As soon as you contact Toppi B.V. (hereinafter: ‘Toppi’), we may receive personal data. Personal data is all data that can be traced back to an individual, such as name or telephone number. Would you like to know more about personal data, please visit the website of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). In this privacy statement, we explain what we do with that information. We always handle your information carefully and store it securely. If you have questions or want to know what information we have about you, please contact us. This privacy statement is specifically aimed at business clients (B2B) and their employees. Toppi does not provide services to private individuals. We may adjust this privacy statement if we deem it necessary. This privacy statement was last modified on 09-07-2026.
1. When does this privacy statement apply?
This privacy statement applies to all personal data that Toppi processes in the context of its B2B services, including AI-driven local marketing solutions, reputation management, and automation of online tasks.
2. Who uses my data?
Toppi is responsible for the use of your personal data as described in this privacy statement. The full details are: Toppi B.V. Keizersgracht 467, 1017DK Amsterdam Chamber of Commerce number 97851590
3. Whose data do we use?
We process the personal data of anyone who has been in contact with us. These are exclusively business clients. We process personal data of contact persons at our business clients, such as employees, decision-makers, and other parties involved in the execution of the agreement.
4. How do we obtain your data?
We receive the data directly from you as soon as you contact us via email, website, telephone, or in any other way. In addition to direct contact moments (email, telephone, etc.), we can also receive personal data via our website, online forms, or from third parties (e.g., payment processors) in the context of the execution of our services.
5. What data do we use from you?
We make use of the following data:
- name;
- business address;
- email address;
- telephone number;
- payment details; and
- financial data
In addition to the mentioned data, we can also process the following data, if relevant to the service provision:
- IP addresses and log files (for security and optimization of our services);
- recordings of sessions during platform interaction, capturing screen activity and peripheral movements; data entered into fields remains obscured;
- data about interactions with our AI models (e.g., input and output of automation processes), insofar as this data does not contain special categories of personal data;
- login details and access means, including API keys and access tokens, insofar as necessary to establish and maintain links with the Client’s accounts or systems.
6. For what do we use your data?
We use your personal data exclusively for the following purposes:
- Executing the agreement with you or your organization, including delivering AI-driven marketing services, reputation management, and automation of online tasks;
- Communication regarding our services, invoicing, and customer service;
- Optimization and improvement of our services, including training and fine-tuning AI models, whereby personal data is used only if necessary and based on a valid legal ground; where possible, data is anonymized;
- Compliance with legal obligations, such as tax retention periods; and
- Security and fraud prevention.
7. How long do we keep your data?
We keep your personal data as long as we are required to do so by law and as long as necessary for the purpose for which we use your data. We apply the following retention periods:
- Invoice and payment data: 7 years. This period is based on the legal tax and administrative retention period.
- Contact details and communication: during the customer relationship + 2 years. During the customer relationship, contact details and communication are necessary for the execution of the agreement. After termination of the customer relationship, we keep this data for 2 more years to allow for potential disputes, warranty claims, or compliance with legal obligations (e.g., handling complaints).
- Usage data and log files: maximum 12 months, unless necessary for security purposes. Usage data and log files are primarily used for system optimization, security, and fraud prevention. A period of 12 months is sufficient to analyze trends and investigate security incidents. If there is a security incident (e.g., a data breach), log files can be kept longer as evidence for investigation or legal purposes.
- Data for statistical purposes: unlimited, provided it is fully anonymized and not traceable to individuals. Anonymized data does not fall under the GDPR because it is not traceable to individuals. This data can be kept indefinitely for statistical analyses, provided it meets the requirements of anonymization (e.g., aggregation, pseudonymization with key destruction). Would you like to know more about how long we keep specific data of yours, please contact us.
8. With whom do we share your data?
Your personal data is used only by us as much as possible. We only share your personal data with third parties if this is necessary for the execution of our agreement with you or if we are legally obliged to do so. Examples include:
- Payment processors (e.g., for invoicing). For processing payments, we use third parties such as Stripe. Such third parties process personal data on our behalf and in accordance with applicable privacy legislation;
- Cloud providers and IT service providers (e.g., for hosting and security);
- Analytics providers (e.g., for platform optimization and product analysis). We utilize PostHog for this purpose, which processes this data on our behalf on servers located within the European Union;
- Government agencies (if legally required). Insofar as these parties process personal data on behalf of Toppi, they qualify as processors and Toppi enters into a data processing agreement with these parties in accordance with applicable privacy legislation. In other cases, such third parties may be independent data controllers, for example when they determine their own purposes and means for processing (such as payment service providers or external platforms). In such cases, Toppi is not responsible for the processing of personal data by these parties. The Client acknowledges that these parties apply their own privacy terms and that the Client may have their own (direct) relationship with these parties. Insofar as personal data is transferred to parties outside the European Economic Area, Toppi ensures as much as possible that this happens in accordance with applicable laws and regulations, for example by using model contract clauses approved by the European Commission or other appropriate safeguards.
