner Online GmbH
Gunzenhausen, Duitsland
Servers, database, object storage and backups that Bravik runs on.All data you record in Bravik.Within the EEA — no transfer to a third country.
STRATO AG
Berlijn, Duitsland
Additional server infrastructure and backups in a second location.All data you record in Bravik.Within the EEA — no transfer to a third country.
Mollie B.V.
Amsterdam, Nederland
Processing subscription payments and — if you connect Mollie — payments from your clients through the client portal.Name, email address, invoice details, payment status and payment reference.Within the EEA — no transfer to a third country.
OpenRouter, Inc.
Verenigde Staten
Reading uploaded receipts and invoices (OCR) and answering questions in the AI assistant. OpenRouter forwards the request to the configured language model (Google and Anthropic among others). Only when you use receipt scanning or the AI assistant. When the self-hosted OCR fallback is active, receipts do not leave our own infrastructure.The receipt image or PDF including everything printed on it, and for the assistant your question plus limited business context (company name, legal form, VAT regime).Transfer to the US under the European Commission's standard contractual clauses (art. 46(2)(c) GDPR), supplemented by a transfer impact assessment.
Storecove B.V.
Amsterdam, Nederland
Access point for sending and receiving e-invoices over the Peppol network. Only if you use Peppol e-invoicing.The full invoice, including your client's name, address and tax numbers.Within the EEA — no transfer to a third country.
bunq B.V.
Amsterdam, Nederland
Retrieving bank transactions to reconcile payments. Only if you activate a bank connection.Account details, transaction amounts, descriptions and the counterparty's name and IBAN.Within the EEA — no transfer to a third country.
Cloudflare, Inc. (Turnstile)
Verenigde Staten
Protecting the login and registration forms against automated abuse.The visitor's IP address and browser characteristics.Transfer to the US under the standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.
Google Ireland Ltd. (Google Analytics)
Ierland, met doorgifte naar Google LLC in de Verenigde Staten
Visitor statistics for the public website. Only after your consent through the cookie banner. On the share pages your clients see (/view/…) no analytics is loaded and nothing is asked.IP address, device and browser data and pages visited.Transfer to the US under the EU-US Data Privacy Framework and the standard contractual clauses.
HeiGIT gGmbH (openrouteservice)
Heidelberg, Duitsland
Calculating travel distances for mileage records. Only when you use mileage tracking.Departure and destination addresses you enter.Within the EEA — no transfer to a third country.
Kamer van Koophandel, Kadaster (PDOK) en de Europese Commissie (VIES)
Nederland respectievelijk de Europese Unie
Looking up company details, addresses by postcode and validating EU VAT numbers.The search term you enter: company name, KVK number, postcode or VAT number.Within the EEA — no transfer to a third country.
Frankfurter (wisselkoersen)
Europese Unie
Retrieving European Central Bank daily rates for invoices in foreign currency.None. Only a currency code and date are requested.Within the EEA — no transfer to a third country.

Outgoing email — invoices and quotes to your clients, reminders and account mail — is sent by our own mail infrastructure, running on the same EEA servers as the rest of Bravik. No additional party is involved. If you configure your own SMTP server in the settings, your client mail goes out through that server instead; you choose that provider and the arrangements with it are yours.

In addition, we provide data to a competent authority where we are legally required to, and to our accountant, adviser or lawyer to the extent necessary; they are bound by confidentiality. In the event of an acquisition or merger, data may transfer to the acquiring party, on the same terms and with prior notice to you.

If you would like advance notice when we add or replace a sub-processor, subscribe via info@studioprimary.com. The procedure is set out in article 6 of the Data Processing Agreement.

Article 9 — Transfers outside the European Economic Area

Bravik runs on infrastructure inside the European Union and most service providers are established in the Netherlands or the EU. At three points data leaves the EEA, and we state that explicitly because it concerns data you entrust to us.

  • OpenRouter, Inc. (United States) — receives the receipt or invoice you have scanned, including everything printed on it, and for the AI assistant your question with limited business context. Only when you use those features.
  • Cloudflare, Inc. (United States) — receives your IP address and browser characteristics on the login and registration forms, to protect against automated abuse.
  • Google (Ireland, with onward transfer to the United States) — Google Analytics and Google Tag Manager on the public website. Without your consent Google receives only anonymous measurement signals (your IP address and the page visited), with no cookies and with no way to recognise you or follow you across visits. Analytics cookies are set only after you consent.

For these transfers we rely on the European Commission's standard contractual clauses (art. 46(2)(c) GDPR), supplemented by a transfer impact assessment and additional measures, and where applicable on the EU-US Data Privacy Framework (adequacy decision of 10 July 2023, art. 45 GDPR). A copy of the safeguards used is available on request.

If you do not want receipts processed outside the EEA, disable automatic receipt scanning and the AI assistant in your settings. The rest of Bravik continues to work in full; you enter receipt data yourself.

Article 10 — AI features

  1. Bravik contains two AI features: reading receipts and invoices, and an assistant that answers questions about your administration. In accordance with art. 50 of the AI Act we state that you are interacting with an AI system.
  2. These features are optional. If you do not use them, nothing is processed for that purpose and nothing is sent to the provider.
  3. What is sent is set out in article 8 and article 9. Your full administration is not shared; each request carries only what that request needs.
  4. Your data is not used to train models. That is contractually agreed.
  5. No automated decision-making producing legal effects or similarly significant effects takes place (art. 22 GDPR). A suggested entry is a suggestion; you confirm it yourself.
  6. AI output can be incorrect. See article 9 of the Terms of Service.

