Trotora er et handelsnavn for MyPixel, en nederlandsk virksomhet (KvK 69247935). Denne erklæringen forklarer hvilke persondata vi behandler, på hvilket rettslig grunnlag, hvem vi deler dem med, og hvordan du kan utøve rettighetene dine under GDPR. Der plattformen ennå ikke gjør alt vi ønsker, sier vi det også her.
1. Who is responsible for your data
The controller of your personal data is MyPixel. Trotora is a trade name of MyPixel, a Dutch business registered with the Chamber of Commerce under number 69247935. Where this policy refers to 'we', 'us' or 'Trotora', it means MyPixel.
- Business
- MyPixel
- Trade names
- Trotora and BaseWire
- Chamber of Commerce (KvK)
- 69247935
- Postal address on request
- Available via [email protected] or through the Dutch Chamber of Commerce register
- Privacy contact
- [email protected]
- General contact
- [email protected]
We have not formally appointed a Data Protection Officer; our privacy contact answers all GDPR requests. If you believe your data is being handled incorrectly you may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
2. What data we process
We process the categories of data listed below. The legal basis (GDPR Art. 6) is shown per category.
| Category | Examples | Legal basis |
|---|---|---|
| Account data | Email, username, display name, password hash, profile photo | Art. 6(1)(b): performance of the contract |
| Profile data | Bio, location, website, skills, experience, certifications | Art. 6(1)(b): performance of the contract |
| Horse profile data | Name, breed, date of birth, photos, training logs | Art. 6(1)(b): performance of the contract |
| Horse health data | Medications, vaccinations, vital signs, vet contacts | Art. 6(1)(b): performance of the contract |
| Usage data | IP address (truncated), device, browser, pages visited | Art. 6(1)(f): legitimate interest in operating and securing the service |
| Payment data | Stripe customer ID, last 4 digits of card, subscription status | Art. 6(1)(b) and Art. 6(1)(c): contract and legal obligation |
| Communication data | Support messages, in-app messages, posts and comments you publish | Art. 6(1)(b): performance of the contract |
| Consent records | Your cookie and marketing choices, with timestamp and truncated IP | Art. 6(1)(c): legal obligation to demonstrate consent |
| Security and moderation data | Login events, security log entries, content flags and moderation actions | Art. 6(1)(f): legitimate interest in fraud prevention and platform safety |
We do not process special categories of personal data about you (such as health or biometric data). Horse health data relates to animals and is not personal data about you, but we still treat it as sensitive operational data.
3. Why we use your data
- To operate the platform
- Authentication, profiles, horse management, social features, marketplace, AI assistant, billing and notifications.
- To keep the platform safe
- Detecting abuse, preventing fraud, moderating content and protecting accounts.
- To improve the platform
- Product analytics (pseudonymised and aggregated where possible) to understand which features are used. Only with your consent.
- To communicate
- Service emails (password resets, billing receipts) are essential. Newsletters and product updates are only sent if you have opted in and can be cancelled at any time.
- To comply with law
- Accounting records, fraud prevention data and responses to lawful requests from authorities.
4. Who processes data on our behalf
We use a small number of carefully selected sub-processors. Transfers outside the European Economic Area rely on the European Commission's Standard Contractual Clauses (SCCs) unless an adequacy decision applies.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of our servers and databases, including our self-hosted file storage (Supabase Storage) and error tracking (Bugsink, Sentry-protocol SDK). For error tracking, PII is scrubbed before sending and browser errors are only captured with analytics consent | Germany (EU) | Within the EEA |
| Firebase / Google Cloud (Google LLC) | Authentication and, only with your consent, Firebase/GA4 analytics | EU / US (multi-region) | SCCs |
| Stripe | Subscription billing and payment processing | Ireland / United States | SCCs |
| Amazon Web Services | Storage of generated reports and PDFs (S3) and automated image moderation (Rekognition) | EU (eu-central-1, Frankfurt) | Within the EEA |
| Vercel | Performance measurement (Speed Insights), only with analytics consent | United States | SCCs |
| PostHog | Product analytics (only with consent) | European Union | Within the EEA |
| Resend | Transactional email (password resets, receipts, notifications) | United States | SCCs |
| OpenAI | Content moderation and AI assistant features | United States | SCCs |
| Google APIs (Translate, Perspective, Places) | Translation, toxicity scoring, place lookup | EU / US | SCCs |
| Cloudflare Turnstile | Bot protection for forms | Global edge network | SCCs |
| Upstash Redis | Rate-limiting and short-lived caching | Region per deployment | SCCs where outside the EEA |
We do not sell your personal data, and we do not allow sub-processors to use it for their own purposes.
