Privacy statement
Last updated: 1 October 2026
This statement tells you which data the IVOL app keeps about you. It also tells you why, who sees it and how long we keep it.
1. Who we are
Van den Brink's High Tech Parts B.V. owns the IVOL app. We are responsible for your data in the app.
Van den Brink's High Tech Parts B.V.
Habraken 2327
5507 TK Veldhoven
The Netherlands
Chamber of Commerce (KvK) number 17097673
Do you have a question about your data? Email ryan@ivol.nl.
2. What the app is for
The app keeps you up to date about your work. In the app you can:
- read announcements and confirm that you have read them;
- see tasks and tick them off when they are done;
- find information, such as contacts, documents and links;
- read how to report sick.
Coordinators and admins also write announcements and tasks themselves.
You do not report sick in the app. The app only shows the phone number and the rules. The app does not keep any sick reports.
3. Which data we keep
On our server we keep:
- your name, email address and phone number;
- the language you choose;
- your role (employee, coordinator or admin) and the groups you are in;
- when you last logged in;
- your device: only the make and model, for example Samsung Galaxy A54;
- your push token: a code we use to send notifications to your phone, and which notification categories the app has on your phone;
- if you turn on logging in with fingerprint or Face ID: a hash of the key the app then uses to log you in, whether it is Android or iPhone, when you turned it on and when you last used the app;
- when you first open an announcement (the app counts that as read), and when you confirm that you have read it;
- which tasks you ticked off, and when;
- messages you write yourself, with the attachments you add;
- the log. It records what admins and coordinators do in the panel and in the app, for example creating an account. It also records when you accepted your invitation and when you changed your language. After a failed login to the panel with the emergency password, the log also shows the IP address.
From October 2026, we remove the location and other details about the photo from new JPEG and PNG photos. We have not changed photos from before that. Photos you take with the camera in the app are always JPEG. Other kinds of files, such as HEIC, are stored as they are.
Your phone also keeps a few things itself. This way the app also works without internet.
- the code that keeps you logged in (not your password), in your phone's secure storage;
- if you turn on logging in with fingerprint or Face ID: a key the app uses to log you in again, with your email address and a number for your account. Your phone only releases it after your fingerprint or face. The app never sees your fingerprint or face, and neither do we: your phone checks that itself;
- your own details: name, email address, phone number, language and role;
- a copy of your announcements, tasks, contacts, links and documents;
- messages you are still writing. After 24 hours the app no longer offers them. They stay until you log out or start a new message;
- attachments you have opened, in a temporary folder.
When you log out, the app wipes your data from your phone, including attachments you have opened. A few settings stay, such as the app language. The page about reporting sick also stays.
Have you turned on logging in with fingerprint or Face ID? Then only that key stays. Anyone whose fingerprint or face is on your phone can then log in as you. If you turn it off in Settings, the app wipes it.
4. Why we may do this
We use your data for two reasons:
- We need it for your employment contract. You need to know what happens at work and what you have to do.
- As your employer, we have a legitimate interest in good communication within the company. That means: we need the app to organise the work.
We do not ask for your consent. The app is part of your work. That is why consent is not the right basis.
5. Who sees what
- Colleagues see your name among the contacts, if you are listed there. They then also see what is listed with it, such as a phone number. Admins decide who is on that list.
- Coordinators see, for their own announcements, who read or confirmed them, and when. For their own tasks, they see who ticked them off, and when. They also see whether someone can receive notifications.
- Admins see and manage your account: name, email address, phone number, role and groups. For all announcements and tasks, they see who read, confirmed or ticked off what. They see the log and when you last logged in. Every month they get an email with the name, email address and last login of everyone with an account. And they can pause ordinary notifications for someone.
If you write an announcement or task, the people who receive it see your name with it. Coordinators see the names of the people in their groups when they send something.
Other colleagues do not see whether you have read or ticked off anything.
6. How long we keep data
We do not keep data longer than we need it. Every night the server deletes what is too old. Deleting means it is really gone.
| Data | How long |
|---|---|
| Your account after you leave the company, with everything that belongs to it: groups, rights, read confirmations, ticked-off tasks, notification data, login sessions and invitations | 12 months after your account was closed |
| An announcement or task that was deleted, with translations, attachments, recipients, read confirmations and reminders | 30 days after it was deleted |
| An announcement or task that stays, with everything that belongs to it | 2 years after it was sent |
| Who read or confirmed an announcement | As long as the announcement exists, at most 2 years |
| The log | 2 years |
| Login sessions, invitations and login codes that are no longer valid | 90 days after they expired or were completed |
| The key for logging in with fingerprint or Face ID | 90 days after you last used the app. Sooner if you turn it off while you are online, change your password or your account is closed. Also if we log you out everywhere because someone may have stolen your login. |
| Technical data about notifications that were sent | As long as the announcement or task exists, at most 2 years |
| Attachments that were never sent | 24 hours |
| Contacts | until an admin removes them |
| The counters that limit how often someone can try to log in: email address and IP address. Other IP addresses are sometimes in the log (above) | 1 day |
| Backups | 14 days |
Did you write an announcement or task that stays? Once your account is deleted, it shows that the author is unknown.
Once your account is wiped, the log no longer shows that it was you. We remove your email address from the log.
7. Who processes data for us
These companies process data on our behalf:
- Hetzner (Germany). The app runs on their server. The data is stored there too.
- Expo (United States). Expo sends the push notifications and checks at every start whether there is a new version of the app. Expo then sees your phone's IP address and system. For a notification, Expo receives the title, the name of the author, the first line and, for a task, the deadline.
- Google. Google delivers push notifications to Android phones through Firebase. Google sees the same text in a notification. Google also sends the app's email, such as invitations, login codes and the monthly overview for admins. And Google handles logging in to the admin panel.
- Apple, once there is an iPhone app. Then Apple delivers push notifications to iPhones.
- Anthropic (United States). Anthropic translates the text of announcements and tasks into the other language.
Does data go to the United States? Then this happens under the EU-US Data Privacy Framework or under standard contractual clauses. Those are agreements the European Commission has approved.
8. Your rights
You have these rights:
- see your data;
- have data corrected when it is wrong;
- have data deleted;
- ask us to do less with your data (restriction);
- object to what we do with your data;
- receive your data in a file you can take with you (portability).
Do you want to use one of these rights? Email ryan@ivol.nl. You will get an answer within one month.
Do you disagree with how we handle your data? Then you can file a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.
9. Security
- The app, the panel and the server always talk over an encrypted connection.
- We keep passwords, login codes, invitation links, the code that keeps you logged in and the key for logging in with fingerprint or Face ID only as a hash. A hash is a code from which you cannot get the password or the code back. A login code is only readable until the email with the code has been sent.
- The app writes no IP addresses and no visited pages into the server's log files. Only error messages go there.
- Your phone keeps your login session in its secure storage.