Back to home

Cards Privacy Policy

Last updated: 07 October 2026

This Privacy Policy explains how Sanera Technologies processes personal data when you use the Cards app and its related services: which data we process, for what purposes and on which legal bases, to whom it is disclosed, how long it is retained, and the rights available to you under the General Data Protection Regulation (GDPR) and the laws of the Netherlands.

01

Introduction and Scope

1.1 Scope

This Privacy Policy applies to the processing of personal data in connection with the Cards mobile application for iOS and Android (the "App"), the public card pages and links generated by the App, the Apple Wallet and Google Wallet passes issued through the App, and the web portal through which organisations administer work cards (together, the "Service"). Our general Privacy Policy, available at sanera.nl/privacy-policy, governs all other services and websites of Sanera Technologies.

1.2 Controller

The controller within the meaning of the General Data Protection Regulation (EU) 2016/679 ("GDPR") is Sanera Technologies, Dalsteindreef, 1112 XJ Diemen, the Netherlands ("Sanera", "we", "us" or "our"). Where an organisation issues work cards to its personnel through the Service, that organisation determines which personal data appears on those work cards and to whom they are issued. In respect of that data, the organisation acts as controller and Sanera processes the data on its behalf as processor.

1.3 Definitions

In this Privacy Policy, "personal data", "processing", "controller" and "processor" have the meanings given to them in Article 4 GDPR. "You" means any natural person who uses the Service or whose personal data is processed through it.

1.4 Summary

  • You decide what your card contains and which details are public. Details you make private are removed from your public page, your contact file and the cards your connections see without delay.
  • We do not sell or rent personal data, we do not display advertising, and the App contains no third-party advertising or analytics software.
  • Your calendar, your device address book, scanned paper business cards, follow-ups and event notes are processed on your device only and are not transmitted to us.
  • You may export your data or delete your account in the App at any time.
02

Personal Data We Process

2.1 Account data

Your e-mail address and name. If you set a password, we store only a one-way cryptographic hash of it. If you sign in with Apple or Google, we receive from that provider your e-mail address, your name (which Apple provides on first sign-in only) and an account identifier, together with a refresh token that we store in encrypted form solely in order to revoke the App's access when you delete your account (see section 12). One-time verification codes are sent to your e-mail address.

2.2 Card data

The information you enter on your cards, which may include your name, job title, organisation, a short description, contact details (such as telephone numbers, e-mail addresses, websites and social media or messaging accounts), a photograph or picture, a logo, the design of the card and, for work cards, a barcode provided by your organisation. You determine for each item whether it is public.

2.3 Connection data

The fact that you are connected with another user, which of your cards each party has chosen to share, and the relevant dates. Notes you record about a connection, and where you met, are visible to you alone. We also process connection requests and blocks.

2.4 Organisation data

Where you belong to an organisation in the Service: your membership and role, invitations sent to or by you, and the organisation's details (name, verified domains, brand colours, logo and subscription status). Administrative actions are recorded in an audit log available to the organisation's administrators. Payments for organisation subscriptions are processed by Stripe; we retain only a customer reference and the subscription status.

2.5 Device, session and security data

For each sign-in: the device name and type, the App version, the IP address and the time. A push notification token for each device on which you have permitted notifications. The devices on which an Apple Wallet pass for your card is installed, so that the pass can be updated. A security log of sign-ins and sensitive account actions, including the IP address and device concerned.

2.6 Card view statistics

The number of times the link or code of a card is opened each day. These figures are aggregated and anonymous: we do not record who opened a card or their IP address.

2.7 Reports and correspondence

The content of any report you submit about another user (see section 10), any correspondence you send to us, and the information needed to handle it.

03

Data Processed Solely on Your Device

The following features operate entirely on your device. The data they use is not transmitted to Sanera:

Calendar

If you enable Meetings, the App reads your calendar in order to display the cards of the persons you are about to meet. The App does not modify your calendar.

Contacts

The App accesses your device's contacts only when you choose to save or update a connection in your contacts. Your address book is never uploaded.

Scanning of paper business cards and codes

Text on a scanned business card, or a code read from a photograph, is recognised on your device. You review the result before anything is saved.

Photo cut-out

The layered photograph effect is generated on your device.

Follow-ups, events and reminders

Follow-ups, event notes and the related reminders are stored on your device only.

Local copies

Your sign-in credentials are held in the secure storage of your device, and copies of your cards are kept for widgets and Wallet passes. This data is removed from the device when you sign out.

