Legal · GDPR
Privacy policy
Last updated: 3 October 2026 · Version 2.2
What changes: you can transfer money between the profiles you keep, and add the monthly overview of a shared profile to your own monthly email. If you use no shared profile and no child profile, nothing changes for you.
This translation is provided for convenience. In case of any discrepancy, the Dutch version prevails.
Budgetto runs on a single server in Germany, operated by GY Digital. Your data lives there, and an encrypted backup of it sits on a second server with the same hosting party, also in Falkenstein. It is kept nowhere else. This document explains what data is collected, why, who gets to see it, and what your rights are under the GDPR.
Who processes your data
GY Digital is the data controller for Budgetto. That is the trading name under which Romain Goyeau works as a student entrepreneur, and the party running the server your data sits on. No data protection officer has been appointed: the processing is too limited in scale and nature to require one.
GY Digital
Romain Goyeau, student entrepreneur
Mechelen area, Belgium
Email: privacy@gy-digital.be
Phone: +32 492 49 38 04
What data we process
Strictly limited to what the app needs:
Account details
First name, last name, email address, currency preference, and your password in bcrypt-hashed form (unreadable, including to the administrator). Since we started sending email, this also covers whether you confirmed your email address, which emails you want to receive, and when and where you made that choice. We keep that last part because we have to be able to show that the choice was yours.
Financial transactions
Everything you enter yourself: name, amount, date, your own notes, category, plus the positions and trades in the Net worth module. It belongs to a profile: your own profile, or a shared profile or child profile you enter it in. For every entry we also keep who made it.
Data through signing in with Google
Only if you use that button. Google then passes us your email address, your first and last name, and an internal Google account ID. No contacts, no calendar, no files, no profile picture that we keep. Sign in with a password and Google is not involved at all.
What you send us yourself
Only if you do so yourself: a message through the contact form in the app, your answers to the short survey, or a reply to a personal message from us in the app. We keep that text with your account, together with the moment you sent it. We also email it to the administrator, with your name and email address, so that you can get a reply; that email goes through Brevo, like our other email. Nobody else gets to see it.
Cookies
The session cookie (budgetto_session) holding a JWT token, valid for 7 days, and, while you sign in with Google, a second cookie for ten minutes. More on the cookie page.
IP address (memory and log)
Briefly in memory for the limits against abuse, such as on sign-in and registration (an hour at most). In addition, the web server and the app keep a technical log of every request: IP address, time, page requested (for a search in Wealth, also the search term, such as a company name) and browser. It is used to track down faults and attacks. The log sits on the same server and is not linked to your account, with two exceptions: when something goes wrong in the app or a request is refused, the app also records your account ID (and that of the profile concerned), never your email address, name or amounts, so that we can fix the fault or spot abuse; and the page requested may contain the number of a profile, for example when you manage a shared profile. The log is gone after 30 days at most; in practice the app log is gone after about a week and the web server log after about two weeks. Your IP address does not go into the database.
Using Budgetto together
If you use Budgetto together with others, we also keep: which profiles you are a member of, in which role and since when; what happens in a shared profile (who added, changed or deleted something, who joined or left); and, in your own profile, who is viewing it, what that person sees and when they last looked. For the person you invite, we do not store the email address in readable form: only an encrypted fingerprint and, for a while, a masked version. A code you get by email to confirm an action is valid for ten minutes at most and is never stored in readable form: the server only keeps an unreadable fingerprint of it, in its memory. If someone no longer wants invitations, we keep only a fingerprint of their address.
Children
If you use Budgetto for or with a child (see "Children and young people"), we also keep the child's first name and month of birth. If the child has their own login, we also keep their account, like any account; the moment the profile was handed over to them; their choices about their parents (who may add entries, who was stopped); when a parent read their profile (one line per parent per hour); and each parent's agreement when the profile is handed over or a new parent is added. The code the child sees when taking over the profile is never stored in readable form.
What we do not process: trackers or analytics on the site (the only count is an anonymous one by Brevo of whether our emails are opened and clicked, see section 12), banking details, location or device identifiers. We buy no data and link nothing to external profiles. If you use Budgetto together with others, you also give us data about someone else: the email address of the person you invite, which we do not store in readable form, and the first name and month of birth of your child.
Using Budgetto together
You can keep track of your money together with others: in a shared profile, or by letting someone view your own profile. What follows applies if you do. What applies to a child is under "Children and young people".
