# Privacy Policy

> Version: 2026-08-15
> Issued: 15 August 2026
> Effective: 15 August 2026
> English is the authoritative version.

## 1. Who we are

This policy explains how Magnolia Squared, a sole proprietorship registered in the Netherlands,
handles personal data in connection with **Hendrik**, including the marketing website at
`https://withhendrik.com`, the product application at `https://app.withhendrik.com`, the trust-core
API at `https://api.withhendrik.com`, public read-only endpoints at
`https://public-api.withhendrik.com`, demonstrations, support, and related services (the
**Service**).

**Business details**

- Registered business: Magnolia Squared
- Legal form: Dutch sole proprietorship (`eenmanszaak`)
- Proprietor: Wessel Hendrik Pannebakker
- Address: Batavengaarde 4, 2408 TA Alphen aan den Rijn, the Netherlands
- Dutch Chamber of Commerce (KVK): 90466659
- VAT identification number: NL004818456B50
- Privacy contact: `privacy@withhendrik.com`

In this policy, **we**, **us**, and **our** mean Magnolia Squared. **Hendrik** means the Service
described above. A future company does not become a party to this policy unless the policy is
formally updated or the business is lawfully transferred to it.

## 2. Scope and our roles

This policy applies to the Service and direct business interactions with us. It does not govern the
independent practices of advertising, commerce, payment, identity, or other third-party platforms.

Our role depends on why personal data is processed:

- **Processor or service provider for customers.** We process customer-connected advertising and
  commerce data, workspace activity, customer analyses and conversations, saved views, audit and
  approval evidence, proposed actions, execution records, provenance, and customer-directed support
  on the business customer's documented instructions. The customer is normally the controller or
  business for that data. Our Data Processing Agreement governs this processing.
- **Independent controller.** We determine why and how to process account, authentication,
  abuse-prevention, platform-security, billing, legal-compliance, demo, business-administration,
  product-analytics, and narrowly scoped service-improvement data for our own purposes. Session
  replay is a Provider-only internal controller activity used for reliability, security,
  troubleshooting, support quality, and quality assurance. It is not exposed to or operated for a
  customer. We do not use prompts, user inputs, or underlying customer evidence for product
  improvement. We may use a generated Agent response for quality assurance and improvement of
  Hendrik under the safeguards in Sections 6 to 8.

One record can support both roles. For example, a workspace audit record may be processed on the
customer's instructions for the customer-facing audit trail and separately for our platform-security
purpose. We apply the processor rules to the first use and the controller rules to the second. Where
an operation has not been classified, we treat the data as Customer Personal Data and apply the DPA
until we document another lawful role. If replay is made customer-directed or customer-accessible,
we will reclassify that use under the DPA before it begins.

If a customer submits a privacy request about data we process for it, we will normally refer the
request to that customer.

## 3. Who may use the Service

The Service is for businesses and their authorized adult representatives. It is not offered to
consumers or minors. Customers must not submit children's data, special-category or sensitive
personal data, shopper contact profiles, or data used to make employment, credit, insurance,
health, legal-rights, or similarly significant decisions about individuals.

## 4. Personal data we handle

This section covers authorized users and customer personnel, demo prospects, support contacts,
people represented incidentally in customer-authorized data, and anonymous or identified visitors
to our marketing, pre-authentication, and product pages. Depending on how a person interacts with
us, we may handle:

- **Account and identity data:** name, work email, display/profile information, organization,
  membership, role, authentication identifiers, login and session metadata.
- **Business and contract data:** company, job role, contact details, order or plan information,
  communications, acceptance records, and contract administration.
- **Billing and usage data:** billing-account identifiers, subscription/access status, invoices, tax
  information, payment status, Analysis Credit grants, reservations, settlements, releases,
  expiries, content-free AI usage and cost-reconciliation records, and fraud signals.
  Payment-card data is handled by Stripe rather than stored by us where Stripe's hosted flows
  are used.
- **Connected-platform data:** advertising accounts, campaigns, budgets, spend, impressions,
  clicks, conversions, attribution, commerce orders and refunds, payment summaries, catalog data,
  and technical provider identifiers. The Service is designed to exclude direct shopper contact
  fields such as names, email addresses, phone numbers, and postal addresses. We apply ingestion-time
  field allowlists intended to drop those fields before storage. If a prohibited field is nonetheless
  ingested, we treat it as an incident, delete it, and correct the allowlist.
- **Customer content and work product:** prompts and other user inputs, conversations, uploaded or
  selected business evidence, analyses, saved views, proposed actions, approvals, generated Agent
  responses, and feedback. Prompts and other inputs are Customer Data. A generated response remains
  protected to the extent that it contains or reproduces personal data or Customer Confidential
  Information.
- **Action and audit data:** policy settings, proposal hashes, approval evidence, execution status,
  rollback attempts, security events, and audit trails.
- **Technical and usage data:** network information, including IP address at Cloudflare and in
  bounded security or public-API logs; device and browser data; URLs; timestamps; feature
  interactions; performance; diagnostics; sanitized logs, errors, traces; and content-free AI usage
  and cost metadata. The PostHog browser client is intended not to send IP addresses; this must be
  verified against the release and provider settings before customer activation.
- **Session replay data:** always-on visual and interaction recordings of anonymous and identified
  visitors across the marketing website, pre-authentication routes, and authenticated product.
  Ordinary inputs and expressly private regions are fully masked. Rendered interface text and Agent
  prompts and responses may remain readable after deterministic redaction of direct identifiers,
  payment-card numbers, and detected secrets. Replay also records layout, pointer and interaction
  events, and timing.
- **Demo and support data:** name, work contact details, scheduling information, qualification
  answers, support requests, and related communications.