Article 11 — Cookies and similar techniques

Art. 11.7a of the Dutch Telecommunications Act requires consent for storing or reading data on your device, except for what is strictly necessary. We apply that distinction as follows.

TypePurposeConsent required
Necessary cookiesStaying logged in, securing the session, CSRF protection, language preference and remembering your cookie choice.No — the service does not work without them
Analytics cookies (Google Analytics)Measuring how many visitors the public website has and which pages are viewed.Yes — cookies are only set after you click accept. The measurement code itself loads immediately, but measures without cookies until you accept
Third-party advertising or tracking cookiesWe do not use these.Not applicable
  1. If you refuse, or do nothing, no analytics cookies are set and you are not identified. The measurement code does stay active in anonymous form (Google Consent Mode v2): Google receives the IP address and the page visited, but cannot link them to you or follow you across visits. Refusing is as easy as accepting.
  2. We store your choice for twelve (12) months in your browser and you can change it at any time via the cookie settings at the bottom of the website.
  3. On the pages your clients see — a shared invoice or quote under `/view/…` and the client portal under `/portal/…` — no measurement code at all is loaded and nothing is asked. Your clients are not measured there, not even anonymously.
  4. In the logged-in environment only necessary cookies are set. The anonymous measurement code may be active there, on the same terms as above.

Article 12 — Your rights

For the data for which we are the controller (article 1) you have the following rights:

  • Access (art. 15) — find out what data we process about you and receive a copy.
  • Rectification (art. 16) — have inaccurate data corrected or completed. Most of it you can change yourself in your settings.
  • Erasure (art. 17) — request deletion, subject to the limits and procedure in article 6.
  • Restriction (art. 18) — have processing frozen, for instance while an objection is being assessed.
  • Portability (art. 20) — receive your data in a structured, commonly used, machine-readable format. Bravik offers CSV, UBL and XAF for this; you need not even ask.
  • Objection (art. 21) — object to processing based on a legitimate interest. You may object to direct marketing at any time and without giving reasons.
  • Withdrawal of consent (art. 7(3)) — where we asked for consent, you can withdraw it as easily as you gave it.
  1. Send a request to info@studioprimary.com. We respond within one month, with a possible two-month extension for a complex request (art. 12(3) GDPR).
  2. Where we have reasonable doubts about your identity we will ask for additional information. We never ask for a copy of your identity document by email.
  3. Exercising your rights is free of charge. Only for manifestly unfounded or excessive, repetitive requests may we charge a reasonable fee or refuse, and we will explain why.
  4. If your request concerns data a Bravik user has recorded about you — for instance because you received an invoice from one of our customers — we are the processor and that user is your point of contact. We will refer you and help that user carry out the request.

Article 13 — Security

We take appropriate technical and organisational measures within the meaning of art. 32 GDPR. These include:

  • encrypted connections (TLS) for all traffic, and encrypted storage of back-ups;
  • passwords stored only as hashes, never readable, not even by us;
  • short-lived access tokens in an httpOnly cookie, with single-use refresh tokens that revoke the entire family on reuse;
  • double-submit cookie protection against CSRF and rate limiting on sensitive endpoints;
  • strict per-organisation separation: every database query is bound to your organisation id, so customers' data cannot reach each other;
  • an audit log of changes affecting money, so it can be established afterwards who did what;
  • production access limited to those who need it, and secrets stored encrypted;
  • regular back-ups and periodic dependency updates.

Found a vulnerability? Report it to info@studioprimary.com. We respond within five working days and will not take legal action against anyone who reports a vulnerability carefully and confidentially, accesses no more data than needed to demonstrate it, and gives us reasonable time to remedy it before publishing.

Article 14 — Personal data breaches

  1. If we establish a personal data breach for which we are the controller, we report it to the Autoriteit Persoonsgegevens (Dutch Data Protection Authority) within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk (art. 33 GDPR).
  2. If the risk to you is likely to be high, we will inform you without undue delay and in clear language, stating what happened, which data is involved and what you can do yourself (art. 34 GDPR).
  3. Where the breach concerns data for which you are the controller, we notify you without undue delay and not the supervisory authority — that notification is yours to make. We supply the information you need for it. The timing and contents are set out in article 8 of the Data Processing Agreement.
  4. We keep an internal register of all breaches, including those not requiring notification.

Article 15 — Right to complain

If you disagree with how we handle your data, please tell us first via info@studioprimary.com — that is usually the quickest route. If we cannot resolve it, you have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Dutch Data Protection Authority), Postbus 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl. You may also go to court.

Article 16 — Minors

Bravik is a business service and is not directed at people under the age of sixteen. We do not knowingly collect data about minors. If you believe this has nevertheless happened, please contact us and we will delete that data as soon as possible.

Article 17 — Changes to this statement

  1. We update this statement when the service, our service providers or the applicable rules give cause to. The version number and date at the top indicate which version you are reading.
  2. For a material change — a new purpose, a new legal basis, a new transfer outside the EEA or a longer retention period — we will inform you in advance by email or in the application.
  3. Earlier versions are available on request.

Article 18 — Contact

ControllerStudio Primary, trading as Bravik
AddressEindhoven, Nederland
Chamber of Commerce (KVK)82701237
Privacy and data requestsinfo@studioprimary.com
Security and vulnerabilitiesinfo@studioprimary.com
Generalhello@bravik.nl
Supervisory authorityAutoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl