Privacy policy
Updated on 9 September 2026
This policy explains how Jobplan handles personal data about account holders, contacts and people whose information is recorded in a workspace.
Who processes your data?
Jobplan is an application for business planning, jobs and collaboration. Jobplan is provided by B de jager installatie techniek, Dutch Chamber of Commerce (KvK) number 84640537, Biesterlaan 130, 3998 KM Schalkwijk, the Netherlands. Privacy contact: [email protected].
The provider determines how data is processed for its own account administration, service delivery and security. For information entered into a business workspace by your employer or client, that business generally determines the purposes and Jobplan acts as a processor. Instructions and arrangements for processing business content are recorded in a data processing agreement. Ask your employer for its own privacy notice as well.
What information does Jobplan hold?
Depending on how the service is used, we process names, email addresses, roles, account status, sign-in times and secured password hashes. Businesses can record working hours, schedules, leave and sickness notifications, jobs, customer contact details, locations, project members, photos, files and work notes. We also record changes, support activity and subscription status. Information comes from you, business administrators, colleagues and supplied customer information.
A sickness notification can contain health information. Do not enter diagnoses, medical details, Dutch citizen service numbers (BSN) or identity documents in notes or uploads. The employer must determine which records are legally permitted and which employees may access them.
Why do we use data?
We use data to provide access, plan work, share progress and special instructions, make files available, provide support and prevent misuse. For our own service delivery, processing is based on the agreement with the customer; for security and support, it is based on our legitimate interest in providing a reliable service. Statutory administration may be based on a legal obligation. The customer business determines the lawful bases for its employee and customer data.
Who has access?
Accounts belong to a separate business workspace. Roles and configured permissions determine what a person can view and change. If an administrator permits colleagues to view each other's work, customer information, photos and notes may also become visible. An authorised platform administrator can temporarily open a business workspace to provide support; support activity and changes are logged.
We use the following service providers:
- Hetzner: hosts the server running the application and primary business storage.
- Cloudflare: website connectivity and security, plus private R2 storage for off-site file copies and backups.
- Stripe: subscription payments and payment and invoice information. Jobplan receives subscription details and payment status. Full card details are not stored in Jobplan.
- Google Workspace: receiving and sending email, including support enquiries.
The data a provider receives depends on its role. International providers may process data outside the European Economic Area. Such transfers require the applicable legal safeguards. Contact [email protected] for information about processing locations and the safeguards applicable to your data. See also the privacy information provided by Hetzner, Cloudflare, Stripe and Google.
Security and storage
The live website uses HTTPS. Passwords are hashed with a salt; access and changes are checked on the server. Backups also contain personal data. These measures do not completely rule out security incidents.
How long do we keep data?
We retain business content and its associated backups for two calendar months after the confirmed termination of the business workspace or subscription. This includes user accounts, schedules, jobs, project files, photos and work notes. When a subscription is cancelled at the end of the paid period, this retention period starts when the subscription actually ends. A single failed payment or a temporary pause in access does not by itself constitute termination.
After this period, the daily cleanup processes deletion from primary storage, off-site file copies and backups. In a shared backup, only the relevant business workspace is removed; other customers' information is retained. If a technical error occurs, deletion is not recorded as complete and the task must be rerun or checked.
If a subscription becomes active again before deletion, the scheduled cleanup for that termination is cancelled. An explicitly deleted business workspace cannot be restored through ordinary reactivation. Permanently deleted content can no longer be recovered from our cleaned backups. Make sure you have saved the information you need before termination.
After cleanup, we retain only a technical business identifier and the termination and deletion dates to prevent an old copy from being restored unintentionally. This record contains no name, email address, files or schedule.
Financial administration is separate. Information we are legally required to retain for accounting, such as invoices, is kept for the applicable tax retention period. For basic records, this is generally seven years. This does not justify retaining all schedules, photos or employee data. Legal obligations or a specific legal dispute may require a different retention period for the information necessary for that purpose.
Support email is managed separately from the business database. Limit personal data in emails to what is needed for the enquiry and contact us if you want to request deletion that also covers correspondence.
Cookies and local preferences
Jobplan uses a session cookie for sign-in, normally valid for up to 12 hours. With ‘Remember me’, the session remains valid for up to 30 days. After 60 minutes without clicking or typing, the session expires even with ‘Remember me’. Automatic refreshes do not count as activity. Support sessions last up to 30 minutes. Signing out or revoking access may end a session earlier. The browser also stores language, theme and the last-used business link. The application code does not include advertising tracking; infrastructure providers' settings must be checked separately.
Your rights and contact
Depending on the processing, you may request access, correction, deletion, restriction or portability, object to processing and withdraw any consent. For business content, first contact your employer or client; for Jobplan's own processing, contact the privacy contact above. We may request proportionate information to verify your identity. Requests are generally handled within one month; any extension will be explained. You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
The current application does not make solely automated decisions with legal or similarly significant effects. If the service changes, this policy must be updated with a new version date.
Prepared using the information requirements of the GDPR and guidance from the Dutch Data Protection Authority.