Both documents in one place, written in plain English and kept short enough that reading them is realistic.
Effective
Last updated
Version
3.2
Entity
Northwind Labs BV
Template notice. This page is placeholder copy supplied with the SaaS Launch Kit. It is written to look and read like a real policy so you can see the layout in context — it is not legal advice and must be replaced with documents reviewed by a qualified lawyer in your jurisdiction before you publish.
Privacy policy
This policy explains what Northwind Labs BV (“Northwind”, “we”, “us”) does with personal data when you visit our website, sign up for an account, or use our services. It is written to be read, not to be survived.
We act as a controller for data about our own website visitors and account holders, and as a processor for the customer data our clients send into the platform. Where we act as a processor, our customer’s own privacy policy and our Data Processing Addendum govern that data.
Data we collect
Information you give us
Account details — name, work email address, company name, job title and password hash.
Billing details — billing address, VAT number and the last four digits of your payment card. Full card numbers are handled by our payment processor and never reach our systems.
Communications — support tickets, emails and anything you send us through a form.
Information we collect automatically
Product usage — pages viewed, features used, and actions taken inside the application, tied to your account.
Technical data — IP address (truncated after 30 days), browser type, operating system, and referring URL.
If you sign in with a single sign-on provider, we receive your name, email address and directory group membership from that provider. If your company is enriched from a public business database, we may receive firmographic attributes such as industry and headcount.
How we use data
We use personal data to provide and secure the service, to bill you, to support you, and to improve the product. Specifically:
Creating and administering your account and workspace.
Delivering the features you have configured, including notifications and integrations.
Detecting, investigating and preventing fraud, abuse and security incidents.
Sending service messages about outages, security matters and material changes.
Sending product updates and marketing, where you have opted in or where we have a legitimate interest and you have not objected. Every marketing email has a one-click unsubscribe.
Producing aggregated, de-identified statistics about how the product is used. These can never be re-identified to a person.
We do not sell personal data. We do not use customer data to train shared machine learning models, and we do not share it with advertising networks.
Legal bases for processing
Where the GDPR applies, we rely on the following legal bases:
Purpose
Legal basis
Providing the service under our terms
Performance of a contract
Billing and financial record keeping
Legal obligation
Security, fraud prevention and abuse detection
Legitimate interests
Product improvement using aggregated data
Legitimate interests
Marketing communications
Consent, or legitimate interests where permitted
Optional analytics cookies
Consent
Sharing and disclosure
We share personal data only in these circumstances:
Sub-processors who provide infrastructure and tooling on our behalf, listed below and bound by written data protection terms.
Within your workspace — other members of your workspace can see your name, email and activity in the audit log.
Legal requirements — where we are compelled by valid legal process. We will notify you unless legally prohibited, and we publish an annual transparency report.
Corporate transactions — in a merger or acquisition, subject to the acquirer honouring this policy. We would notify you at least 30 days ahead.
Sub-processors
The following third parties process personal data on our behalf. We notify customers by email and RSS at least 30 days before adding or replacing any sub-processor, and you may object during that window.
Sub-processor
Purpose
Location
Amazon Web Services
Cloud infrastructure & storage
Ireland (eu-west-1) / USA (us-east-1)
Cloudflare
CDN, DNS and DDoS protection
Global edge
Stripe
Payment processing
USA, EU
Twilio SendGrid
Transactional email delivery
USA, EU
Zendesk
Customer support ticketing
EU (Frankfurt)
Datadog
Application monitoring and logs
EU (Paris)
Snowflake
Internal analytics warehouse
EU (Frankfurt)
International transfers
Workspaces created in the EU region store customer data exclusively in the European Economic Area. Where personal data is transferred outside the EEA — for example, when our US-based support team assists you — we rely on the European Commission’s Standard Contractual Clauses, supplemented by encryption in transit and at rest, and by access controls that restrict support access to the minimum necessary.
Retention
Category
Retention period
Account records
Duration of the contract, plus 90 days
Customer event data
As configured by the customer; deleted within 30 days of contract end
Billing and invoicing records
7 years, as required by Dutch tax law
Support conversations
3 years from last contact
Security and audit logs
12 months
Backups
35 days, rolling
Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict the processing of your personal data, and to object to processing based on legitimate interests. You may also withdraw consent at any time without affecting processing that already happened.
To exercise any right, email privacy@northwind.example.com. We respond within 30 days and do not charge a fee. If you are unhappy with our response, you may complain to your local supervisory authority; ours is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
If you are a member of a customer workspace, we may need to refer your request to that customer, who is the controller of that data. We will tell you if that happens.
Cookies
We use a small number of cookies. Essential and preference cookies are set without consent because the service cannot function without them or because they simply store a choice you made. Analytics cookies are set only if you opt in.
Name
Category
Purpose
Duration
nw_session
Essential
Keeps you signed in.
Session
nw_csrf
Essential
Protects forms against cross-site request forgery.
You can change your cookie preferences at any time from the footer of any page, or block cookies entirely in your browser. Blocking essential cookies will sign you out.
Security
We maintain an information security programme certified to SOC 2 Type II and aligned with ISO 27001. Controls include encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access with mandatory multi-factor authentication, annual third-party penetration testing, and a formal incident response process.
In the event of a personal data breach affecting your data, we will notify affected customers without undue delay and within 72 hours of becoming aware, with what we know at the time and what we are doing about it.
Changes to this policy
We will post any changes on this page and update the “last updated” date. For material changes we will email account owners at least 30 days before the change takes effect. Previous versions are available on request.
