Privacy Policy — Banny.io
Last updated: 23 april 2026
Banny.io takes the protection of personal data seriously. In this privacy policy we explain which data we collect when you visit our website, download our pricelist, create an account in our web application or become a customer. We also explain how we use that data, who we share it with and what rights you have.
This policy is written for both visitors of banny.io and users of our web application at app.banny.io.
1. Who we are
Banny.io is a B2B software service, operated by:
Banny B.V.
Registered address: Oudezijds Voorburgwal 129-1, 1012 EP Amsterdam, Nederland
Chamber of Commerce (KvK) number: 99624796
VAT number: NL869066146B01
Website: https://banny.io
Web application: https://app.banny.io
Email for privacy questions: info@banny.io
We are the data controller within the meaning of the General Data Protection Regulation (GDPR) for the processing activities described in this policy.
Do you have a specific privacy question, or do you want to exercise one of your rights? Send a message to info@banny.io. We generally respond within 30 days.
2. What data we collect
We only process personal data that is necessary for the purposes set out in this policy. Below we describe, per situation, which data we record.
2.1 Website visitors
When you visit our website, we automatically collect limited technical data such as IP address (shortened or anonymised where possible), browser type, pages visited, referrer and time of visit. We do this through cookies and similar techniques — see section 7.
2.2 Pricelist download (lead form)
When you download our pricelist, we ask for:
Business email address
Company name
We use this data to send you the pricelist and to then add you to our email nurture funnel (a limited series of follow-up emails). You can unsubscribe at any time using the link at the bottom of every email.
2.3 Contact or demo form
If you contact us or request a demo, we process the data you fill in, such as name, email address, company name, job title and the content of your message. We use this data to answer your question and, if applicable, to schedule a demo.
2.4 Account holders in our web application
When you or your employer creates an account on app.banny.io, we record among other things:
Name
Business email address
Company name and (where relevant) job title
Login credentials (passwords are stored in encrypted form)
Usage data from the application (which features are used, timestamps, error messages, technical logs)
This data is necessary to give you access to the service, to make the service work technically and to maintain, secure and improve it.
2.5 Paying customers
For customers with a paid subscription, we additionally process:
Billing details (company name, address, VAT number, Chamber of Commerce number)
Contractual and financial records (invoices, subscription tier, billing history)
2.6 Recipients of marketing and nurture emails
If you are in our email funnel (for example via the pricelist or another sign-up moment), we process your email address, company name and statistics about your email interaction (opens, clicks) through our email provider Brevo. This allows us to send relevant content and to improve our communications.
2.7 Job applicants (optional)
If you apply for a role with us, we process the data you send us (CV, cover letter, contact details) exclusively for the recruitment process. We retain this data for a maximum of 4 weeks after the process concludes, or 1 year if you give us consent to do so.
3. Purposes and legal bases
We only process personal data when there is a valid legal basis. Below is an overview per purpose:
Providing our service (app.banny.io) — Legal basis: performance of the contract with you or your employer. Without this data we cannot deliver the service.
Invoicing and financial administration — Legal basis: legal obligation (including the statutory tax retention) and performance of the contract.
Sending the pricelist and related nurture emails — Legal basis: legitimate interest (direct marketing to business leads who actively asked for information), with a clear option to unsubscribe at any time. For other marketing communications we request explicit consent where required.
Responding to contact or demo requests — Legal basis: legitimate interest or pre-contractual measures.
Analytical and functional cookies on our website — Legal basis: legitimate interest (understanding and improving our website), to the extent these cookies are configured in a privacy-friendly way. For other analytical cookies we request consent via the cookie banner.
Marketing and advertising pixels (Meta, Google, LinkedIn) — Legal basis: consent via the cookie banner. These tags are only loaded after you have given consent. You can withdraw your consent at any time.
Securing our service, fraud prevention and logging — Legal basis: legitimate interest and, where applicable, legal obligation.
Job applications — Legal basis: pre-contractual measures and, for retention after the process, consent.
4. Who we share data with
We do not sell your data. We only share it with parties that help us deliver our service. With all of these parties we sign a data processing agreement (or a comparable arrangement) so that your data remains properly protected.
The main recipients are:
Brevo (Sendinblue SAS, France) — sends our transactional emails (e.g. password reset, account notifications) and marketing emails (including the pricelist and nurture funnel). Brevo also tracks statistics on email interaction.
Meta Platforms Ireland Ltd. (Facebook, Instagram) — we use the Meta Pixel and the Meta Conversions API to measure advertising effectiveness and for remarketing. These tags are only loaded with your consent.
Google Ireland Ltd. (Google Ads) — we use Google Ads conversion tracking to measure campaign effectiveness.
LinkedIn Ireland Unlimited Company — we use the LinkedIn Insight Tag and LinkedIn Ads conversion tracking to measure effectiveness and for remarketing.
