Privacy Policy
How Promastro collects, uses and protects your personal data, in compliance with the GDPR and Belgian law.
Last updated: 27 May 2026This policy describes how Promastro collects, uses and protects the personal data of the users of the site promastro.be, in accordance with the General Data Protection Regulation (GDPR — EU 2016/679) and the Belgian law of 30 July 2018.
1. Data controller
For any question regarding the processing of your data, or to exercise your GDPR rights: contact@promastro.be.
2. Data collected
2.1 Visitor account
- Last name, first name, email address, password (bcrypt-hashed);
- History of favourites, reviews submitted, messages sent;
- IP address (anonymised by HMAC-SHA256 hash) for rate limiting.
2.2 Professional account
- The visitor account data above;
- Company name, VAT number (stored as a SHA256 hash — never in clear text), CBE number;
- Professional contact details (address, phone, professional email, website, social media);
- Description, photos, before/after projects, declared certifications;
- KYC data (scanned ID document) when the Pro chooses to request identity verification — stored encrypted, access restricted to the moderation team;
- Payment history, invoices issued.
2.3 Browsing data
- Pages viewed (internal analytics, anonymised IP);
- Technical and functional cookies (see cookie policy).
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Account creation and management | Performance of the contract |
| Invoicing, payments, accounting | Legal obligation + contract |
| VAT (VIES) and CBE verification | Legitimate interest (fraud prevention) |
| Automated moderation of reviews (AI Claude) | Legitimate interest (service quality) |
| AI search and suggestions | Legitimate interest + consent |
| Transactional emails (payment, welcome, etc.) | Performance of the contract |
| Anonymised usage statistics | Legitimate interest |
| Subscription audit log to Google Sheets (pseudonymised data: company initials + partial email + pseudonymous identifiers) | Legitimate interest (internal business tracking) |
4. Processors and recipients
Promastro uses the following processors, governed by data processing agreements (DPA) compliant with the GDPR:
- Mollie B.V. (Netherlands) — payment service provider, processes banking data and SEPA mandates;
- Brevo (France, formerly Sendinblue) — sending of transactional emails;
- Anthropic PBC (United States) — provider of the AI Claude used for moderation, search and the generation of descriptions. Transfers governed by the Standard Contractual Clauses (SCC) approved by the European Commission;
- Horus / Falco (Belgium) — issuance of PEPPOL electronic invoices;
- Contabo GmbH (Germany) — server hosting (data stored in the EU).
- Google LLC (United States) — storage of a business audit log (Google Sheets) fed via the Bit Integrations plugin. Only pseudonymised data is transferred (company name initials such as “P. D. SRL”, partial email such as “du***@***.be”, SHA256 hash of the VAT number, internal pseudonymous identifiers). No directly identifying personal data is sent to Google. Transfers governed by the Standard Contractual Clauses (SCC) approved by the European Commission and by the EU-US Data Privacy Framework (Google has been certified since 2023). Compliant with GDPR Art. 4.5 (pseudonymisation) + Art. 25 (privacy by design).
No data is sold, rented or transferred to third parties for commercial purposes.
5. Retention periods
- Active account: as long as the user does not delete it;
- After termination: 90 days of technical archiving before permanent deletion (daily cron cleanup);
- Invoices and accounting data: 7 years (Belgian legal obligation);
- Technical logs (errors, security): 30 days;
- Cookies: duration specified in the cookie policy.
6. Your rights
In accordance with the GDPR, you have the following rights:
- Access to your data;
- Rectification in the event of inaccuracy;
- Erasure (“right to be forgotten”) — see account deletion page;
- Portability — export of your data in a structured format;
- Restriction of processing;
- Objection to processing based on legitimate interest;
- Withdrawal of consent at any time, where the processing is based on consent.
To exercise your rights: contact@promastro.be. A maximum response time of one month is guaranteed.
7. Complaint
If you believe that your rights are not being respected, you may lodge a complaint with the Belgian Data Protection Authority (DPA): dataprotectionauthority.be.
8. Security
Promastro implements technical and organisational measures to protect your data: systematic HTTPS connection (TLS), two-factor authentication for administrators, password hashing (bcrypt), AES-256 encryption of sensitive data (KYC, secrets), daily backups, logging of admin access.
9. Changes
This policy may be updated. Substantial changes are notified by email to the users concerned. The date of the last update is shown at the top.

