Legal
Privacy Policy
bycordo.com
Effective date: 31 July 2026
Version 2026-07-31-2
This is the same Privacy Policy that is presented and accepted inside the byCordo iOS app.
1. Who We Are
By Cordo is a Netherlands-based personal concierge and life management service. We offer dedicated personal assistant services primarily to clients in the United States, Europe, and other English and Spanish-speaking markets, supported by a client-facing iOS app and a restricted internal administration portal.
- Business name: By Cordo
- Legal form: Sole Proprietorship/Eenmanszaak
- Location: The Netherlands
- KvK / Chamber of Commerce number: 42019309
- Contact email: info@bycordo.com
- Website: bycordo.com
By Cordo acts as the data controller for personal data processed to operate our website and iOS app, manage user accounts, provide complimentary trials and concierge services, communicate with users, maintain security, comply with legal obligations, and operate our business. When by Cordo processes personal data on a client's documented instructions solely to provide an authorised concierge service, by Cordo acts as a data processor. That processing is governed by the Data Processing Agreement included in our Service Level Agreement.
2. What This Privacy Policy Covers
This Privacy Policy explains how by Cordo processes personal data when you:
- Visit our landing page (bycordo.com)
- Create an account in the by Cordo iOS app, including during a complimentary trial
- Communicate with us
- Interact with our services
We apply European privacy standards (GDPR) to all users and clients, regardless of location. This is a deliberate choice and a core part of our values.
3. What Personal Data We Collect
3.1 Website Visitors
When you visit bycordo.com, Vercel may process technical request data needed to host and secure the website, such as an IP address, browser and device information, the requested page, and security logs. We also use Vercel Web Analytics to collect anonymous, aggregated information about page views, referrers, approximate country, browser, operating system, and device type. Vercel Web Analytics does not use cookies and does not store analytics events against an IP address. We use this information to understand how the website is used and improve it.
3.2 Prospective Clients and Trial Users
When you express interest in by Cordo or create an app account for a complimentary trial, we may collect:
- Your first name and email address;
- Optionally your last name;
- Email-verification information;
- App-account and login information;
- Your acceptance of the Service Level Agreement and Privacy Policy;
- Requests, tasks, messages, preferences, and other information you provide during the trial;
- Technical, security, and app-usage information.
3.3 Service Delivery Data
Depending on the services you request, we may also process task and request details, communications, service preferences, household or family information, key contacts, and credentials provided temporarily for an authorized task. Nothing is sold inside the by Cordo app, so we do not process payment instruments or card details through the app.
3.4 Data We Do Not Routinely Collect
We do not routinely collect:
- Special category data, such as information about racial or ethnic origin, political opinions, religious beliefs, biometric data, or health.
- Personal data from third-party data brokers or data enrichment services.
We do not purchase personal data from data brokers or data enrichment services. We may receive personal data about family members, children, contacts, or other individuals from a user where it is necessary to complete an authorised concierge request.
Where you voluntarily provide special category data for a task, such as dietary requirements or health information relevant to travel, we process it only for that task and with the data subject's explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR, unless another legal exception applies. Consent may be withdrawn at any time.
4. Legal Basis for Processing
Under the GDPR, we must have a lawful basis for every processing activity. We rely on the following:
| Legal Basis | What This Means | Examples |
|---|---|---|
| Contract | Processing is necessary to perform our agreement with you (Art. 6(1)(b) GDPR). | Delivering concierge services, managing tasks, operating the app, and managing service delivery through the internal portal. |
| Legitimate Interest | Processing is necessary for our legitimate business interests, balanced against your rights (Art. 6(1)(f) GDPR). | Improving our services, website analytics, fraud prevention, business administration. |
| Consent | You have given clear, informed consent for a specific purpose (Art. 6(1)(a) GDPR). | AI-assisted features (opt-in), marketing emails, non-essential cookies. |
| Explicit Consent for Special Category Data | You have explicitly agreed to the processing for a specific purpose under Articles 6(1)(a) and 9(2)(a) GDPR. | Health, dietary, religious, accessibility, or similar information needed for a request you have asked us to complete. |
| Legal Obligation | Processing is necessary to comply with a legal requirement (Art. 6(1)(c) GDPR). | Tax records, financial reporting, responding to lawful data access requests. |
Where we rely on consent, you may withdraw it at any time by contacting us at info@bycordo.com. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
5. How We Use Your Data
- Service delivery: To provide, manage, and improve the concierge services you have requested, including task management, research, bookings, and coordination on your behalf.
