PRIVACY NOTICE

Last updated 10 September 2026. Applies to handyhand.dk, handyhand.nl and the Handyhand apps.

This notice explains how Pinploy ApS, trading as Handyhand ("Handyhand", "we", "us"), processes personal data when you use our website, our apps or our services, or when you contact us. It is written for both customers (people who post tasks) and Handyhanders (people who carry out tasks), and covers our Danish and Dutch markets. Where the two markets differ, the difference is stated.

It was rewritten in September 2026 following a full data protection impact assessment (DPIA) of the platform. The public version of that assessment, including the risks we found and the actions we are taking, is available at Data Protection Impact Assessment.

CONTENTS

  1. Who we are and how to contact us
  2. Where your data comes from
  3. What data we process
  4. Why we process it and our legal basis
  5. Identity verification and national identity numbers
  6. Screening of messages and content
  7. Features that use artificial intelligence
  8. Automated decisions and your right to human review
  9. Who we share your data with
  10. Transfers outside the EU and EEA
  11. How long we keep your data
  12. Cookies and tracking
  13. Marketing messages
  14. Social logins
  15. How we protect your data
  16. Children
  17. Your rights and how to use them
  18. What happens when you delete your account
  19. Issues we are fixing
  20. Changes to this notice

1. WHO WE ARE AND HOW TO CONTACT US

The data controller is:

Pinploy ApS (trading as Handyhand)
CVR no. 40021892
Tordenskjoldsgade 14, 4. th.
København K 1055
Denmark

For any question about your personal data, or to exercise your rights, email [email protected] with "Privacy" in the subject line, or write to the address above. We answer within one month. We have not yet appointed a data protection officer; we are assessing whether we are required to and will publish the contact details here if we do.

2. WHERE YOUR DATA COMES FROM

Most of the data we process is data you give us or that is created when you use Handyhand. We also receive data from a small number of other sources:

  • You: when you create an account, fill in your profile, post a task, make an offer, chat, review, pay, contact support or take part in a survey.
  • Identity providers: MitID (Denmark) through our identity broker Criipto, and Google, Apple and Facebook if you sign in with them. See sections 5 and 14.
  • Our payment provider Stripe: the outcome of identity and bank-account verification, and payment status.
  • Public registers: the Danish CVR register, the Dutch KVK register and the EU VIES service for business accounts, and the Danish BBR building register, which we look up from your address to describe your property (building year, size, heating) so tasks can be matched better.
  • Your device and browser: technical data described in section 3, collected automatically.
  • Other users: ratings, reviews, reports and messages that concern you.

3. WHAT DATA WE PROCESS

CategoryExamplesWho it concerns
Identity and contactName, email address, phone number, profile picture, date of birth, preferred languageEveryone with an account
Identity verificationMitID verification result (Denmark), CPR number (Denmark), BSN (Netherlands), business registration number (CVR or KVK), Stripe verification statusHandyhanders; business customers
LocationAddress of a task, your home address, map coordinates, GPS location from the app when you allow it, approximate location from your IP addressCustomers (task address); Handyhanders (service area)
Task contentDescriptions, photos and videos you upload, dates, budget, insurance choicesCustomers; may incidentally include family members or neighbours who appear in photos or text
CommunicationsChat messages, offer messages, reasons given for declining or cancelling, support conversations, chatbot and voice-assistant conversations, records of emails, SMS and push notifications sent to youBoth sides
FinancialPayment history, refunds, payouts, invoices, stored credit, coupons, bank-account details for payouts. Card numbers are held by Stripe, never by usBoth sides
TaxIncome earned through Handyhand and the identifiers the tax authorities require (see section 5)Handyhanders above the reporting thresholds
Reputation and derived dataRatings, reviews, completion and cancellation rates, tier level, price suggestions, safety and quality indicators, "last online" timeMainly Handyhanders; customers are also rated
Technical and usageDevice identifiers, push tokens, IP address, browser and operating system, pages viewed, actions taken, marketing attribution parameters, your consent choicesAll visitors and users
MarketingWhether you have agreed to marketing, how you interact with our emails, segments used for reactivation campaignsUsers who have agreed to marketing

We do not ask for health data, criminal records or other special categories of data, and our staff are instructed not to request or accept identity documents or criminal-record certificates. Because task descriptions and chat are free text, you may nonetheless disclose such information yourself. Please do not include health or other sensitive details in tasks or messages; if you do, it is protected in the same way as the rest of your data, but we cannot prevent the other party from seeing it.

4. WHY WE PROCESS IT AND OUR LEGAL BASIS

The GDPR requires us to have a legal basis for each purpose. This table sets out both.

