Privacy Policy
Last updated: 20 juli 2026
Kekstra B.V. is committed to protecting your personal data. This policy explains what data we collect, how we use it, and your rights.
1. Who are we?
Kekstra B.V. is responsible for the processing of personal data as described in this policy. Contact: info@kekstra.com
2. What data do we collect?
- Dealer company name, contact person, and contact details
- Customer email addresses for quotations and invoices
- Dealer portal usage (login times, activities)
- Technical data (IP address, browser) for security purposes
3. How do we use your data?
- Fulfillment of the agreement (portal access, quotations, invoices)
- Appointment notifications and reminders
- WhatsApp communication on the dealer's behalf, only after the customer has consented to be contacted via WhatsApp
- Security and fraud prevention
- Compliance with legal obligations
WhatsApp messages are processed through the WhatsApp Business Platform (Meta). Each dealer connects their own WhatsApp Business number; we act as a technology provider on the dealer's behalf.
4. Google account and Google Calendar
Dealers can connect their own Google account to synchronise appointments with Google Calendar. In doing so we process only:
- the dealer's OAuth access and refresh tokens
- the identifier (ID) of the connected calendar
- appointment data created in the portal (date, time, customer name, quotation reference)
We use this access solely to create, update and delete appointments for that dealer. No other calendar data is read, used or shared.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This data is not used for advertising and is never sold.
5. How do we protect your data?
We apply appropriate technical and organisational measures to protect data, in particular sensitive data such as Google tokens:
- Encryption in transit: all communication with the portal and with Google uses HTTPS/TLS.
- Encryption at rest: OAuth access and refresh tokens are stored encrypted using AES-256.
- Access restriction and isolation: data is strictly separated per dealer; a dealer can access only their own data. Access to production systems is limited to authorised personnel on a need-to-know basis.
- Secure authentication: passwords are hashed with bcrypt, sessions are HttpOnly/Secure with a limited lifetime, and brute-force protection is in place.
- Secrets outside the source code: API keys and client secrets are kept as environment variables and are never stored in the source code.
- Deletion: as soon as a dealer disconnects the Google integration, the stored tokens are deleted immediately.
6. How long do we retain your data?
We retain personal data no longer than necessary for the purposes for which it was collected, or as required by law (up to 7 years for financial data).
7. Sharing with third parties
We do not sell your data. We may share data with service providers (hosting, email) bound by data processing agreements.
8. Your rights
You have the right to access, correct, delete, restrict, and port your data. Contact us at info@kekstra.com.
9. Cookies
We use only functional cookies essential for the portal to operate. No third-party tracking cookies are used.
10. Complaints
For questions or complaints, contact info@kekstra.com.
© 2026 Kekstra B.V. — Nederland
← Back