Vercel Inc. — hosting partner for our marketing website banny.io and our web application at app.banny.io. Form input (for example pricelist downloads) is processed by our own systems and forwarded directly to our email software. Data is stored in data centres within the EU, unless stated otherwise.
Other processors under a data processing agreement — for example our CRM, support and error monitoring software. These parties process data solely on our behalf and on our instructions.
In exceptional cases we may share data with competent authorities when legally required, or with advisors (accountant, lawyer) to the extent necessary.
5. Transfers outside the EEA
A number of our processors are based in, or have parent companies in, the United States. When your data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:
Meta, Google and LinkedIn — these parties operate under the EU–US Data Privacy Framework (DPF) and/or under Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by appropriate technical and organisational measures.
Brevo is based in the European Union (France). Data storage takes place within the EU.
Vercel Inc. — data is hosted within the EU. Should that change, we will work with SCCs or another valid transfer mechanism.
More information, or a copy of the safeguards used, is available on request via info@banny.io.
6. Retention periods
We do not retain personal data longer than necessary for the purposes for which it was collected. In concrete terms:
Account data of active customers — for as long as the account is active and the contract runs.
Account data after termination — up to 12 months after the end of the contract, unless a legal retention obligation requires us to keep it longer.
Invoicing and financial records — 7 years (Dutch statutory tax retention, art. 52 General Tax Act).
Marketing and nurture emails (Brevo) — until you unsubscribe or after 24 months of inactivity, after which we remove you from our active lists.
Leads from the pricelist form — up to 24 months after the last contact moment, or sooner if you opt out.
Contact / demo requests — up to 12 months after the contact is concluded, unless a customer relationship is established.
Server and application logs — a maximum of 12 months, unless longer retention is necessary for security or legal disputes.
Cookies — see the cookie banner for the retention period per cookie.
Job application data — 4 weeks after the process concludes, or 1 year with consent.
7. Cookies and similar techniques
On our website and in our web application we use cookies and similar techniques (such as pixels and local storage). We distinguish three categories:
Functional cookies — necessary for the website and the application to work properly (e.g. staying logged in, filling in forms). These are always placed.
Analytical cookies — help us understand how our website is used. Where required, we ask for your consent.
Marketing cookies — for advertising and remarketing via Meta, Google and LinkedIn. These cookies and pixels are only placed after you have given your consent via the cookie banner.
You can adjust your cookie preferences at any time via the cookie banner on our website. A complete overview of the individual cookies, their purpose and retention period is available in the cookie settings.
8. Your rights
Under the GDPR you have the following rights:
Right of access — an overview of which personal data we process about you.
Right to rectification — have incorrect data corrected.
Right to erasure ("right to be forgotten") — in certain cases we can delete your data.
Right to restriction — temporarily halting the processing.
Right to data portability — receive your data in a structured, commonly used format.
Right to object — to processing based on legitimate interest, including direct marketing.
Right to withdraw consent — for processing activities for which we rely on your consent (such as marketing pixels).
You can exercise these rights by sending an email to info@banny.io. We may ask you to verify your identity before we handle your request. We generally respond within 30 days.
To unsubscribe from marketing emails you can use the unsubscribe link at the bottom of every email — you do not need to send a separate request for that.
9. Lodging a complaint with the Autoriteit Persoonsgegevens
If you believe we are not processing your data correctly and we cannot resolve this together, you always have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority):
Website: https://autoriteitpersoonsgegevens.nl
Postal address: Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag
We appreciate it if you also get in touch with us via info@banny.io, so that we have the opportunity to resolve your complaint ourselves.
10. Security
We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, unwanted disclosure and unlawful processing. This includes, among other things:
Encrypted connections (TLS/HTTPS) for all traffic to our website and web application.
Encrypted storage of passwords (hashing) and of sensitive data where applicable.
Access control based on the need-to-know principle, with unique personal accounts and, where possible, multi-factor authentication for employees.
Logging and monitoring of our systems.
Regular back-ups and recovery procedures.
Data processing agreements with all of our suppliers.
An internal process for reporting and handling data breaches, in line with the notification obligation to the Autoriteit Persoonsgegevens.
Should a data breach nonetheless occur despite our measures, we will follow our internal procedure and, where necessary, inform the Autoriteit Persoonsgegevens and the people affected.
11. Changes to this policy
We may update this privacy policy from time to time, for example when we introduce new services or when laws and regulations change. The most recent version is always on this page, with the date Last updated at the top. In the case of significant changes, we will inform our customers and email subscribers where reasonably possible.
Last updated: 23 april 2026
12. Contact
Do you have questions about this privacy policy, about how we handle your data, or do you want to exercise one of your rights? Get in touch with us:
Email: info@banny.io
Post: Banny B.V., Oudezijds Voorburgwal 129-1, 1012 EP Amsterdam, Nederland
We are happy to help.