Version 1 · last updated 26 September 2026
Privacy policy
This policy explains which personal data ZZP Accountant processes, why, and what your rights are. It applies to the website accountant.senturk.dev and the application at app.accountant.senturk.dev.
1. Who is responsible
ZZP Accountant is provided by Onur Senturk, a private individual in the Netherlands ("we"). For your account data we are the controller. For the bookkeeping data you enter about your own customers and suppliers, you are the controller and we process it on your behalf, as described in section 6.
Questions and requests about your data go through the contact form. No account is needed to use it.
2. What we process
- Account data: your email address, a hashed password, two-factor authentication settings and recovery codes, and the date you accepted our terms.
- Bookkeeping data you enter: your company details, invoices, purchases, bank statements and uploaded receipts. These can contain names, addresses, KvK and VAT numbers, IBANs and amounts relating to you, your customers and your suppliers.
- Contact form messages: the name, email address and message you send us.
- Technical data: short-lived server logs needed to run and secure the service, which can include your IP address.
We do not use analytics, advertising or tracking cookies, and we do not sell or share your data for marketing.
3. Why, and on what legal basis
- To provide the service you signed up for: account data and bookkeeping data (performance of a contract, GDPR article 6(1)(b)).
- To keep the service secure and prevent abuse: technical data and two-factor authentication (legitimate interest, article 6(1)(f)).
- To answer you: contact form messages (legitimate interest, article 6(1)(f)).
4. Cookies
The application only sets cookies that are strictly necessary: to keep you signed in, to protect forms against forgery, to remember your language, and, if you choose it, to remember a trusted browser for two-factor authentication. The website sets no cookies.
5. Where your data is stored
Data is stored in Microsoft Azure data centres in the European Union (Sweden Central for the application, West Europe for the website). Microsoft acts as our sub-processor under its data protection terms. Where Microsoft personnel outside the EU may access data for support or security, this is covered by the EU Standard Contractual Clauses. Data is encrypted in transit and at rest.
6. Data you enter about others
When you record customers, suppliers or bank transactions, you decide what is entered and why, so you are the controller of that data and we are your processor. We only process it to provide the service to you, keep it confidential, secure it as described here, and help you respond to requests from the people concerned. Our terms contain the processing arrangements.
7. How long we keep data
- Bookkeeping data is kept while your account exists, because Dutch law requires businesses to keep their records for seven years (ten for real estate). You can ask for an export at any time.
- When you close your account, we delete your data after giving you the chance to export it, unless you ask us to keep it for your retention period.
- Backups are kept for up to 30 days. Server logs are kept for up to 30 days.
- Contact form messages are deleted once your question has been handled, and at the latest after one year.
8. Your rights
You can ask to access, correct, delete, restrict or export your personal data, and object to processing based on legitimate interest. Some deletion requests may be limited by the legal retention period for bookkeeping records. Send requests through the contact form; we respond within one month.
You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
9. Changes
If we change this policy we update the version and date at the top. We tell signed-in users about significant changes before they take effect.