If you use Trotora as a business customer (for example a stable, company or event organiser) and we process personal data of your staff, clients or visitors on your behalf, our standard Data Processing Agreement applies automatically, see trotora.com/dpa.
5. How long we keep data
| Data category | Retention period |
|---|---|
| Account and profile data | For as long as the account is active. Removed within 30 days after deletion. |
| Horse profiles and content you posted | For as long as the account is active. You can delete individual items at any time. |
| Billing and invoicing records | Up to 7 years to meet Dutch fiscal retention obligations. |
| Messages and support communication | In-app messages: for as long as the conversation exists or until you delete your account. Support correspondence: up to 24 months after resolution. |
| Security logs | Up to 12 months unless required longer for an active incident. |
| Consent records | 5 years after the consent was withdrawn or expired, for audit purposes. |
| Backups | Encrypted backups roll over within 30 days; deleted data disappears from backups within that window. |
6. Your rights and how to use them
Under the GDPR you have the following rights:
- Right of access to the personal data we hold about you (Art. 15).
- Right to rectification of inaccurate data (Art. 16).
- Right to erasure of your account and personal data (Art. 17).
- Right to data portability: receive your data in a structured, machine-readable format (Art. 20).
- Right to object to processing based on legitimate interest, including for analytics or moderation (Art. 21).
- Right to restrict processing in specific cases (Art. 18).
- Right to withdraw consent at any time, where consent is the legal basis.
You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
7. Children and young users
Trotora is intended for users aged 16 and over. Under the Dutch implementation of GDPR Art. 8, parental consent is required to process the personal data of children under 16 based on consent.
8. Automated content moderation
We may use automated tools to scan uploaded content for abuse and unsafe material:
- AWS Rekognition checks uploaded images for explicit content.
- OpenAI Moderation API screens text for hate, harassment and self-harm signals.
- Google Perspective scores text for toxicity.
We act as a deployer of these third-party AI tools: they assist our human moderators and do not, on their own, impose sanctions on you without human review. When content is blocked or limited you are told the reason, and every moderation action can be appealed via the in-app appeal flow (GDPR Art. 22 and the Digital Services Act).
9. Horse health and animal data
You can record medical and care details about your horses, including medications, vaccinations, vital signs and contact details of your vet. This is data about animals, not personal data about you, but we treat it as sensitive operational data: access is limited to the account that owns the horse and any collaborators you explicitly invite.
If a vet contact is added to your horse's profile, that vet's contact details become processed personal data. We only use them to display the contact within your account and never share them with third parties.
10. How we secure your data
- All connections to Trotora use TLS encryption.
- Passwords are hashed with bcrypt. They cannot be read by us.
- Session cookies are HTTP-only, Secure and SameSite-flagged.
- Two-factor authentication is available for all accounts.
- Access to production systems is restricted, logged and audited.
- We monitor for brute-force login attempts and suspicious activity.
In the unlikely event of a data breach affecting your personal data, we will notify you and the Dutch Data Protection Authority within 72 hours, in line with GDPR Art. 33–34.
11. International data transfers
Trotora is operated from the Netherlands. Most processing happens within the European Economic Area. Some sub-processors are based in the United States, see section 4. All transfers outside the EEA are covered by the European Commission's Standard Contractual Clauses.
12. Changes to this policy
We update this policy when the platform changes or when the law requires it. The 'last updated' date at the top reflects the most recent change. For material changes we will notify you in the app or by email before the new version takes effect.
13. Contact
Questions about this policy or about how we handle your data?
- Email [email protected]
- Or write to Trotora via the postal address on request (see section 1)
You may also lodge a complaint with the Autoriteit Persoonsgegevens (Dutch Data Protection Authority) at autoriteitpersoonsgegevens.nl.