Rovalta
Legal

Privacy Policy

Last updated: 2026-07-31

This Privacy Policy explains how Kraken Immo (Aurélien Kinet, enterprise number BE 1008.509.394), operator of the Rovalta service, processes personal data in accordance with the EU General Data Protection Regulation (GDPR) and Belgian law.

1. Scope and data controller

The data controller is Kraken Immo. You can reach us at [email protected] (data-protection contact / DPO: [TO CONFIRM — DPO email, if appointed]). This policy covers personal data of website visitors and account holders.

Note on company data: information about Belgian legal entities and their representatives comes from official public registers (BCE/KBO, NBB, Moniteur belge). Where this includes personal data of company officers, we process it on the basis of our legitimate interest in providing a business-information service, and in reliance on its public-register status.

2. What personal data we collect

Depending on how you use the Service, we may collect:

  • account data: name, email address, password (hashed), and preferences;
  • usage data: pages viewed, searches, and actions within the Service;
  • technical data: IP address, browser and device information, and cookies (see our Cookie Policy);
  • communications: messages you send us (e.g. support requests).

3. Purposes and legal basis (GDPR Art. 6)

  • providing and operating the Service — performance of a contract (Art. 6(1)(b));
  • account security, fraud prevention and service improvement — legitimate interest (Art. 6(1)(f));
  • analytics on aggregate usage — legitimate interest (Art. 6(1)(f)); see Security & analytics below;
  • legal and accounting obligations — legal obligation (Art. 6(1)(c));
  • optional communications, where applicable — consent (Art. 6(1)(a)).

4. How data is shared

We do not sell your personal data. We share it only with processors that help us run the Service (e.g. hosting, email delivery), bound by data-processing agreements, and where required by law or competent authorities.

5. No transfer outside the EEA

Our infrastructure and processors are located within the European Economic Area (EU hosting). We do not transfer your personal data outside the EEA. Should this change, we will rely on an appropriate GDPR transfer mechanism and update this policy.

6. Your rights as a data subject

Under the GDPR you have the right to:

  • access your personal data;
  • have inaccurate data rectified;
  • have your data erased (“right to be forgotten”), where applicable;
  • restrict processing;
  • data portability;
  • object to processing based on legitimate interest;
  • not be subject to solely automated decision-making with legal effect;
  • withdraw consent at any time, where processing is based on consent.

To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit, www.autoriteprotectiondonnees.be).

7. Retention

We keep personal data only as long as necessary for the purposes above or as required by law. Account data is deleted or anonymised after account closure, subject to legal retention periods.

8. Security and analytics

We apply appropriate technical and organisational measures to protect personal data. For usage analytics we rely on a privacy-first, self-hosted solution on EU infrastructure; it does not share your data with third-party advertising networks.

9. Applicable law and jurisdiction

This policy is governed by Belgian law and the GDPR. Disputes fall within the jurisdiction of the competent Belgian courts.

10. Amendments

We may update this policy. The current version is always published here.

Privacy Policy — Rovalta — Rovalta