Addrow / Privacy Policy
Privacy Policy
Last updated: August 9, 2026
1. Introduction
Welcome to Addrow (“we”, “our”, or “us”), a service provided by vanrossum.dev, a company registered in The Netherlands. We are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (GDPR/AVG) and other applicable Dutch and European privacy laws.
This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our service at https://addrow.io.
2. Data Controller
The data controller responsible for your personal data is:
- Company: vanrossum.dev (trading as Addrow)
- Address: Schoolstraat 70, 6721 CS, Bennekom, The Netherlands
- KVK number: 66761743
- Email: hello@addrow.io
3. Personal Data We Collect
We collect the following types of personal data:
Account information
- Name
- Email address
- Password (encrypted)
- Locale and display preferences
Business and billing details
- Company name, address, VAT number, Chamber of Commerce number
- Bank account details you enter for invoices (for example IBAN)
- Payment details processed by our payment providers (we do not store full card numbers on our servers)
Service data
- Invoices, contacts, expenses, profiles, notes, and related files you create
- Optional bank account and transaction fields when you connect a bank via Ponto (Isabel Group), such as IBAN, amounts, dates, counterpart names, and remittance text
- Messages and attachments you send to the AI assistant
- Early access signups (name and email)
Technical data
- IP address (may be anonymized for analytics)
- Browser type and version
- Device and log information needed for security and debugging
4. Legal Basis for Processing
Under the GDPR, we process your personal data based on the following legal grounds:
- Contract performance (Art. 6(1)(b)): to provide Addrow, manage your account, send invoices, and process payments.
- Legitimate interests (Art. 6(1)(f)): to improve the product, prevent abuse, and keep the service secure.
- Legal obligation (Art. 6(1)(c)): to meet tax and accounting requirements where applicable.
- Consent (Art. 6(1)(a)): for optional marketing communications and for features that require explicit consent.
5. How We Use Your Data
We use your personal data to:
- Provide and maintain the Addrow invoicing service
- Create, store, send, and export invoices, expenses, and related documents
- Power optional AI features (assistant chat, receipt assistance) under your control
- Match connected bank payments to your invoices (and stop reminders for paid invoices) when you enable bank connection
- Manage your account, subscription, and support requests
- Process payments and send receipts where relevant
- Communicate about product updates, security, and service notices
- Comply with legal obligations
Bank connection purpose (Ponto)
If you connect a bank account through Ponto (Isabel Group), we process account and transaction data only to help you match incoming payments to open invoices and related bookkeeping in Addrow (for example marking invoices paid and stopping reminders). We do not use bank data for marketing, advertising, credit scoring, or selling to third parties. You pay Ponto for the bank connection; Addrow is the software that reads the feed for matching. You can disconnect at any time; unmatched bank rows may be deleted, while match history needed for invoice audit may be retained with the invoice record.
6. AI Processing
When you use AI features in Addrow, relevant account data (for example invoice or expense context you ask about) and content you submit may be sent to our AI providers solely to generate a response for you.
Your content is not used to train the foundation models behind those providers under our arrangements. Providers process data under data processing agreements with GDPR-aligned safeguards.
You can turn the assistant off in account settings. You remain responsible for reviewing AI-suggested actions before approving them.
7. Data Sharing and Third Parties
We may share data with:
- AI providers: to process assistant and extraction requests you initiate
- Payment providers: for online payment links and subscriptions (for example Mollie or Stripe, depending on your setup)
- Bank connectivity providers: Ponto (Isabel Group) when you connect bank accounts for payment matching
- Cloud hosting and storage: infrastructure for the application and files (for example object storage for PDFs and receipts)
- Email delivery: to send transactional mail such as invoices and account messages
- Analytics: privacy-focused, anonymized analytics only, if enabled
We require processors to comply with GDPR through appropriate agreements. We do not sell your personal data.
8. International Data Transfers
Some providers may process data outside the European Economic Area (EEA). When that happens, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, or transfers to countries with an adequacy decision.
9. Data Retention
We retain personal data for as long as needed to:
- Provide the service to you
- Comply with legal obligations (for example tax retention periods under Dutch law)
- Resolve disputes and enforce agreements
For bank connections we keep structured transaction fields needed for matching and audit while the connection is active or while a match is linked to an invoice. We do not retain full raw bank API dumps longer than needed for debugging; production defaults avoid storing them. You may delete account data subject to legal retention requirements. After account closure we delete or anonymize data within a reasonable period unless law requires longer storage.
10. Your Rights Under GDPR
You have the right to:
- Access a copy of your personal data
- Rectification of inaccurate data
- Erasure (“right to be forgotten”) where applicable
- Restriction of processing in certain cases
- Data portability of data you provided
- Object to processing based on legitimate interests
- Withdraw consent where processing is based on consent
To exercise these rights, email hello@addrow.io. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
11. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and secure password storage. No method of transmission or storage is fully secure; we work to protect your data and to respond to incidents promptly.
12. Children
Addrow is not directed at children under 16. We do not knowingly collect personal data from children.
13. Changes
We may update this Privacy Policy from time to time. Material changes will be indicated by updating the date above and, where appropriate, by notice in the product or by email.
14. Contact
Questions about this policy: hello@addrow.io.