Last updated: 22 August 2026
Who we are (data controller)
boeq is developed and published by Damdy (handelsnaam boeq), a sole proprietorship (eenmanszaak) registered with the Dutch Chamber of Commerce (KvK) under number 95578277, BTW-id NL005162251B98, Segment 3 Box E3933, 6921 RC Duiven, Netherlands. Contact: info@boeq.app.
The short version
This policy covers two different things, so we've split it in two. The boeq app is local-first: it stores your bookkeeping data only on your device and never phones home, so there is nothing for us to collect. This website runs a waitlist signup form, and when you use it we store the email address you give us — that's the only personal data we process. Nothing else on this site tracks you: no cookies, no analytics, no third-party scripts.
Part 1 — The boeq app on your device
Your bookkeeping data — invoices, receipts, transactions, contacts, tax figures — is stored only on your device, encrypted at rest. The app does not run a server, has no account system, and never receives, collects, or transmits your data. There is no analytics, no tracking, and no advertising in the app.
Nothing leaves your device, except when you choose it:
- iCloud Drive backup (optional). When you create a backup, boeq writes an encrypted archive to your own iCloud Drive. The archive is encrypted on your device with a passphrase you set, using Argon2id key derivation and AES-256. Apple stores the file but cannot read its contents, and neither can we. If you lose the passphrase, the backup is unrecoverable — there is no recovery mechanism.
- Moneybird migration (optional, one-time). If you choose to import from Moneybird, boeq connects directly from your device to Moneybird's API using a token you provide, and copies your data locally. The data flows Moneybird → your device. We are not involved and receive nothing.
Because we never receive this data, there is no processing on our side for the GDPR/AVG to apply to. You remain in sole control of your own data on your own device: view, edit, export, or permanently delete it at any time from within the app (Settings → Wipe all data removes everything). Uninstalling the app removes the local database.
Part 2 — This website and the waitlist
When you submit the waitlist form on boeq.app, or the equivalent gate at demo.boeq.app before trying the demo, we store a record with the following fields:
- Email address — required, to send you the waitlist welcome email and later a download notice.
- Name — only collected from the demo.boeq.app gate; empty for signups made directly on this site.
- Source — which page the form was submitted from, so we know what content is working.
- Created-at timestamp — when you signed up.
- Status — whether the welcome email has gone out yet.
- Last-email-at — when we last emailed you.
- ip_country — a country code derived from Cloudflare's edge network at the moment you submit the form. We do not store the IP address itself in this record.
- ua_family — a coarse device/browser bucket (for example "macos-safari"), not a fingerprint.
- Tags — internal labels for list segmentation.
- Consent record — the moment you consented, and the exact wording shown to you when you did. We store this because the GDPR requires us to be able to demonstrate what you actually agreed to.
Separately, to stop abuse of the form, we keep a short-lived rate-limit counter keyed by IP address and the current minute. That counter is automatically deleted after 90 seconds and is never linked to your waitlist record.
Processors. We use two processors to run this form: Cloudflare, which hosts the site and stores the waitlist records in its Workers KV storage, and MailChannels, which delivers the one welcome email your signup triggers. MailChannels processes data in the United States; that transfer is covered by the EU Standard Contractual Clauses (SCCs).
Legal basis. We process this data on the basis of your consent (GDPR Art. 6(1)(a)) — you give it by submitting the form.
Retention. We keep waitlist records for 24 months from the date you signed up, after which they are deleted automatically (the KV entry carries a matching expiration).
Cookies and local storage
This site sets no cookies. It runs no analytics and
loads no third-party scripts or fonts — fonts are self-hosted. The
only thing this site ever writes to your browser is a single
localStorage entry recording your light/dark theme
choice, and only after you click the toggle. That's a preference you
actively requested, which places it under the exemption in ePrivacy
Art. 5(3) / Telecommunicatiewet Art. 11.7a — so it needs no consent
and this site carries no cookie banner. None is needed.
How to unsubscribe
Every email we send carries a one-click unsubscribe link at the bottom. You can also mail notify@boeq.app directly. Either way, unsubscribing deletes your waitlist record.
Your rights
Under the GDPR/AVG (Art. 15–21) you have the right to access, rectify, or erase your data, to receive a copy in a portable format, to object to processing, and to withdraw your consent at any time. To exercise any of these for your waitlist record, email info@boeq.app. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
Children
boeq is a bookkeeping tool for business owners and is not directed at children.
Changes
We will update this page if what the app or this website collects changes, and update the date above.
Contact
info@boeq.app — Damdy (handelsnaam boeq), KvK 95578277.