Legal

Privacy Policy

Last updated: June 2026

This English translation is provided for your convenience. Only the Dutch version of this privacy policy is legally binding. Read the Dutch version

BrewerSync is a platform for breweries and beer festivals. In this privacy policy we explain which personal data we process, for what purposes, with whom we share it and what rights you have. We process data in accordance with the General Data Protection Regulation (GDPR).

Data controller

The data controller for the data processed through BrewerSync is:

Afiant B.V.

Lorentzstraat 89

2665 JG Bleiswijk

The Netherlands

KvK: 61946281

Email: privacy@brewersync.com

Which data we process

Depending on how you use BrewerSync, we process:

  • Account data: name, email address and (encrypted) password of users and breweries.
  • Company and customer data: which you enter yourself to manage your brewery, orders and customers.
  • Festival data: data of organizers, participants and (anonymous) visitors of a festival site.
  • Visitor email addresses: only if a festival visitor requests a beer overview themselves. These are stored encrypted.
  • Usage data: anonymous statistics such as page views and filter actions, to improve the product.

What we use data for, and on what legal basis

We use data for the following purposes, each with the corresponding legal basis:

  • Providing the service (logging in, account and brewery management, transactional emails such as login links and confirmations): to perform the agreement with you.
  • Invoicing and accounting: to comply with a legal obligation.
  • The beer overview for festival visitors: on the basis of your consent, which you can withdraw at any time.
  • Security and product improvement (anonymous usage statistics): on the basis of our legitimate interest in keeping the service secure and usable.

We do not sell personal data.

Processors

To provide the service, we engage carefully selected processors:

  • Supabase: database and storage.
  • Vercel: hosting of the application.
  • Resend: sending and receiving email.
  • Moneybird: invoicing and accounting.
  • Mollie: payment processing.

Data processing agreements have been (or are being) concluded with these parties.

Transfers outside the EEA

Some of our processors are established in or process data in the United States. To the extent that personal data is thereby processed outside the European Economic Area, we ensure appropriate safeguards, such as the European Commission's standard contractual clauses (Standard Contractual Clauses) and/or certification under the EU-US Data Privacy Framework.

Retention period

We do not retain data longer than necessary for the purposes above. We retain invoicing and accounting data for seven years due to the statutory fiscal retention obligation. Festival visitor data is used for the promised overview and then deleted or anonymized.

Security

We take appropriate technical and organizational measures. Access to data is protected at the database level, connections run via encryption (TLS) and sensitive data such as visitor email addresses is stored encrypted.

Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction and portability of your data, and the right to object. Where we process data on the basis of consent, you can withdraw that consent at any time. To make a request, email privacy@brewersync.com. You can also lodge a complaint with the Autoriteit Persoonsgegevens.

Cookies

We only use functional cookies that are necessary to log in and make the service work, plus anonymized usage statistics. We do not place tracking or advertising cookies. Our visitor statistics are cookieless and anonymized — we store no IP addresses or personal data, so no cookie banner is required.

Contact

Questions about this privacy policy or your data? Email privacy@brewersync.com or get in touch with us.