Donarazv0.2.2 - bèta

Legal

Privacy Policy

Last updated: 24 September 2026

This policy explains what personal data Donaraz collects, why we collect it, who we share it with and what you can do about it. It covers both the businesses that run promotions on our platform and the customers who submit claims on the promotion pages we host.

1.Who we are

Donaraz is an omni-channel gifting platform operated by Athom, registered in the Netherlands. Businesses use Donaraz to run gift, cashback and reward promotions end to end: the claim page, the serial number check, the approval, the carrier label and the emails that tell the customer their reward is on its way.

This policy applies to donaraz.com, the Donaraz dashboard, our API, and the public claim pages we host on donaraz.app subdomains and on our customers’ own domains. You can reach us about anything in this policy at:

Athom / Thom Knepper
G.E.C. Ribbiuslaan 14
3161 HB Rhoon, Netherlands
KvK: 89070399
BTW: NL004687939B33
[email protected]

2.Controller or processor: which applies to you

Donaraz handles two very different kinds of personal data, and our responsibilities differ for each. Read the part below that describes you.

2.1When you are a business user

If you register a workspace, sign in to the dashboard or subscribe to a plan, Athom is the data controller for your account, billing and usage data. We decide why and how that data is processed, and this policy governs it in full.

2.2When you submit a claim

If you are a customer submitting a claim on a promotion page, the business running that promotion is the controller. It decides which promotion to run, what proof to ask for and who qualifies. Athom acts as a processor on that business’s documented instructions, under a data processing agreement. We handle your claim data to deliver the service that business asked for; we do not use it for our own purposes.

You can exercise your rights with either party. If you contact us about claim data, we will forward your request to the relevant business and help them answer it.

3.Information we collect

3.1Information you give us

  • Account details: name, email address, phone number, a hashed password and, if you enable it, an encrypted two-factor authentication secret
  • Workspace details: company name, address, Chamber of Commerce and VAT numbers, logo, brand colours and domain settings
  • Promotion configuration: products, reward rules, promotion terms, eligible serial number ranges, eligible countries and claim form fields
  • Billing details: company billing address and the payment details you enter directly with our payment providers
  • Support messages: the content of emails, tickets and any files you send us

3.2Information claimants submit

  • Contact details: name, email address and, where the promotion requires it, phone number
  • Delivery address for physical rewards: street, house number, postal code, city and country
  • Proof of purchase: serial numbers, receipt or invoice images, order numbers and product photos, as configured by the business
  • Bank details: account holder name plus IBAN, or domestic account number and BIC, for cashback payout rewards only
  • Answers to any additional questions the business added to the claim form

3.3Information we collect automatically

  • Log data: IP address, browser and device type, referring page, requested URL and timestamp
  • Session data: which workspace you are working in and which roles apply to your session
  • Claim page analytics: page views and conversion events, counted against a random, HTTP-only session identifier that is not linked to your account
  • Product analytics and error reports from the dashboard, including stack traces and the actions leading up to an error

3.4Information from other sources

  • Shipment status and tracking events from carriers (DHL eCommerce, PostNL, GLS, DPD, UPS, FedEx)
  • Payment, subscription and payout status from Stripe and Mollie
  • Delivery, bounce and complaint events from our email providers
  • Bot and abuse signals from Cloudflare and Cloudflare Turnstile

4.How we use your information

We use the data described above to:

  • Run the platform and keep every workspace’s data separated from every other workspace
  • Authenticate you, enforce roles and permissions and support two-factor authentication
  • Validate serial numbers and proof of purchase, and block duplicate or fraudulent claims
  • Create carrier labels, track shipments and report delivery status back to the business
  • Send transactional email: claim received, approved or rejected, shipped, and tracking updates
  • Process subscriptions and payouts and issue invoices
  • Report promotion performance to the business running the promotion
  • Provide support, investigate errors and improve the product
  • Meet our legal, tax and accounting obligations

We do not sell your personal data, we do not share it with advertising networks, and we do not use your content or claim data to train AI models.

5.Legal basis for processing (GDPR)

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract: providing the platform to business users and processing claims so a promised reward can be delivered
  • Legitimate interests: securing the platform, preventing fraudulent and duplicate claims, understanding how the product is used and improving it, and defending legal claims
  • Legal obligation: retaining invoices and accounting records and responding to lawful requests from authorities
  • Consent: non-essential cookies and marketing email. You can withdraw consent at any time, and doing so does not affect processing that already took place

Where we process claim data as a processor, the business running the promotion determines the legal basis and is responsible for informing claimants.

6.Who we share information with

We share personal data only where it is needed to run the service, and always under a contract that limits what the recipient may do with it.

