Privacy Policy

⚠️ Draft — legal review pending. This document was prepared with AI support as a starting point. Before it is used as a definitive legal document, it must be reviewed and approved by a qualified legal professional, with special attention to fields marked [TO CONFIRM].

Last updated: June 14, 2026.

1. Introduction

This Privacy Policy explains how Ativaly processes personal data when you use our Service, in line with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Use this policy together with our Terms of Use.

2. Who is responsible for your data

Ativaly's data-processing relationship has two layers:

Legal identification of the entity responsible for Ativaly (name, registration number, address, and data protection contact, if applicable): [TO CONFIRM].

3. What personal data we process

Data subject categoryExample dataController
Account owner (Customer)Name, email, phone, billing data, subscription historyAtivaly
Customer employeesName, email, phone, role/permissions in the platformCustomer
End customers (delivery recipients)Name, delivery address, phone, order/delivery historyCustomer
Usage and technical dataIP address, session identifiers, error records without sensitive dataAtivaly

We do not collect special categories of data (health, biometrics, ethnic origin, political opinions, etc.) and ask Customers not to enter them into the platform.

4. Purposes and legal bases

PurposeData categoryLegal basis (GDPR)
Create and manage the Customer account, billing, and supportAccount owner dataPerformance of a contract — art. 6(1)(b)
Enable the Customer to manage employees, end customers, routes, and deliveriesEmployee and end-customer dataLegitimate interest of the Customer and Ativaly in providing the contracted service — art. 6(1)(f)
Maintain security, prevent abuse, and diagnose technical issuesUsage and technical recordsLegitimate interest — art. 6(1)(f)
Comply with legal and tax obligationsBilling dataLegal obligation — art. 6(1)(c)

We do not use your data for automated decisions with legal effects or for marketing profiling without an additional legal basis.

5. Subprocessors

To operate the Service, we use service providers that process data on our behalf, under contract and only for the purposes described in this policy:

SubprocessorPurposeLocation / notes
SupabaseDatabase, authentication, and storage[TO CONFIRM — data hosting region]
Google Cloud Platform (GCP)Hosting infrastructure and support services[TO CONFIRM — data hosting region]
StripePayment processingStripe acts as an independent controller for payment data; Ativaly stores only customer/subscription identifiers, never full card data.

Where data is transferred outside the European Economic Area, we ensure appropriate safeguards, such as European Commission standard contractual clauses. [TO CONFIRM — final processing locations and transfer mechanisms after signing DPAs with subprocessors.]

We do not sell personal data to third parties.

6. How long we keep your data

After a record is deleted by you or by the Customer, we retain data for a short period before permanent deletion to allow error recovery and comply with audit obligations:

CategoryRetention after deletion
Account owner (Customer)90 days
Customer employees30 days
End customers (delivery recipients)30 days
Delivery history3 years
Payment dataManaged by Stripe according to Stripe's policy

After these periods, data is permanently and automatically deleted from our systems.

7. Your rights

If you are the data subject for an Ativaly account owner, you may exercise the following rights directly, subject to legal conditions:

If you are an employee or end customer of a business using Ativaly, the Customer business is the controller for your data and is the entity you should contact first. Ativaly provides Customers with tools to respond to those requests, including deletion, and will cooperate with the Customer when necessary.

To exercise rights with Ativaly, contact us at [TO CONFIRM — privacy contact email address].

8. Right to complain to a supervisory authority

You have the right to lodge a complaint with a supervisory authority, particularly in the EU Member State where you live or work, or where you believe a data protection violation occurred.

In Belgium, the competent authority is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données — "GBA/APD"). [TO CONFIRM — confirm this contact point after Ativaly's legal registration with the GBA, as planned in the internal compliance roadmap.]

9. Security

We apply appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or alteration, including customer data isolation, encryption in transit, and role-based access control. Technical logs are filtered so they do not include sensitive personal data such as emails, phone numbers, or addresses.

10. Cookies and similar technologies

Our marketing site uses a small number of cookies, including cookies essential for the site to function. Where applicable, we ask for your consent before using non-essential cookies through a cookie notice.

11. Children's data

The Service is intended for businesses and their adult collaborators and customers. We do not direct the Service to children and do not intend to knowingly collect children's personal data.

12. Changes to this policy

We may update this Privacy Policy periodically, for example to reflect changes to the Service, our subprocessors, or applicable law. For significant changes, we will notify you with reasonable advance notice.

13. Contact

For questions about this Privacy Policy or the processing of your personal data, contact us at [TO CONFIRM — privacy contact email address].