Privacy Policy
Last updated: June 2026
This English translation is provided for your convenience. Only the Dutch version of this privacy policy is legally binding. Read the Dutch version
BrewerSync is a platform for breweries and beer festivals. In this privacy policy we explain which personal data we process, for what purposes, with whom we share it and what rights you have. We process data in accordance with the General Data Protection Regulation (GDPR).
Data controller
The data controller for the data processed through BrewerSync is:
Afiant B.V.
Lorentzstraat 89
2665 JG Bleiswijk
The Netherlands
KvK: 61946281
Email: privacy@brewersync.com
Which data we process
Depending on how you use BrewerSync, we process:
- Account data: name, email address and (encrypted) password of users and breweries.
- Company and customer data: which you enter yourself to manage your brewery, orders and customers.
- Festival data: data of organizers, participants and (anonymous) visitors of a festival site.
- Visitor email addresses: only if a festival visitor requests a beer overview themselves. These are stored encrypted.
- Usage data: anonymous statistics such as page views and filter actions, to improve the product.
What we use data for, and on what legal basis
We use data for the following purposes, each with the corresponding legal basis:
- Providing the service (logging in, account and brewery management, transactional emails such as login links and confirmations): to perform the agreement with you.
- Invoicing and accounting: to comply with a legal obligation.
- The beer overview for festival visitors: on the basis of your consent, which you can withdraw at any time.
- Security and product improvement (anonymous usage statistics): on the basis of our legitimate interest in keeping the service secure and usable.
We do not sell personal data.
Processors
To provide the service, we engage carefully selected processors:
- Supabase: database and storage.
- Vercel: hosting of the application.
- Resend: sending and receiving email.
- Moneybird: invoicing and accounting.
- Mollie: payment processing.
Data processing agreements have been (or are being) concluded with these parties.
Transfers outside the EEA
Some of our processors are established in or process data in the United States. To the extent that personal data is thereby processed outside the European Economic Area, we ensure appropriate safeguards, such as the European Commission's standard contractual clauses (Standard Contractual Clauses) and/or certification under the EU-US Data Privacy Framework.
Retention period
We do not retain data longer than necessary for the purposes above. We retain invoicing and accounting data for seven years due to the statutory fiscal retention obligation. Festival visitor data is used for the promised overview and then deleted or anonymized.
Security
We take appropriate technical and organizational measures. Access to data is protected at the database level, connections run via encryption (TLS) and sensitive data such as visitor email addresses is stored encrypted.
Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction and portability of your data, and the right to object. Where we process data on the basis of consent, you can withdraw that consent at any time. To make a request, email privacy@brewersync.com. You can also lodge a complaint with the Autoriteit Persoonsgegevens.
Cookies
We only use functional cookies that are necessary to log in and make the service work, plus anonymized usage statistics. We do not place tracking or advertising cookies. Our visitor statistics are cookieless and anonymized — we store no IP addresses or personal data, so no cookie banner is required.
Contact
Questions about this privacy policy or your data? Email privacy@brewersync.com or get in touch with us.