Privacy statement
MassagePlan handles personal data in two different roles, and they carry different responsibilities. This page covers both, starting with the one most readers are here for.
Last updated: 11 September 2026
1. Employee data in the platform
When a massage practice books through MassagePlan, that practice decides what is recorded and for how long. In GDPR terms the practice is the controller and MassagePlan is the processor: we act on their instructions and never use employee data for our own purposes, and never sell it or use it to train models.
- What is recorded
- Name, email address and password. Depending on what the employer requires: phone number, department and personnel number. Plus the bookings themselves, and a reason if a booking is cancelled.
- How it is protected
- Phone number, personnel number and cancellation reason are encrypted in the database. Passwords are hashed with Argon2id and never stored or recoverable in readable form. Traffic runs over HTTPS, and administrators must use two-factor authentication.
- Who can see it
- Each massage practice is fully separated from every other one, so no practice can reach another practice's data. Within a company, colleagues cannot see who booked which slot: an employee sees only which times are free and which booking is their own. A contact person sees only their own company, and a masseur only the days they work.
- How long it is kept
- An account with no activity is anonymised automatically after the retention period the practice sets, 12 months by default: name, email, phone and personnel number are removed and the booking history is kept unlinked. The record of changes is kept for 24 months.
- What employees can do themselves
- Download your own data as a file, correct your own details, turn off announcement emails, and delete your account, which anonymises it immediately. All of it from your own account, without asking anyone.
- Record of changes
- Changes to bookings, accounts and settings are logged so a practice can see what happened and when. Personal details are stripped out of those log entries before they are stored.
Are you an employee with a question about your data, or do you want it removed? Ask your employer or the massage practice first: they decide, and we act on their instruction. You can always reach us at info@massageplan.nl as well.
2. This website
For this website MassagePlan is the controller itself. It is deliberately plain: no tracking, no analytics, no advertising, and no cookies other than the ones the application itself needs once you sign in.
- If you mail us
- We keep your message and your address for as long as it takes to answer you and to follow up on it. Nothing more.
- Server logs
- The web server records requests, including IP addresses, for security and troubleshooting.
- No third parties
- Everything on this page, down to the typeface, is served from our own servers. Your browser contacts nobody else, so no other party gets to see your IP address.
- Where it is hosted
- The platform and its backups are hosted by Server.Biz, on servers in the Netherlands.
3. Your rights and how to reach us
You can ask to see your data, correct it, have it removed, or object to how it is used. Mail info@massageplan.nl and we will answer within a month. If you are not satisfied, you can take it to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.
MassagePlan | info@massageplan.nl