Privacy
What data is processed, why, for how long, and what rights you have.
Translated from the French. Where the language versions differ, the French text prevails.
Dernière mise à jour : 2026-09-24
Configuration incomplète : companyName, address, bce, vat, email. Renseignez les variables LEGAL_* avant la mise en ligne.
Controller
For your own account's data — your address, your sign-ins, your billing — the controller is the publisher:
Two distinct roles, not to be confused
For YOUR clients' data — names, site addresses, intervention photos, signatures — we are the processor and you are the controller. We use it only to run the service, on your instructions. The corresponding commitments are in the data processing agreement.
What we process, and what for
- Account and authentication: email address, one-time codes, a passkey where used, sign-in timestamps — performance of the contract (art. 6.1.b GDPR).
- Business content: clients, sites, catalogues, work orders, photos, signatures — performance of the contract, on your behalf.
- Billing: credits bought, orders published, payments — legal accounting obligation (art. 6.1.c) and performance of the contract.
- Technical logs: IP address, request id, errors — legitimate interest in securing and repairing the service (art. 6.1.f). Email addresses and phone numbers are hashed there.
- Messages sent through the contact form: what you write and your address — legitimate interest in answering.
For how long
- Unconfirmed account: deleted automatically after the period the operator sets (14 days by default).
- Active account: for the whole relationship, then 30 days to allow reactivation or an export.
- Work orders and attachments: as long as your account exists. They are your proof of intervention; we do not erase them on our own initiative.
- Accounting records: 7 years, as Belgian law requires.
- Technical logs: 90 days.
- Contact messages: 24 months.
Who else has access
Nobody, apart from the strictly necessary technical providers listed below. No data is sold, rented or used for advertising. No transfer outside the European Economic Area takes place.
- Hetzner Online GmbH — Hosting of the application, the database and the files. (Germany / Finland (EU))
- Fournisseur SMTP de l'éditeur — Sending transactional email: sign-in codes, orders sent to clients. (European Union)
Cookies
The site sets only the cookies it needs to work: your session, the chosen language, the CSRF protection. They follow nobody from one site to another and therefore ask for no consent. There is no analytics and no advertising tracker; the day there is one, a banner will appear and you will be able to refuse it.
Your rights
You can ask for access, correction, erasure or restriction of your data, object to processing based on legitimate interest, and get your data back in a machine-readable format — the export is in the settings, without writing to us.
To exercise those rights: write to the publisher.
You can lodge a complaint with the Belgian Data Protection Authority, rue de la Presse 35, 1000 Brussels — contact@apd-gba.be.
Security
- Encryption in transit (HTTPS) for every access to the service.
- Separation per company: every request is filtered on the company of the signed-in account, without exception.
- Sign-in without a password: a one-time code by email, or a passkey where that option is enabled.
- Virus scanning of uploaded files before they are stored.
- Encrypted backups with a tested restore.