Privacy Policy
Version of 2026-08-05
This policy describes how Saubeo SRL (Rue Rafhay 198, 4630 Soumagne, Belgium, CBE 0704.742.612 — "we") processes personal data in connection with the Hoteo service. Privacy contact: privacy@hoteo.be (general enquiries: support@hoteo.be).
1. Who is responsible for what?
Hoteo is used by businesses (heating professionals) to manage their own clients. Two situations coexist:
- Your data as a Hoteo user (account, subscription, support): Saubeo is the data controller — that is the subject of this policy.
- Your clients' data that you enter into Hoteo (names, addresses, job sites, invoices…): you are the data controller and Saubeo is the data processor. This processing is governed by the data processing agreement (DPA), which forms part of the terms of service.
2. Data we collect
- Account and organisation: surname, first name, e-mail address, phone number, language; company identity (name, CBE/VAT number, address — where applicable pre-filled from the Belgian Crossroads Bank for Enterprises).
- Subscription and billing: chosen plan, billing history; payment card data is processed directly by Stripe and never passes through our servers.
- Identity verification (Peppol): when electronic invoicing is activated, an identity verification may be carried out by our provider Veriff.
- Usage and security data: sign-in log (timestamp, IP address, browser, approximate location), audit log of actions in the application.
- Communications: support requests, transactional e-mails (delivery/read status).
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the Service (account, features, support) | Performance of the contract |
| Subscription billing, accounting | Legal obligation |
| Identity verification for access to the Peppol network | Legal obligation / performance of the contract |
| Security (intrusion prevention, sign-in log, alerts) | Legitimate interest (securing the Service) |
| Improving the Service (technical diagnostics) | Legitimate interest |
| Communications about the Service (news, end of trial) | Performance of the contract / legitimate interest |
| Audience measurement of the public website hoteo.be | Consent |
We make no fully automated decisions producing legal effects concerning you, and we do not sell your data.
4. AI assistant
When you use the assistant, your question and the data strictly necessary to answer it are transmitted to our provider Mistral AI (France, EU hosting), which acts as a data processor. Your data is not used to train models. The assistant's suggestions must be verified before use.
5. Recipients and processors
Your data is accessible only to our team (logged access, least privilege) and to our processors: hosting, payment, e-mail and SMS delivery, Peppol access, bank connection, AI assistant, identity verification, audience measurement of the public website. The up-to-date named list (provider, location, transfer safeguards) is published on the page /legal/sous-traitants, which is its authoritative source. Public authorities may receive data where required by law.
6. Transfers outside the European Union
Our data is hosted in the European Union. Some providers involve a transfer outside the EU — in particular Stripe (United States), certified under the EU-U.S. Data Privacy Framework and covered by standard contractual clauses as a fallback. Details per provider can be found on the page /legal/sous-traitants.
7. Retention periods
| Data | Period |
|---|---|
| Account and organisation data | Duration of use of the service. Cancelling the subscription deletes nothing (back to the free plan, data kept). Voluntary deletion (account or organisation) is immediate, permanent and irreversible once confirmed via the email link |
| Subscription invoices issued by Saubeo | 10 years (our own Belgian accounting obligations) |
| Sign-in and security log | 12 months, deleted together with the account |
| Support communications | 3 years after closure |
| Peppol identity verification (Veriff) | Hoteo keeps no identity document, no photo and no data extracted from the document (processed by Veriff under its own policy) — only the technical session reference, the verification status and, in case of failure, the reason communicated by Veriff; kept for the duration of use of the service |
| Residual copies in backups | Purged on backup rotation, 30 days at most after deletion; restoring a backup re-applies the deletions |
Deletion is available as self-service in the application (Settings > My account for your account; Settings > My data for the whole organisation, administrators). The deletion flow enforces a prior export step (complete archive: JSON per module, invoice PDFs, attachments — right to portability, Art. 20 GDPR) and reminds you that keeping your accounting documents (10 years, Belgian obligation) is your responsibility: after deletion, Hoteo keeps no copy of your data and can no longer return anything. Your decision is timestamped (version of the accepted text, IP address) as proof.
Your individual account (member of an organisation) can be deleted in two ways: by yourself (Settings > My account, confirmation via e-mail link) or by an administrator of your organisation. In both cases deletion is immediate: e-mail address, first name, last name and password are erased from the account, and your current session is cut off. The only things that remain, under your organisation’s responsibility (legitimate interest, Art. 6.1.f GDPR), are your name in its operational data (for example past jobs scheduled under your name) and, for a deletion decided by the administrator, the named trace in its internal log. When you request erasure yourself, no named data remains in that log: your past actions appear there as “Deleted user”. These elements disappear when the organisation itself is deleted.
8. Your rights
You have the rights of access, rectification, erasure, restriction, portability, objection and, where applicable, withdrawal of consent. Exercise them through the application (Settings) or by e-mail to privacy@hoteo.be; we reply within one month (a period that may be extended by two months for complex or numerous requests — we would inform you within the first month). Proof of identity may be requested in case of doubt.
9. Complaints
You may lodge a complaint with the Belgian Data Protection Authority: Rue de la Presse 35, 1000 Brussels — dataprotectionauthority.be.
10. Security
Encryption of communications (TLS), strict segregation of data per organisation, role- and permission-based access control, anti-intrusion account lockout, audit log of write operations, support access subject to your explicit authorisation and logged, regular backups, EU hosting.
11. Cookies and local storage
Two distinct environments coexist:
- The Hoteo application (
app.hoteo.app) uses no advertising cookies or audience trackers — only strictly necessary technical storage, which does not require consent. - The public website hoteo.be uses Google Analytics 4 to measure its audience, only after your consent, given via the banner shown on your first visit: nothing is loaded or transmitted to Google before you agree, and refusing is as easy as accepting.
Full details (local storage purposes, cookies involved, durations) can be found on the page /legal/cookies.
12. Updates to this policy
Each version is dated. In the event of a substantial change, we will inform you by e-mail or in the application. Previous versions are available on request.