Privacy & data processing
How the Care4Fresh API handles data. Last updated: 9 June 2026. Version 1.
Who we are
The Care4Fresh API is operated by Care4iT B.V., registered in the Netherlands (KvK 08101579, VAT NL810300904B01), Grote Voort 293 A, 8041 BL Zwolle. For data-protection questions, contact info@care4it.nl.
Your data and your customers' data
The API gives your integrations programmatic access to your Care4Fresh administration(s): products, relations, prices, stock, sales orders, and statistics. This includes personal data about your customers (such as names, addresses, and contacts) and sensitive business data (such as pricing and sales history).
For that data, you (or your organization) are the data controller and Care4iT acts as a processor on your behalf, under your Care4Fresh agreement and its data-processing terms.
What the API itself collects
To operate, meter, and secure the service, the API records:
- Request logs: timestamp, HTTP method, endpoint path, response status, duration, and the user, API key, or connected app that made the call, plus the administration accessed. Used for usage metering and billing, support, and abuse/security detection. For successful requests, the request and response content is not stored; for failed requests (error responses), a truncated copy of the request and response content may be kept short-term to help diagnose the problem (see retention below).
- Account and access data: users, API keys, organizations and memberships, granted administrations and data scopes, and OAuth app connections (which app, which scopes, when authorized).
- Network data: the source IP address of requests, used for rate limiting, optional IP/geo restrictions, and security.
The API does not retain a copy of the business data it returns; that data lives in your Care4Fresh administration and is served on request.
Why we process it (legal basis)
- To provide the service you requested and operate your administration access (performance of contract).
- To meter usage and bill correctly (performance of contract).
- To keep the service secure, prevent abuse, and maintain an audit trail (legitimate interest).
How long we keep it
We apply storage limitation in two tiers:
- Personal details in request logs (source IP address, user-agent, and query parameters) are removed after 90 days; after that, a log entry keeps only non-personal billing facts (which endpoint, the status, when, and which key/account).
- Diagnostic content for failed requests (the truncated request and response content kept for error responses, as described above) is removed after at most 30 days.
- Billing records are kept for as long as your account is active and, because they substantiate your invoices, for the statutory financial-records retention period (seven years in the Netherlands).
Account, key, and connection records are kept while your account is active and removed when it is closed. Contact info@care4it.nl about data we hold about you.
Connecting third-party apps (OAuth)
When you connect a third-party app (for example an AI assistant) to your Care4Fresh account, you authorize that app to receive the data it queries on your behalf, limited to the permissions (scopes) you grant at the consent screen. That data flows to the app provider's infrastructure, which may be outside the EU, where it is processed and stored under the app provider's own terms and privacy policy (which you should review before connecting). In that arrangement the app provider acts as a further processor that you authorize.
You can review and revoke connected apps at any time in the Care4Fresh portal under Account → Connected apps. Revoking immediately stops further access.
Your rights
Depending on your role and applicable law, you may have rights to access, correct, export, or erase personal data, and to object to or restrict certain processing. Because Care4iT typically acts as a processor for your customers' data, requests about that data should go to the relevant controller (your organization). For data the API holds about you as a user, contact info@care4it.nl.
International transfers
Care4iT processes this data within the EU/EEA (the Netherlands). Connecting a third-party app may transfer your data outside the EU/EEA; those transfers are governed by that provider's terms and safeguards.
Changes
We may update this statement; the version and date above change when we do. Material changes relevant to connected apps are reflected in the consent-screen notice, which is versioned and recorded when you authorize an app.