Privacy Statement (GDPR)

Last updated: 28-07-2026

Credimigo B.V. ("Credimigo", "we"), established at Vossiusstraat 20, 1071AD Amsterdam, Dutch Chamber of Commerce (KvK) number 81707169, VAT identification number NL003597297B90, attaches great value to the protection of personal data and processes it in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy legislation. This privacy statement describes which data we process, for what purpose, on what legal basis, how long we retain it and what rights data subjects have.

Introduction

Credimigo B.V. is the controller for the processing of personal data as described in this statement, unless Credimigo acts as a processor on behalf of its business customers (see the Data Processing Agreement).

What data do we process?

Depending on the use of the Platform, we process, among other things:

  • name;
  • e-mail address;
  • phone number;
  • company data;
  • Dutch Chamber of Commerce (KvK) number;
  • VAT number;
  • invoice data;
  • payment data;
  • communication (including correspondence between User and Debtor that takes place via the Platform);
  • IP address;
  • log files and usage data of the Platform.

Legal bases for processing

We process personal data only if and insofar as a legal basis as referred to in Article 6 GDPR is present, including:

  • performance of the agreement: for creating accounts, processing invoices, sending reminders, carrying out AI Recovery and processing payments;
  • legitimate interest: for fraud prevention, security, product improvement and direct marketing to business relations, whereby we always weigh the interests involved and do not allow our interest to override that of the data subject;
  • legal obligation: for complying with fiscal, accounting and other legal obligations;
  • consent: insofar as required, for example when placing marketing cookies (see the Cookie Statement).

Why do we process this data?

We process personal data to:

  • create and manage accounts;
  • process invoices;
  • send reminders;
  • carry out AI Recovery;
  • process payments;
  • prevent and combat fraud;
  • provide customer service;
  • comply with legal obligations;
  • improve the software and services, including the (further) development of AI models based on anonymised or aggregated data where possible.

AI use

Credimigo uses artificial intelligence (AI) for, among other things:

  • drafting communication towards Debtors;
  • translations;
  • classification of responses;
  • calculating Recovery Scores;
  • workflow advice;
  • fraud detection.

Where necessary, human review takes place, in particular for decisions that have legal effects or otherwise significantly affect the data subject. Data subjects have the right not to be subjected to a decision based solely on automated processing that has legal effects on them, unless an exception referred to in Article 22 GDPR applies. Data subjects can have such a decision reviewed by a Credimigo employee by contacting info@credimigo.com.

Automated decision-making and profiling

Recovery Scores and fraud detection signals may have characteristics of profiling. Credimigo does not take decisions based solely on automated processing (including profiling) that have legal effects on the data subject, without the possibility of human intervention, unless this is necessary for entering into or performing an agreement, is based on explicit consent, or is permitted by law with appropriate safeguards.

Integrations

When a User creates a connection with, for example, Moneybird, Exact, Stripe, Mollie or Shopify, only the data necessary for the chosen functionality is processed. The User is itself responsible for lawfully creating such a connection and for informing its own customers/Debtors thereof, insofar as this rests on the User as controller.

For payment data and the actual collection of payments, it applies in particular that Stripe (or a comparable payment service provider chosen by the User) processes the payment itself and pays it out to the User. In that process, Credimigo processes only the data needed to display the payment status in the Platform (such as paid/unpaid and date), and is not itself a recipient or custodian of the funds paid. The payment service provider's own privacy statement and terms apply to its processing of payment data.

Retention periods

Personal data is not retained longer than necessary for:

  • performance of the agreement;
  • compliance with legal obligations (including the tax retention obligation of, in principle, 7 years for administrative data);
  • fiscal retention obligations;
  • dispute resolution, including the period within which claims can be brought.

After expiry of the applicable retention period, personal data is deleted or anonymised, unless a longer retention period is legally required or justified.

Sharing of data

Personal data is only shared with:

  • payment providers;
  • cloud suppliers;
  • communication providers;
  • AI service providers;
  • legal partners, if the User chooses this.

Where required, data processing agreements or appropriate contractual safeguards have been concluded with these parties. Credimigo does not sell personal data to third parties.

Transfer outside the EEA

Insofar as personal data is transferred to recipients outside the European Economic Area (for example certain AI or cloud suppliers), Credimigo ensures appropriate safeguards, such as the European Standard Contractual Clauses (SCCs), an adequacy decision of the European Commission, or a comparable legally valid transfer mechanism.

Rights of data subjects

Data subjects have, among others, the right to:

  • access to their personal data;
  • correction of inaccurate data;
  • erasure of data ("right to be forgotten"), insofar as no legal retention obligation or other legitimate interest precludes this;
  • data portability;
  • restriction of processing;
  • object to processing, including objection to processing for direct marketing purposes and to profiling;
  • withdraw previously given consent, without this affecting the lawfulness of processing before the withdrawal.

Requests can be sent to: info@credimigo.com. Credimigo responds within the statutory period of one month, which period can be extended by two months in the case of complex or numerous requests.

Data subjects also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Security

Credimigo takes appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration and misuse. See the Security page for more information.

Changes

Credimigo may amend this privacy statement from time to time. The most current version can always be consulted via the Platform and the website.