Privacy Policy

Controller: Stichting Outpapier, the Netherlands ("Operator", "we", "us")
Contact: [email protected]
Website: outpapier.nl
Last updated: 2026-05-14

This Privacy Policy explains how the Operator collects, uses, stores, and protects personal data in connection with:

  • the catalog.ID membership network (the "Network");
  • the Catalog desktop software (the "Software"); and
  • the Catalog Cloud Services (the "Cloud Services").

This policy should be read alongside the Catalog.ID Membership Agreement, the Catalog EULA and Cloud Services Terms, the Webshop Terms, and the CPR Terms.


1) Who we are

The Operator is a foundation established in the Netherlands. We operate the catalog.id membership network and the Catalog.org Cloud Services under a license from the Developer, Roberto Bourgonjen.

For the purposes of the General Data Protection Regulation (GDPR), the Operator is the data controller for the personal data described in this policy.


2) What personal data we collect

2.1 Account and registration data

When you create an account, we may collect:

  • name or pseudonym;
  • email address;
  • telephone number;
  • postal address;
  • public/private encryption keypair metadata (the public key is stored; the private key remains on your device).

2.2 User Content

Files, media, recordings, metadata, tags, comments, and other content you create, import, record, or upload to the Cloud Services. User Content may be encrypted or unencrypted depending on your choices.

2.3 Member Shared Data

Data shared between Members via the Network, including encrypted attributes, messages, files, links, provenance records, decryption keys, and identity assertions.

2.4 Payment and transaction data

  • BIT token purchase records, wallet balances, and usage history;
  • payment method details (processed by our payment provider; we do not store full payment card numbers).

2.5 Technical and operational data

  • IP addresses, device identifiers, browser type, operating system;
  • timestamps, file sizes, service usage logs, security logs;
  • network and connection data;
  • error reports and diagnostics.

2.6 Communication data

  • Messages you send to us (e.g., support requests);
  • dispute filings and arbitration correspondence.

3) How we use your data

We process personal data for the following purposes and legal bases:

Purpose Legal basis (GDPR Art. 6)
Providing and operating the Network and Cloud Services Performance of contract (Art. 6(1)(b))
Account creation, authentication, and security Performance of contract (Art. 6(1)(b))
Processing BIT token transactions and billing Performance of contract (Art. 6(1)(b))
Permanent archival of User Content (Cloud Services) Legitimate interest (Art. 6(1)(f)) — preserving cultural and intellectual works; consent where applicable
Provenance recording and process archiving Legitimate interest (Art. 6(1)(f)) — supporting IP claims and creative attribution
Enforcing our terms, dispute resolution, and trust/safety Legitimate interest (Art. 6(1)(f))
Security monitoring, fraud prevention, and abuse detection Legitimate interest (Art. 6(1)(f))
Complying with legal obligations (e.g., tax, law enforcement) Legal obligation (Art. 6(1)(c))
Communicating service updates and material changes Performance of contract (Art. 6(1)(b))

We do not use your personal data for advertising profiling or sell your data to third parties.


4) Encryption and privacy by design

The Catalog ecosystem is built on privacy-by-design principles:

  1. End-to-end encrypted Attributes. Certain Attributes are stored end-to-end encrypted. The Operator cannot read the plaintext of encrypted Attributes unless a decryption key is shared with us.
  2. Key-based sharing. When you share an encrypted Attribute, the decryption key is delivered encrypted to the recipient's public key. The Operator facilitates key delivery but does not have access to plaintext unless a key is specifically shared with us.
  3. Encrypted User Content. If you encrypt your User Content before uploading, the Operator's processing is limited to storage, transport, and legal compliance.
  4. Operational metadata. Even where content is encrypted, we necessarily process technical metadata (timestamps, file sizes, usage logs) to operate and secure the services.

The Operator acts as controller for account and operational metadata processing needed for service operation, security, billing, and legal compliance, even where some content fields are end-to-end encrypted.


5) Permanent archiving and the right to erasure

5.1 Archival by design

The Cloud Services are designed for permanent archiving. File histories, versions, edits, and provenance records may be retained indefinitely. Deletion may be technically impossible or restricted.

5.2 Legal basis for permanent retention

We rely on legitimate interest (Art. 6(1)(f) GDPR) for permanent archival retention, balancing the public and cultural interest in preserving intellectual works and provenance records against individual privacy interests. Where content is uploaded in non-encrypted form, users grant an archival license under the Catalog EULA and Cloud Services Terms (Section 11.3) that supports this retention.
We apply safeguards to reduce impact on privacy, including access controls, encryption, pseudonymisation where possible, purpose limitation, and restricting access and publication where appropriate. Where erasure is not possible due to the archival design or legal obligations, we will seek to meet the intent of a request through restriction of processing, minimising exposure, and other protective measures, where feasible.

5.3 Erasure requests

We acknowledge your right to request erasure under Article 17 GDPR. However, due to the archival design:

  • Encrypted content: if we cannot access the plaintext, erasure of the encrypted blob may not meaningfully affect your privacy, but we will assess each request individually.
  • Non-encrypted content: where the archival license and legitimate interest apply, we may not be able to delete content but can apply safeguards such as restricting public access, pseudonymizing associated account data, or removing personal identifiers from metadata.
  • Account data: upon account termination, we will delete or anonymize account registration data (name, email, phone, address) within a reasonable period, except where retention is required by law or for the exercise or defense of legal claims.

We will respond to erasure requests within one month as required by GDPR Article 12(3), and will explain any limitations and the safeguards applied.

5.4 If you require deletion

If you require the ability to fully delete content, do not upload it to the Cloud Services. Use the Software in Standalone/Local mode only.