Profiles. Your money belongs to a profile. Nobody else sees your own profile, unless you let someone view it yourself, or you are under 18 and received your profile from a parent. In a shared profile, all members see everything in it, including what was there before they joined, with the first name of whoever entered it. What happens in a shared profile (who added, changed or deleted something) is kept for 12 months. You can always leave a shared profile, without anyone else having to approve, and download a copy first. What you entered then stays in the profile for the other members, with your first name as long as your account exists.
Viewing. Viewing is off by default. If you let someone view your own profile, you choose what that person sees: everything, or only your net worth. A viewer cannot add, change or download anything. You can always see who is viewing and when they last looked, and you stop it in one click.
Invitations. If someone invites you, we do not store your email address in readable form: only an encrypted fingerprint and a masked version (like m***e@gmail.com). The masked version disappears as soon as the invitation closes, after 21 days at the latest; we delete the fingerprint 30 days later. If you no longer want invitations, we keep only that fingerprint, until you lift that choice yourself. An address gets at most one invitation email per profile and three in total per seven days.
Temporarily off. We can temporarily switch off using Budgetto together for technical reasons, for everyone or for some users. Anyone who then temporarily cannot open a shared profile, a profile they view or their child's profile gets a message in the app; a child with their own login also gets one if their parents temporarily cannot view their profile. Switching it off deletes nothing: what is in a profile is kept, and as soon as it is possible again, access is back as it was.
Children and young people
A parent can also use Budgetto for and with their child. What follows applies if you do.
A child profile. A parent can keep track of their child's money in a child profile; the child does not log in to it. We then keep the child's first name, month of birth and what the parents enter. A second parent is only added if every other parent agrees.
From 13. A parent can hand the child profile over to the child. The child creates their own account with their own email address and chooses their month of birth themselves; we do not check it. To make sure the profile reaches the right child, the child sees a code that their parent has to type in, and every parent has to agree. After that, the profile belongs to the child, with everything in it.
What parents see. Until the child is 18, the parents can read everything in their profile. They only add entries if the child allows it, and then only change or delete what they entered themselves. They cannot download a copy or move anything to their own profile. The child can see which parents view the profile, when they opened it (90 days, at most one line per parent per hour) and what they did in it (12 months); a parent cannot see when another parent looked. A second profile that the parents cannot see does not exist for a child yet. Until they are 18, a child with their own login cannot create a shared profile, let anyone view their profile or create a child profile.
From 16. The child can stop the viewing themselves, one parent at a time, without a password. That parent gets a notification in the app, not an email, and cannot come back on their own.
At 18. For a child with their own login, the viewing stops automatically, at midnight; the child and the parents get a notification in the app 30 days before. A child profile without its own login becomes read-only for the parents at 18; they get a notification in the app and an email 30 days before (see section 12), and can hand the profile over to their child, download a copy or delete it. We do not delete it automatically: it is kept until a parent hands it over or deletes it. If shared use is temporarily switched off for technical reasons at that time, that advance notification may not be sent.
Month of birth. The child can later only move their month of birth earlier, not later; their parents then get a notification. Anyone who gives 18 or older no longer has parents viewing, and that cannot be undone. We keep the month of birth with their profile, also after they turn 18, because we need it to stop the viewing correctly. We also keep the moment the profile was handed over to the child for as long as the account exists: that way the child keeps seeing what their parents did in the profile before, and we can count how many accounts came about this way.
Deleting. The child can always delete their account and profile themselves. Everything is then gone from the app straight away, for their parents too, who get a notification about it, and from the backups after 30 days at most. We cannot delete a copy a parent downloaded earlier.
Emails. Emails about a child never mention their name, a date or an address. The monthly summary with amounts is off for a child under 18 who received their profile from a parent; the child can switch it on themselves.
Help. A plain-language explanation is in the app, on the page where the child takes over the profile. Something on your mind? In Dutch, Awel listens for free and anonymously: call 102 or chat at awel.be. In French, call 103 or chat at 103ecoute.be.
Why we process it
Performance of the contract (Art. 6(1)(b) GDPR)
Without an account we cannot provide the service. Your transactions are literally what you want to do with the app. This also covers the email you get right after registering and the button that confirms your address: without a working address we cannot tell you anything about your own account.
