Data Controller
| Organisation | Inprovo |
| Product | Chup · family chores app |
| Location | Netherlands |
| Contact | privacy@chup.nu |
| DPO appointed | No (not required based on size) |
1. Account management
| Goal | Creating and managing user accounts and family profiles |
| Legal basis | Performance of a contract (Art. 6(1)(b) GDPR) |
| Data subjects | Parents, children (via parental authority) |
| Details | Name, email address, password (hashed), profile photo, date of birth (encrypted), phone number (encrypted), role (parent/child) |
| Retention period | As long as the account is active. Without a paid subscription, deleted after 90 days of inactivity, following a warning by email. Recoverable for 30 days after deletion, then permanently erased. |
| Security | Password hashed (bcrypt), date of birth and phone number AES-256 encrypted, HTTPS, session encryption |
| Processors | Hetzner (hosting, EU/Germany) |
2. Messages (Chat)
| Goal | Communication between family members and linked families |
| Legal basis | Performance of a contract (Art. 6(1)(b) GDPR) |
| Data subjects | All family members who use the chat function |
| Details | Message content, voice messages, read receipts, timestamps |
| Retention period | As long as the account is active. Upon account deletion: all messages erased. |
| Security | End-to-end encrypted (AES-256-GCM). Message content is encrypted on the user's device before it reaches our servers. Chup cannot view the content. |
| Processors | Hetzner (encrypted storage), Pusher (real-time delivery, metadata only) |
3. Photos and documents
| Goal | Safely storing and sharing family photos and documents |
| Legal basis | Performance of a contract (Art. 6(1)(b) GDPR) |
| Data subjects | Family members, children shown in photos |
| Details | Photos, documents, thumbnails. Location data (EXIF) is automatically removed before encryption. |
| Retention period | As long as the account is active. Upon deletion: erased immediately and irretrievably. |
| Security | End-to-end encrypted. Each file has a unique encryption key (FEK). EXIF metadata is removed client-side. Files are uploaded directly to encrypted storage without server involvement. |
| Processors | Hetzner Object Storage (encrypted blobs, EU/Germany) |
4. Financial data
| Goal | Household budget book: insight into the family's income and expenses |
| Legal basis | Performance of a contract (Art. 6(1)(b) GDPR) |
| Data subjects | Parents who use the financial module |
| Details | IBAN (encrypted), bank balance (encrypted), transactions (encrypted), budgets, savings goals |
| Retention period | As long as the bank connection is active. Upon disconnection: transaction data erased. |
| Security | End-to-end encrypted (AES-256-GCM). IBAN and balance additionally encrypted with a family-specific key. |
| Processors | Tink (bank connection, EU), Hetzner (encrypted storage) |
5. Payment and billing
| Goal | Processing of subscription payments and invoicing |
| Legal basis | Performance of a contract (Art. 6(1)(b) GDPR) and legal obligation (Art. 6(1)(c), tax retention obligation) |
| Data subjects | Paying parents |
| Details | Name, address, email address, payment method, invoice amounts, Mollie customer ID |
| Retention period | Invoices: 7 years (statutory retention period). Payment details: as long as the subscription is active. |
| Security | HTTPS, encrypted database, Mollie PCI-DSS certified |
| Processors | Mollie (payment processing, Netherlands), Apple (in-app purchases, US with EU safeguards) |
6. Chores, calendar and household
| Goal | Manage family chores, calendar, shopping lists, wish lists and rewards |
| Legal basis | Performance of a contract (Art. 6(1)(b) GDPR) |
| Data subjects | All family members |
| Details | Task descriptions, calendar items, shopping lists, wish lists, points and rewards |
| Retention period | As long as the account is active. |
| Security | HTTPS, encrypted database, access control per family |
| Processors | Hetzner (hosting) |
7. Childminder
| Goal | Daily report and planning between childminder and parents |
| Legal basis | Performance of a contract (Art. 6(1)(b) GDPR) |
| Data subjects | Childminders, parents, children |
| Details | Daily reports (meals, sleep, mood, activities), planning, holidays, photos of children |
| Retention period | As long as the childminder link is active. |
| Security | HTTPS, encrypted database, access control per link |
| Processors | Hetzner (hosting) |
8. Email and notifications
| Goal | Transactional emails (login links, confirmations) and push notifications; measuring whether emails have been opened and clicked |
| Legal basis | Performance of a contract (Art. 6(1)(b) GDPR); legitimate interest for the measurement (Art. 6(1)(f) GDPR) |
| Data subjects | All users with an email address or mobile device |
| Details | E-mail address, name, notification content, device tokens (push notifications), for each e-mail sent the subject and the time it was opened and clicked |
| Retention period | Device tokens: as long as the device is active. Mail log: as long as the account is active. Email logs at the sender: in accordance with processor policy. |
| Security | TLS in transit, device tokens in encrypted database |
| Processors | Postmark (email, US with EU safeguards), Firebase Cloud Messaging (push, Google, US with EU safeguards) |
9. Contact form and support
| Goal | Answering questions and complaints via the contact form |
| Legal basis | Legitimate interest (Art. 6(1)(f) GDPR) |
| Data subjects | Visitors and users who get in touch |
| Details | Name, email address, message content, attachments |
