Privacy and Data Use Policy
This Privacy and Data Use Policy (hereinafter the "Policy") explains how GIVEACTIONS SRL, a company established in Belgium, with its registered office at 1, rue des phlox 1170 Brussels, registered under number BE0734.404.222, processes personal data in connection with the use of the ALIOS platform (hereinafter the "Platform").
This Policy applies in particular:
- to visitors of the giveactions.com website;
- to users of the Platform;
- to representatives and contact persons of business customers;
- to any data contained in the files and communications submitted to the Platform;
- to persons who contact us.
This Policy has been drawn up in accordance with Regulation (EU) 2016/679 ("GDPR") and the applicable Belgian data protection legislation.
1. Data controller
The controller of the personal data processed in connection with the Platform's own operation is:
GIVEACTIONS SRL
1, RUE DES PHLOX 1170 BRUXELLES
BE0734.404.222
(hereinafter "we", "our" or the "Company").
For certain personal data contained in communications submitted by our customers, our role may be that of a processor within the meaning of the GDPR, where we process such data on behalf of and in accordance with the instructions of the customer.
In such cases, the customer concerned remains the controller and determines the purposes for which the data are processed.
Where necessary, the respective obligations of the customer and the Company are set out in a data processing agreement ("Data Processing Agreement" or "DPA").
2. Applicable principles
We undertake to process personal data in accordance with the principles of the GDPR, in particular the principles of:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality;
- accountability.
We collect and use personal data only to the extent necessary for the purposes described in this Policy.
3. Data we may process
Depending on your use of the Platform, we may process the following categories of data.
3.1. Account data
When an account is created and used, we may process:
- surname and first name;
- business email address;
- job title or professional role;
- name of the company or organisation;
- business contact details;
- account credentials;
- subscription information;
- Platform usage history;
- information necessary for account management.
3.2. Platform usage data
We may also process certain technical information relating to the use of the Platform, such as:
- IP address;
- date and time of login;
- browser or device information;
- technical logs;
- information about the features used;
- information necessary for security and the prevention of abuse.
These data are used primarily to ensure the operation, security and technical improvement of the Platform.
4. Communications and files submitted to the Platform
The Platform allows the Customer to submit communications in various forms, including:
- texts;
- images;
- videos;
- documents;
- files containing advertising, commercial, institutional or environmental content.
Depending on their nature, such content may contain personal data concerning identifiable persons.
We process such content in order to provide the analysis service offered by the Platform.
Processing may include, in particular:
- receipt of the file;
- its temporary or long-term storage on our infrastructure;
- its technical processing;
- its analysis by our artificial intelligence systems;
- the generation of a result and recommendations;
- the retention of the result in the Customer's account history.
5. We do not share Customers' communications
The communications, files and content submitted by Customers are not used by the Company to build a public database or to publish Customers' communications.
Except with the Customer's prior consent or where required by law, we do not disclose to third parties the communications submitted to the Platform or the detailed results of the analyses.
Data are processed only to the extent necessary to provide the Service and for the purposes described in this Policy.
6. Use of artificial intelligence technologies
Certain features of the Platform rely on artificial intelligence technologies provided, in particular, by Google.
Content submitted to the Platform may be transmitted to the technical services required for these features to operate, in accordance with the contracts and settings applicable to those services.
We select and configure these services so as to enable our solution to operate under appropriate conditions of security and confidentiality.
However, processing by a third-party artificial intelligence provider may involve certain data being processed by that provider.
The providers and processors concerned may be updated where necessary to ensure the operation or development of the Platform.
Where required by law, any transfers of data to countries outside the European Economic Area are governed in accordance with the GDPR.
7. Purposes of processing
We may process personal data for the following purposes:
a. Provision of the Platform
In order to:
- create and administer accounts;
- provide access to the Platform;
- process submitted files;
- carry out analyses;
- produce results and recommendations;
- retain the history of analyses;
- ensure the technical operation of the Service.
b. Subscription management
In order to:
- manage subscriptions;
- verify access rights;
- manage free trials and promotional codes;
- issue and manage invoices;
- monitor payments.
c. Security
In order to:
- secure the Platform;
- detect fraudulent use;
- prevent unauthorised access;
- detect and resolve technical incidents.
d. Communication with Customers
In order to:
- respond to requests;
- communicate with users;
- send information necessary for the operation of the Service;
- inform Customers of significant changes.
e. Improvement of the Service
We may use certain technical and statistical data in order to:
- identify problems;
- improve performance;
- improve usability;
- measure use of the Service;
- develop new features.
Where we use statistics derived from analyses, we ensure that they are aggregated or anonymised so as not to allow the identification of a Customer, its communication or a data subject.
8. Statistics and aggregated data
We may produce overall statistics from the use of the Platform.
