MyChef Food Safety | Based in The Hague | Chamber of Commerce 27278553 | Version: 1.0.1 | 10-05-2026

MYCHEF FOOD SAFETY | HACCP App | Privacy Statement

Important: this privacy statement concerns the processing of personal data by MyChef Food Safety for the website, account registration, support and general use of the HACCP App. For personal data that a customer enters into the application for its own employees, suppliers or operational records, that customer often acts as the controller and MyChef Food Safety acts as the processor.

1. Identity and scope

1.1. This privacy statement applies to the processing of personal data of visitors, contact persons, prospective and existing customers, account users and support contacts.

1.2. MyChef Food Safety is the controller for processing activities that it determines itself, such as account management, authentication, support, security, invoicing and service communications.

1.3. For customer data recorded by customers in the MyChef Food Safety App for their own organisation, staff or processes, the customer may be the controller. In that case, the processing arrangements are additionally governed by the data processing agreement.

2. Personal data we process

2.1. Account and identification data: first name, last name, email address, user role, organisation name and login details.

2.2. Usage and application data: records, notes, timestamps, audit logs, device/browser information and technical log data for security and troubleshooting.

2.3. Communication data: content of support requests, emails, contact history and any attachments you provide.

2.4. Contract and administration data: customer name, invoice and payment data, correspondence about quotations, subscriptions and contract management, where applicable.

2.5. Other data: only when you provide it yourself or when it is necessary for performing the agreement, security or compliance with laws and regulations.

3. Purposes and legal bases

3.1. Performance of the agreement: for account registration, authentication, access management, delivery of the service, support and management of your organisation environment.

3.2. Legitimate interest: for security, logging, fraud prevention, product improvement, incident investigation and safeguarding continuity of the service, insofar as this outweighs your privacy interests.

3.3. Legal obligation: for administration, tax retention obligations, handling security incidents or other statutory obligations.

3.4. Consent: only where truly necessary, for example for optional communications or non-essential technologies.

4. Recipients, processors and sub-processors

4.1. We only share personal data with third parties insofar as this is necessary for the service, security or compliance with laws and regulations.

4.2. For hosting and database infrastructure, we use Supabase as a processor or sub-processor, depending on the specific allocation of roles in the processing.

4.3. When we engage other processors or sub-processors, we ensure that appropriate contractual and organisational safeguards apply.

5. Transfers outside the EEA

5.1. Personal data is preferably processed within the European Economic Area (EEA).

5.2. If personal data is nevertheless transferred outside the EEA, this will only take place if there is a valid transfer mechanism, such as an adequacy decision or appropriate safeguards, including Standard Contractual Clauses where necessary.

6. Security

6.1. We take appropriate technical and organisational security measures, including access restrictions, authentication, logging, encryption where appropriate, backup and recovery measures, and measures against loss, unauthorised access and unlawful processing.

6.2. We periodically evaluate security measures and tighten them where necessary.

7. Retention periods

7.1. MyChef Food Safety does not retain personal data for longer than necessary for the purpose for which it was collected, unless a statutory retention obligation or compelling interest requires a longer retention period.

7.2. Account and service data are generally retained for as long as the agreement is in force. After termination, we delete or anonymise personal data within a reasonable period, unless statutory retention obligations or ongoing disputes justify longer retention.

7.3. Administrative data subject to tax or statutory retention obligations is retained for as long as that obligation applies.

8. Your rights

8.1. You may request access, rectification, deletion, restriction of processing, data portability and, where applicable, object to processing.

8.2. Where processing is based on consent, you may withdraw that consent at any time. This does not affect the lawfulness of prior processing.

8.3. You also have the right to lodge a complaint with the Dutch Data Protection Authority.

9. Data breaches and incidents

9.1. In the event of a personal data breach, we act in accordance with the GDPR. Where required, we notify the competent supervisory authority and/or the data subjects.

10. Changes

10.1. MyChef Food Safety may amend this privacy statement, for example in the event of changes in legislation, the service or the processors used. The most current version is made available through the website or application.

11. Contact

11.1. For privacy questions or requests, you can contact us at info@mychef-foodsafety.com.

12. Data processing agreement

12.1. In addition to this Privacy Statement, MyChef Food Safety also uses a data processing agreement for customer data processed in the application.