Terms of service
These terms form a binding agreement between you (“Customer”) and Northwind Labs BV, registered in Amsterdam, the Netherlands (KvK 84120993). By creating an account, signing an order form, or using the service, you agree to them.
If you are agreeing on behalf of a company, you confirm you have authority to bind that company. Where a signed order form or master services agreement exists, it takes precedence over these terms to the extent of any conflict.
Accounts and access
You are responsible for the activity of every user in your workspace and for keeping credentials secure.
You must be at least 18 and legally able to enter into a contract.
Workspace owners may add, remove and change the permissions of users at any time.
You must notify us promptly at security@northwind.example.com if you suspect unauthorised access.
Acceptable use
You agree not to, and not to permit anyone else to:
Use the service unlawfully, or to store or transmit unlawful, infringing or malicious material.
Send us special categories of personal data — health, biometric, or financial account data — unless we have agreed to it in writing.
Reverse engineer, decompile, or attempt to derive the source code of the service, except where that restriction is prohibited by law.
Resell, sublicense or provide the service as a standalone offering to third parties.
Probe, scan or test the vulnerability of the service without our written permission. Our responsible disclosure programme is the sanctioned route.
Circumvent usage limits, or use automated means to place unreasonable load on the service.
We may suspend access without notice where continued use presents a security risk, a legal risk, or a material threat to service availability for other customers. We will restore access as soon as the cause is resolved.
Fees and billing
Fees are as stated on our pricing page or in your order form, exclusive of VAT and other applicable taxes.
Monthly plans renew monthly; annual plans renew annually. Both renew automatically unless cancelled before the renewal date.
Upgrades take effect immediately and are prorated. Downgrades take effect at the next renewal.
Invoices are due on receipt for card payments and within 30 days for invoiced accounts. We may suspend the service on accounts more than 30 days overdue after written notice.
We may change prices with 60 days written notice, effective at your next renewal. Your current term is never repriced mid-term.
Fees are non-refundable except as set out in our 30-day satisfaction guarantee or where required by law.
Customer data and data processing
You retain all rights in the data you send to the service (“Customer Data”). You grant us a limited licence to host, process and transmit Customer Data solely to provide the service, to support you, and to comply with law.
Where Customer Data contains personal data, our Data Processing Addendum applies and is incorporated into these terms by reference. Under it we act as your processor, process only on your documented instructions, maintain appropriate technical and organisational measures, and assist with data subject requests and impact assessments.
On termination we make Customer Data available for export for 30 days, after which it is deleted from active systems within 30 days and from backups within 35 days. We will certify deletion in writing on request.
We may use aggregated, de-identified data derived from use of the service to operate and improve it. Such data never identifies you, your users or your customers, and is never shared in a form that could.
Intellectual property
We retain all rights in the service, including software, documentation, designs and trademarks. These terms grant you a non-exclusive, non-transferable right to use the service during your subscription term, and nothing more.
If you send us feedback or suggestions, you grant us an unrestricted right to use them without obligation or compensation. We will not identify you as the source without your permission.
Confidentiality
Each party may receive information from the other that is marked confidential or that a reasonable person would understand to be confidential. Each party agrees to protect the other’s confidential information with at least the care it uses for its own, to use it only in connection with this agreement, and to disclose it only to personnel and advisers with a need to know who are bound by equivalent obligations. These obligations survive for three years after termination, and indefinitely for trade secrets.
Warranties and disclaimers
We warrant that the service will perform materially in accordance with our documentation, and that we will provide it with reasonable skill and care. On the Scale plan we additionally warrant 99.9% monthly uptime, with service credits as the exclusive remedy for failure to meet it.
Except as expressly stated, the service is provided “as is”. To the maximum extent permitted by law we disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose and non-infringement. We do not warrant that the service will be uninterrupted or error-free, or that the signals it produces will be accurate predictions of customer behaviour. Northwind supports commercial judgement; it does not replace it.
Limitation of liability
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, goodwill or data, however caused.
Each party’s total aggregate liability arising out of this agreement is limited to the fees paid or payable by you in the twelve months preceding the event giving rise to the claim.
These limits do not apply to: your obligation to pay fees; either party’s indemnification obligations; breach of confidentiality; or liability that cannot be limited by law, including death or personal injury caused by negligence, and fraud.
Term and termination
Either party may terminate for convenience at the end of the then-current subscription term by giving notice before renewal.
Either party may terminate immediately for material breach that remains uncured 30 days after written notice.
Either party may terminate immediately if the other becomes insolvent or enters administration.
On termination your right to use the service ends, and the export and deletion process in the data section applies.
Sections covering fees accrued, confidentiality, intellectual property, disclaimers, liability and governing law survive termination.
Governing law and disputes
These terms are governed by the laws of the Netherlands, without regard to conflict of law rules. The courts of Amsterdam have exclusive jurisdiction, except that either party may seek injunctive relief in any court of competent jurisdiction to protect its intellectual property or confidential information.
Before filing a claim, each party agrees to attempt resolution in good faith by escalating to senior representatives for 30 days. Nothing in this section limits any consumer rights you may have under mandatory local law.
Changes to these terms
We may update these terms to reflect changes in the service or the law. Material changes are notified to account owners by email at least 30 days before taking effect, and take effect at your next renewal. If you do not accept a material change, you may terminate before it takes effect and we will refund any prepaid fees for the unused portion of your term.
Questions about these terms? Write to legal@northwind.example.com or Northwind Labs BV, Keizersgracht 241, 1016 EA Amsterdam, the Netherlands.