04

Purposes and Legal Bases

We process personal data for the following purposes and on the following legal bases:

Performance of a contract (Article 6(1)(b) GDPR)

Providing the Service: your account, cards, public page, connections and Wallet passes; sending verification codes, invitations and service messages; and, for organisations, the administration of members, invitations, work cards and subscriptions.

Consent (Article 6(1)(a) GDPR)

Push notifications and access to your camera, photo library, contacts and calendar, each of which the App requests only through your device's permission prompt. You may withdraw consent at any time in your device settings, without affecting the lawfulness of processing before withdrawal.

Legitimate interests (Article 6(1)(f) GDPR)

Maintaining the security and integrity of the Service, preventing fraud, spam and abuse, handling reports about users and their content, and compiling anonymous view statistics. We have balanced these interests against your rights and limit the data processed to what is necessary.

Legal obligation (Article 6(1)(c) GDPR)

Retaining billing records as required by Dutch tax law, responding to lawful requests from public authorities, and meeting our obligations as a hosting service provider under the Digital Services Act (Regulation (EU) 2022/2065).

Matters we do not undertake

We do not sell or rent personal data, display advertising, track you across applications or websites owned by other companies, or use your personal data to train artificial intelligence models. We do not engage in automated decision-making, including profiling, that produces legal or similarly significant effects within the meaning of Article 22 GDPR.

05

Visibility and Recipients

5.1 Persons with your link or code

Any person who has your card's link or code can see your name and the details you have made public, including on the Wallet pass and in the contact file they may save.

5.2 Your connections

Your connections see the cards you have chosen to share with them, limited to the public details on those cards, and kept up to date. Contact details you keep private are never shown. You may remove a connection or block a user at any time; the other user is not notified.

5.3 Your organisation

If you hold a work card, your organisation's administrators can see your work card, your role and the number of connections of that work card, but not the identity of those connections. They have no access to your personal card or its connections.

5.4 Directory synchronisation

An organisation may connect its Google Workspace or Microsoft Entra ID directory, or an identity provider using SCIM (such as Okta). In that case we receive the name, work e-mail address and account status of persons on the organisation's verified domains, in order to invite new personnel and deactivate the work card of a person who leaves. Deactivating a work card does not affect that person's personal account or personal card. When the organisation disconnects its directory, we delete the access credentials it granted.

5.5 Sanera personnel

A limited number of authorised Sanera personnel may access account information where necessary for support, the handling of reports and security. Such access is logged.

5.6 Processors

We engage the following processors, each bound by a data processing agreement and permitted to process personal data only on our documented instructions:

  • Render Services, Inc.: hosting of the Service's servers in Frankfurt, Germany.
  • MongoDB, Inc. (MongoDB Atlas): database hosting for accounts, cards and connections.
  • Amazon Web Services EMEA SARL (Amazon S3): storage of card photographs and logos.
  • Resend: delivery of e-mail sent by the Service.
  • Apple Inc. and Apple Distribution International Ltd.: Sign in with Apple, Apple Wallet and push notifications on iOS.
  • Google LLC and Google Ireland Limited: Sign in with Google, Google Wallet and Firebase Cloud Messaging on Android.
  • Stripe Payments Europe, Ltd.: payment processing for organisation subscriptions.

5.7 Other disclosures

We may disclose personal data where required by Dutch or European Union law, in response to a binding order of a court or competent authority, or to a successor in the event of a merger, acquisition or transfer of all or part of our business, subject to equivalent safeguards.

06

International Transfers

Certain processors are established in, or may access personal data from, countries outside the European Economic Area. Where personal data is transferred to such a country, the transfer is based on an adequacy decision of the European Commission, including the EU-U.S. Data Privacy Framework where the recipient is certified under it, or on the Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by additional safeguards.

07

Retention Periods

We retain personal data no longer than necessary for the purposes for which it is processed:

  • Account, card, connection and membership data: until you delete it or delete your account.
  • Sign-in sessions: up to 180 days, or 60 days of inactivity; ended sessions are deleted after 30 days.
  • Push notification tokens: until you sign out, or after 90 days of inactivity.
  • Verification codes: one hour (codes cease to be valid after ten minutes).
  • Apple and Google refresh tokens: until your account is deleted, at which point they are revoked and erased.
  • Unanswered connection requests and removed connections: 30 days.
  • Invitations: 90 days after expiry.
  • Anonymous daily view statistics: 400 days.
  • Security log: 400 days, including after an account has been deleted, for the detection and investigation of abuse.
  • Organisation audit log: two years.
  • Reports: until resolved, and thereafter for one year.
  • Photographs and logos: until you replace or remove them. A cached link preview may continue to display a previous image for up to 24 hours.
  • Billing records of organisations: seven years, as required by Dutch tax law.
08

Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, one-way hashing of passwords, storage of credentials in the secure storage of your device, re-authentication for sensitive actions such as data export and account deletion, and restricted and logged access by personnel. No method of transmission or storage is entirely secure, and we review these measures regularly.

