Privacy statement
This privacy statement was last updated on 30 September 2026.
Njoin, located at Reduitlaan 27, 4814 DC Breda, the Netherlands, is responsible for the processing of personal data as set out in this privacy statement. The last section describes how the Njoin app and platform handle personal data. There, Njoin processes data on behalf of the organisation that uses Njoin.
Contact details
NjoinReduitlaan 27
4814 DC Breda
The Netherlands
njoin.com
development@njoin.com
Personal data we process
Njoin processes your personal data when you visit our website, contact us or become a customer. We process the following personal data:
- First and last name
- Email address
- Phone number, if you give it to us
- IP address
- Internet browser and device type
Special and/or sensitive personal data we process
Our website and services do not intend to collect data about visitors who are under the age of 16, unless they have permission from a parent or guardian. We cannot check whether a visitor is older than 16. If you believe that we have collected personal data about a minor without that permission, please contact us at development@njoin.com and we will delete it.
Why we process personal data
Njoin processes your personal data for the following purposes:
- To answer your questions and to arrange a demo or send you an offer when you ask for one. We do this to take steps at your request before entering into an agreement.
- To perform our agreement with your organisation, for example to contact you as a contact person and to send invoices. We do this to perform that agreement and to meet our statutory obligations, such as keeping our financial records.
- To deliver our website and keep it secure. We do this on the basis of our legitimate interest in a working and secure website.
We do not send newsletters and we do not use your data for advertising.
Automated decision-making
Njoin does not make decisions based on automated processing about matters that can have (significant) consequences for individuals. These are decisions taken by computer programs or systems without a person being involved.
How long we retain personal data
Njoin does not retain your personal data for longer than is strictly necessary to achieve the purposes for which it was collected. We use the following retention periods:
| Personal data | Retention period |
|---|---|
| Contact details | Maximum 2 years after last contact |
| Customer, contract and invoice details | 7 years (statutory retention obligation) |
| Web server logs, including IP address | 30 days |
Sharing personal data with third parties
Njoin does not sell your personal data. We only share it with third parties when this is necessary to perform our agreement with you or to comply with a legal obligation. The service providers that host our website and email process data on our behalf. We have a data processing agreement with them to ensure the same level of security and confidentiality of your data. Njoin remains responsible for these processing activities.
Cookies and similar technologies
Njoin's website does not use cookies or similar technologies, such as tracking pixels or analytics scripts. It does not load fonts, scripts or other content from third parties, so visiting it does not share your data with anyone else. That is why we do not ask for cookie consent.
Viewing, modifying or deleting data
You have the right to view, correct or delete your personal data. You also have the right to restrict or object to the processing of your personal data by Njoin, and the right to data portability. This means you can ask us to send the personal data we hold about you in a computer file to you or to another organisation of your choice.
You can send a request to view, correct, delete, restrict, object or transfer your personal data to development@njoin.com. To make sure that the request was made by you, we may ask you for additional information to verify your identity. We will respond to your request as soon as possible, but within four weeks.
Njoin would also like to point out that you can file a complaint with the national supervisory authority, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
How we secure personal data
Njoin takes the protection of your data seriously and takes appropriate measures to prevent misuse, loss, unauthorised access, unwanted disclosure and unauthorised modification. All connections to our website and services are encrypted. If you have the impression that your data is not properly secured or there are indications of misuse, please contact us at development@njoin.com.
Privacy policy – Njoin app and platform
Organisations use Njoin for access to their buildings, visitor management and bookings, through the Njoin app, the portal and the backoffice. The organisation that uses Njoin is the controller of the personal data processed on the platform. Njoin processes this data on its behalf, as a processor, only on its instructions and under a data processing agreement. The privacy statement of that organisation also applies.
Data processed
Depending on the features your organisation has enabled, this can include:
- Account details, such as your name, email address, phone number, company, language and, if you add one, a profile photo
- Access details, such as the locations, doors and lockers you have access to, your access badges and passes, and records of when access was granted or used
- Visits and bookings, such as visitor invitations, the details of the visitors you invite, and the workplaces, rooms or lockers you book
- Device data required for the operation of the app, such as the device model and operating system, a push notification token and the public key of your device
Use of data
This data is used exclusively for access management and the workplace services of the relevant organisation, in order to:
- give you access to the buildings, doors and lockers you are authorised for;
- issue and manage your digital keys, access badges and passes;
- invite visitors and handle bookings;
- send you invitations and notifications about visits, access and bookings.
Where data is stored
Platform data is stored on the internal network of the organisation that uses Njoin, not in Njoin's cloud. Njoin's cloud services only pass messages between your device and that network. These messages are end-to-end encrypted, so Njoin's cloud services cannot read them. Only you and your organisation's systems can. The private key the app uses for this is generated on your device, stored in its secure hardware, and never leaves the device.
Device permissions
The app asks for your permission before it uses the following features of your device:
- Camera, to scan QR codes, for example to link your account
- NFC, to read access badges and to open NFC locks
- Photos, only when you choose an image, such as a profile photo
- Local network, to find services on your local network
- Notifications, to inform you about visits, access and bookings
You can withdraw these permissions at any time in the settings of your device. Some features will then no longer work.
Sharing data with third parties
We only pass on what is needed to deliver a message to you:
- Brevo and Bird receive your email address or phone number and the content of the message, to send you emails and text messages such as visitor invitations.
- Google (Firebase Cloud Messaging) and Apple receive the push token of your device, to deliver notifications to it. They may process this token outside the European Economic Area. In that case we rely on an adequacy decision, such as the EU-US Data Privacy Framework, or on the European Commission's standard contractual clauses.
Retention period and management
The data is managed by the organisation that uses Njoin, which decides how long it is kept. Access rights end when the organisation revokes them. When the organisation ends its contract with Njoin, its data is no longer processed by Njoin.
Your responsibilities
Your digital keys, access badges and passes are strictly personal and may not be shared with others. If your device is lost or stolen, report it to your organisation as soon as possible so that it can revoke your access.
Contact
For questions about the data processed in the app or on the platform, or to exercise your rights, please contact the organisation that gave you access to Njoin. Because Njoin is its processor, that organisation handles these requests, and we help it do so. You can also contact us at development@njoin.com; we will forward your request to the relevant organisation.