Privacy Policy
⚠️ Draft — legal review pending. This document was prepared with AI support as a starting point. Before it is used as a definitive legal document, it must be reviewed and approved by a qualified legal professional, with special attention to fields marked [TO CONFIRM].
Last updated: June 14, 2026.
1. Introduction
This Privacy Policy explains how Ativaly processes personal data when you use our Service, in line with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Use this policy together with our Terms of Use.
2. Who is responsible for your data
Ativaly's data-processing relationship has two layers:
- When you are the account holder (the business owner subscribed to Ativaly): Ativaly is the controller for account data such as name, email, billing data, and usage history, for contractual, support, and billing purposes.
- When the data is about employees and end customers that you manage in the platform: Ativaly acts only as a processor, processing that data on your behalf and according to your instructions. You (the Customer business) are the controller for that data and are responsible for having a valid legal basis to collect and share it with Ativaly.
Legal identification of the entity responsible for Ativaly (name, registration number, address, and data protection contact, if applicable): [TO CONFIRM].
3. What personal data we process
| Data subject category | Example data | Controller |
|---|---|---|
| Account owner (Customer) | Name, email, phone, billing data, subscription history | Ativaly |
| Customer employees | Name, email, phone, role/permissions in the platform | Customer |
| End customers (delivery recipients) | Name, delivery address, phone, order/delivery history | Customer |
| Usage and technical data | IP address, session identifiers, error records without sensitive data | Ativaly |
We do not collect special categories of data (health, biometrics, ethnic origin, political opinions, etc.) and ask Customers not to enter them into the platform.
4. Purposes and legal bases
| Purpose | Data category | Legal basis (GDPR) |
|---|---|---|
| Create and manage the Customer account, billing, and support | Account owner data | Performance of a contract — art. 6(1)(b) |
| Enable the Customer to manage employees, end customers, routes, and deliveries | Employee and end-customer data | Legitimate interest of the Customer and Ativaly in providing the contracted service — art. 6(1)(f) |
| Maintain security, prevent abuse, and diagnose technical issues | Usage and technical records | Legitimate interest — art. 6(1)(f) |
| Comply with legal and tax obligations | Billing data | Legal obligation — art. 6(1)(c) |
We do not use your data for automated decisions with legal effects or for marketing profiling without an additional legal basis.
5. Subprocessors
To operate the Service, we use service providers that process data on our behalf, under contract and only for the purposes described in this policy:
| Subprocessor | Purpose | Location / notes |
|---|---|---|
| Supabase | Database, authentication, and storage | [TO CONFIRM — data hosting region] |
| Google Cloud Platform (GCP) | Hosting infrastructure and support services | [TO CONFIRM — data hosting region] |
| Stripe | Payment processing | Stripe acts as an independent controller for payment data; Ativaly stores only customer/subscription identifiers, never full card data. |
Where data is transferred outside the European Economic Area, we ensure appropriate safeguards, such as European Commission standard contractual clauses. [TO CONFIRM — final processing locations and transfer mechanisms after signing DPAs with subprocessors.]
We do not sell personal data to third parties.
6. How long we keep your data
After a record is deleted by you or by the Customer, we retain data for a short period before permanent deletion to allow error recovery and comply with audit obligations:
| Category | Retention after deletion |
|---|---|
| Account owner (Customer) | 90 days |
| Customer employees | 30 days |
| End customers (delivery recipients) | 30 days |
| Delivery history | 3 years |
| Payment data | Managed by Stripe according to Stripe's policy |
After these periods, data is permanently and automatically deleted from our systems.
7. Your rights
If you are the data subject for an Ativaly account owner, you may exercise the following rights directly, subject to legal conditions:
- Access — obtain a copy of the personal data we process about you;
- Rectification — correct inaccurate or incomplete data;
- Erasure — request deletion of your data, subject to the retention periods above;
- Restriction and objection — request restriction of processing or object to processing based on legitimate interest;
- Portability — receive your data in a structured, commonly used format.
If you are an employee or end customer of a business using Ativaly, the Customer business is the controller for your data and is the entity you should contact first. Ativaly provides Customers with tools to respond to those requests, including deletion, and will cooperate with the Customer when necessary.
To exercise rights with Ativaly, contact us at [TO CONFIRM — privacy contact email address].
8. Right to complain to a supervisory authority
You have the right to lodge a complaint with a supervisory authority, particularly in the EU Member State where you live or work, or where you believe a data protection violation occurred.
In Belgium, the competent authority is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données — "GBA/APD"). [TO CONFIRM — confirm this contact point after Ativaly's legal registration with the GBA, as planned in the internal compliance roadmap.]
9. Security
We apply appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or alteration, including customer data isolation, encryption in transit, and role-based access control. Technical logs are filtered so they do not include sensitive personal data such as emails, phone numbers, or addresses.
10. Cookies and similar technologies
Our marketing site uses a small number of cookies, including cookies essential for the site to function. Where applicable, we ask for your consent before using non-essential cookies through a cookie notice.
11. Children's data
The Service is intended for businesses and their adult collaborators and customers. We do not direct the Service to children and do not intend to knowingly collect children's personal data.
12. Changes to this policy
We may update this Privacy Policy periodically, for example to reflect changes to the Service, our subprocessors, or applicable law. For significant changes, we will notify you with reasonable advance notice.
13. Contact
For questions about this Privacy Policy or the processing of your personal data, contact us at [TO CONFIRM — privacy contact email address].