09

Your Rights

9.1 Rights under the GDPR

Subject to the conditions of the GDPR, you have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20), the right to object to processing based on legitimate interests (Article 21), and the right to withdraw consent at any time (Article 7(3)).

9.2 Exercising your rights in the App

  • Edit your cards and make any detail public or private.
  • Choose which cards each connection may see, remove a connection, block a user or report a user.
  • Deactivate a Wallet pass, for example on a lost device (Account > Wallet passes).
  • Review your sign-ins and end any session (Account > Signed-in devices and Account > Recent activity).
  • Export your data in a machine-readable format (Account > Export my data).
  • Delete your account (Account > Delete account).
  • Withdraw permission for notifications, camera, photos, contacts or calendar in your device settings.

9.3 Requests by e-mail

You may also exercise your rights by contacting us at the address in section 16. We may ask you to verify your identity, and we will respond within one month of receipt, which may be extended by two further months where necessary in accordance with Article 12(3) GDPR.

9.4 Supervisory authority

You have the right to lodge a complaint with a supervisory authority, in particular the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). We would appreciate the opportunity to address your concern first.

10

Reporting and Content Moderation

10.1 Submitting a report

You may report a user whose card or conduct you consider unlawful, misleading, offensive or otherwise inappropriate, using Report on that user's card or connection request in the App, or the report link on a public card page. A report records the reason you select, any note you add, the card concerned and, for reports made in the App, your account identifier. You may also block the user at the same time.

10.2 Confidentiality

The reported user is not informed of your identity. Reports submitted through a public card page are anonymous.

10.3 Handling of reports

Reports are reviewed by authorised Sanera personnel, and we endeavour to review each report within 24 hours. Where a report is substantiated, we may remove content, deactivate a card or suspend the account concerned. Reports are processed on the basis of our legitimate interest in keeping the Service safe and our obligations under the Digital Services Act, and are retained as set out in section 7.

11

Device Permissions

The App requests each of the following permissions only when you first use the feature concerned. The App remains usable if you decline:

  • Camera: to photograph your card picture and to scan QR codes and paper business cards.
  • Photo library: to select a picture or logo, or to read a code from an image.
  • Contacts: to save a connection to your contacts at your request.
  • Calendar (read only): to display the cards of persons you are meeting.
  • Notifications: for connection requests, accepted connections and your own reminders.
  • NFC: to write the link to your card onto an NFC tag.
12

Account Deletion

12.1 Deleting your account

You may delete your account at any time under Account > Delete account. Upon deletion we:

  • erase the details of all your cards, including photographs and logos, and deactivate their public pages and links;
  • void your Wallet passes, which thereafter display your name only and no longer update;
  • delete your connections (for both parties), blocks, sessions and push notification tokens;
  • revoke the App's access to your Apple ID or Google Account where you signed in with Apple or Google, so that the App no longer appears among the applications using that account;
  • erase the name and e-mail address of your account and end your organisation memberships.

12.2 Exceptions

If you own an organisation in the Service, you must transfer ownership or delete the organisation before deleting your account. Entries in the security log and reports concerning your account are retained for the periods set out in section 7. Data stored only on your device (section 3) is removed when you sign out or uninstall the App.

12.3 Other means

If you are unable to sign in, you may request deletion by e-mail and we will delete the account after verifying your identity. You may also revoke the App's access independently: on iOS under Settings > [your name] > Sign in with Apple, and for Google at myaccount.google.com under Security, Your connections to third-party apps and services.

13

Children

The Service is not directed at persons under the age of 16, and we do not knowingly process personal data of children under that age. If you believe that a child under 16 has created an account, please contact us and we will delete it.

14

Third-Party Links

Cards may contain links to websites and services operated by third parties, including links added by other users. Sanera is not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.

15

Changes to This Privacy Policy

We may amend this Privacy Policy from time to time. The date of the latest revision is shown at the top of this page. Where an amendment materially affects the processing of your personal data, we will notify you in the App or by e-mail before it takes effect.

16

Contact

Questions, requests and complaints concerning this Privacy Policy or the processing of your personal data in Cards may be addressed to:

Contact

Sanera Technologies

Email: info@sanera.nl

Phone: +31 (6) 39 65 25 54

Dalsteindreef, 1112 XJ Diemen, Netherlands