## 5. How we obtain data

We receive data directly from users and customers; from customer-authorized advertising, commerce,
marketplace, measurement, CRM, lifecycle, subscription, and payment platforms in Hendrik's current
connector catalog; from identity, billing, scheduling, email, analytics, and infrastructure
providers; and automatically from use of the Service. Catalog presence does not mean a connector is
available to every customer. Customers are responsible for having the rights, notices, and lawful
bases needed to connect platforms and instruct us to process their data.

## 6. Why we use personal data and our legal bases

Where EEA data-protection law applies, we rely on the following bases:

| Purpose                                                                                                   | Typical data                                                                                           | Legal basis when we are controller                                                                                                                                                                    |
| --------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Provide accounts, the Service, support, billing, and requested demos                                      | Account, contract, billing, support, demo, and technical data                                          | Contract; steps requested before contract; legitimate interests                                                                                                                                       |
| Authenticate users, enforce access, prevent abuse, secure and troubleshoot the Service                    | Identity, login, security, redacted logs/errors/traces                                                 | Contract; legitimate interests; legal obligation where applicable                                                                                                                                     |
| Administer contracts, taxes, accounting, disputes, and legal claims                                       | Contract, billing, audit, and communications data                                                      | Contract; legal obligation; legitimate interests                                                                                                                                                      |
| Send transactional, service, security, billing, and one-to-one demo follow-up messages                    | Account, contact, contract, and demo data                                                              | Contract; legitimate interests                                                                                                                                                                        |
| Understand adoption, reliability, and performance and improve the Service                                 | Product/acquisition analytics and sanitized diagnostics that exclude Customer Personal Data            | Consent where device storage/access or local law requires it; otherwise legitimate interests where lawful                                                                                             |
| Record privacy-redacted replay for reliability, security, troubleshooting, support, and quality assurance | Interface, interaction, timing, and deterministically redacted prompt/response content                 | Legitimate interests for personal-data processing. The Service currently starts replay without a separate consent control; local device-storage/access law may impose a separate consent requirement. |
| Review selected Agent responses for quality assurance and improvement of Hendrik                          | Generated responses after deterministic redaction; no prompt, underlying evidence, or raw tool payload | Performance of the contract and legitimate interests, subject to the confidentiality authorization in the Terms and the safeguards below                                                              |
| Establish, exercise, or defend legal claims and comply with binding requests                              | Relevant account, contract, audit, security, or customer data                                          | Legal obligation; legitimate interests                                                                                                                                                                |

We do not send newsletters, perform behavioral advertising, or use third-party ad retargeting unless
we later introduce separate notices and any required consent or opt-out controls.

Where we act as a processor, our customer's documented instructions—not this controller lawful-basis
table—govern the processing.

## 7. Cookies, local storage, analytics, and session replay

The Service uses browser storage for authentication, security, preferences, continuity, product
analytics, and privacy-redacted session replay. Replay starts on the marketing website and
pre-authentication routes and continues in the authenticated product application. It is retained for
up to 30 days.

We are responsible for the replay safeguards; a user warning is not a substitute for privacy by
design. Ordinary form fields and expressly private regions are fully masked. Interface text and
Agent prompts and responses can remain readable after deterministic redaction of email addresses,
payment-card numbers, labelled names, detected secrets, and the authenticated user's known name and
email. We do not record network bodies or headers, console output, element attributes, cross-origin
iframe contents, URL query strings, or fragments in replay. Access is limited to authorized
personnel for the stated replay purposes and is subject to the 30-day maximum. Point-of-entry
notices reinforce the prohibited-data rules in the Terms but do not transfer responsibility for a
redaction failure to a visitor, user, or customer.

