Privacy Policy

How Chief Tools uses personal data when you visit our websites, create an account, purchase a service, or contact us.

Version 2026-08-01 · Published

1. Who we are

Alboweb B.V., trading as Chief Tools, is registered in the Netherlands under Chamber of Commerce number 70975574 and VAT identification number NL858531343B01. Our postal address is Titus Brandsmahove 52, 2717 TG Zoetermeer, the Netherlands. You can contact us at privacy@chief.app or through our contact page.

2. When Chief Tools is controller or processor

Chief Tools is controller for account administration, billing, service analytics, security, fraud prevention, support, communications, legal compliance and our business relationship with you. We determine why and how that data is used.

When a customer places personal data into Domain Chief, Cert Chief, Deploy Chief, Tny, Bill.do, FlowGuard, Backup Chief or Socket Chief for its own purposes, the customer generally acts as controller and Chief Tools acts as processor. That processing is governed by our Data Processing Agreement.

3. Data we use and why

Data or activity How and why we use it
Account details, including name, email, authentication data, teams and preferences.
Purpose and basis
Create and administer your account, provide requested services and send essential account or service messages — performance of our contract (Article 6(1)(b)). Protect accounts and investigate misuse — our legitimate interest in operating secure services (Article 6(1)(f)).
Provision
Your name, email and authentication information are required to enter into and perform the contract. Without them, we cannot create or secure an account. Preferences and optional profile or team fields are optional; omitting them only limits the related feature.
Retention
For the account’s lifetime, followed by deletion from active systems and expiry from backups within 90 days, except where another period below applies.
Purchase, subscription, invoice, payment status, billing address, tax and transaction information.
Purpose and basis
Process purchases, subscriptions and refunds — performance of our contract (Article 6(1)(b)). Keep tax and accounting records — compliance with our legal obligations (Article 6(1)(c)). Prevent fraud, resolve disputes and establish legal claims — our legitimate interests in protecting Chief Tools and its customers (Article 6(1)(f)).
Provision
Order and payment information is contractually required, and invoice or tax information may be legally required. Without the required information, we cannot complete or maintain the purchase, issue a valid invoice or provide the paid service.
Retention
For the statutory financial-record retention period, generally seven years in the Netherlands.
Support requests, contact forms, emails and related service information.
Purpose and basis
Provide requested pre-contract or customer support and handle service complaints — steps requested before entering into a contract or performance of our contract (Article 6(1)(b)). Respond to other enquiries, troubleshoot and retain a proportionate support history — our legitimate interests in communicating with business contacts and improving support (Article 6(1)(f)). Meet applicable complaint or legal duties — compliance with legal obligations (Article 6(1)(c)).
Provision
Contact details and enough information to understand and answer the request are required if you want a response. Additional diagnostic information is optional, but without it we may be unable to investigate or resolve the issue.
Retention
Normally up to 24 months after the request is resolved, or longer where needed for a dispute or legal duty.
IP address, user agent, request metadata, authentication events, security alerts and diagnostic information.
Purpose and basis
Protect users and services, prevent abuse, investigate incidents and maintain reliability — our legitimate interests in providing secure and dependable services (Article 6(1)(f)). Meet applicable security, data-protection and incident-response duties — compliance with legal obligations (Article 6(1)(c)).
Provision
This information is generated automatically when you use a website or service. Security metadata necessary to operate or protect a service cannot generally be disabled while using it; blocking required requests or authentication information may prevent access.
Retention
Normally 30 to 90 days, with relevant records retained longer where necessary to investigate an incident or establish legal claims.
Website and product usage measurements.
Purpose and basis
Measure aggregate use and improve our websites and services — our legitimate interest in understanding and improving our services (Article 6(1)(f)). Where applicable law requires consent for non-essential measurement, we process it only with consent (Article 6(1)(a)).
Provision
This information is not contractually or legally required and is observed rather than requested from you. You may object to legitimate-interest processing. Where we ask for consent, refusing or withdrawing it does not affect access to the service.
Retention
According to the analytics provider’s configured retention and then in aggregate form.
Domain names, registrant and contact information supplied when registering or managing a domain.
Purpose and basis
Register, renew, transfer and manage the selected domain and meet registrar or registry requirements necessary to provide it — performance of our contract (Article 6(1)(b)). Keep information required by applicable registration, tax or other law — compliance with legal obligations (Article 6(1)(c)). Prevent abuse and handle registration disputes — our legitimate interests in protecting the domain service and the rights of others (Article 6(1)(f)).
Provision
The domain and required registrant, contact, eligibility and verification information are contractual requirements and, depending on the registration, may also be required by law or registry rules. Without them, we cannot register or maintain the domain; inaccurate or incomplete information may lead to rejection, suspension or cancellation.
Retention
For the registration relationship and any period required by the registrar, registry, tax or other applicable rules.
Values submitted to Package Trends or another public Chief Tools utility, together with request and security metadata.
Purpose and basis
Process the submitted value and return the requested result — performance of the service contract (Article 6(1)(b)). Protect public utilities, enforce limits and prevent abuse — our legitimate interest in keeping those tools secure and available (Article 6(1)(f)).
Provision
Using a public tool is optional, but its requested input is required to produce a result. Request and security metadata is generated automatically and is necessary to operate and protect the tool. Do not submit sensitive personal data.
Retention
Submitted personal data is retained only as needed to produce the result and operate the relevant feature. Request and security metadata follows the 30-to-90-day period above unless an incident or legal claim requires longer retention.