9. Where do we store your data?
Our primary data storage and processing takes place within the European Economic Area (EEA). If we use service providers outside the EEA, we ensure appropriate safeguards, such as EU Standard Contractual Clauses or Binding Corporate Rules.
10. How secure is your data with us?
We have done a great deal to secure your data as well as possible, both organizationally and technically. We have secured our systems and various means of communication to ensure that your data does not end up in the hands of others. We have taken, among others, the following technical and organizational measures in the sense of Article 32 of the GDPR to protect your data:
- Data encryption;
- Access management and authentication;
- Regular security audits and penetration tests; and
- Training of employees in the field of data protection. Do you have questions about the specific way of securing, please contact us.
11. What may you ask of us?
Because we use personal data of you or your organization, you have various rights. We list these rights for you below.
- Right to information We must explain to you in an understandable and clear way what we do with your data and what control you have over it. Therefore, we explain extensively in this privacy statement which data we collect from you and how we handle your data.
- Right of access You may always ask us to view the data we have about you.
- Right to correction You may ask us to have your data corrected if it is incorrect or incomplete.
- Right to object You may object to the processing of your data if you do not agree with the way we handle your personal data.
- Right to data portability Are you a client of ours or have you given permission for the use of your data, then you may ask us to send you the digital data we have about you. This way you can transfer that data to another organization if you wish.
- Right to restriction You may ask us to restrict the use of your data. This means that in certain cases we may only store your data but not use it.
- Right to be forgotten You may ask us to delete all data we have about you. We will then delete all data that is traceable to you. In some cases, we cannot or may not delete your data yet. For example, we must keep some data for 7 years for the tax authorities.
- Right to file a complaint
You may file a complaint about the way we handle your data. If you have a complaint, we would like to resolve it for you. Please contact us for this. You may also lodge your complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Of course, we hope it does not come to that, but in the extreme case, you may also go to court. In that case, it is the court in the registered office of Toppi that will handle your complaint. For business clients, it applies that you can exercise these rights on behalf of your employees, insofar as you are legally authorized to do so and this is in accordance with the GDPR.
12. How do I submit a request or complaint?
Send your request or complaint to us via info@toppi.io. We will process your request or complaint within 30 days. If it concerns multiple requests or complaints or if your request or complaint is complex, this may take more time. In that case, we will contact you within 60 days at the latest. We may ask you to identify yourself. In that case, we ask for data to be sure that you are the right person whose personal data it is or that you have the authority to represent the persons whose personal data it is.
13. Which rules apply to this privacy statement?
Our privacy statement must meet various conditions. You can find these conditions in particular in the General Data Protection Regulation (GDPR). In addition to the GDPR, we adhere to the Dutch Implementation Act GDPR and other applicable laws and regulations in the field of data protection.
14. What do we do with data of minors?
As an organization, we focus only on (adult) business clients. If we inadvertently process personal data of minors in the context of a business relationship, we will delete this data immediately, unless we have received permission from a parent or guardian.
15. Do you have a question about this privacy statement?
Do you have a question about our privacy statement? Please feel free to contact us by sending an email to info@toppi.io. We are happy to help you.
16. Cookies, Analytics, and Session Recording
Toppi utilizes cookies and equivalent technologies on its website to a limited extent. These are employed exclusively for functional requirements and, where applicable, for analytical purposes to evaluate and enhance the user experience on our website. For product analytics within our platform, we engage PostHog. PostHog deploys cookies and similar technologies to process the following data:
- details regarding page visits and utilized features;
- technical specifications such as browser type, hardware, language, and IP address;
- error reports produced by the platform; and
- recordings of sessions during platform interaction, capturing screen activity and peripheral movements. This data is utilized solely to comprehend platform usage, troubleshoot technical incidents, and refine our Services. Sensitive information, including passwords and text entered into input fields, remains obscured within your browser and is never disclosed to PostHog. PostHog operates as a processor for Toppi under a formal data processing agreement, maintaining data on servers situated within the European Union. Session recordings are retained for a maximum of 30 days, while other analytical data is kept for up to 12 months, consistent with the usage data retention policy in Article 7. You may object to such processing at any time by contacting info@toppi.io. Where legally mandated, we will solicit your prior approval before deploying non-essential cookies. You maintain the right to deactivate cookies through your browser configuration.
17. Changes to this privacy statement
We reserve the right to amend this privacy statement. Amendments will be published on our website and, if applicable, communicated to you via email. The use of our services after an amendment counts as acceptance of the amended terms.