In the event of any discrepancy, the French version prevails.
This policy explains which personal data is processed when you visit senzyapp.com, create an account, use the my.senzyapp.com application or contact Senzy, why it is processed, how long it is kept and what your rights are.
Senzy is a service intended for professionals. The word “customer” refers to the company or organisation that subscribes to the service; “user” refers to any person who logs in to the application with an account created by a customer; “visitor” refers to any person who browses the website.
1. Who is responsible for your data
The service is operated by Baptiste De Coker, trading under the business name Senzy, Rue Pierre Curie 32/1, 4630 Soumagne, Belgium, BCE 0788.581.789 (hereinafter “Senzy” or “we”). Contact for any question relating to personal data: support@senzyapp.com. Senzy is not required to appoint a data protection officer and has not appointed one.
Senzy acts in two different capacities, and your rights are exercised differently depending on the case:
| Situation | Senzy’s role | Who decides the purposes |
|---|---|---|
| You visit the website, fill in a form, create an account, subscribe to a plan, contact support | Controller | Senzy |
| You are an employee, colleague or contact of a customer who has entered your data in the application (employee record, assigned vehicle, expense report, training, ticket…) | Processor acting on behalf of the customer | The customer, your employer or principal |
In the second case, Senzy processes your data only on the customer’s instructions and in accordance with the data processing agreement (DPA) annexed to the Terms and Conditions. To exercise your rights over that data, contact the customer first; Senzy assists the customer in its response (see section 7).
2. Which data is processed, and why
2.1 Data for which Senzy is the controller
| Purpose | Data | Data subjects |
|---|---|---|
| Responding to a request sent via the contact form | Name, email address, subject, message | Visitors |
| Creating the account and the company at sign-up | First name, last name, email address, password (stored hashed), language; company name, size, address, company phone and email, VAT number, Peppol identifier, first name, last name and email of the billing contact | Administrator who signs up, billing contact |
| Verifying the VAT number | VAT number (query to the European Commission’s VIES service, result kept) | Customer |
| Processing a request to join an existing company | First name, last name, email, VAT number of the company concerned | Person requesting to join |
| Managing the subscription and billing | Email and name of the billing contact, billing name and address, VAT number, Stripe customer and subscription identifiers, billing history, promotional codes used. Senzy neither receives nor stores any card number: payment is processed by Stripe. | Customer, billing contact |
| Sending service emails (account confirmation, invitation, password reset, end of trial, end of access, storage thresholds) | Email address, first name, last name, language, sending log (recipient, type, timestamp, status) | Users, administrators |
| Providing support | Content of requests and messages exchanged, identity of the author, company, plan, timestamps; log of support sessions opened by Senzy on a customer’s account (reason, intent, duration) | Administrators and users who contact support |
| Ensuring the security of the service | Login credentials, IP address and timestamp of logins (kept by our authentication host), execution logs of automated tasks | Users |
| Logging in with a Google or Microsoft account (optional) | Email address and name transmitted by the identity provider, technical identifier of the account | Users who choose this option |
Senzy collects no data for advertising purposes, carries out no profiling and sells no data.
2.2 Data processed on behalf of customers (Senzy as processor)
The customer enters in the application the data needed to manage its assets and its staff. By nature, this may include:
| Module | Typical categories of personal data |
|---|---|
| Employees and access | Identity, work email, phone, employee number, job title, department, line manager, site, start date, status, access rights, display preferences |
| Resources (vehicles, phones, devices, equipment, installations, stock) | Assignment of a resource to a person, licence plate, chassis number, mileage, line number, IMEI, serial numbers, assignment history, photos of resources |
| Contracts and vendors | Contact details of vendor contacts, internal persons responsible for contracts |
| Skills and training | Qualifications held, dates obtained and expiry dates, sessions attended, attendance, results, certificate numbers, supporting documents, training evaluations, training requests and their justification |
| Expense reports | Expenses declared, amounts, dates, receipts, mileage, approval, rejection and payment comments |
| Tickets and incidents | Reporter, assignee, description, exchanges, information about third parties involved (claims) |
| Free-text fields and attachments | Any content the customer chooses to place there |
The customer alone is responsible for the lawfulness of the data it enters. Data processed in the application is confidential and protected as such (HR data, expenses, equipment assignments), but the application is not designed to process special categories of data within the meaning of Article 9 GDPR (health, trade union membership, beliefs, biometric or genetic data, sexual orientation, ethnic origin). If the customer nevertheless enters such data, for example in a free-text field, an attachment or a receipt, it does so under its own responsibility and Senzy processes it with the same level of protection as the customer’s other data.