Legitimate interest (Art. 6(1)(f) GDPR)
Rate limits on sign-in and registration to limit abuse, and the technical log with your IP address to track down faults and attacks (see section 2). The IP address is shared with nobody and kept nowhere except briefly in memory and for 30 days at most in that log. The monthly summary rests on the same ground: it only covers your own figures and sells you nothing. You can object with one click in the email or with the switch in the app, and it stops straight away. What you send us yourself (a message, your survey answers, a reply to a message in the app) is kept and read on the same ground of legitimate interest: to reply to you and to make Budgetto better.
Consent (Art. 6(1)(a) GDPR)
For the reminder email only. It is off by default, you switch it on yourself, and you can withdraw that consent at any time without anything else changing. We note when and where you switched it on, because consent you cannot demonstrate does not exist.
Using Budgetto together, and children
A shared profile and viewing are a service you ask for yourself: performance of the contract (Art. 6(1)(b) GDPR). We keep a child profile because the parent has a legitimate interest in it that coincides with their child's interest (Art. 6(1)(f) GDPR). The account of a child with their own login is based on the contract with the child, who uses the service themselves (Art. 6(1)(b) GDPR), and the parents' viewing on their legitimate interest, as parents, in keeping an eye on their minor child's money, with the child's interest first (Art. 6(1)(f) GDPR). We send the invitation email to someone who does not have an account yet on the basis of legitimate interest (Art. 6(1)(f) GDPR), with a link to stop receiving invitations. The activity of a profile, the record of when a parent viewed and the codes to confirm something serve security and show who did what; they also rest on legitimate interest (Art. 6(1)(f) GDPR).
You are not obliged to provide this data, but without an email address and a password there can be no account and therefore no service. The reminder email is the only thing that rests on consent: every other email exists because you created an account, because you asked for it, or because someone invited you or did something in a profile you are a member of (see section 12).
How long we keep it
For as long as you have an account. When you click Delete account in Settings, your account and your own profile, with all transactions and categories, are removed from the database immediately and permanently, including your email preferences and your sending history. If you share a profile with others (a shared profile, a child profile or your child's profile), that profile stays for whoever is still in it: what you entered in it stays there, without your name. A shared profile or child profile with nobody else left in it disappears along with your account; you see this beforehand. Server backups keep your data for 30 days at most, after which it is gone everywhere. The backup made every night is encrypted straight away, a copy of it sits on a second Hetzner server in Falkenstein (Germany), and the key to open it is not on the server. The technical log of the web server and the app, which contains your IP address, is gone after 30 days at most. Of the emails we send we keep a technical log (which kind of email, to which account, whether it went out, never the content) and that log is cleared automatically after 90 days. The app also keeps a technical log of the fixed costs that are booked automatically (the number of the profile and of the fixed cost, how often it recurs, how many times and up to which day it was booked, never an amount or a name), which is gone after about two months. Your email preferences and the fact that you unsubscribed do stay for as long as your account exists: forgetting an unsubscribe would mean sending you again what you had just switched off. Brevo, the service that sends our email, also keeps its own sending log. That sits with Brevo and there is no setting to shorten that period; our contract with them does state that everything is destroyed or anonymised at the latest one hundred days after it ends, with a certificate on request. What you sent us through the contact form, the survey or a reply to a message in the app stays with your account and is deleted along with it. The copy that arrived by email with the administrator is deleted on request. For using Budgetto together and for children, these periods also apply:
- →The activity of a shared profile, a child profile or the profile of a child with their own login (who added, changed or deleted something, who joined or left), and in your own profile who viewed it: 12 months.
- →When a parent read the profile of their child with their own login: 90 days.
- →An invitation: the masked version of the address until it closes, 21 days at most; the invitation itself, with the fingerprint of the address, until 30 days after it closes. The count of invitation emails per address: 8 days at most.
- →The fingerprint of an address that no longer wants invitations: until that address lifts it.
- →Notifications in the app about using Budgetto together and about children: 30 days after you read them, otherwise 90 days.
- →Counters per person per day (codes, invitations, emails) that slow down abuse: 2 days.
- →The month of birth of a child with their own login and the moment they received their profile: as long as their account exists.
- →A child profile without its own login of a child who turned 18: we do not delete it automatically; it stays until a parent hands it over to the child or deletes it.