These statistics may relate, in particular, to:
- the number of analyses performed;
- the general categories of risks identified;
- general trends;
- statistics relating to the types of communications analysed.
We ensure that statistics used for general or communication purposes do not allow the direct identification of a Customer, a specific communication or a natural person.
We will not publish the content of a communication or its detailed result without the prior authorisation of the Customer concerned, unless required by law.
9. Legal bases for processing
Depending on the nature of the processing, we may rely in particular on the following legal bases:
Performance of the contract
Where the processing is necessary to provide the Platform, manage the account or perform the subscription taken out by the Customer.
Compliance with a legal obligation
Where we must retain or process certain data in order to comply with a legal obligation, in particular in accounting, tax or judicial matters.
Legitimate interest
Where the processing is necessary for our legitimate interests, for example to:
- secure the Platform;
- prevent fraud;
- improve the Service;
- defend our rights;
- manage our relationship with our business customers.
In such cases, we ensure that our interests do not unjustifiably override the rights and freedoms of the data subjects.
Consent
Where the processing requires consent, such consent is obtained in accordance with the requirements of the GDPR.
Consent may be withdrawn at any time where the processing is based on this legal basis.
The withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.
The Data Protection Authority points out that a legal basis must be identified for each processing operation and communicated to the data subjects.
10. Sensitive data
The Platform does not have the specific purpose of collecting or processing special categories of personal data within the meaning of Article 9 of the GDPR.
However, communications submitted by Customers may potentially contain such data.
The Customer undertakes to submit only the data necessary for the use of the Service and to comply with the obligations applicable to it.
Where possible and relevant, we recommend that the Customer avoid submitting personal data that are not necessary for the analysis.
Special categories of data enjoy enhanced protection under the GDPR and their processing requires specific conditions to be met.
11. Data concerning third parties
A Customer may submit content including personal data concerning persons other than itself.
In such cases, the Customer is responsible for ensuring that it has an appropriate legal basis and that it complies with its information obligations towards the data subjects where these apply.
Where we act as the Customer's processor, we process such data in accordance with the Customer's documented instructions and the provisions of the applicable DPA.
12. Recipients of the data
Personal data may be made accessible, to the extent necessary, to the following categories of recipients:
- authorised staff of the Company;
- technical service providers necessary for the operation of the Platform;
- hosting providers;
- artificial intelligence service providers;
- IT and security service providers;
- payment service providers or banking institutions;
- professional advisers where necessary;
- public or judicial authorities where required by law.
We do not sell our users' personal data to third parties.
The service providers we use are selected with regard to their data protection obligations and, where required, appropriate agreements are concluded with them.
13. Data hosting
The Platform's data are hosted on servers used by the Company.
Our hosting provider is Google Cloud (Google Cloud EMEA Limited).
The application servers, the database and the files submitted to the Platform are hosted in the europe-west1 region, in Belgium.
These servers are therefore located within the European Economic Area (EEA).
We implement technical and organisational measures designed to protect data against unauthorised access, loss, destruction, alteration or unauthorised disclosure.
14. International transfers
Where personal data are transferred or made accessible to a recipient located outside the European Economic Area, we ensure that such transfer is carried out in accordance with the requirements of the GDPR.
Depending on the circumstances, a transfer may be based in particular on:
- an adequacy decision of the European Commission;
- standard contractual clauses;
- another appropriate safeguard provided for by the GDPR.
The artificial intelligence analyses rely on Google's Vertex AI service, used via its global endpoint: analysis requests may therefore be processed by Google in data centres located outside the EEA. Such processing is governed by the European Commission's standard contractual clauses included in the Google Cloud data processing terms. Google does not use content submitted via Vertex AI to train its models.
Information on the main international transfers and the applicable safeguards may be obtained by contacting maximevdm@giveactions.com.
15. Retention period
We retain personal data only for as long as necessary for the purposes for which they are processed, unless a longer retention period is required by law.
The retention periods are as follows:
| Category | Retention period |
|---|---|
| Account data | For the duration of the account + 12 months after its closure |
| Billing data | 7 years, in accordance with Belgian accounting and tax obligations |
| Submitted communications | 12 months after the analysis |
| Analysis results | For the duration of the account |
| Analysis history | For the duration of the account |
| Technical data/logs | 12 months |
| Support requests | 3 years after the last exchange |
Where the Customer requests the deletion of its data, we delete or anonymise them within a reasonable period, subject to data that we must retain under a legal obligation or for the establishment, exercise or defence of legal claims.
16. Deletion of data
The Customer may request the deletion of its data and its analysis history by sending a request to:
Deletion may result in the permanent loss of the analyses concerned.
Where we act as a processor, certain deletion requests may need to be handled in accordance with the instructions of the Customer acting as controller.
