Legal
Privacy Policy
Effective 1 October 2026
Simple Comments is built to store as little as possible. Your report data stays in your report. We only keep what you write in comment columns, plus what we need to run your account and licenses.
01Who we are
Simple Comments is made by Glyph Company (“Glyph”, “we”, “us”), registered in the Netherlands with the Chamber of Commerce (KVK) under number 78263042. You can reach us at contact@glyph.company.
This policy covers the Simple Comments visual for Power BI, the website and dashboard at powerbi.glyph.company, and the service that stores comments.
02Our two roles
- ·Account and billing data: we decide how this data is used, so we are the controller.
- ·Comments: the license holder decides what is written in reports, so they are the controller and we process comments on their behalf as a processor. If you need a data processing agreement, email us.
03Data we collect
- ·Account: your email address, your password (stored only as a secure hash), and when you signed up and last logged in.
- ·Billing: company name, VAT number, address, postal code, city, country, billing email, and your invoices. Card and other payment details are handled by Stripe. We never see or store full card numbers.
- ·Licenses: your license keys, their plan, label, expiry date, and renewal status.
- ·Comments: the text written in each comment column, the time it was last changed, and a row key, all linked to a license. The row key is a one-way SHA-256 hash of the Context field names and values, created inside the visual.
- ·Technical data: when your browser or the visual contacts our servers, our providers process your IP address, browser type, and the time of the request to deliver and secure the Service.
- ·Messages: anything you send us by email.
04Data we don’t collect
- ·Your report data. Display and Context values never leave your report. We only receive the hashed row key, and it can’t be turned back into those values.
- ·The identity of the Power BI users who view or edit comments. Comments are linked to a license key, not to a person.
- ·Analytics or advertising data. We don’t use tracking tools on the website or in the visual.
05How we use your data
- ·To provide the Service: creating your account, issuing license keys, checking licenses, and storing and serving comments. Legal basis: performing our contract with you.
- ·For billing and accounting: charging for licenses, issuing invoices, and keeping records. Legal basis: our contract with you, and our legal obligations under Dutch tax law.
- ·To keep the Service secure: preventing abuse, fraud, and attacks. Legal basis: our legitimate interest in running a safe service.
- ·To contact you: account confirmations, password resets, and notices about your licenses, renewals, and payments. We don’t send marketing emails without your consent.
07International transfers
Some of our providers may process data outside the European Economic Area, for example in the United States. When they do, the transfer is protected by safeguards such as the EU Standard Contractual Clauses or the EU-US Data Privacy Framework.
09How long we keep it
- ·Account and license data: for as long as your account exists.
- ·Comments: until you delete them from the dashboard or delete your account. Comments are kept after a license expires, so they come back if you renew.
- ·Billing records and invoices: seven years, as required by Dutch tax law, even after you delete your account.
- ·Technical logs: for a short period (usually 24h), as needed for security and troubleshooting.
When you delete your account, your account, licenses, comments, and billing details are removed from our systems. Copies in backups are overwritten as our providers’ backup cycles run.
10Your rights
Under the GDPR, you have the right to access, correct, delete, and export your personal data, to restrict or object to how we use it, and to withdraw any consent you gave.
You can do most of this yourself:
- ·Change your email address or password on the Account page.
- ·Export a license’s comments as a JSON file, or delete them, from the dashboard.
- ·Delete your account and all of its data on the Account page.
For anything else, email contact@glyph.company. We reply within 10 business days. If you’re not happy with how we handle your data, you can complain to the Dutch Data Protection Authority, Autoriteit Persoonsgegevens.
11Security
All connections use HTTPS. Passwords are stored as secure hashes, and each account can only access its own data. Comments can only be read and written with a valid license key.
Comment text is not end-to-end encrypted, and anyone with a license key can read its comments. Don’t put passwords or sensitive personal data in comments, and keep license keys private. No system is completely secure, but we take reasonable technical and organizational measures to protect your data.
12Children
The Service is meant for businesses and is not intended for anyone under 16. We don’t knowingly collect data from children.
13Changes to this policy
We may update this policy. The latest version is always on this page, with its effective date. If we make an important change, we will email you before it takes effect.
14Contact
Questions about your data or this policy? Email contact@glyph.company.