TelMaar privacy statement
Last updated: 18 August 2026
This is a translation for your convenience. In case of any discrepancy, the Dutch text prevails.
This privacy statement explains how Mega Software (“we”, “us”) processes personal data within TelMaar, our financial administration platform. It applies to relations (customers, suppliers and their contact persons) whose data we process for the purposes of our services.
1. Who we are
Mega Software, established in The Hague, registered with the Dutch Chamber of Commerce under number 94577056, is the controller for the personal data processed within TelMaar.
2. Purposes of processing
We process personal data solely for the following purposes:
- Keeping the financial administration (bookkeeping, bank transactions, journal entries).
- Invoicing: drawing up, sending and collecting quotes and invoices.
- Customer relationship management: maintaining the customer and supplier file, correspondence and tasks.
- Complying with legal obligations, including tax and administrative retention duties.
3. Legal basis
Processing is based on one or more of the following legal bases under the GDPR:
- Performance of a contract (article 6(1)(b) GDPR), such as delivering a product or service.
- Legal obligation (article 6(1)(c) GDPR), such as the statutory retention duty for tax purposes.
- Legitimate interest (article 6(1)(f) GDPR), such as maintaining the customer relationship and preventing fraud.
4. Categories of personal data
Depending on the relation, we may process the following data:
- Name and address details, email address(es) and telephone number(s) of contact persons.
- Position or role within the organisation of the relation.
- Company details such as Chamber of Commerce and VAT numbers, insofar as these are traceable to a natural person, for example in the case of sole traders.
- Financial data relating to quotes, invoices and payments (amounts, payment status, IBAN in the case of manual payment).
- Notes, activities and tasks linked to the file of the relation.
- Login details of customer portal users (email address, session data).
5. Retention periods
Personal data is kept no longer than necessary for the purpose of the processing, taking statutory retention duties into account. For the financial administration (invoices, quotes, entries and underlying supporting documents) a statutory retention period for tax purposes of 7 years applies in the Netherlands. This data is retained for that period, including after an erasure request by the data subject (see article 6).
Other personal data not covered by the retention duty is deleted or anonymised as soon as it is no longer necessary, or earlier at the request of the data subject.
6. Rights of data subjects
Under the GDPR, data subjects have the following rights:
- The right of access to the personal data processed about them.
- The right to rectification of inaccurate or incomplete data.
- The right to erasure (the “right to be forgotten”), within the limits of the statutory retention duty: personal data outside the financial administration is deleted or anonymised; data that forms part of the financial administration is retained until the end of the statutory retention period but is no longer used for other purposes.
- The right to restriction of processing and the right to object.
- The right to data portability, insofar as applicable.
- The right to lodge a complaint with the Dutch Data Protection Authority.
A request can be submitted using the contact details under article 11. We respond within the statutory period of one month.
7. Sub-processors
To provide our services we use the following sub-processors, which may process personal data on our behalf:
- Supabase: database, authentication and file storage.
- Vercel: hosting and execution of the application.
- Resend: sending transactional email.
- Stripe: processing online payments.
- Mollie: processing online payments, including iDEAL.
- Cloudflare: security, DNS and content delivery (CDN).
- Anthropic: processing the questions and documents submitted through the assistant (see article 9).
Appropriate arrangements on the protection of personal data have been made with every sub-processor, laid down in a data processing agreement where applicable.
8. Transfers outside the European Economic Area
Our processing takes place within the EEA in principle. A number of the sub-processors listed in article 7 are established in the United States or may provide support from there. Insofar as personal data is processed outside the EEA in that context, this takes place on the basis of an adequacy decision of the European Commission (including the EU-US Data Privacy Framework) or on the basis of the standard contractual clauses (SCCs), supplemented by appropriate technical measures such as encryption in transit and at rest.
9. Assistant and automated decision-making
TelMaar includes an assistant that answers questions in plain language, reads receipts and invoices, and proposes bookings and planning. For that purpose the question asked and the data or documents concerned are processed by Anthropic. The assistant is available only to users with a financial role; other users have no access to it.
The assistant only makes proposals. A booking, invoice or payment is created only after a user confirms it. There is therefore no decision-making based solely on automated processing that produces legal effects or similarly significantly affects the data subject, as referred to in article 22 GDPR. The data submitted is not used to train third-party models.
10. Visitors to our website and cookies
Anyone visiting telmaar.nl without signing in leaves behind only the data that is technically needed to display the page. We place only strictly necessary and functional cookies and use no analytics, advertising or tracking cookies. Exactly which cookies these are, for what purpose and how long they are kept, is set out in our cookie statement.
If someone completes the contact form, we process the name, email address, any company name and the message provided in order to answer that question. The basis is our legitimate interest in being able to respond to messages. These messages arrive in our email environment and are not used for unsolicited advertising.
11. Security and contact
We take appropriate technical and organisational measures to protect personal data against loss or unlawful processing. For details, see our data processing agreement.
For questions about this privacy statement or to exercise your rights, you can contact us:
- Email: privacy@telmaar.nl
- Mega Software, established in The Hague, Chamber of Commerce number 94577056.
12. Changes
We may amend this privacy statement from time to time. The most recent version is always available on this page.