01
Roles of the parties
For personal data that the business customer enters or receives through the service in its relationship with its own contacts, the business customer acts as controller and Limuvo acts as processor. The roles are assessed processing activity by processing activity, according to the purposes and means actually determined.
02
Subject matter, duration and purposes
Limuvo processes data only to provide, operate, secure and support the use of the platform in accordance with the documented instructions of the business customer, these terms and the features activated by that customer. The processing lasts for the provision of the service and until the data is returned or deleted under this agreement, subject to a legal retention obligation.
03
Data and data subjects
Depending on the configuration, data may include identifiers and contact details, exchanges, requests, attachments, notes, tasks, appointments, priorities, statuses and technical logs. Data subjects may include the business customer's contacts, prospects, customers, authorised users and team members.
04
Instructions and customer obligations
The business customer confirms that its instructions are lawful, that it has an appropriate legal basis and that it informs data subjects where required. It determines the purposes of its processing, the access granted to its users and the data it imports. Any additional instruction must be sent to Limuvo in writing and remain compatible with the service and applicable law.
05
Confidentiality and security
Limuvo ensures that persons authorised to process the data are bound by confidentiality. Limuvo implements technical and organisational measures appropriate to the risk in accordance with Article 32 GDPR, and accesses customer data only where necessary to provide the service, support, security or comply with a legal obligation.
06
Assistance and personal data breaches
Taking into account the nature of the processing and the information available, Limuvo assists the business customer in responding to rights requests and meeting its obligations concerning security, personal data breaches, data protection impact assessments and prior consultation. If Limuvo becomes aware of a personal data breach affecting customer data, Limuvo informs the business customer without undue delay.
07
Subprocessors and transfers
Limuvo engages a subprocessor for customer data only with the business customer's prior written authorisation. The general authorisation in this agreement covers the subprocessors listed on the dedicated page; before any addition or replacement, Limuvo informs the business customer in writing so that it can object on legitimate data protection grounds. Each subprocessor is contractually bound by at least equivalent protection obligations. Transfers outside the European Economic Area are governed by the applicable mechanism under Chapter V GDPR.
08
Return and deletion
At the end of the service and on the business customer's instruction, Limuvo returns or deletes customer data unless Union or Belgian law requires its retention. Data retained for that sole obligation remains protected and is not used for another purpose.
09
Information and audit
Limuvo makes available the information reasonably necessary to demonstrate compliance with this agreement and allows audits or inspections required by the GDPR, subject to reasonable notice, confidentiality safeguards and arrangements that do not unduly disrupt the service.
10
Order of precedence
If this agreement conflicts with the terms of use regarding the processing of customer data, this agreement prevails for that processing. It does not reduce mandatory obligations under the GDPR or applicable Belgian law.