6.1Infrastructure and service providers

These providers process personal data on our behalf as sub-processors:

ProviderWhat they doData involved
RailwayApplication hosting, managed PostgreSQL database and Redis cacheAll platform data
CloudflareDNS, CDN, web application firewall and Turnstile bot protectionRequest metadata, IP addresses, challenge tokens
DigitalOcean Spaces (Amsterdam)Object storage for logos, product images and proof-of-purchase uploadsUploaded files
StripeSubscription billing and card paymentsBilling contact and payment details
MolliePayment and payout processing for European payment methodsPayment and payout details
SequenzyTransactional and notification email deliveryRecipient name, email address, message content
ResendTransactional email delivery and delivery, bounce and complaint webhooks, used alongside SequenzyRecipient name, email address, message content
PostHog (EU Cloud)Product analytics and error tracking in the dashboardUsage events, error reports, pseudonymous identifiers

6.2Shipping carriers

Donaraz is not a carrier. Businesses connect their own carrier accounts, so shipping data flows through the business’s existing relationship with DHL eCommerce, PostNL, GLS, DPD, UPS or FedEx. We send the carrier only what a label needs: recipient name, delivery address, package weight and dimensions, and an email address or phone number where the carrier uses it for delivery notifications. Carriers act as independent controllers for that data under their own privacy policies.

6.3The business running the promotion

Claim data is visible to, and exportable by, the business whose promotion you claimed under, and to the team members it has granted access. That business’s own privacy policy governs what it does with the data afterwards.

6.4Legal requests

We may disclose data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims. We assess each request and disclose no more than what is required.

6.5Business transfers

If Athom is involved in a merger, acquisition or sale of assets, personal data may transfer as part of that transaction. We will notify affected users before their data becomes subject to a different privacy policy.

7.Serial numbers, proof of purchase and fraud prevention

Where a promotion requires it, we check the serial number or proof of purchase submitted against the ranges and lists the business uploaded, and we keep a record of serial numbers that have already been used so the same purchase cannot be claimed twice.

We also apply Cloudflare Turnstile, rate limiting and duplicate detection to claim pages to stop automated abuse. Where a claim is rejected, we retain a record of the rejection so the business can handle disputes.

These checks filter claims; they are not final decisions. The business running the promotion makes or confirms the decision to approve or reject a claim, so no decision with legal or similarly significant effects is taken by automated means alone.

8.How long we keep data

  • Account and workspace data: for as long as the workspace is active, and deleted within 30 days of account closure
  • Claim data: for the period the business running the promotion instructs, plus any statutory retention period. Where no instruction is given, our default is the promotion period plus 24 months
  • Serial number usage records: for as long as duplicate-claim protection requires, and at most seven years
  • Uploaded proof-of-purchase files: deleted together with the claim record they belong to
  • Invoices and accounting records: seven years, as required by Dutch tax law
  • Server and access logs: 90 days
  • Product analytics: pseudonymised, up to 24 months
  • Backups: rotated continuously and fully purged within 90 days

9.Security

We apply technical and organisational measures appropriate to the sensitivity of the data we hold:

  • All traffic is served over HTTPS, and data is encrypted in transit
  • Passwords are hashed with bcrypt; we never store them in a readable form
  • Two-factor authentication secrets and stored carrier and integration credentials are encrypted at rest with AES-256
  • Session cookies are HTTP-only, Secure and SameSite-scoped, and signed so they cannot be tampered with
  • Role-based access control limits what each team member can see and do inside a workspace
  • Uploaded files are private and served through short-lived, signed links rather than public URLs
  • Cloudflare Turnstile and rate limiting protect claim pages and authentication endpoints
  • Staff access to production data is limited to what is needed for support and operations

No system is completely secure. If a breach affects your personal data, we will notify the supervisory authority and, where required, the people affected, within the deadlines the GDPR sets.

10.International transfers

Our application, database and file storage are hosted in the European Union, with uploads stored in Amsterdam and product analytics on PostHog’s EU Cloud.

Some providers, notably Stripe and Cloudflare, may process limited data outside the European Economic Area. Where that happens, the transfer is covered by an adequacy decision or by the European Commission’s Standard Contractual Clauses together with additional safeguards. You can ask us for details of the safeguards that apply.

11.Your rights

Under the GDPR and comparable laws you have the right to:

  • Access the personal data we hold about you and receive a copy
  • Have inaccurate or incomplete data corrected
  • Have your data erased, where no legal ground requires us to keep it
  • Receive your data in a structured, machine-readable format and have it transferred
  • Restrict processing while a dispute about accuracy or lawfulness is resolved
  • Object to processing based on our legitimate interests
  • Withdraw consent at any time, where processing is based on consent

Write to [email protected] to exercise any of these rights. We respond within 30 days. If your request concerns a claim you submitted, contact the business running the promotion as well, since it is the controller for that data. You also have the right to complain to your local supervisory authority; in the Netherlands that is the Autoriteit Persoonsgegevens.

12.Children

The Donaraz dashboard is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16 through our own services. If a promotion is aimed at minors, the business running it is responsible for obtaining valid parental consent and for meeting any additional local requirements.

If you believe a child has given us personal data, contact [email protected] and we will delete it promptly.

13.Changes to this policy

We update this policy when our processing changes. For material changes we give at least 14 days’ notice by email or through a notice in the dashboard before the change takes effect. The date at the top of this page always shows when it was last revised, and continued use after a change takes effect means you accept the updated policy.

14.Contact

For privacy questions, requests about your data, or details of the safeguards we apply to international transfers, contact us at [email protected] or write to:

Athom / Thom Knepper
G.E.C. Ribbiuslaan 14
3161 HB Rhoon, Netherlands
KvK: 89070399
BTW: NL004687939B33
[email protected]