Where your data physically sits
On a single server in a data centre in Germany, so inside the European Union. Hosting runs through Hetzner Online GmbH, in their data centre park in Falkenstein:
Hetzner Online GmbH
Am Datacenter-Park 1, 08223 Falkenstein/Vogtland, Saxony, Germany
Registered office: Industriestr. 25, 91710 Gunzenhausen, Germany
Hetzner provides the machine and the physical security and acts as a processor within the meaning of Article 28 GDPR: they process your data solely on our instructions and may do nothing with it themselves. That also applies to the encrypted backups: besides the server, they sit on a second Hetzner server (a Storage Box), in the same data centre park in Falkenstein. Without the key, which is not on the server, they are unreadable. No copy of the database is kept with any other party or in any other country. To check that a backup can actually be used, we occasionally open one on the administrator's computer in Belgium, only to count whether it is complete, and delete it straight afterwards.
Who we share it with
With nobody who does anything with it.
No Google Analytics, no Meta Pixel, no Cloudflare Insights, no CDN for code. Your browser only talks to this server, never to an advertising or analytics service. Your data is never sold, rented or shared for commercial purposes. Below is the full list of parties that get to see anything, and why: the hosting party, the service that sends our email (Brevo, France), Google if you use that button, and two price services if you invest. In addition, other users see what you share with them, and the parents of a child with their own login see that child's profile: that is explained under "People you let in".
Hetzner (Germany)
The hosting party above. They hold the data physically because the server and the encrypted backups sit with them, but they only process it on our instructions.
Brevo (France, for our email only)
We do not send email ourselves: that runs through Brevo SAS in Paris, a French company. Brevo sees your email address and the email itself, so also your first name in the greeting and, for the monthly summary, your monthly totals and the names of your categories, and, if you switch it on yourself, those of a shared profile, with its name. For an invitation, Brevo sees the address of the person invited, and the first name and a masked version of the address of the person inviting; for the other emails about using Budgetto together, the first name of whoever joined and the name of a shared profile, never the name of a child. Never your transactions, your notes, your merchants or your net worth. Brevo only sends on our instructions and is therefore a processor within the meaning of Article 28 GDPR. The email leaves from inside the European Union; if Brevo uses a party outside the European Economic Area for part of the service, that happens under the European Commission standard contractual clauses or under an adequacy decision. Brevo does count how often our email is opened and clicked; that is part of its system and cannot be switched off for this kind of email. What we did do: it is set to anonymous, so those counts are not tied to your address. We do not use those figures for anything. Switch off all email and the monthly summary and the reminder stop; what still goes through Brevo is listed in section 12. If you send us something yourself through the contact form, the survey or a reply to a message in the app, the email with your text to the administrator also goes through Brevo.
Google (only when signing in with Google)
If you use that button, you are sent to Google to sign in. Google therefore knows you have a Budgetto account and sees your IP address while doing so. For users in Europe, Google Ireland Limited is itself the controller for this, under its own privacy terms. Sign in with email and password and none of this happens.
Yahoo Finance and Frankfurter (only when you invest)
For prices, our server requests a ticker symbol from Yahoo Finance and an exchange rate from the open Frankfurter service, which publishes the daily rates of the European Central Bank. All that goes out is the symbol or the currency pair, such as TTWO or EUR/USD. No name, no email address, no amounts, no quantities, nothing that shows who is asking. Because your browser never contacts those services itself, they do not see your IP address either: they only see our server. Prices are cached in a shared way, so ten people holding the same share generate one request per day between them.
Authorities, only where the law requires it
Under a valid court order we are legally obliged to hand over data. That has never happened. If it does, we will tell you unless the law forbids it.
The administrator
Budgetto works with your figures itself: your balance, your forecast, your monthly overview and the fixed costs that are booked automatically. The administrator does not look at them. Your transactions, amounts, notes, categories and positions are not read by the administrator, and our statistics are counts only, such as the number of accounts or of emails sent, without amounts, names, descriptions or any other details. Technically the administrator of the server can reach them, as with any service that calculates with your figures: this is a commitment, not a lock. What you send us yourself, such as a message or your answers to the survey, we do read, because that is why you send it.
People you let in
A member of a shared profile sees everything in it, including what was there before they joined, and can write in it. Someone viewing your own profile sees what you chose, everything or only your net worth, and cannot add or download anything. The parents of a child with their own login read that child's profile until they are 18 and only write in it if the child allows it; they cannot see when another parent looked, or what the child decided about another parent. A child profile without its own login is managed by the parents together. Nobody else sees your own profile, unless you let someone view it yourself, or you are under 18 and received your profile from a parent. If you transfer money between two profiles you keep (your own profile, a shared profile or a child profile without its own login), the transfer appears in both. Someone who can only see one of the two profiles sees that you made it and how much, not from or to which profile. If you delete your account, it stays in the other profile, without your name.