| Retention period | Maximum 12 months after last contact. |
| Security | HTTPS, encrypted database |
| Processors | Hetzner (hosting) |
10. Newsletter
| Goal | Inform about Chup updates and news |
| Legal basis | Consent (Art. 6(1)(a) GDPR, double confirmation) |
| Data subjects | Registered visitors |
| Details | E-mail address, optional name |
| Retention period | Until unsubscribed. |
| Security | HTTPS |
| Processors | Postmark (email sending) |
11. Error logging and monitoring
| Goal | Detecting and resolving technical errors in the application |
| Legal basis | Legitimate interest (Art. 6(1)(f) GDPR) |
| Data subjects | Users experiencing an error |
| Details | Error messages, stack traces, request context (URL, headers). No encrypted content (E2E data is not readable by the server). |
| Retention period | In line with Flare's retention policy (default 30 days). |
| Security | TLS in transit, Flare EU hosting |
| Processors | Flare (error tracking, EU) |
12. Cloud storage import
| Goal | Importing photos from Dropbox, Google Drive or OneDrive into the encrypted vault |
| Legal basis | Consent (Art. 6(1)(a) GDPR, user initiates connection) |
| Data subjects | Users linking a cloud storage account |
| Details | OAuth tokens (stored encrypted), folder list. Imported photos are encrypted client-side. |
| Retention period | OAuth tokens: until disconnection. Photos: see processing 3. |
| Security | OAuth tokens AES-256 encrypted, photos end-to-end encrypted for storage |
| Processors | Dropbox, Google, Microsoft (folder list only via OAuth, photo content is processed client-side) |
13. Photo vault key
| Goal | Being able to open and restore the photo vault on every device in the family using the recovery code |
| Legal basis | Performance of a contract (Art. 6(1)(b) GDPR) |
| Data subjects | Families setting up the photo vault |
| Details | Two encrypted copies of the family key (one with a key derived from the vault password, one with a key derived from the recovery code), the corresponding salts and a fingerprint (SHA-256) of the key. The password and recovery code themselves are never stored or sent. For a folder shared with a linked family: the folder key encrypted with the family key of both families (and until acceptance, a maximum of 7 days, with a key derived from the sharing code), plus for each file the file key encrypted with the folder key. |
| Retention period | As long as the account is active. |
| Security | Key derivation in the browser with PBKDF2-SHA-256 (600,000 rounds), AES-256-GCM. Only the family administrator can replace the material, and only with proof of knowledge of the key. |
| Processors | Hetzner (database, EU/Germany) |
14. Linked calendars
| Goal | Show appointments from a school system, sports club or your own calendar in the family calendar and, on request, put Chup appointments back in your own calendar |
| Legal basis | Performance of a contract (Art. 6(1)(b) GDPR), at the user's request |
| Data subjects | Family members whose calendar is linked, including children (timetable, via parental authority) |
| Details | Calendar link (encrypted), access tokens or app-specific password (encrypted), email address of the linked account, calendar names, appointments (title, time, location, description) |
| Retention period | As long as the link exists. Upon disconnection: link, tokens and imported appointments erased, appointments placed by Chup removed from your own calendar. Past lessons from a class timetable remain in the calendar until the link is broken. |
| Security | Links, tokens and passwords AES-256 encrypted, HTTPS. Data from Google is used in accordance with the Google API Services User Data Policy, including the Limited Use requirements. |
| Recipients | At the user's request: Google, Microsoft or Apple (the user's own calendar). For school holidays: the Dutch central government (only the region, no personal data). |
Overview of processors
| Processor | Goal | Location | Data Processing Agreement |
| Hetzner | Server hosting and file storage | Germany (EU) | Yes |
| Mollie | Payment processing | Netherlands (EU) | Yes |
| Postmark | E-mail sending | US (EU safeguards) | Yes |
| Firebase (Google) | Push notifications | US (EU safeguards) | Yes (Google DPA) |
| Tink (Visa) | Bank connections | Sweden (EU) | Yes |
| Flare | Error logging | EU | Yes |
| Apple | In-app purchases | US (EU safeguards) | Yes (Apple EULA) |
| Cloudflare | CAPTCHA (Turnstile) | US (EU safeguards) | Yes |
Technical and organisational measures
- End-to-end encryption (AES-256-GCM) for photos, messages, documents and financial data
- Encryption keys only exist on family members' devices, not on the server
- EXIF metadata (location, camera) automatically removed on photo upload
- Passwords hashed with bcrypt
- Sensitive fields (phone number, date of birth, IBAN) individually encrypted with AES-256
- HTTPS on all connections
- Content Security Policy (nonce-based, no inline scripts)
- Subresource Integrity on all JavaScript files
- Two-factor authentication available (TOTP and SMS)
- Authorisation via policies (family members only see their own family data)
- Recovery server physically separated at a different provider
- Regular security audits
Rights of data subjects
Data subjects can exercise their rights (access, rectification, erasure, restriction, data portability, objection) by getting in touch via privacy@chup.nu. Chup also offers a built-in data export function and account deletion function in the app.
Complaints can be submitted to the Dutch Data Protection Authority.