There is no in-product replay consent or disable control. A person may use browser controls that
block the analytics endpoint, but the Service does not promise that such blocking will preserve all
functionality. Requests to access or erase replay-linked personal data may be sent to
`privacy@withhendrik.com`. An anonymous visitor may help us locate a recording by providing the
approximate date and time, page path, browser/device details, and the PostHog distinct identifier if
available. We will not require information that is disproportionate to the request.

## 8. AI processing

The Service sends selected customer prompts, evidence, and instructions to Anthropic in the United
States as its interactive AI provider. Under Anthropic's commercial terms, Anthropic acts as our
processor, does not train its generative models on commercial inputs or outputs by default, and
ordinarily retains API inputs and outputs for up to 30 days. Longer security, abuse, legal, or
feedback retention may apply under Anthropic's published terms. We do not use customer confidential
content to train a general-purpose model.

We do not use a prompt, user input, underlying evidence, or raw tool payload for product
improvement. We may select a generated Agent response for quality assurance or improvement of
Hendrik, particularly where the response was incorrect, unexpected, or did not follow the user's
apparent intent. Before product-improvement review, we apply deterministic direct-identifier,
payment-card, and secret redaction and restrict access to authorized personnel. The response remains
personal data and Customer Confidential Information to the extent it contains or reproduces either.
We do not publish it, use it for advertising, or use it to train a general-purpose model.

AI outputs may be inaccurate, incomplete, stale, or unsuitable. The Service is designed for human
review by advertising and commerce professionals. It does not make legally significant decisions
about individuals and must not be used for such decisions.

For the purposes of Regulation (EU) 2024/1689 (the **EU AI Act**), we intend to act as provider of
the AI system comprised in the Service and our business customers ordinarily act as deployers.
Regulated roles nevertheless follow actual conduct. A customer may become a provider or other
regulated operator by placing the Service or a substantially modified system on the market under
its own name, substantially modifying it, or changing its intended purpose. The Service is not
intended for, and must not be used for, a high-risk purpose under Article 6 or Annex III, or for a
prohibited practice under Article 5. Users are told when they interact with AI and when output is
AI-generated. Customers remain responsible for human oversight and any further disclosure required
when they pass output to another person.

## 9. When we disclose data

We disclose personal data only as needed:

- to the named infrastructure, identity, AI, analytics, observability, email, scheduling, and billing
  providers described in our Subprocessor List;
- to customer-selected source and destination platforms when the customer connects or instructs an
  action involving those platforms;
- to professional advisers, auditors, insurers, prospective transaction counterparties, and
  authorities under appropriate confidentiality or legal controls;
- to comply with law, binding legal process, or urgent safety and security needs; and
- in connection with a lawful merger, financing, reorganization, sale, or transfer of the business,
  subject to appropriate safeguards and notice where required.

We do not sell personal data or share it for cross-context behavioral advertising. Except for the
narrow Agent-response use described in Sections 6 and 8, we do not use prompts, user inputs,
underlying evidence, raw tool payloads, or other processor data outside the customer's documented
instructions except as required by law. The response use is separate controller processing
expressly authorized in the Terms; it does not convert the corresponding prompt or evidence into
our data.

## 10. International transfers

We are established in the Netherlands, so a transfer from an EEA customer to us is not by itself a
restricted international transfer. The Service uses global providers and does **not** promise
EU-only processing or data residency. We and our providers may process data in the EEA, UK, United
States, and other disclosed countries.

For onward transfers by us, we require an applicable lawful mechanism: an adequacy decision, a
verified Data Privacy Framework certification, Standard Contractual Clauses concluded with the
recipient, the UK Addendum or IDTA, or another lawful mechanism. We complete transfer assessments and
supplementary measures where required. The Data Processing Agreement and the versioned Subprocessor
List provide further terms for customer data.

## 11. Retention and deletion

We retain personal data only for the applicable purpose, contract, legal requirement, dispute, or
documented retention period. The retention schedule is:

| Category                                                                                                   | Intended period or rule                                                                                                                                                                                                     |
| ---------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Connected customer source data                                                                             | Maximum 730 days; business customers may configure or instruct a shorter period and may instruct earlier erasure under the DPA                                                                                              |
| Customer conversations, outputs, saved views, and active workspace content                                 | During the contract and the default 60-day reversible workspace-deletion period, unless the customer instructs immediate non-reversible deletion; then active-system purge unless another listed rule or legal hold applies |
| Workspace export after deletion request                                                                    | Intended to remain available for the first 30 days of the default 60-day deletion period, where safe; unavailable after an immediate-deletion instruction                                                                   |
| PostHog product analytics, acquisition analytics, sanitized errors/logs, and content-free AI metadata      | Up to 84 months                                                                                                                                                                                                              |
| PostHog session replay of anonymous website visitors, pre-authentication visitors, and authenticated users | Up to 30 days                                                                                                                                                                                                               |
| Redacted Agent-response copies selected for quality assurance or product improvement                       | Up to 90 days after selection, unless earlier erasure or a legal hold applies; anonymous learnings that no longer constitute personal data or Customer Confidential Information may be retained                             |
| Axiom sanitized logs and sampled traces                                                                    | Up to 30 days                                                                                                                                                                                                               |
| On-host operational and public-API security logs/traces and metrics                                        | 30 days for logs/traces; 90 days for metrics                                                                                                                                                                                |
| Sync provenance                                                                                            | 180 days                                                                                                                                                                                                                    |
| Action, approval, and audit records                                                                        | Five years after the relevant action or record, unless a longer legal hold is required                                                                                                                                      |
| Support and demo correspondence                                                                            | 24 months after the last interaction, unless needed for an active contract, request, dispute, or legal obligation                                                                                                           |
| Billing, tax, fraud, and accounting records                                                                | For the period required by applicable tax, accounting, anti-fraud, and legal-claims law                                                                                                                                     |
| Disconnected credentials                                                                                   | Revoked and destroyed promptly in active systems; historical reporting data follows its separate retention period                                                                                                           |
| Encrypted backups containing actively deleted data                                                         | Expire no later than 12 days after the active-system purge (or 12 days after an instructed immediate deletion); isolated from ordinary processing and used only for disaster recovery                                       |

An owner-initiated workspace deletion immediately pauses syncs, scheduled work, and execution. It is
reversible for 60 days by default. A customer may instead instruct immediate, non-reversible deletion,
which removes the export and restoration window. At final purge, active customer data and
credentials are deleted or reconciled across systems we control; limited billing, security, audit,
legal-claim, and deletion-receipt data may remain where necessary, for the period above, and
access-restricted. If a backup must be restored, deletion records must be reapplied so deleted data is
not silently resurrected.

## 12. Security

We use administrative and technical controls designed for the risk, including server-side tenant
scoping and role checks, least-privilege service identities, encryption in transit, encrypted
credentials and backups, two-phase approval for external writes, immutable audit evidence, redaction
and telemetry allowlists, monitored backups, and incident response procedures. No system is
perfectly secure. Customers must protect their accounts, use appropriate roles, review access, and
notify `security@withhendrik.com` of suspected compromise.

We do not claim a certification that has not been independently obtained.

## 13. Your rights and choices

Depending on location and applicable law, individuals may have rights to access, correct, delete,
restrict, object to, or receive a portable copy of personal data; appeal certain refusals; and opt
out of sale, sharing, targeted advertising, or certain profiling. In the EEA, a person may object to
processing based on legitimate interests, including replay, based on their particular situation. We
do not currently sell personal data, share it for behavioral advertising, or conduct covered
high-impact profiling.

Send requests to `privacy@withhendrik.com`. We may verify identity and authority,
ask for information needed to locate the data, and apply lawful exceptions. Authorized agents must
provide proof of authority. If we process the data for a customer, we will direct the request to that
customer and assist as required by our DPA. Anonymous website visitors may request access to, object
to, or erase replay-linked data by giving the limited locating information described in Section 7;
a requester does not need a Hendrik account.

EEA users may complain to their local supervisory authority. Our lead authority is the Dutch Data
Protection Authority (`Autoriteit Persoonsgegevens`). US residents may contact their state regulator
where applicable. People elsewhere may contact the competent privacy regulator for their location.

We have not appointed a data protection officer because we have determined that the statutory
appointment thresholds do not currently apply. Because we are established in the Netherlands, no
EEA representative is required. We review whether a local representative or other appointment is
required when our processing or customer footprint materially changes.

## 14. Changes to this policy

We may update this policy as the Service, law, or vendors change. We will give at least 30 days'
advance notice of a materially adverse change where practicable. Changes required urgently for law
or security may take effect sooner, with prompt notice. The effective date and archived version will
identify the policy that applied.

## 15. Contact

- Privacy and rights: `privacy@withhendrik.com`
- Security reports: `security@withhendrik.com`
- Support: `support@withhendrik.com`
- Legal notices: `legal@withhendrik.com`
- Postal address: Magnolia Squared, Batavengaarde 4, 2408 TA Alphen aan den Rijn, the Netherlands

We provide customer support by email. The target—not a guaranteed service level—is a response
within seven days.