Transfers outside the European Economic Area
Your account, your transactions and your net worth data stay on the servers in Germany and do not leave the EEA. There are two cases where traffic does go outside the EEA, and neither involves data that shows who you are:
- →When fetching share prices, our server contacts Yahoo Finance, a service of a US company. What goes out is a ticker symbol, sent by the server. No personal data.
- →If you sign in with Google, that sign-in runs through Google, which may also process data outside the EEA. Google LLC is certified for this under the EU-US Data Privacy Framework, the European Commission adequacy decision. This only happens if you use that button.
Security
Technical measures running on this instance:
- →Passwords hashed with bcrypt (12 rounds), not reversible.
- →Sessions in httpOnly cookies, unreadable to JavaScript, not stealable through XSS.
- →Rate limits on sign-in, registration and captcha to stop brute force.
- →HTTPS through Caddy (automatic TLS, HSTS headers).
- →Security headers (helmet): X-Frame-Options, X-Content-Type-Options, Referrer-Policy.
- →Content-Security-Policy: the browser only runs scripts from this server and loads nothing from any other website, so a script that someone might slip into a page does not run.
- →CAPTCHA and honeypot at registration to keep bots out.
- →Access per profile: every request passes a check that decides, per profile, who may do what, and an automated test tries every route with every role.
- →Erasing: what you delete is also overwritten in the database, not just released.
- →Backups of the database every night, encrypted straight away with a key that is not on the server, and also on a second Hetzner server. All backups, including the copies of the whole server at Hetzner, are gone after 30 days at most.
In the event of a data breach that poses a risk to your rights and freedoms, we report it to the Data Protection Authority within 72 hours, and directly to you if the risk is high.
No automated decisions
Budgetto makes no decision about you that produces legal effects or significantly affects you (Art. 22 GDPR). The monthly forecast estimates your balance from your own figures; under the GDPR that may count as profiling (Art. 4(4)), but it remains a calculation that only the people allowed to see that profile can see, with no scoring, no credit assessment and no advice going anywhere. The age limit of 18 for a child with their own login is a date taken from the month of birth the child gave themselves, not a judgement about the person.
Your rights (GDPR)
You have the following rights under the GDPR. Most of them are built straight into the app. You can always email a request; we reply within one month.
Right of access
You can see most of it yourself in the app: your account, your profiles and what is in them, in a shared profile the activity too, and as a child with your own login also when your parents looked. What you cannot see yourself, such as the technical log of our emails, or whether your address is on the list of people who no longer want invitations, we give you on request. If you do not have an account, for example because someone invited you, email us from the address concerned: all we have of it is a fingerprint and, while an invitation is open, a masked version.
Right to rectification
Through Settings you can change your profile details. Transactions and categories can be edited directly on their own page.
Right to erasure (right to be forgotten)
One click in Settings, Delete account. Confirm with your password, or with a code we send to your email address if you only sign in with Google. Your own data is then gone straight away; what happens to a shared profile or a child profile, you see beforehand, and it is explained in section 4.
Right to data portability
Export your data yourself as CSV or JSON with the export button in the app, or request it by email.
Right to restriction of processing
Email us if you want your data left in place without further use, for example while a complaint is being handled.
Right to object
Email the administrator if you want to object to processing based on legitimate interest.
Shared profiles
If you ask for access or a copy, you also get what is in a shared profile you are or were a member of, never someone else's own profile. As long as you are a member, you can change or delete what you entered yourself, and download a copy of the profile. If you want something removed, do it before you leave: after that, your entries stay for the other members, because the profile belongs to them too. If you delete your account, your name disappears from those entries.
Children
A child with their own login exercises their rights themselves, like any user: they see and download their profile, move their month of birth earlier themselves (later only on request, because the viewing depends on it) and can delete their account. For a child profile without its own login, the parents do this, as legal representatives. A parent of a child with their own login does not get a copy of their child's profile.
