Security
This page answers the questions we get most often about how BrandDeck handles data and security. For the full legal detail, see our Privacy Policy and Cookie Policy. Need a signed Data Processing Agreement (DPA)? Email hello@branddeck.co and we'll send one over.
Who we are
BrandDeck is built and operated by Snoepfabriek B.V., trading as BrandDeck, based in Utrecht, the Netherlands (Vondellaan 146, 3521 GH Utrecht).
Where your data lives
We run an EEA-first setup: your data is hosted in Germany by default and we don't move it outside the EEA without a lawful safeguard in place. Supabase's contracting entity is registered in Singapore, but the data itself stays in Frankfurt, and that relationship is covered by the EU Standard Contractual Clauses under Supabase's Data Processing Agreement, so it meets GDPR's requirements for that kind of arrangement.
Application and uploaded files (brand assets, logos, images)
Hetzner Online GmbH, Gunzenhausen, Germany (EU/EEA)
Account and login data
Supabase, Central EU (Frankfurt) region
Who else touches your data, and why
Provider
What for
Role
Hetzner Online GmbH
Hosting the application and your uploaded files
Sub-processor
Supabase Pte. Ltd.
Managed database for account and login data
Sub-processor
Mollie B.V.
Payment processing for subscriptions
Independent controller (not a sub-processor; doesn't see your brand content)
Google Identity Services
Optional "Sign in with Google"
Only used if you choose it; not authorised to receive your content
Sendinblue SAS (Brevo)
Newsletters and product updates
BrandDeck's marketing tool; separate from your account data
We don't sell your data, and we don't use your brand content to train general-purpose AI models unless you explicitly ask us to and we agree the terms in writing.
Security, in brief
All traffic is encrypted in transit (HTTPS/TLS); the database is encrypted at rest.
Access is role-based: admins and editors have different permissions, and shared brands can be public, protected, or invite-only depending on what you choose.
Backups run daily, are encrypted, stored separately from live data, and expire within 14 days of deletion.
We're not ISO 27001 certified yet — we're working towards it — but our contractual security commitments apply regardless of certification status.
How long we keep things
Your content stays for as long as you use BrandDeck. If you close your account, you have 30 days to export anything you need; after that, active data is deleted and any remaining backup copies age out within 14 days. Full detail is in the Privacy Policy.
If something goes wrong
If we ever detect a data breach affecting your account, our internal target is to notify you within 24 hours of becoming aware of it, and to keep you updated as we learn more.
Your rights
Wherever GDPR applies, you can ask to access, correct, export, or delete your personal data, or object to how we use it. Reach us at hello@branddeck.co and we'll respond within a month.
Questions?
This page is a summary, not a substitute for the full policies. For the complete legal text, see the Privacy Policy and Cookie Policy. For a signed DPA or any other question about data handling, email hello@branddeck.co.
