MySubs

Privacy policy

Last updated: 4 September 2026

1. Who we are

MySubs (mysubs.nl) is a platform for member administration, memberships, prepaid strip cards and access with a digital membership pass. We provide the service through the website, the organisation dashboard and the My Subs app.

Address: Gieskesstraat 43A, 7554 LB Hengelo, the Netherlands. Chamber of Commerce (KvK): 93173962. Privacy questions: info@mysubs.nl.

2. Who is responsible

There are two roles, depending on how you use MySubs.

The organisation (club, association, foundation or business) you belong to is the controller for your member data: name, contact details, address, memberships, door scans and payment status. MySubs processes that data as a processor on the organisation’s instructions.

MySubs is the controller for organisation-admin accounts, for use of the website and app (sign-in, security, support) and for data we need to provide and bill the service to organisations.

For access, correction or deletion of member data, start with the organisation. You can delete your MySubs account in the app or email info@mysubs.nl.

3. What we process

Depending on how you use MySubs, we may process:

  • Members: first name, last name, email, phone number, date of birth, address (street, postcode, city, country), profile photo if uploaded, memberships, prepaid cards and tickets.
  • Organisation admins: name, email, password (hashed), optional two-factor authentication, organisations you are linked to.
  • Access: rotating pass codes, door scans (time, organisation, granted or denied).
  • Payments: whether a payment or direct debit succeeded, via Mollie on the organisation’s account. We do not store full bank or card numbers for collection.
  • App and sign-in: device name, session/access tokens, one-time login codes by email.
  • Website: technical server logs (such as IP address) for as short as reasonable.

4. Why, and on what basis

We process data to provide the service: accounts, member administration, scanning passes, memberships and prepaid cards, and payments via Mollie.

Legal bases: performance of a contract (organisation subscription or membership with an organisation), legitimate interest (security, abuse prevention, improving the service) and legal obligation where it applies. Where we rely on consent (for example an optional photo), you can withdraw it.

5. Camera in the app

The camera is used only to scan a membership pass (QR code) at the door. We do not record photos or video for this purpose and we do not use the microphone. Scans are stored with the organisation as an access event, not as camera footage.

6. Payments (Mollie)

If an organisation charges for memberships or cards, payment runs through Mollie B.V. on that organisation’s Mollie account. Money goes from the member to the organisation, not to MySubs (except any platform fee the organisation pays us). Mollie’s own privacy statement: https://www.mollie.com/privacy.

7. Who we share data with

We do not sell personal data. We share data only where needed:

  • With the organisation you belong to or administer.
  • With Mollie for payments, if the organisation has connected it.
  • With hosting, email and infrastructure providers that run the service, under confidentiality terms.
  • With Apple or Google if you install the app from their store; they process their own store data.
  • If the law requires us to.

8. Retention

We keep member and transaction data while the organisation uses the environment and thereafter as needed for administration or disputes. If you delete your account in the app, we delete your login account. Data the organisation must keep for legal or accounting reasons (for example payment history) may remain with that organisation until they erase it or close their environment.

9. Security

Access uses encrypted connections (HTTPS). Passwords and login codes are not stored in readable form. Organisation admins can enable two-factor authentication. Membership passes rotate so a screenshot does not stay valid.

10. Your rights

You have rights of access, rectification, erasure, restriction, portability and objection under the GDPR. Members can delete their MySubs account in the app. For member data held by an organisation, contact that organisation or info@mysubs.nl. You can complain to the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

11. Cookies and embedded services

The marketing site uses functional scripts (including fonts and layout). We do not set advertising cookies. If we add analytics cookies later, we will say so here.

12. Minors

Organisations may also enrol youth members. The organisation is responsible for parental or guardian consent where the law requires it. The app is not a social network for children.

13. Transfers outside the EEA

We prefer to host in the EU. If a provider processes data outside the European Economic Area, we do so only with appropriate safeguards (such as an adequacy decision or standard contractual clauses).

14. Changes

We may update this policy when the service or the law changes. The date at the top applies. For material changes we inform organisations through the service or by email.

info at mysubs.nl· Terms of use· Support

Privacy policy