- App and internal portal operation: To maintain your app account, provide task tracking, messaging, shared notes, calendar functions, and preference management, and allow authorized by Cordo personnel to manage service delivery through the internal portal.
- Communication: To respond to your requests, provide task updates, send check-in messages, and coordinate with you.
- Service time administration: To record the assistant time logged on your account, show your remaining complimentary time and the date your trial ends, and administer the services governed by this Agreement.
- Service improvement: To understand how our services and iOS app are used, identify improvements, and develop new features. This is based on aggregated, non-identifying data.
- AI-assisted features (opt-in only): Where you have opted in, to use AI tools for summarizing research and drafting communications.
- Legal compliance: To comply with applicable laws, regulations, and legal processes.
We will never use your data for purposes incompatible with those listed above without informing you and, where required, obtaining your consent.
6. AI & Automation
By Cordo may use artificial intelligence tools to enhance service delivery. Our approach is built on transparency and choice:
- Opt-in, not opt-out: AI features are always presented as options. If you prefer zero AI involvement, you lose nothing in service quality.
- Human oversight: Your assistant maintains final oversight and is responsible for reviewing AI-assisted outputs before they are delivered to you. AI assists, it never decides on your behalf. Before using an external AI tool, we remove or replace information that could identify a client or another individual.
- No data exploitation: Your data is never used to train AI models, never shared with third-party AI providers for their own purposes, and never monetized.
- Transparency and choice: Before we use an AI-assisted feature for your request, we explain what it does and ask whether you want to use it. You can change your choice at any time by contacting us.
If we introduce a materially different AI use, we will inform you before it affects your data and ask for consent where required.
7. Who We Share Your Data With (Service Providers)
We do not sell, rent, or trade personal data. We use third-party service providers to help operate our website, app, internal portal, communications, and services. When by Cordo acts as a data controller, these providers may process personal data on our behalf. When by Cordo acts as a data processor for a client, these providers may act as subprocessors under the Data Processing Agreement included in our Service Level Agreement.
| Service Provider / Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| Dashlane | Internal password and credential management | Client credentials (logins/passwords) provided solely for task fulfillment and stored in the encrypted vault | EU / United States (SCCs) |
| Google Workspace | Business email and internal document management | Email content, attachments, contact details | EU / United States (SCCs) |
| Railway | App backend, internal administration portal, and database hosting | Account information, agreement-acceptance records, task details, messages, app history, assistant updates, time records, device-token records, and technical and security logs | EU |
| Resend | Email service provider | Name, email address, and email content for account, security, and service communications, and for marketing emails where the user has opted in. | United States (SCCs) |
| Vercel | Website hosting and website analytics | Technical website and analytics data | United States (SCCs) |
SCCs = Standard Contractual Clauses, the EU-approved legal mechanism for transferring personal data to countries outside the European Economic Area. These clauses ensure that your data receives the same level of protection regardless of where it is processed.
We will update this list when we add or change service providers or subprocessors. Material changes will be communicated to affected users.
8. International Data Transfers
By Cordo is based in the Netherlands (EU). However, several of our service providers and subprocessors are based in the United States. When personal data is transferred outside the European Economic Area (EEA), we ensure adequate safeguards are in place:
- Standard Contractual Clauses (SCCs): EU-approved contractual terms that bind the receiving party to protect data to European standards. These clauses ensure that your data receives the same level of protection regardless of where it is processed.
- Adequacy decisions: Where the European Commission has determined that a country provides adequate data protection.
- Supplementary measures: Additional technical and organizational safeguards where required, such as encryption in transit and at rest.
We do not transfer data to countries or organizations that cannot demonstrate adequate protection. You may contact us at info@bycordo.com to request information about the specific safeguards in place for any transfer.
9. How Long We Keep Your Data
For retention purposes, a “trial user” is anyone who creates an app account and receives complimentary service time. Completing or using all complimentary trial time does not automatically close the account or terminate access to the app.
