Skip to content
Privacy & security

Steering on trust starts with trust in the system

An Obeya holds the core of what an organisation is working on: goals, obstacles, decisions. We believe you should be able to decide who can reach that: people and AI alike.

In short

  • What is processed: names and email addresses of staff, and the work a team puts into the software: boards, cards, journals and e-learning answers. Plus the contact and billing details of customers.
  • Who can reach it: the organisation decides for itself who sees what. Private boards are for members only, and even our own administrators cannot enter without a temporary access request that the board's Navigator approves.
  • How long it is kept: sent emails and the card bin 30 days by default, the audit log 400 days by default, account details as long as the account exists and billing details as long as the law requires.
  • How the AI connection works: the AI follows the user's permissions and can see no more than that user can. Private boards are out of reach for any AI, and a connection can be withdrawn at any moment.

Access that you decide

The organisation decides for itself who sees what. Boards are visible within your own organisation by default; teams can be set as a real access boundary, and boards are only shared where that is done deliberately: to look along or to work together.

For sensitive subjects there are private boards: accessible to members only, extra protected with a password and not shareable outside that circle. Even our own administrators cannot enter without a temporary access request that the board's Navigator approves by email, and then only to look along, for a few hours.

AI without a back door

The AI connection follows the user's permissions: the AI can only reach what that user is allowed to see. Private boards are fully shielded from the AI connection; that boundary is laid down in the system itself and cannot be worked around. A connection or key can be withdrawn at any moment.

Careful with personal data

We handle personal data carefully, in line with the GDPR. Deleted information can be restored for a limited period and is then permanently cleaned up, and anyone who leaves the organisation can be anonymised on request. We are happy to answer questions about data processing in a conversation.

Privacy statement

Who processes what

This statement describes how Wendbaarsturen processes personal data, as the GDPR requires.

For the data that customer organisations put into the software (names and email addresses of staff, boards, cards, journals, e-learning answers) the customer organisation is the controller and Wendbaarsturen is the processor: we process that data only to deliver the service, and we make no decisions about it ourselves.

For our own administration (contact and billing details of customers, requests through the website) Wendbaarsturen is itself the controller.

Purposes and legal bases

  • Delivering the service (accounts, boards, training, e-learning, email with sign-in links): necessary for the performance of the contract.
  • Security and accountability (the audit log per organisation: who did what, when; never the content of the work): legitimate interest; an organisation has to be able to answer that question about itself.
  • Billing and customer contact: performance of the contract and a legal (tax) obligation.
  • Improving the screens: our own usage measurement in our own database, without user id, IP address or free text; no external analytics, no advertising, no profiling. Legitimate interest, and it can be switched off per organisation (Organisation → Settings → Way of working).

How long we keep things

Cleaning up happens automatically, every day:

  • sent emails: 30 days;
  • live session data (participants, votes, attendance): 30 days;
  • the card bin: according to the organisation's own term, 30 days by default;
  • the audit log: according to the organisation's own term, 400 days by default;
  • individual usage measurements: 30 days, after that only daily totals without identifiable data (up to 400 days);
  • expired sessions, sign-in links and connection tokens: immediately during the daily clean-up.

We keep account details for as long as the account exists; billing details for as long as the law requires.

Where the data is held

All customer data is held in one database in the European Union and the application runs on servers in Frankfurt. We use these sub-processors:

  • Neon (database, EU): the place where everything is held, encrypted at rest;
  • an object store in the EU with a provider other than Neon and Vercel, for a nightly, encrypted copy of the database (the back-up); that provider cannot read the content. The copy is made by GitHub, which briefly processes the data in doing so but does not keep it;
  • Vercel (hosting, functions in Frankfurt) and Vercel Blob (file storage);
  • Resend and as a fallback Strato, Germany (sending invitation and system email);
  • Anthropic (US) for our own AI functions: creating training and demonstration material. Your data does not pass through there. We do not put AI to work on the content of your boards. If you want an AI assistant working on your boards, you connect your own Claude or ChatGPT; that data then goes to your AI supplier, not to ours. Private boards are out of reach for any AI. That boundary sits in the system itself.

We never share data with third parties for advertising or for our own purposes.

Your rights

Everyone whose data we process has the right to access, rectification, erasure, restriction, portability and objection.

If you work at a customer organisation, address your request to the administrator of your own organisation. They are the controller and can, among other things, have your account anonymised: your name and email address then disappear permanently from the software and the log, while the team's work history stays intact.

If you cannot resolve it with your organisation, or if it concerns data for which Wendbaarsturen is itself responsible, get in touch with us. You also always have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, via autoriteitpersoonsgegevens.nl.

Data breaches and vulnerabilities

If we discover a data breach that poses a risk, we report it without undue delay to the organisations affected and, where the law requires it, within 72 hours to the Autoriteit Persoonsgegevens. Found a security problem? Report it to us directly and not publicly; the current reporting route is on wendbaarsturen.nl/.well-known/security.txt and our agreements with reporters are on Report a vulnerability.

This statement was last updated on 4 September 2026.