Privacy Policy
Last updated: 18 August 2026
This Privacy Policy describes how we collect, use, and share information about you when you use our website and services.
Information We Collect
Information You Provide
We collect information you provide directly to us, such as when you:
- Create an account or an organization
- Record your own business data in the service, such as clients, products, quotes, orders and invoices
- Purchase credits
- Contact us for support
This information may include your name, email address, postal address, phone number, and the business data you enter.
We do not collect or store your payment card details. Where a payment is taken, the card details are entered on the payment provider's own pages and never reach this service.
Information We Collect Automatically
When you use our services, we automatically collect certain information, including:
- Log information: our servers record technical information about requests made to the service, including access times, the pages or endpoints requested, and your IP address. This is used to operate and secure the service and to diagnose faults.
- Cookies: we use cookies that are necessary for the service to function, such as keeping you signed in and remembering your language preference. We do not use analytics or advertising cookies, and we do not build a profile of your activity. See our Cookie Policy for the detail.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send you technical notices, updates, and support messages
- Respond to your comments, questions, and requests
- Monitor and analyze trends, usage, and activities
- Detect, investigate, and prevent fraudulent transactions and other illegal activities
- Personalize and improve your experience
Information Sharing
We may share information about you as follows:
- With Service Providers: We share information with third-party vendors who provide services on our behalf.
- For Legal Reasons: We may share information if we believe disclosure is necessary to comply with applicable laws or legal processes.
- With Your Consent: We may share information with your consent or at your direction.
Data Retention
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
Your Rights
Depending on your location, you may have certain rights regarding your personal information, including:
- The right to access your personal information
- The right to correct inaccurate information
- The right to delete your personal information
- The right to object to processing
- The right to data portability
Security
We take reasonable measures to help protect information about you from loss, theft, misuse, unauthorized access, disclosure, alteration, and destruction.
Connected Payment Accounts
This section applies when an organization using this service connects its own payment provider account (currently Mollie) so that it can invoice its customers through that account.
What the connection authorizes
Connecting is an explicit act performed by an administrator of the organization, through the provider's own authorization screen. We request the narrowest set of permissions the invoicing features need:
organizations.readandprofiles.read— to identify which account was connected and display its name back to the organizationpayment-links.write— to create a payment link for one of that organization's own invoicespayments.read— to read the status of those payments so an invoice can be reconciled as paid
We do not request permission to move funds, to issue refunds, or to read payments unrelated to the invoices created through this service.
What we store
For each connected account we store: the access and refresh tokens, the token expiry, an identifier and a non-reversible fingerprint of the encryption key used, the provider's organization and profile identifiers and the account name it reports, an opaque token used to address that organization's webhook, which administrator connected the account and when, the connection status, and the time and result of the most recent automated connection check.
Tokens and API keys are encrypted at rest with AES-256-GCM and are never stored in readable form. They are reachable only through a single server-side boundary and are never sent to a browser.
Where the money goes
Payments made by an organization's customers settle into that organization's own provider account. We do not hold, route or take a share of those funds. Payment card details are entered on the provider's pages and never reach this service.
Isolation between organizations
Each organization's credentials are stored against that organization alone and are used only for that organization's own invoicing. One organization's connection is never used to act for another.
Disconnecting
An administrator can disconnect the account at any time from the organization's provider settings. Disconnecting destroys the stored encrypted credentials for that account.
Please also review your authorized applications in your provider's own dashboard after disconnecting. Our disconnect request presents the access token, and depending on the provider the associated refresh token may remain valid on the provider's side. Revoking access in the provider's dashboard is the only way to be certain the authorization is fully withdrawn.
Retention
The encrypted credentials themselves are destroyed at the moment you disconnect, as described above.
The remaining non-credential metadata for a disconnected account — its status history, the results of automated connection checks, and which administrator connected it and when — is retained for as long as the organization exists, so that a connection or payment-routing question raised after the fact can still be answered. It is removed when the organization is deleted.
Deleting an organization or account, and your responsibility to export first
Deleting an organization permanently removes its data from this service, and we cannot restore it afterwards. Before you delete an organization or an account, it is your responsibility to download or otherwise retain any records you need or are required by law to keep — in particular your accounting documents, which Belgian law obliges you to preserve for a period that does not end when you stop using this service.
What deletion actually means, in the two places your data lives. In the live service the data is erased immediately and irreversibly, and at the latest within 30 days of the end of your subscription. Our backups are a separate matter: an image already written cannot be edited, so copies of your data persist in the backup rotation and are purged by that rotation within 90 days at the latest. Those backups are never restored or consulted during that period except to recover the service from an incident.
We do not keep a copy on your behalf, we will not produce one for you later, and we cannot retrieve a deleted organization from a backup on request. The 90-day figure is stated because it is the truth about how backups work, not because a copy is held for you.
These are the same periods we commit to in Annexe II of our Data Processing Agreement.
Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Email: info@itops.be
Company: ITOPS SRL — company number (KBO/BCE) 0772513047
Address: 106 rue du Marais, 6150 Anderlues, Belgium