Privacy notice
Last updated: 27 July 2026
Written to be read. Where a clause has a practical consequence, the consequence is stated rather than implied.
Who is responsible
ApiNavi B.V., Amsterdam, is the controller for data about account holders and site visitors. For coordinates and addresses you send through the API on behalf of your own users, you are the controller and we are the processor — the DPA covers that relationship.
What we process
Account data: name, work email, company, billing details. Kept for the life of the account and seven years afterwards where tax law requires it.
Operational logs: request timestamps, endpoint, response status, latency, truncated IP and key identifier. Kept 30 days, then aggregated into counters with no request-level detail.
Query content — the addresses and coordinates in your requests — is processed to produce a response and is not retained after the response is returned, except in a 24-hour error-diagnosis buffer that is access-controlled and purged on schedule.
What we do not do
We do not build advertising profiles, we do not sell or share query data with data brokers, and we do not use your query content to train models.
The site sets no analytics or advertising cookies. The only cookie is a theme preference stored locally, which never leaves the browser.
Where it is stored
EU accounts are served and stored in the EU by default. Scale and Enterprise plans can pin storage to the EU or the US contractually. Subprocessors and their locations are listed on the subprocessors page.
Your rights
Access, correction, erasure, portability, restriction and objection, exercisable at [email protected]. We respond within 30 days.
You can complain to your local supervisory authority; for us that is the Autoriteit Persoonsgegevens in the Netherlands.
These are commercial terms, not legal advice. They were drafted to be read by the people who have to live with them; have your own counsel read them before you rely on them.
Questions about this document go to [email protected].