3. On which legal basis
| Processing | Legal basis (Art. 6 GDPR) |
|---|---|
| Sign-up, account, provision of the application, support, service emails | Performance of the contract (Art. 6(1)(b)) — including during the free trial period |
| Billing, retention of invoices, VAT verification | Legal obligation (Art. 6(1)(c)): Belgian accounting and VAT legislation |
| Contact form, request to join a company | Pre-contractual steps taken at your request (Art. 6(1)(b)) |
| Security, logs, prevention of fraud and abuse, logging of support sessions | Legitimate interest (Art. 6(1)(f)): protecting the service and customers’ data |
| Login via Google or Microsoft | Performance of the contract, at your initiative |
| Data entered by the customer in the application | Determined by the customer, as controller |
Senzy sends no newsletter and no unsolicited commercial communication. If a newsletter is offered one day, it will rely on your consent, revocable at any time.
4. Who has access to your data
4.1 Within Senzy
Senzy is operated by a single person. Senzy’s access to customers’ data, through its internal tools, is protected by two-factor authentication, limited to the needs of support and service supervision, and logged: every support session on a customer’s account is opened for a stated reason, limited to 60 minutes and recorded. The log of these accesses is kept for three years and provided to the customer on request.
4.2 Processors and recipients
Senzy uses the following providers, bound by contract and subject to the same protection obligations:
| Provider | Role | Data location | Transfer safeguards |
|---|---|---|---|
| Supabase Pte. Ltd (Singapore) | Hosting of the database, authentication, files and server functions | European Union — AWS Stockholm region (Sweden) | Data in the EU; standard contractual clauses (modules 2 and 3) incorporated in the Supabase DPA v1 of 01/08/2026 for any maintenance access |
| Netlify, Inc. (United States) | Hosting and delivery of the website and the application; execution of the website’s forms | Worldwide delivery network; no customer data stored durably | Standard contractual clauses incorporated in the Netlify DPA of 09/06/2026 |
| Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (United States) | Payment, subscriptions, issuing of invoices, billing portal | European Union and United States | Data Privacy Framework (verified) and standard contractual clauses |
| Horus Software SA (Belgium, BCE 0478.696.879), operator of the Falco application | Transmission of invoices via the Peppol network | European Union — data centres in Luxembourg | Provider established in the EU, no transfer |
| Plus Five Five, Inc. (United States), operator of the Resend service | Sending of service emails and of scheduled reports as attachments | European Union region | Data Privacy Framework and standard contractual clauses incorporated in the Resend DPA of 27/08/2026 |
| PDFShift SASU (128 rue la Boétie, 75008 Paris, France) | Generation of PDF documents (expense reports, resource records, reports); the document content passes through for conversion and is returned immediately, without being stored | European Union — OVH data centres in France | Provider established in the EU, no transfer; PDFShift DPA signed |
| European Commission — VIES service | Verification of the validity of the VAT number at sign-up | European Union | Public authority, no transfer |
| Google Ireland Ltd. / Microsoft Ireland Operations Ltd. | Identity providers, only if you choose to log in with a Google or Microsoft account | According to the provider’s terms | You are bound by the privacy policy of the provider you choose |
The website may display content hosted by third parties: an illustration image served by Pexels and YouTube demo videos, loaded only when you click “Play” (cookie-free mode). Loading this content transmits your IP address to these providers.
Senzy may also disclose data to a public authority where the law requires it, and to its advisers (accountant, legal counsel) to the strict extent necessary.
No data is sold, rented or passed on for marketing purposes.
4.3 Transfers outside the European Union
Data is hosted in the European Union. Some providers are companies established in the United States; where access from a third country is possible, it is governed by the European Commission’s standard contractual clauses (Decision 2021/914) or by the provider’s certification under the EU–US Data Privacy Framework. A copy of the safeguards can be obtained on request from support@senzyapp.com.
5. How long your data is kept
General rule for customer accounts: 70 days after the end of your subscription or trial, without reactivation, your company and its data are deleted, after two email reminders.
In practice: at the end of access (unconverted trial or effective end of a cancelled subscription), the company switches to read-only and its data remains viewable and exportable. A first reminder is sent to the administrators 30 days later, a final warning at 37 days, the company is suspended at 40 days, and Senzy carries out the permanent deletion when the 70-day period expires. Subscribing to a plan during this period ends the process. Deletion covers the company, all data entered, stored files and the login accounts of its users; it is irreversible.
