Skip to content
My Wealth ManagementMy Wealth Planner · planning & record-keeping
Menu

Privacy Policy

Privacy Policy

This Privacy Policy explains how VanderVegt financiële dienstverlening processes personal data for the public My Wealth Management website, contact by email or telephone, and limited development or testing of My Wealth Planner. It is product transparency documentation, not specialised legal advice.

Last updated: 29 September 2026

1. Who we are

Controller: VanderVegt financiële dienstverlening (eenmanszaak)

My Wealth Management is a brand operated by VanderVegt financiële dienstverlening.

Strevelsweg 700, 303 BOX C5104
3083 AS Rotterdam
the Netherlands

KVK: 60120703
Establishment number: 000029348617
VAT ID: NL002021279B39

Privacy and data requests: support@mywealthmanagement.eu · Phone +31 10 311 5436

Products covered today: this informational website at www.mywealthmanagement.eu, and contact about My Wealth Planner (package eu.mywealthmanagement.app).

2. Scope of this version

This version covers:

  • Visiting the public website
  • Contacting us by email or telephone
  • Any closed development or testing of My Wealth Planner under our control

My Wealth Planner is not yet publicly available on Google Play. PLUS is not active and cannot be purchased. Before a public app or PLUS release, we will review and update this policy where processing changes.

3. Website technical data

To deliver pages securely and reliably, hosting infrastructure may process technical request data. Depending on how hosting and related Google services operate, that may include items such as IP address, date and time, requested URL, status code, referrer, browser or device information, user-agent, latency or cache metadata, and a coarse location indication where that appears in hosting logs.

Listing these fields does not mean every field is kept as a long-term project archive. We distinguish delivery processing by the host, Google’s operational processing as infrastructure provider, and any project-accessible Cloud Logging export. Whether project-specific Cloud Logging is enabled for this Hosting site will be verified during the separate Hosting deployment step if it cannot be confirmed locally.

4. Purposes

  • Make the website available
  • Deliver pages securely and reliably
  • Prevent abuse and attacks
  • Investigate technical faults
  • Answer questions
  • Handle privacy and deletion requests
  • Comply with legal obligations
  • Establish, exercise or defend concrete legal claims where necessary

We do not use website analytics, advertising trackers or behavioural profiling on this site.

5. Legal bases

  • Legitimate interests: secure, reliable and reachable hosting; ordinary correspondence; security investigation
  • Taking steps at your request: answering a question or privacy request you initiate
  • Legal obligation: privacy requests and mandatory administration where applicable
  • Consent: only if we actually ask for it for a specific activity (we do not run a cookie consent banner because we do not use consent-requiring marketing cookies)

6. Recipients

  • Google / Firebase for hosting and related technical infrastructure (and Google’s relevant subprocessors at a functional level)
  • STRATO for business email and mail archiving
  • Competent authorities where legally required
  • Professional advisers only where necessary

Google Play is not a current website processor. If a public app and Play Billing later go live, Google Play would process payment-related data under Google’s terms; that future processing will be described when it becomes current.

7. International transfers

Firebase Hosting uses global infrastructure. Google and its subprocessors may process data outside the European Economic Area. Where required, the provider uses applicable contractual or other recognised safeguards. The project-specific contracting party and acceptance of processor terms will be checked during Hosting deployment if not already documented locally. We do not claim that all Firebase processing stays only in the EEA.

8. Cookies and tracking

This website’s own code does not add Google Analytics, Tag Manager, advertising pixels, marketing cookies or profiling. We do not use a cookie banner because we do not deploy consent-requiring tracking techniques. Hosting and the browser may still process technical data needed to deliver the page. The absence of marketing trackers does not mean that no personal data is processed at all.

9. Email

If you email us, we process the address and content you send, to answer your question or request. Please do not send passwords or unnecessary sensitive documents. Email is processed via STRATO.

Ordinary correspondence is kept no longer than needed for handling and reasonable aftercare. A target of twelve months after closing a matter is intended, but account-level archive settings at the email provider must still be aligned before we publish a firm twelve-month deletion guarantee. Fiscal records, complaints, security incidents and disputes may be kept longer under the periods below.

10. Retention

  • Ordinary email correspondence: no longer than needed for handling and aftercare (twelve months after closing is the intended target once provider rules are aligned)
  • Demonstrable fiscal administration records: seven years
  • Complaint, security-incident and dispute files: up to five years after closure, unless a concrete legal obligation or claim requires longer
  • Ongoing legal claim: as long as necessary
  • Active test-account data: as long as needed for the test purpose, or until a valid deletion request is completed
  • Removal from the active application environment after a valid, verified deletion request: operational aim within a maximum of 30 days (approved operational commitment; the detailed procedure is still being finalised and is currently manual)
  • Legal response to a privacy request: within one month; for complex or numerous requests the statutory period may be extended, and we will inform you within the first month
  • After an Authentication account is deleted, Firebase product documentation describes that authentication information may remain in the provider’s live and backup systems for up to about 180 days — a general product term, not a project-specific timer we control

A policy for unused accounts is not yet final and will be set before a public app release. Firestore point-in-time recovery was disabled in a recent technical audit; short historical document versions may still exist for about one hour under product defaults. No scheduled Firestore backups were found in that audit.

11. App in development (not public)

During closed testing, My Wealth Planner may use Firebase Authentication and Cloud Firestore so a test user can sign in and save planning data they enter (for example profile fields, goals, plans, records and reports). That processing is for development and testing, not a public launch. Automated full account wipe is not yet implemented; verified deletion from the active environment is handled manually toward the 30-day operational aim above.

Future PLUS / Google Play Billing processing is not current. When PLUS exists, existing goals, plans, records and reports are required to remain readable after a PLUS period ends (approved release requirement — must be implemented and tested before public PLUS launch).

12. Account and data deletion

See Account deletion for how to request deletion, timing, and Play-subscription notes. You may also email support@mywealthmanagement.eu.

13. Your rights

Depending on applicable law, you may have rights to information, access, rectification, erasure, restriction, objection, and data portability where applicable; and to withdraw consent where consent is the basis. You may lodge a complaint with the Autoriteit Persoonsgegevens (Netherlands). Contact us first at support@mywealthmanagement.eu. We may ask for proportionate identity checks. We respond within one month, with statutory extension where applicable.

14. No automated decision-making on this website

This website does not profile visitors for marketing, does not make solely automated decisions with legal or similarly significant effects, and does not make personal product recommendations.

15. Children

My Wealth Planner is directed at adults aged 18+.

16. Changes

We may update this policy when the product, infrastructure or legal requirements change. The “Last updated” date will change when we do. Material changes before a public paid app release will be reviewed again.

17. Contact

support@mywealthmanagement.eu · +31 10 311 5436

See also Account deletion, Terms of use, Contact, and Disclaimer.