Privacy Policy
Last updated: 2 September 2026
1. Who we are, and which role we play
PestHulpApp is pest control software operated by Brightnsolutions, trading from the Netherlands. You can reach us at the addresses in section 13.
Two different relationships are described in this policy, and it matters which one applies to you:
- If you are our customer — a pest control business using the software — we are the controller for your account data, and the processor for everything you put into the platform.
- If your details are in the platform because a pest control business visited your property, that business is the controller. We process your data on their instructions. Ask them first; we will help them answer you.
Where we act as processor we do not decide what data is collected or why. We act on our customer's instructions and on what the law requires of us.
2. What data we handle
Account data (we are controller)
Name, work email address, company name, role, hashed password, and the login and audit records needed to keep the account secure.
Platform data (we are processor)
Everything a pest control business records while working: their clients and contacts, property addresses, scheduled and completed visits, pests found and how severe, monitoring point readings, products applied with quantity and registration number, photographs taken on site, written recommendations, client signatures, quotes, reports and invoices.
Mailbox data (we are processor)
When a business connects an enquiry mailbox, the content of messages we identify as pest control enquiries, and the details taken from them. See section 4.
Technical data
IP address, browser and device type, timestamps, and error and access logs. We keep these to run the service, investigate faults and detect abuse.
What we deliberately do not handle
We do not process payment card details — we have no payment integration. We do not collect special categories of personal data, and ask customers not to record any in free-text fields.
3. Why we process it, and on what legal basis
- To deliver the service you signed up for — performance of a contract.
- To keep accounts secure and investigate misuse — legitimate interest.
- To meet legal obligations, including retention of biocide application records — legal obligation.
- To connect a mailbox and read enquiries — consent, given by an administrator and withdrawable at any time.
- To improve reliability and diagnose faults — legitimate interest, using the least data that answers the question.
4. Google user data (Gmail)
PestHulpApp can connect to a Gmail mailbox so that customer enquiries arriving by email become work items automatically. This section describes exactly what that involves, because it is the part people ask about most, and it is written to be checked rather than skimmed.
What we request
With explicit consent we request one Google permission: gmail.readonly. It is read-only. The application cannot send, reply to, modify, delete, label or archive anything in a mailbox, and we never request permission that would let it.
Whose mailbox
An administrator connects one shared company enquiry mailbox — typically info@ or offerte@. We do not ask for, and cannot reach, an individual employee's personal mailbox. The connection is per business, not per employee.
What we do with it
We read incoming messages to decide whether each is a pest control enquiry. Where it is, we create a task containing what the sender wrote: their name and contact details, the property address, the pest reported and how urgent it appears. Staff then contact the customer and schedule a visit. The purpose is to stop somebody re-typing what the customer already wrote.
What we discard
Messages that are not pest control enquiries — newsletters, invoices, supplier mail, personal correspondence — are recognised as such and discarded. Their content is not written to our database and is not retained anywhere in our systems.
Automated classification
To make that decision and extract those details, message content is processed by Google Vertex AI in the europe-west4 region. Under Google Cloud's terms, content sent to Vertex AI is not used to train Google's models. No message content is sent to any other third party, ever.
How it is secured
Enquiry data is stored in EU data centres. The credential permitting mailbox access is held in Google Secret Manager, never in our application database, and never appears in any screen, export, API response or log file.
What we never do with it
We do not sell Google user data. We do not use it for advertising or profiling. We do not use it to train our own or anyone else's models. We do not transfer it to third parties except the infrastructure providers in section 5, who process it on our behalf under contract.
Withdrawing access
An administrator can disconnect the mailbox at any time from the settings screen. That revokes our access with Google and permanently deletes the stored credential. Access can also be withdrawn directly at myaccount.google.com/permissions. Tasks already created stay in the account as business records and can be deleted like any other record.
How long enquiry data is kept
A task created from an enquiry is a business record and lives as long as the account keeps it. Raw message content beyond the extracted details is not stored.
4a. Limited Use disclosure
PestHulpApp's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Who else processes the data
We use a small number of providers, each under a data processing agreement. We do not add one without updating this list.
- Google Cloud Platform (EU regions) — hosting, database, file storage and secret storage.
- Google Vertex AI (europe-west4) — automated classification of enquiries and drafting of report text. Not used for model training.
- Google Maps Platform — geocoding of property addresses and driving times between them, used to plan a technician's route. Addresses are sent; names are not.
- Google Firebase — hosting for this website.
- Our email provider — delivery of reports, quotes, invoices and service notices.
6. Where the data lives
Customer data is stored in EU data centres. Some providers above are US-headquartered; where any processing occurs outside the EEA it takes place under the European Commission's Standard Contractual Clauses. We choose EU regions wherever a provider offers them, which is why the AI processing is pinned to europe-west4 rather than a global endpoint.
7. How long we keep it
- Account data — for as long as the account is open, then twelve months.
- Platform data — controlled by our customer; deleted on their instruction or on account closure, subject to the line below.
- Biocide application records — retained for the period Dutch regulation requires, because they must remain available for inspection even after an account closes.
- Invoices and financial records — seven years, as Dutch tax law requires.
- Technical logs — ninety days.
- Mailbox credentials — deleted immediately on disconnection.
8. How we protect it
- Encryption in transit (TLS) and at rest.
- Every record is scoped to one business; queries cannot cross that boundary.
- Access to production is limited to those who need it, and is logged.
- Credentials live in a managed secret store, never in the database or source code.
- Passwords are hashed, never stored or recoverable in readable form.
9. Your rights
Under the GDPR you may:
- Ask what personal data we hold about you and receive a copy
- Have inaccurate data corrected
- Ask for your data to be deleted
- Object to processing, or ask us to restrict it
- Receive your data in a portable, machine-readable form
- Withdraw consent you have given, without affecting what was lawful before
- Complain to the Autoriteit Persoonsgegevens, the Dutch supervisory authority
Write to the privacy address in section 13. We answer within one month. If the data reached us through a pest control business, we will point you to them, because it is their record — and we will help them respond.
10. Cookies
This website uses only what is needed to serve the page and remember your language. We do not use advertising or cross-site tracking cookies. The application itself stores a session token so you stay logged in.
11. If something goes wrong
If a breach affects personal data we will notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it where the law requires, and tell affected customers without undue delay, with what we know and what we are doing about it.
12. Children
The service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16.
13. Contact
Privacy questions, or to exercise a right
For anything about your personal data — a copy of it, a correction, deletion, an objection, a complaint, or a question about this policy — write to our privacy contact. Say what you are asking for and which pest control business is involved if you know it, so we can find the right record. sales@regproconsultancy.nl
Sales, pricing and general questions
For pricing, a demo, onboarding, contract questions, or anything about your account, write to our sales address. We answer in Dutch or English. sales@regproconsultancy.nl
Changes to this policy
We update this page when what we do changes. The date at the top always reflects the current version, and material changes are announced to customers in the application before taking effect.