Legal
Privacy statement
How De Herstellers handles personal data from software vendors and their systems.
Updated: 11 August 2026
Who we are
DeHerstellers builds, hosts and maintains API integrations between automotive software platforms. Our customers are software vendors. We are the controller for the limited personal data we collect through this website and through our commercial relationships, and a processor for personal data that flows through integrations we operate on behalf of a vendor.
What we collect
- Request wizard submissions. Company name, contact name, work email address, and the technical details you describe about the integration you need.
- Correspondence. Email and meeting notes related to an engagement.
- Operational data. Logs, error traces and delivery metrics produced by integrations we host, which may contain identifiers such as VINs, dealer numbers or customer references supplied by the vendor.
This website sets no advertising or tracking cookies. The only browser storage we use is a local theme preference and a local draft of an unfinished request form; both stay on your device and are never transmitted to us.
Why we use it
- To scope, quote and deliver an integration you asked us to build.
- To operate, monitor and support integrations under an agreed service level.
- To meet legal, tax and accounting obligations.
Our legal bases are the performance of a contract, our legitimate interest in responding to a business enquiry, and compliance with legal obligations.
Data flowing through integrations
When we operate an integration, we process the payloads a vendor routes through it strictly on that vendor's documented instructions. We do not use that data for our own purposes, do not sell it, and never approach the vendor's end customers. Field-level scope, retention and deletion terms are fixed per integration in a data processing agreement.
Retention
- Request submissions and correspondence: up to 24 months after last contact.
- Operational logs: 30 days by default, unless the vendor agrees otherwise.
- Invoices and contracts: as long as statutory retention periods require.
Sharing and sub-processors
We share data only with sub-processors needed to run our service — hosting, error monitoring and email delivery — all contracted under the GDPR and hosted in the EU unless a vendor agreement states otherwise. A current sub-processor list is available on request.
Security
Credentials are stored in a managed secret store, transport is TLS-only, access is least-privilege and audited, and every integration runs in an isolated environment per vendor. We report a confirmed personal data breach to affected vendors without undue delay and within 24 hours of detection.
Your rights
You can request access, correction, deletion, restriction or portability of your personal data, and object to processing based on legitimate interest. If we process data on behalf of a vendor, direct your request to that vendor and we will support them. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Contact
Privacy questions: privacy@deherstellers.example. We answer within five working days.
Changes
We update this statement when our processing changes. Material changes are communicated to active vendors by email before they take effect.