Privacy Policy
This privacy policy explains how United Playgrounds processes personal data in UP-OS, the internal business application used by the agencies of the United Playgrounds group for client management, projects, planning, HR, invoicing, documents and related work. It applies to everyone whose data is processed in UP-OS: our employees and freelancers who use it, contacts at our clients, suppliers and prospects, and visitors who use a public form, chat widget or share link served by UP-OS.
1. Who is responsible
The controller for the processing described here is United Playgrounds B.V., Archangelkade 30B, 1013 BE Amsterdam, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number [KvK number]. Where an agency within the group uses UP-OS for its own clients and staff, that agency may act as joint controller for its own data.
For any question about this policy or your personal data, contact us at privacy@unitedplaygrounds.nl.
2. What data we process
Users of UP-OS (employees and freelancers)
- Account data: name, work email address, profile photo, password hash, two-factor authentication settings, login sessions, IP address and browser information.
- Employment and HR data: job title, department, agency, contract details, working hours, leave and absence, expense claims, and other data needed to administer employment (including data exchanged with our payroll provider).
- Work data: projects, tasks, time entries, planning and capacity, documents, comments, issues, meeting notes and activity in connected tools (for example code repositories and Slack).
- Calendar and file data from connected Google or Microsoft accounts, as described in section 4.
- Usage and technical data: application logs, error reports and an audit history of changes made to records.
Business contacts (clients, suppliers and prospects)
- Name, job title, company, business email address, phone number and LinkedIn profile URL.
- Interactions with us: meetings, emails, offers, projects, invoices, newsletter subscriptions and engagement (opens, clicks, unsubscribes).
- Publicly available business information about a person or company, which we may enrich from commercial data providers and public sources (see section 6).
Visitors of public forms, chat and share links
- The information you enter in a form or chat, the time of submission, and technical data such as IP address and browser information.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Providing UP-OS to our staff: accounts, login, security | Performance of the employment or service contract; legitimate interest in securing our systems |
| Project management, planning, time registration and invoicing | Performance of contracts with staff and clients; legal obligation (bookkeeping and tax) |
| HR administration and payroll | Performance of the employment contract; legal obligation |
| Managing client relationships and sending offers | Performance of a contract or steps prior to entering into one; legitimate interest |
| Business development and outreach to prospects | Legitimate interest in B2B marketing, balanced against your interests; you can object at any time |
| Newsletters | Consent, or legitimate interest for existing clients; every newsletter contains an unsubscribe link |
| Handling public form submissions and chat messages | Steps at your request prior to a contract; legitimate interest in answering your question |
| Logging, error reporting and change history | Legitimate interest in operating, securing and improving UP-OS |
We do not use personal data for automated decision-making that produces legal or similarly significant effects for you.
4. Google user data
When you sign in with Google, UP-OS requests access to the following data in your Google account:
- Basic profile (name, email address, profile picture) — to create and identify your UP-OS account.
- Google Calendar, read-only (
calendar.readonly) — to show your availability in planning, and to match calendar events to clients and projects. UP-OS never creates, changes or deletes calendar events. - Google Drive (
drive) — to create and open project folders and files, to let you attach Drive files to records in UP-OS, and to read the content of files you link so they can be searched and summarised inside UP-OS.
UP-OS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features described above.
- We do not sell Google user data, and do not use or transfer it for advertising, for credit-worthiness or lending purposes, or to build user profiles for third parties.
- We do not use Google user data to develop, improve or train generalised AI or machine-learning models.
- People only read Google user data with your consent, where necessary for security purposes or to comply with the law, or where it has been aggregated and anonymised for internal operations.
- We transfer Google user data to third parties only as needed to provide these features (for example to our hosting and AI processors listed in section 6), to comply with the law, or as part of a merger or acquisition with notice to you.
You can revoke UP-OS's access at any time on your Google account permissions page. Signing in with a Microsoft account works the same way for the Microsoft profile and calendar data UP-OS requests.
5. AI features
UP-OS contains AI-assisted features, such as an assistant, document review, summaries of meetings and files, and drafting of texts. To provide them, relevant content (which may include personal data) is sent to an AI model provider — Google (Gemini / Vertex AI) by default. These providers act as our processors, process the content only to return a result, and under our agreements with them do not use it to train their models. AI output is always presented to a person, who decides what to do with it.
6. Who we share data with
We do not sell personal data. We share it only with service providers that process it on our behalf under a data processing agreement, with other agencies in the United Playgrounds group where they work on the same clients or employ the same people, and with authorities where the law requires it. Depending on which features are used, our service providers include:
| Provider | Purpose |
|---|---|
| Google Cloud (EU region) | Hosting, database, file storage, background tasks, logging and error reporting |
| Google (Workspace, Gemini / Vertex AI) | Sign-in, calendar and Drive integration, AI features |
| Microsoft | Sign-in and calendar integration for Microsoft accounts |
| Anthropic | Alternative AI model provider, when configured |
| Email delivery providers (SMTP, SendGrid) | Sending system email and newsletters, and recording delivery and engagement events |
| Slack | Notifications and messaging integration |
| Exact Online | Bookkeeping and invoicing |
| SD Worx | Payroll and HR administration |
| Teamleader, HubSpot, Forecast, Notion, GitLab, Granola | Importing and synchronising client, project, time, document, development and meeting-note data from tools we use |
| Apollo, Hunter, Bright Data | Enriching business contact and company data from public and commercial sources |
| ElevenLabs, fal | Generating voice and video for internal news updates |
7. Transfers outside the EEA
We host UP-OS in the European Union. Some of the providers above are based in, or may access data from, countries outside the European Economic Area, notably the United States. Where that happens, we rely on the EU–US Data Privacy Framework for certified providers, or on the European Commission's Standard Contractual Clauses with supplementary measures where needed.
8. How long we keep data
- User accounts: for the duration of employment or engagement, and deactivated afterwards; account data is deleted or anonymised within 12 months unless a longer period is required below.
- HR and payroll data: as long as the law requires — generally 2 to 7 years after employment ends, depending on the type of record.
- Financial records (invoices, time entries used for invoicing): 7 years, as required by Dutch tax law.
- Business contacts and prospects: as long as there is an active business relationship, and up to 2 years after the last meaningful contact; removed sooner if you object.
- Public form submissions and chat messages: up to 2 years, unless they lead to a business relationship.
- Logs and error reports: up to 90 days. Change history is kept as long as the record it belongs to.
9. Security
We protect personal data with appropriate technical and organisational measures, including encryption in transit and at rest, encrypted storage of third-party credentials, two-factor authentication, role- and capability-based access control so people only see what their role requires, restricted projects, an audit trail of changes, and data processing agreements with our providers. If a data breach occurs that is likely to put your rights at risk, we notify the Dutch Data Protection Authority and, where required, you.
10. Cookies
UP-OS uses functional cookies that are strictly necessary to keep you signed in and secure your session, and local browser storage to remember interface preferences. Where analytics are enabled, they are used only to understand how the application is used and to improve it. We do not use advertising or tracking cookies.
11. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased, where we have no legal obligation or overriding interest to keep it;
- restrict processing, or object to processing based on legitimate interest — including at any time to direct marketing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting processing that took place before.
To exercise these rights, email privacy@unitedplaygrounds.nl. We respond within one month. We may ask you to verify your identity first.
If you believe we process your data unlawfully, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), or with the supervisory authority in your own EU country.
12. Changes to this policy
We may update this policy when UP-OS or the law changes. The date at the top shows when it was last changed. For significant changes, we inform users of UP-OS in the application.