Right to lodge a complaint
With the Data Protection Authority, Drukpersstraat 35, 1000 Brussels: gegevensbeschermingsautoriteit.be
Changes to this policy
If we change this document, we raise the version number at the top and set the date to today. For significant changes, you get a message in the app on your next visit. Version 2.2 describes transfers between the profiles you keep and the monthly overview of a shared profile in your own monthly email. It only applies to people who use them themselves, and no new recipient is added; that is why you do not get a message about it in the app. Version 2.1 opens the features for children to everyone: a child profile, and their own login from 13. What we keep and who sees it does not change; that is why you do not get a message about it in the app. Version 2.0 described using Budgetto together for everyone: shared profiles, viewing and invitations, what we keep for them and for how long, and who sees what; anyone who already had an account then got a message about it in the app. Version 1.8 says that if you only sign in with Google, you confirm deleting your account with a code sent by email. Version 1.7 described using Budgetto together and children with their own login when they were only open to testers; versions 1.6 and 1.5 corrected details about the technical log, the cookies, the list of our emails and the backups.
Email we send
Budgetto sends little email, and never anything meant to sell you something. This is the complete list. What you receive is your own choice, in the app under Settings, Preferences, and you can change that choice at any time.
- →Welcome and confirming your address Once, right after you register. We explain how the app works and ask you to click a button so we know the address is really yours. Legal basis: performance of the contract (Art. 6(1)(b) GDPR). Until you confirm, no periodic email goes out at all. If you change your address later, we ask for that confirmation again and the rest pauses until then.
- →Confirmation when you switch something off One short email after you unsubscribe, so you have it in writing that it worked and how to switch it back on. Such a receipt is required by law (Belgian Royal Decree of 4 April 2003); that email has no unsubscribe link of its own, because it is the unsubscribe.
- →Emails about your password Only when you ask for one yourself or when your password changes: the link to choose a new password (valid for an hour), an explanation if your account works with Google, and a notice after your password has been changed, so you notice if someone else did it. Legal basis: performance of the contract (Art. 6(1)(b) GDPR). No unsubscribe link: they are part of using your account safely.
- →What you ask for yourself Under Preferences you can send yourself a new confirmation email, or a test email to check that our emails arrive (it is the welcome email once more). You only get them when you press the button yourself. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
- →Your month in three figures On the first of the month, with your own figures for the month before: what came in, what went out, what was left, your three biggest categories and on how many days you recorded something. No transaction names, no notes, no amount in the subject line. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). You can switch it off in the app or with one click at the bottom of the email. If you switch on the monthly overview of a shared profile, your monthly overview also includes that profile's totals and its three biggest categories, with its name. That email goes through Brevo like the others. The other members can see on the profile's page that you switched it on.
- →Reminder to record something Off by default. Switch it on and you get a nudge in the evening on a day you recorded nothing, at the rhythm you pick. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Ignore it a few times and it stops by itself.
- →A code to confirm it is you Only when you ask for one yourself: a code to confirm an action, for example to delete your account if you only sign in with Google, to delete a profile or to give someone access. Valid for ten minutes. Legal basis: legitimate interest (Art. 6(1)(f) GDPR), the security of your account. No unsubscribe link: it is part of using your account safely.
- →An invitation Only when someone invites you to a shared profile, to view their profile, as a parent of a child, or to give you, as a child, your own profile: an email with the first name of the person inviting you, a masked version of their address and a link to the invitation. At most one per profile and three in total per seven days, and never advertising. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). At the bottom there is a link to stop receiving invitations from anyone.
- →Emails about a shared profile Only when something happens that concerns you: someone accepted your invitation and you need to confirm who it is, someone was added to a profile you are a member of, or someone is viewing your own profile from today. Whoever joined is named by first name, with the name of a shared profile; never amounts. Legal basis: performance of the contract (Art. 6(1)(b) GDPR). No unsubscribe link: these emails are part of using a shared profile safely, and they are only sent when something happens.
- →Emails about a child Only when you are a parent in a child's profile and something happens that concerns you: your agreement is needed, a parent was added, the profile was handed over to the child, or a child profile without its own login will soon become or is now read-only because the child turns 18. Never amounts, and never the child's name, a date or an address. Legal basis: performance of the contract (Art. 6(1)(b) GDPR). No unsubscribe link: these emails are part of using a child's profile safely. If you have unsubscribed from all emails, you only get the messages about a child turning 18 in the app.
At the bottom of every periodic email there is an unsubscribe link that works immediately, plus a link to switch everything off at once. Brevo counts anonymously how often our email is opened and clicked; that cannot be switched off, and we do not use those figures for anything. Your address is never used for a newsletter, an offer, or anything from somebody else.
Contact
Questions, requests or complaints about your data: email privacy@gy-digital.be or call +32 492 49 38 04. More about who is behind it at gy-digital.be.