6) Data sharing and recipients

We may share personal data with the following categories of recipients:

6.1 Other Members

When you share Attributes, User Content, or Member Shared Data with other Members, those Members receive access to the shared data (including via decryption keys). Sharing is controlled by you.

6.2 Sub-processors

We use third-party service providers to operate our infrastructure and services. These sub-processors process personal data on our behalf under data processing agreements that ensure GDPR compliance.

Current sub-processors:

Provider Purpose Location
Cloudflare, Inc. CDN, DDoS protection, DNS, traffic security Global (EU–U.S. Data Privacy Framework certified; may also rely on Standard Contractual Clauses and supplementary measures where required)
Mollie B.V. (mollie.com) Payment processing for BIT token purchases Netherlands (EU)

We will maintain an up-to-date list of sub-processors on our website (outpapier.nl).

6.3 Law enforcement and legal obligations

We may disclose personal data where required by law, regulation, court order, or competent authority request.

6.4 Dispute resolution

In connection with disputes under the Catalog.ID Membership Agreement or Catalog EULA and Cloud Services Terms, relevant data may be shared with arbiters, mediators, or the Review Board, subject to confidentiality obligations.

6.5 Successor or transferee

In the event of a transfer of operations to another operator (e.g., another Catalog federation entity), personal data may be transferred to the successor, subject to appropriate safeguards and notice.


7) International data transfers

Our servers are located in the European Union. We do not intentionally transfer personal data outside the EU/EEA for storage.

However, Cloudflare operates a global CDN network and may temporarily process traffic data (IP addresses, request headers, cached content) at edge locations outside the EU/EEA. Cloudflare is certified under the EU-US Data Privacy Framework and has Standard Contractual Clauses (SCCs) in place. The processing is transient (caching and routing) and does not involve permanent storage of personal data outside the EU.

If we engage additional sub-processors outside the EU/EEA in the future, we will ensure appropriate safeguards are in place (e.g., adequacy decisions, SCCs, or binding corporate rules) and update this policy accordingly.


8) Data retention

Data category Retention period
Account registration data Duration of account + reasonable period after termination (or as required by law)
User Content (non-encrypted, Cloud Services) Permanent (archival by design)
User Content (encrypted, Cloud Services) Permanent (archival by design; plaintext inaccessible to the Operator)
BIT token transaction records Duration of account + 7 years (Dutch tax/accounting obligations; longer where legally required—some records may require up to 10 years)
Technical and security logs Up to 12 months (or longer where required for security investigation or legal obligation)
Dispute and arbitration records Duration of the dispute + 5 years (limitation period)
Communication/support data Up to 3 years after resolution

9) Your rights

Under the GDPR, you have the following rights:

Right Description
Access (Art. 15) Request a copy of the personal data we hold about you.
Rectification (Art. 16) Request correction of inaccurate or incomplete data.
Erasure (Art. 17) Request deletion of your data, subject to the limitations described in Section 5 of this policy.
Restriction (Art. 18) Request that we restrict processing in certain circumstances.
Portability (Art. 20) Receive your data in a structured, commonly used, machine-readable format, or request transfer to another controller.
Objection (Art. 21) Object to processing based on legitimate interest. We will cease processing unless we demonstrate compelling legitimate grounds.
Withdraw consent (Art. 7(3)) Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

How to exercise your rights

Contact us at [email protected] with your request. We will verify your identity and respond within one month. We may request additional information to verify your identity (for example, confirming control of the email address or phone number on file). If the request is complex or we receive many requests, we may extend this by a further two months, with notice.

Right to lodge a complaint

If you believe we have not handled your data properly, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):

  • Website: autoriteitpersoonsgegevens.nl
  • Postal: Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag

10) Data portability on account termination

When you terminate your account or your membership ends:

  1. You may request an export of your personal data and User Content in a structured, commonly used format before or within a reasonable period after termination.
  2. Account registration data (name, email, phone, address) will be deleted or anonymized within a reasonable period after termination, except where retention is required by law.
  3. User Content uploaded to the Cloud Services is subject to the permanent archival policy and may not be deletable (see Section 5).

11) Cookies and tracking

The Software (desktop applications) does not use cookies. The Cloud Services web interfaces and website (outpapier.nl) may use:

  • Strictly necessary cookies: for authentication, session management, and security. These do not require consent.
  • No advertising or tracking cookies. We do not use third-party advertising trackers or analytics cookies.

Cloudflare may set security-related cookies (e.g., __cf_bm) for bot protection. These are strictly necessary for security and do not track you for advertising purposes.


12) Security measures

We implement appropriate technical and organizational measures to protect personal data, including:

  • end-to-end encryption for supported Attributes and User Content;
  • encryption in transit (TLS) for all network communications;
  • encryption at rest for stored data;
  • access controls and authentication for systems and personnel;
  • security logging and monitoring;
  • regular security assessments.

No system is completely secure. If you suspect a security incident or unauthorized access to your account, contact us immediately at [email protected].


13) Children

The Network, Software, and Cloud Services are not intended for persons under 18 years of age. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected data from a person under 18, we will take steps to delete that data and terminate the associated account.


14) Changes to this policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice via the Network, the Software, or our website. The "Last updated" date at the top indicates the most recent revision. Continued use of our services after the effective date of changes constitutes acceptance.


15) Contact

Stichting Outpapier
Website: outpapier.nl
Email: [email protected]
Data Protection Officer (DPO): Not appointed (not required for our current activities)

For privacy-related requests, please include "Privacy" or "GDPR" in your email subject line to help us route your request promptly.