PurposeLegal basis
Running the marketplace: your account, tasks, offers, chat, matching, payments, payouts, invoices, disputes and the cancellation rulesPerformance of our contract with you (Article 6(1)(b))
Keeping accounting recordsLegal obligation (Article 6(1)(c)): the Danish Bookkeeping Act (5 years) and Dutch tax law (7 years)
Reporting Handyhander income to the tax authoritiesLegal obligation (Article 6(1)(c)): EU Directive 2021/514 (DAC7) as implemented in Danish and Dutch law
Verifying identity and business registrationContract, and our legitimate interest in a safe marketplace (Article 6(1)(f)). National identity numbers are processed under the specific rules in section 5
Preventing fraud and abuse: detecting duplicate or banned accounts, checking sign-up location, screening messages for off-platform contact, suspending accountsLegitimate interest (Article 6(1)(f)) in protecting users and the payment guarantee. Automated decisions are subject to the safeguards in section 8
Ratings, reviews, tier levels and completion statisticsContract and legitimate interest in a trustworthy marketplace
Service notifications by email, SMS, push and in the appContract
Customer support, including our chatbot and voice assistantContract and legitimate interest in resolving problems
Improving the service: product analytics and improving our AI featuresLegitimate interest, and your consent for analytics cookies
Marketing emails, SMS and push notificationsYour consent (Danish Marketing Practices Act §10; Dutch Telecommunications Act Article 11.7)
Advertising measurement and marketing cookiesYour consent (Danish Cookie Order; Dutch Telecommunications Act Article 11.7a)
Review invitations through TrustpilotLegitimate interest; you can object at any time
Security logging, evidence in disputes and legal claimsLegitimate interest and legal obligation

Where we rely on legitimate interest you have the right to object; see section 17.

5. IDENTITY VERIFICATION AND NATIONAL IDENTITY NUMBERS

MitID (Denmark). Handyhanders in Denmark can verify their identity with MitID through our identity broker, Criipto. We receive your verified name, date of birth and CPR number and show a "verified" badge on your profile. Verification is optional but increases trust and is required for some features.

CPR and BSN numbers. We process Danish CPR numbers under section 11 of the Danish Data Protection Act and Dutch BSN numbers under Article 46 of the Dutch GDPR Implementation Act. We use them only to identify you uniquely for identity verification and, where you meet the reporting thresholds, for the tax reporting described below. We never show your number to other users, and we are removing it from documents where it is not legally required.

Tax reporting (DAC7). EU law requires digital platforms to report the income of sellers who complete 30 or more paid tasks or earn EUR 2,000 or more in a calendar year. If you reach either threshold we report your name, address, date of birth, tax identification number (CPR or BSN, or CVR/KVK for businesses), bank account and total income and fees to the Danish Tax Agency (Skattestyrelsen) or the Dutch Tax Administration (Belastingdienst) by 31 January of the following year, and we tell you what we reported.

Businesses. If you register as a business we look up and store your company name, address and VAT status from the CVR or KVK register and the EU VIES service.

6. SCREENING OF MESSAGES AND CONTENT

To protect users from fraud and to keep tasks on the platform, where payments are guaranteed, we screen chat messages, offer messages and uploaded images for contact details and attempts to move a job off the platform. Screening is automatic: a rule-based check runs first, and where it finds something suspicious the text or image may be assessed by an AI model (see section 7). Repeated attempts can lead to a warning or suspension; any suspension can be appealed and is reviewed by a person (section 8).

We also run automatic moderation of profiles, reviews and comments for offensive content. Staff can read messages when they handle a dispute, a report or a support request. We do not read messages for any other purpose.

7. FEATURES THAT USE ARTIFICIAL INTELLIGENCE

Several features use AI models. In each case you are interacting with, or affected by, an automated system:

  • Price suggestions when you create a task, based on similar tasks completed on the platform.
  • Offer recommendations that explain to a customer which offer may fit best, based on ratings, tier and completion history.
  • Cleaning of decline reasons: when a customer declines an offer with a written reason, an AI model removes contact details and offensive language before the Handyhander sees it.
  • Support chatbot and voice assistant on our support channels. Conversations and call transcripts are stored to resolve your case and improve the service.
  • Message and content screening described in section 6.
  • Generated email content for reactivation emails, if you have agreed to marketing.

The models are provided by OpenAI and Anthropic and run on their infrastructure under contracts that prohibit them from using your data to train their models. Text is sent only to the extent needed for the feature. AI-generated text about you (for example a cleaned decline reason) is labelled as such, and you can ask us to review it.

