Yuimaru is a product of Progression Workshops, a trade name of the sole proprietorship (eenmanszaak) of Kevin Buoren Shiue, registered with the Dutch Chamber of Commerce under KvK number 93142854, VAT number NL005001145B96, at Munnikenstraat 1 A 4, 2315 KT Leiden, the Netherlands.
Contact for anything in this policy: buoren@vaguely.nl.
We are not required to appoint a Data Protection Officer and have not appointed one. Kevin Buoren Shiue handles data protection matters directly.
This policy explains what we do with data about the people who run events — organizers who create accounts, use the Service, and contact us.
If you are an event attendee, this policy is probably not the one you want.
When you register for someone’s event through Yuimaru, that organizer decides what to ask you and what to do with your answers. They are responsible for your data; we only hold it on their behalf, under a contract that restricts us to acting on their instructions. Ask the organizer for their privacy notice, or contact them directly to exercise your rights. If you contact us and we can identify which organizer you registered with, we will pass your request to them.
Account data. Name, email address, organization name, and the plan you are on. Collected when you sign up. Your sign-in credentials — passkeys or password — are handled by our identity provider, Hanko; we do not receive or store them.
Billing data. Billing name and address, country, and payment references. Invoices are retained for tax purposes. We do not receive or store your card details; those go to our payment provider.
Usage data. Which features you use, when you log in, actions taken in the Service. Used to operate the Service, diagnose faults, and understand which features matter.
Technical data. IP address, browser and device type, and timestamps, in server and application logs.
Support correspondence. Emails you send us and our replies, including anything you tell us in the course of a support request.
Communications preferences. Whether you have opted in to product announcements.
We do not use advertising trackers, and we do not sell or share your data with data brokers. We use no third-party analytics.
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account | To provide the Service you signed up for | Performance of a contract |
| Bill you and keep invoices | To take payment and meet tax obligations | Contract; legal obligation |
| Provide support | To answer your questions | Contract |
| Keep the Service secure and diagnose faults | To protect the Service and its users | Legitimate interests |
| Understand feature usage | To decide what to build and fix | Legitimate interests |
| Send service messages — outages, billing, changes to terms | To keep you informed about the Service you use | Contract; legitimate interests |
| Send product announcements | To tell you about new features | Consent |
| Defend or bring legal claims | To protect our position | Legitimate interests |
Where we rely on legitimate interests, we have considered your rights and concluded our interest does not override them. You may object at any time — see below.
Service messages are not marketing and you cannot opt out of them while you hold an account. Product announcements are optional and every one carries an unsubscribe link.
We use a small number of providers to run the Service. Each is bound by contract to protect your data and to act only on our instructions:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and infrastructure | Germany |
| Hanko GmbH | Account authentication and sign-in | European Union |
| Scaleway SAS | Sending account and service email | France |
| Mollie B.V. | Processing your subscription payment | Netherlands |
| Kees de Boekhouder | Bookkeeping and tax filing | Netherlands |
| Google Cloud EMEA Limited | Serving static files and storing uploaded images | European Union |
We use no error monitoring or analytics provider that receives your data. The current list is maintained at static.getyuimaru.com/docs/subprocessors.
We may also disclose data where the law requires it, or to establish or defend legal claims. If we are ever compelled to hand over data, we will tell you unless we are legally prohibited from doing so.
We do not sell your data. If the business is ever transferred to a successor, your data would transfer with it and we would tell you first.
Your data is stored within the European Economic Area. Our hosting, authentication, email, and file storage all use European regions.
Google, which serves our static files and stores uploaded images, is part of a US-parented group that carries out some support and operational processing outside the EEA. That is covered by Standard Contractual Clauses and by Google’s certification under the EU-US Data Privacy Framework.
If any other provider requires a transfer outside the EEA, we will only make it under an adequacy decision or Standard Contractual Clauses with any necessary supplementary measures, and we will identify it on the provider list above.
| Data | Retention |
|---|---|
| Account and usage data | While your account is active, then 90 days after termination |
| Invoices and billing records | 7 years, as Dutch tax law requires |
| Support correspondence | 2 years from last contact |
| Server and application logs | 30 days; authentication and security events 90 days |
| Backups | Deleted on rotation, currently 30 days |
| Marketing consent records | Until withdrawn, then a record of the withdrawal |
You can ask us to delete your account data sooner. We will, except where we are legally required to keep it — invoices being the main case.
We protect your data using TLS on all connections, encrypted backups, role-based access control, and network isolation between the application and database. Infrastructure access is restricted to Kevin Buoren Shiue and protected by SSH key authentication; account sign-in is handled by our identity provider (Hanko).
We publish our full security measures at static.getyuimaru.com/docs/security.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a high risk to your rights, we will tell you without undue delay.
We use only what the Service needs to work:
We do not use advertising or cross-site tracking cookies, and we use no analytics. Because we use only strictly necessary cookies, we do not display a consent banner.
Under the GDPR you can ask us to:
You can export most of your data yourself from within the Service at any time. For anything else, email buoren@vaguely.nl. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Dutch data protection authority:
Autoriteit Persoonsgegevens
Postbus 93374, 2509 AJ Den Haag
autoriteitpersoonsgegevens.nl
If you live in another EU country, you may complain to your local authority instead.
The Service calculates prices, applies discounts, and can gate registration on eligibility criteria — but those rules are configured by event organizers, not by us, and they apply to attendees rather than to organizer accounts.
We do not make automated decisions about you that produce legal effects or similarly significantly affect you.
The Service is for people organizing events and is not directed at children. We do not knowingly collect data from anyone under 16 in an organizer capacity.
Attendees may include children where an organizer runs events for them. In that case the organizer is responsible for parental consent and for handling that data lawfully.
We may update this policy. If a change materially affects your rights we will tell you by email at least thirty days before it takes effect. The version and date at the top always show the current one, and previous versions are available on request.