Privacy policy

This policy covers SDG Admin, the app that clients of SDG Development use to manage their website, and this website. SDG Development is the trade name of Sem de Groot. Questions go to info@semdegroot.com.

Who is responsible

SDG Development (Sem de Groot) is responsible for the data the app processes about your account.

The enquiries that visitors send through a client's website belong to that client. The client is responsible for that data, and SDG Development processes it on the client's behalf. The privacy policy on the client's website explains what happens to it.

What data the app processes

Your account: your email address, your role on each site and your password. We only store the password in hashed form (scrypt), never readable.

Your sessions and devices: the kind of device (for example "iPhone 15 Pro"), the platform, the app version, when you were last active, and a random code per installation. We only store that code hashed. This lets you see under Security where you are signed in and sign a device out. We do not store an IP address or a location with this.

Notifications: if you turn notifications on, we store a push token so we can notify you about a new enquiry or booking.

Photos and videos: only what you choose to upload to your site. The app cannot look through your photo library by itself.

Crash data: if the app crashes, an error report goes to Sentry. It contains no name, email address or IP address.

Face ID, Touch ID and your fingerprint stay on your device. The app only learns whether it succeeded.

What for

Only to make the app work: signing you in, securing your sessions, sending your notifications and fixing errors. We do not use your data for advertising, we do not track you across other apps, and we do not sell anything.

The legal basis is the agreement with you or your employer about managing the website, and our legitimate interest in a secure, working app.

Who else sees the data

We use a few service providers that process the data only for us:

Amazon Web Services (servers and email, in Frankfurt, Germany).

Sentry (crash reports, in Germany).

Expo, Apple and Google (delivering push notifications). For notifications a push token may be processed outside the European Union; appropriate safeguards apply, such as the European Commission's standard contractual clauses.

How long

A session expires after 7 days without use. A device stays linked until you sign it out, and we keep at most 10 per account. Crash reports are deleted after at most 90 days. We keep your account and its sessions, devices and push tokens for as long as you have access to a site. Deletion works as described on the Delete your account page.

This website

This website sets no cookies and keeps no visitor statistics. The server keeps technical access logs (such as your IP address and the requested address) to investigate outages and abuse. Those logs are deleted automatically.

Your rights

You may access, correct or delete your data, object to its use, or ask for a copy. Email info@semdegroot.com; we reply within a month. If you disagree with how we handle your data, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Last updated 30 September 2026