8. AUTOMATED DECISIONS AND YOUR RIGHT TO HUMAN REVIEW

Some decisions are made automatically because they need to happen instantly or at scale:

  • An account may be suspended automatically if it matches the identifiers of an account that was previously banned or of an account with a very high cancellation rate, or if a date of birth under 18 is entered.
  • Sign-up may be blocked when the location of your connection does not match the market you are signing up for.
  • Your tier level, the fee you pay and certain feature limits are calculated from your completed tasks, earnings and cancellation history.
  • Cancellation penalties are applied according to the published cancellation rules.

For any decision that significantly affects you, you have the right to obtain human review, to express your point of view and to contest the decision (GDPR Article 22). Suspensions can be appealed from the message you receive or by contacting support; appeals are decided by a person. We are extending this so that every automated suspension is reviewed by a person and every such message explains the reason and how to appeal.

9. WHO WE SHARE YOUR DATA WITH

We share data with other users where the service requires it, with companies that process data on our behalf ("processors", bound by contract to act only on our instructions), with advertising and analytics partners where you have consented, and with authorities where the law requires.

Other users

Your public profile (name, photo, description, ratings, reviews, verification badges, tier and "last online") is visible to other users. Task descriptions, photos, dates and the task's city and postcode are visible to Handyhanders; the exact address is shown only to the Handyhander whose offer you accept. Once an offer is accepted, both parties can see each other's name and phone number so the work can be arranged.

Processors and partners

RecipientWhat they do for usWhere
Amazon Web ServicesHosting, file storage and sending of emailsEU (Frankfurt)
CloudflareNetwork security and bot protectionGlobal network; US company
StripePayments, payouts, bank-account and identity verification. Stripe is also a controller for its own anti-money-laundering dutiesEU and US
CriiptoMitID identity broker (Denmark)EU
Dinero (Visma)Bookkeeping and invoices (Denmark)EU
OpenAI and AnthropicAI models for the features in section 7US
Google Cloud (Vision, Maps, Places)Reading text in screened images; address search and mapsUS
VapiVoice assistant on our support line, including call transcriptsUS
Twilio and other SMS gatewaysSending SMSEU and US
Expo, Apple and GoogleDelivering push notifications to your deviceUS
PostHogProduct analytics (with your consent for analytics cookies)EU
Mautic (self-hosted)Our own marketing email system, used only if you have agreed to marketingEU
TrustpilotReview invitations after a completed taskEU and US
Google (Analytics, Ads, Tag Manager via Stape), Meta, Microsoft Advertising, Reddit, TikTok, OpenAI Ads, affiliate networks (AdTraction, Trackwise)Measuring advertising and analytics, only with your consent for statistics and marketing cookies. The full list of tags and cookies is in the cookie settings (section 12)Mostly US
IP geolocation serviceApproximate location of your connection at sign-up, for fraud prevention. We are replacing this with a method that does not send your IP address to a third partyUS
Slack, Telegram, n8nInternal alerts and automation; they receive system status, not your profileUS and EU

Authorities and legal requests

We report to the Danish and Dutch tax authorities as described in section 5, and we disclose data to police, courts or regulators when we are legally required to. We may also share data in connection with a merger, sale or reorganisation of our business, in which case this notice continues to apply.

10. TRANSFERS OUTSIDE THE EU AND EEA

Your data is stored in the EU. Some of the providers in section 9 are based in the United States or process data there. For those transfers we rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses together with a transfer impact assessment. You can ask us for a copy of the safeguards that apply to a specific provider.

11. HOW LONG WE KEEP YOUR DATA

We keep data only as long as we need it for the purpose it was collected for, or as long as the law requires. Our retention schedule, adopted in September 2026 as part of our DPIA, is below. We are bringing all systems into line with it by 31 December 2026.

DataKept for
Your account and profileUntil you delete your account (see section 18)
Tasks, offers, chat messages, photos and reviews24 months after the task was completed or cancelled, then anonymised
Payment, payout and invoice records5 years after the end of the financial year (Denmark) or 7 years (Netherlands)
Tax reports and the data in themAs required by the tax authorities, currently 5 years
National identity numbersUntil they are no longer needed for verification or tax reporting, then deleted
Login sessions and IP logs30 days
Phone verification records30 days
SMS and email delivery logs90 days
Support conversations, chatbot and voice transcripts90 days after the case is closed
Fraud-prevention and moderation records24 months
Sign-up security data12 months
Consent recordsFor as long as you have an account, plus 3 years
Technical logs7 days

12. COOKIES AND TRACKING

We use cookies and similar technologies. Necessary cookies keep you logged in and remember your choices and need no consent. Statistics cookies (analytics, session recordings) and marketing cookies (advertising measurement and pixels) are only set with your consent, which we ask for through the cookie banner the first time you visit. You can change or withdraw your choice at any time:

The cookie banner lists every cookie and tag we use, its provider and how long it lasts. Our apps ask for permission before using the device's advertising identifier, in line with Apple's and Google's rules. We do not respond to browser "Do Not Track" signals because there is no agreed standard for them; your cookie choice is the setting that applies.