17. Rights of data subjects
Subject to the conditions and limitations laid down by the GDPR, data subjects have, in particular, the following rights:
- right of access to their data;
- right to rectification;
- right to erasure;
- right to restriction of processing;
- right to object;
- right to data portability where this right applies;
- right to withdraw consent where the processing is based on consent;
- right not to be subject to a decision based solely on automated processing where the conditions of the GDPR are met.
Any request may be sent to:
We may request reasonable information to verify the identity of the requester where necessary to prevent any disclosure to an unauthorised person.
The Data Protection Authority points out that the right to information covers, in particular, the purposes, legal bases, recipients, international transfers and retention periods.
18. Automated decision-making and artificial intelligence
The Platform uses artificial intelligence technologies to analyse the communications submitted by Customers.
The results generated by the Platform are intended to provide decision support.
They do not, in themselves, constitute a legal, administrative or commercial decision taken by the Company in respect of a natural person.
In particular, the Platform is not intended to take automated decisions producing legal effects concerning, or similarly significantly affecting, a natural person.
The results must be interpreted by the user and, where necessary, be subject to human review.
19. Security
We implement reasonable and appropriate technical and organisational measures to protect personal data against the risks associated with their processing.
These measures may include, in particular:
- access control;
- authentication;
- restriction of access rights;
- infrastructure protection measures;
- backups;
- logging;
- incident detection and prevention measures;
- incident management procedures.
Access to communications and detailed results is restricted to persons or service providers who need it to provide or maintain the Service.
We regularly reassess security measures in light of changing risks and technology.
The GDPR requires a level of security appropriate to the risk, in particular against unauthorised or unlawful processing and against accidental loss, destruction or damage of data.
20. Data breaches
In the event of a personal data breach, we will apply the procedures laid down by the GDPR and the applicable legislation.
Where we act as a processor, we will inform the Customer acting as controller under the conditions set out in the applicable DPA and within the time necessary to enable it to comply with its own obligations.
21. Cookies and similar technologies
The website and the Platform may use cookies or similar technologies.
These technologies may be used in particular to:
- ensure the operation of the website;
- maintain a user session;
- secure accounts;
- protect the website's forms against abuse and bots.
Cookies that are not strictly necessary are used in accordance with the applicable rules and, where required, after obtaining the user's consent.
We use no audience measurement tools and no advertising cookies (neither Google Analytics nor Google Tag Manager). The technologies used are as follows:
| Technology | Purpose | Duration |
|---|---|---|
| "csrftoken" cookie (website) | Form security, strictly necessary | 1 year |
| Session token in the browser's local storage (Platform) | Keeping the user logged in, strictly necessary | Until logout |
| Google reCAPTCHA (website forms) | Protection against bots and abuse; Google may collect technical data about the device and browser | In accordance with Google's policy |
| Google Fonts | Display of fonts; the IP address is transmitted to Google when loading | No cookie set |
As these technologies are strictly necessary for the operation and security of the website and the Platform, they do not require prior consent.
22. Commercial communications
We may use our Customers' business contact details to send them information relating to their account, their subscription or the operation of the Service.
Commercial communications will be sent in accordance with the applicable rules on direct marketing and electronic communications.
Where consent is required, we will request it before sending the communications concerned.
The recipient may unsubscribe from commercial communications at any time via the mechanism provided in the communications or by contacting us.
23. Aggregated and anonymised data
We may use data that have been aggregated or irreversibly anonymised in order to produce statistics, analyses and general information.
Once properly anonymised, such data no longer constitute personal data within the meaning of the GDPR.
We may, in particular, use such data to:
- measure general trends in greenwashing;
- improve our methodologies;
- analyse general trends observed on the Platform;
- produce statistics;
- improve the operation of the Service;
- communicate general information about the Platform's activity.
We do not seek to re-identify individuals from anonymised data.
24. Links to third-party services
The Platform or our website may contain links to third-party services or websites.
We are not responsible for the privacy practices of those services.
We recommend that users consult the applicable privacy policies when using a third-party service.
25. Changes to the Policy
We may amend this Policy to take account, in particular, of:
- changes to the Platform;
- changes in the technologies used;
- legal or regulatory developments;
- changes to our processing practices.
In the event of a substantial change affecting the rights or expectations of data subjects, we will implement appropriate measures to inform the data subjects concerned.
The date of last update shown at the beginning of this Policy will be amended accordingly.
26. Complaint to the Data Protection Authority
Any person who considers that their personal data are being processed in breach of the GDPR may lodge a complaint with the competent supervisory authority.
In Belgium, the competent supervisory authority is:
Data Protection Authority (APD)
Rue de la Presse 35
1000 Bruxelles
Belgique
+32 (0)2 274 48 00
[contact[at]apd-gba.be](mailto:contact@apd-gba.be)
27. Contact
For any questions regarding this Policy or the processing of personal data, you may contact us:
GIVEACTIONS SRL
1, RUE DES PHLOX 1170 BRUXELLES