| Data Type | Retention Period | Reason |
|---|---|---|
| Website analytics | We retain access for the reporting window provided by our current Vercel plan. We review this period when the plan changes. | Standard analytics retention; anonymized where possible |
| Initial enquiries without an app account | 12 months after last contact | Responding to and following up on enquiries |
| Marketing email address and consent record | Until consent is withdrawn. We may retain a minimal suppression record afterwards to honour the opt-out. | Sending marketing emails the user chose to receive and recording their preference |
| Trial-user and app-account data | Until six months after the latest of the end of the 30-day Trial period, the user's last account activity, or account creation where the Trial period never begins. | Maintaining the user's account and service history, allowing service reactivation, and resolving support questions |
| Deleted-account service data | Deleted or anonymised within 30 days, subject to stated legal exceptions | Account closure and deletion processing |
| Invoices and financial records | 7 years after termination | Dutch tax law (Belastingdienst) requirement |
| Service Level Agreements and acceptance records | 7 years after the end of the service relationship | Evidence of the agreement and terms accepted; statutory recordkeeping where applicable; establishment, exercise, or defence of legal claims |
| Communication logs (email) | The same 6-month period that applies to the related app account and service relationship | Maintaining service history and resolving service-related questions |
The user can delete the account in the app at any time, under Account. Deleting the account immediately removes the account and its service data, including tasks, messages, calendar entries, notification settings and the session on the device. Any remaining copies in backups or operational records are deleted or anonymised within 30 days unless a longer period is necessary to comply with a legal obligation or to establish, exercise, or defend legal claims. If the account is not deleted, app-account and service data is retained for the applicable six-month period described in the table above. Completing the complimentary trial does not automatically close the app account.
10. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): You can request a copy of all personal data we hold about you.
- Right to rectification (Art. 16): You can ask us to correct any inaccurate or incomplete data.
- Right to erasure (Art. 17): You can ask us to delete your personal data. We will comply unless retention is necessary to comply with a legal obligation or to establish, exercise, or defend legal claims. You can also delete your account and its data yourself in the byCordo app, under Account.
- Right to restrict processing (Art. 18): You can ask us to temporarily stop processing your data while we resolve a concern.
- Right to data portability (Art. 20): You can request your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): You can object to processing based on legitimate interest. We will stop unless we can demonstrate compelling grounds.
- Right to withdraw consent (Art. 7): Where processing is based on consent, you can withdraw it at any time.
- Right to lodge a complaint: You have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.
To exercise any of these rights, contact us at info@bycordo.com. We will respond without undue delay and within one month. Where permitted by the GDPR, this period may be extended by up to two further months because of the complexity or number of requests. We will notify you of any extension and the reason within the first month.
Dutch Data Protection Authority (Autoriteit Persoonsgegevens): autoriteitpersoonsgegevens.nl
11. Cookies
Our website may use cookies and similar technologies. Cookies are small text files stored on your device when you visit a website.
Types of cookies we may use:
- Strictly necessary cookies: Required for the website to function (e.g., session management, security). These do not require consent.
- Analytics cookies: Help us understand how visitors use our website (e.g., pages visited, time on site). Only placed with your consent.
- Functional cookies: Remember your preferences (e.g., language, region). Only placed with your consent.
We do not use advertising or tracking cookies. We do not serve ads and we do not share cookie data with third parties for advertising purposes. If analytics cookies are used, we will display a cookie consent banner on your first visit. You can manage your cookie preferences at any time through your browser settings or through the consent tool on our website.
12. How We Protect Your Data
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- Encrypted data transmission (HTTPS/TLS) across all services
- Encrypted data storage for sensitive information
- Password management via Dashlane with unique, strong credentials
- Two-factor authentication on critical internal business and administration accounts
- Public app registration with email verification and acceptance of the Service Level Agreement
- Regular access reviews and principle of least privilege
- Secure communication channels between the client app and by Cordo's internal administration portal
- Confidentiality obligations are included in the Service Level Agreement accepted during app registration
If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and explain what happened, the likely consequences, and the steps we are taking. Where required, we will notify the Dutch Data Protection Authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
13. Children's Privacy
The byCordo app and service are intended for adults. Our services are not directed at children under the age of 16, and we do not collect personal data directly from children under 16. If you believe we have inadvertently collected such data, please contact us at info@bycordo.com and we will delete it promptly.
When clients share information about their children in the context of service delivery (e.g., school schedules, activity coordination), this data is processed solely for the purpose requested and is subject to the same protections described in this statement.
14. Third-Party Links
Our website, app, or communications may contain links to third-party websites or services. Those third parties process personal data under their own privacy policies. We encourage you to review the applicable privacy information before providing personal data directly to them.
15. Changes to This Privacy Policy
We may update this privacy policy from time to time to reflect changes in our practices, services, or legal requirements. When we make material changes:
- We will update the “Effective date” at the top of this statement.
- We will notify affected users through the app, by email, or through another appropriate communication channel.
- For significant changes affecting your rights, we will seek your renewed consent where required.
We encourage you to review this statement periodically.
16. Contact Us
If you have questions about this privacy policy, your personal data, or wish to exercise any of your rights, please contact us:
info@bycordo.combycordo.com
The Netherlands
We aim to respond to all privacy-related inquiries within 30 days.