Legal

Privacy Policy

Last updated: 2026-09-12

This Privacy Policy explains how Aurélien Kinet (enterprise number BE 1008.509.394), a sole trader established in Belgium and operator of the Rovalta service, processes personal data in accordance with the EU General Data Protection Regulation (GDPR) and Belgian law.

1. Scope and data controller

The data controller is Aurélien Kinet. You can reach us at [email protected]. Our data protection contact (DPO) is [email protected].

This policy covers three groups of people: visitors of the website, account holders, and natural persons who appear in the company information we publish (company officers, founders, liquidators and shareholders named in official records). Section 4 is written for that third group.

2. What personal data we collect from visitors and account holders

Depending on how you use the Service, we may collect:

  • account data: name, email address, password (hashed), and preferences;
  • billing data: plan, invoices and payment status. Card numbers are handled by our payment processor and never reach our servers;
  • usage data: pages viewed, searches, and actions within the Service;
  • technical data: IP address, browser and device information, and cookies (see our Cookie Policy);
  • communications: messages you send us (for example support requests).

3. Purposes and legal basis (GDPR Art. 6)

  • providing and operating the Service, including billing: performance of a contract (Art. 6(1)(b));
  • account security, fraud prevention and service improvement: legitimate interest (Art. 6(1)(f));
  • analytics on aggregate usage: legitimate interest (Art. 6(1)(f)); see Security and analytics below;
  • detailed analytics: consent (Art. 6(1)(a)), given in the cookie banner and withdrawable at any time;
  • legal and accounting obligations: legal obligation (Art. 6(1)(c));
  • optional communications, such as a newsletter: consent (Art. 6(1)(a)), which you can withdraw at any time.

4. Company officers and persons appearing in public registers

The Service publishes information about Belgian companies taken from official public sources: the Crossroads Bank for Enterprises (BCE/KBO), the annual accounts filed with the National Bank of Belgium (NBB, Central Balance Sheet Office) and the Belgian Official Gazette (Moniteur belge / Belgisch Staatsblad). Where these records concern a natural person, the following information is personal data:

  • surname and first name;
  • the function or mandate held, the company concerned, and the start and end dates of the mandate;
  • the address as published in the source register, where the source publishes one;
  • shareholdings and participations as reported in the annual accounts;
  • publications in the Official Gazette that mention the person;
  • professional contact details that the company publishes on its own website (function, professional e-mail address, telephone number).

We process this data on the basis of our legitimate interest (Art. 6(1)(f)): providing businesses, professionals and the public with reliable information on the persons who represent and control Belgian companies. This information is published by law for the purpose of legal publicity, relates to the professional sphere of the persons concerned, and is republished without alteration. We do not collect it from the persons themselves, which is why we inform them through this policy (Art. 14 GDPR).

Company websites: where a company publishes on its own website the professional contact details of the persons who represent it, we may collect them and show them on that company's page, next to the company, never as a profile of the person. We limit this to professional contact data, we re-verify it against the website, and we delete it at the latest 24 months after the last verification or as soon as the company removes it.

What we do not do: we do not compute any score, rating or risk assessment about a natural person. Financial health scores and indicators are calculated on companies only. We do not collect data from social networks, personal profiles or any other source that is not an official register or the company's own website, and we take no automated decision with legal effect on anyone.

Retention: we keep this data as long as it is published in the source register. After a mandate ends, we keep it as historical information for at most 20 years after the end date, and we delete it earlier on a justified request.

Your rights and how to exercise them: write to [email protected] with your name, the company concerned, the data you refer to and what you ask for, together with proof of identity (a copy of an identity document with the photo and national number masked is sufficient). We answer within one month. On simple request we mask a private address. A mandate itself is legal publicity and remains in the official registers; we examine each objection in the light of your particular situation and, where we keep the mandate visible, we tell you why. If the source record is wrong, the correction must be made at the source (the BCE/KBO through the enterprise court or a business counter, the NBB for annual accounts); we then align at the next synchronisation, or earlier on request.

5. Connectors and third-party AI assistants

You may choose to connect your Rovalta account to a third-party assistant, such as Claude (Anthropic) or ChatGPT (OpenAI), through a connector we offer. The assistant then sends requests to Rovalta on your behalf.

  • what we receive: the identity of the linked account and the parameters of each request (search terms, enterprise numbers, the tool called);
  • what we do not receive: the content of your conversations, your files, or the assistant's memory;
  • what we keep: a log of each request (time, account, tool, parameters) for security, quotas, billing and abuse prevention, retained for 12 months.

The assistant provider processes your conversation, including the data Rovalta returns to it, as an independent controller under its own privacy policy, possibly outside the European Economic Area. Rovalta has no control over that processing. You can revoke the connection at any time from your Rovalta account or from the assistant; revocation invalidates the access tokens immediately.

6. How data is shared

We do not sell your personal data. We share it only with processors that help us run the Service (hosting, email delivery, payment processing), bound by data-processing agreements, and where required by law or competent authorities.

7. No transfer outside the EEA

Our infrastructure and processors are located within the European Economic Area (EU hosting). We do not transfer your personal data outside the EEA. The only exception is a transfer you initiate yourself by using a third-party assistant, as described in section 5. Should our own practice change, we will rely on an appropriate GDPR transfer mechanism and update this policy.

8. Your rights as a data subject

Under the GDPR you have the right to:

  • access your personal data;
  • have inaccurate data rectified;
  • have your data erased (right to be forgotten), where applicable;
  • restrict processing;
  • data portability;
  • object to processing based on legitimate interest;
  • not be subject to solely automated decision-making with legal effect;
  • withdraw consent at any time, where processing is based on consent.

To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit, www.autoriteprotectiondonnees.be).

9. Retention

We keep personal data only as long as necessary for the purposes above or as required by law. Account data is deleted or anonymised after account closure, subject to legal retention periods (invoices are kept for the period required by tax law). Retention of officer data and connector logs is described in sections 4 and 5.

10. Security and analytics

We apply appropriate technical and organisational measures to protect personal data. For usage analytics we rely on a self-hosted solution on EU infrastructure, which does not share your data with third-party advertising networks. It measures audience in aggregate on all visits and stores a visitor identifier in your browser's local storage for that purpose. Optional statistics, by contrast, are switched on only with your consent, and you can withdraw it at any time through the “Cookie preferences” link. Full detail in the Cookie Policy.

11. Applicable law and jurisdiction

This policy is governed by Belgian law and the GDPR. Disputes fall within the jurisdiction of the competent Belgian courts.

12. Amendments

We may update this policy. The current version is always published here, with its date at the top of the page.