13. MARKETING MESSAGES

We only send marketing emails, SMS or push notifications if you have ticked the box for it, and you can opt out at any time from the unsubscribe link in every email, from your notification settings in the app or on the website, or by contacting us. Service messages about your tasks, offers and payments are not marketing and continue for as long as you have an account. If you have agreed to marketing, some emails may be written by an AI model based on the tasks you have posted before.

14. SOCIAL LOGINS

If you sign in with Google, Apple or Facebook we receive your name, email address and, where available, your profile picture and a technical identifier from the provider. We use them only to create and sign you into your Handyhand account. The provider's own privacy policy governs what it does with the fact that you used it to sign in.

15. HOW WE PROTECT YOUR DATA

We use encrypted connections, access controls based on roles, logging of administrative actions, hashed passwords and contractual security requirements for all processors. Card data never touches our systems; it is handled by Stripe, which is PCI DSS certified. Our DPIA identified further hardening we are carrying out during autumn 2026, including field-level encryption of national identity numbers and bank details and an external penetration test. No system is completely secure; if a breach affects your data and poses a risk to you, we will inform you and the supervisory authority as the law requires.

16. CHILDREN

Handyhand is for adults. You must be 18 or older to create an account. We do not knowingly collect data from anyone under 18, and if we learn that an account belongs to a minor we deactivate it and delete the data. We are adding an age confirmation step at sign-up. If you believe a minor has an account, please contact us.

17. YOUR RIGHTS AND HOW TO USE THEM

Under the GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify data that is inaccurate or incomplete. Most profile data you can change yourself in your settings.
  • Erase your data, subject to the records we must keep by law (section 18).
  • Restrict processing in certain situations.
  • Receive your data in a portable format (data portability).
  • Object to processing based on legitimate interest, including review invitations and the "last online" indicator, and to direct marketing at any time.
  • Withdraw consent at any time, without affecting processing that took place before.
  • Obtain human review of automated decisions that significantly affect you (section 8).

To use these rights, update your details at https://handyhand.dk/platform/indstillinger/personlige-oplysninger or email [email protected] with "Privacy" in the subject. We may ask you to confirm your identity. We respond within one month; if a request is complex we may extend this by two months and will tell you why. A self-service download of your data is being added to your account settings.

You also have the right to complain to a supervisory authority. In Denmark this is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk. In the Netherlands it is the Autoriteit Persoonsgegevens, www.autoriteitpersoonsgegevens.nl. We would appreciate the chance to resolve your concern first.

18. WHAT HAPPENS WHEN YOU DELETE YOUR ACCOUNT

You can delete your account in your settings once you have no ongoing tasks or offers and no paid stored credit. When you do, we remove your name, contact details, address, date of birth, profile text and pictures, your marketing profile and your pending tasks and offers, and we deactivate the account. Your record is kept in anonymised form so that completed tasks, payments, invoices and reviews remain consistent for the other party and for our accounting and tax obligations; these records are deleted when the retention periods in section 11 expire. Chat messages you sent remain visible to the other party with your name replaced. If your account is under investigation for fraud we may keep specific evidence for as long as the investigation requires. We are extending the deletion routine to cover every system that holds your data, including our external providers.

19. ISSUES WE ARE FIXING

Our September 2026 DPIA found several things that did not meet our own standards. We would rather tell you than hide them. Each has an owner and a deadline in the public DPIA action plan:

  • Some statistics and marketing tags loaded before visitors had given consent in the cookie banner. We are correcting the tag configuration so that nothing non-essential runs without consent (target 31 October 2026).
  • Email addresses and phone numbers of signed-in users were being passed to our analytics and advertising tools in a form they should not have received. We are stopping this and asking the providers to delete what was collected (target 31 October 2026).
  • Account deletion did not remove data from every system, and we had no written retention schedule. Both are being fixed (target 31 December 2026).
  • Some automated suspensions were not reviewed by a person. Human review is being introduced (target 31 December 2026).

Progress is reported in the Data Protection Impact Assessment.

20. CHANGES TO THIS NOTICE

We update this notice when our processing changes. Material changes are announced in the app or by email before they take effect. Change history:

  • 10 September 2026: full rewrite following our data protection impact assessment. Added the Netherlands market, identity verification and tax reporting, message screening, AI features, automated decisions, the complete list of recipients, retention periods, transfer safeguards and the account-deletion explanation. Corrected earlier statements that we process no sensitive data and receive no data from third parties.
  • 26 February 2024: previous version.