The customer may at any time request the early deletion of its company by writing to support@senzyapp.com; Senzy carries it out within 30 days after verifying the identity of the requester (administrator of the company).
| Data | Retention period |
|---|---|
| Account data and data entered in the application | Duration of the contract, then 70 days under the rule above |
| Change audit log (history in the application) | 12, 24 or 36 months depending on the plan subscribed, within the duration of the contract |
| Archived scheduled reports | 12 months |
| Contact form messages | 1 year |
| Requests to join a company | 1 year |
| Support requests and related exchanges | 1 year after the end of access of the company concerned |
| Log of Senzy support sessions | 3 years |
| Sending logs of service emails | 1 year |
| Technical execution logs | 90 days |
| Record of a company’s deletion (name, VAT number, dates, author of the operation) | 3 years |
| Invoices and accounting data | 7 years (Belgian legal obligation), kept at Stripe and in Senzy’s accounts |
| Login data (authentication logs of the host) | According to the host’s policy |
6. How your data is protected
Senzy applies measures proportionate to the nature of the data processed:
- Isolation per customer: every piece of data is attached to a company and access rules are enforced at the database level itself, not only in the interface;
- Encryption in transit (TLS) and at rest, provided by the hosts;
- Rights management by the customer: permissions per module (no access, own data, view, modify) and per site; a user sees only what their administrator has opened to them;
- Authentication: passwords stored hashed, complexity requirements, login possible via an identity provider, two-factor authentication mandatory for Senzy staff;
- Traceability: change log available to the customer’s administrators, logging of every access by Senzy support;
- Effective deletion: files deleted in the application are removed from storage by a purge queue; the data of a deleted company is erased from the database and from storage;
- Backups: carried out by the database host ; they are encrypted and used only for disaster recovery.
No system is infallible. In the event of a data breach likely to result in a risk to your rights, Senzy notifies the Data Protection Authority within 72 hours and informs the customers concerned without undue delay, in accordance with Articles 33 and 34 GDPR and the DPA.
7. Your rights
You have the rights of access, rectification, erasure, restriction of processing, objection and, where processing is based on the contract, portability (Art. 15 to 21 GDPR).
If you are an employee or a contact of a Senzy customer, your data is processed on behalf of your employer or principal: send your request to them. They have the tools in the application to view, correct, export and delete your data; Senzy assists them if necessary. If you contact Senzy directly, we will forward your request to the customer concerned and inform you accordingly.
If you are in a direct relationship with Senzy (visitor, person signing up, administrator, billing contact), write to support@senzyapp.com. Senzy replies within one month, extendable by two months for complex requests, after reasonable verification of your identity. Exercising your rights is free of charge, except for manifestly unfounded or excessive requests.
You may lodge a complaint with the Belgian Data Protection Authority (Rue de la Presse 35, 1000 Brussels, +32 2 274 48 00, contact@apd-gba.be, www.dataprotectionauthority.be) or with the supervisory authority of your country of residence (CNIL in France, CNPD in Luxembourg).
8. Cookies and local storage
The senzyapp.com website sets no cookie and uses no audience measurement tool or advertising tracker. No consent banner is therefore displayed.
The my.senzyapp.com application uses the browser’s local storage (localStorage), strictly necessary for its operation: a session token to keep you logged in, and display preferences (menu state, recent searches, chosen view). This information stays on your device, is not transmitted to third parties and is not used to track you. It does not require consent within the meaning of the ePrivacy rules. You can clear it at any time through your browser settings; you will then be logged out.
If Senzy one day introduces audience measurement, it will be chosen without cookies and without identifying visitors, and this section will be updated before it is activated.
9. Miscellaneous
Minors. The service is for professionals only and is not intended for persons under 18. Senzy does not knowingly collect data about them.
Automated decisions. Senzy takes no decision producing legal effects concerning you based solely on automated processing. The application’s automatic alerts (deadlines, thresholds, reminders) are configured by the customer and have no effect on persons outside the customer’s organisation.
Changes. This policy may be amended to reflect changes in the service or in the regulations. Any substantial change is notified to the customers’ administrators by email or in the application at least 30 days before it takes effect. The dated version online prevails.
Contact. support@senzyapp.com — Baptiste De Coker, Rue Pierre Curie 32/1, 4630 Soumagne, Belgium.
Related documents: Legal notice · Terms and Conditions