4. Public tools and Package Trends

Package Trends and public Chief Tools utilities may receive values you submit, request metadata and basic usage or security information needed to produce a result and prevent abuse. These services are not intended for confidential, special-category, criminal-conviction or other sensitive personal data. Do not submit such data to a public tool.

5. Where data comes from

We receive data directly from you, other members of your team, the services you connect, payment providers, domain registrars and registries, authentication providers, and public technical sources such as DNS and certificate records. A customer may also submit personal data about its personnel, users, visitors, registrants or other contacts when using a service.

6. Who receives data

We disclose data only where needed for the purposes above. Recipients can include our service providers and subprocessors, payment and accounting providers, professional advisers, competent authorities, and domain registrars or registries. Registrars, registries, banks, payment providers and accounting parties may act as independent controllers for their own legal and operational purposes.

We do not sell personal data. If Chief Tools or the relevant business is reorganised, acquired or transferred, data may be disclosed under appropriate confidentiality and legal safeguards.

7. International transfers

Providers may process data outside the EEA. Where GDPR Chapter V applies, we rely on an adequacy decision, the EU-US Data Privacy Framework for an eligible recipient, the European Commission’s Standard Contractual Clauses with supplementary measures where appropriate, or another lawful safeguard. Contact privacy@chief.app for information about a relevant safeguard.

8. Cookies and similar technologies

We use technologies that are necessary for authentication, security, preferences and service operation. We also use Fathom Analytics for privacy-focused website measurement. Where a non-essential technology requires consent, we will ask before using it. Your browser can remove or block stored cookies, although required functionality may then stop working.

9. Your rights

Depending on the circumstances, you may request access, correction, deletion, restriction or portability of your personal data, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw that consent without affecting earlier processing. These rights can be subject to legal conditions and exceptions.

Send a request to privacy@chief.app. We may ask for information needed to verify your identity. If Chief Tools processes the data only for a customer, we will direct the request to that customer or assist it as required by our DPA.

You may complain to the Dutch Autoriteit Persoonsgegevens or another competent EEA supervisory authority. We would appreciate the opportunity to address your concern first.

10. Security

We use technical and organisational measures designed for the risks involved, including access controls, encrypted transport, hashing of passwords, encryption of selected high-risk credentials, multi-factor authentication options, monitoring and backups. No online service can guarantee absolute security.

11. Children

Chief Tools is not directed to children under 16. If you believe a child supplied personal data to us without appropriate authorisation, contact us so we can investigate and take appropriate action.

12. Changes

We may update this policy when our services, providers or legal obligations change. We will place the current policy on this page and notify account holders of material changes by an appropriate direct method. A Privacy Policy explains processing; it is not accepted through consent merely because you continue using a service.

Need help?

We are happy to help you with any questions you might have.

  Documentation   Roadmap   Report a bug   Get in touch