01
Roles of the customer and Limuvo
For customer and contact data managed in the business customer's workspace, the customer determines the purposes and essential means of processing. Limuvo then acts as processor to provide, secure and support the service. Limuvo acts as controller for account administration, billing, support, security and its legal obligations.
02
Categories of data
Depending on the features enabled, the service may process account and company data, contact details, messages, requests, attachments, notes, tasks, appointments, priorities, statuses, histories, payment data, and technical or security information.
03
Data sources
Data comes from users, workspace owners, Limuvo forms and, when the business customer enables them, the accounts and connected services it authorises. Payment or email-delivery data may also come from the relevant providers.
04
Purposes and legal bases
Processing supports service delivery, account and payment management, support, platform security and reliability, legal obligations and the integrations requested by users. The legal basis depends on the purpose and role of the party concerned: the business customer remains responsible for the basis applying to its own contacts' data.
05
Recipients and access
Data is available to authorised workspace users according to their roles and permissions and, where necessary, staff handling support or security. Technical providers may support hosting, the database, email delivery, payments, AI and integrations; their list is published on the Subprocessors page.
06
Integrations and AI assistance
An integration processes data only when configured by the business customer. If AI assistance is enabled, content necessary for the request may be sent to the configured provider to produce a suggestion. Professional content sent by the business customer is not used to train Limuvo's own models. A user remains responsible for reviewing, adjusting where needed and validating any suggestion before a decision or communication.
07
Subprocessors and international transfers
Technical providers required for the service are contractually governed. Where a provider processes data outside the European Economic Area, Limuvo relies on the applicable transfer mechanism, such as an adequacy decision or standard contractual clauses, and reviews appropriate safeguards.
08
Retention periods
Data is retained for the account, contract, stated purposes and applicable obligations, then deleted or archived. Accounting records follow statutory periods. Temporary tokens expire quickly and a limited deletion log may be retained for up to 365 days for security and proof of operations.
09
Security
Limuvo implements measures appropriate to the risk, including server-side sessions with protected cookies, hashed passwords, role and permission controls, logical separation by company, server-side checks, security headers and audit logs. No safeguard removes all risk; suspected incidents should be reported promptly.
10
Data-subject rights
Depending on the processing, an individual may request access, rectification, erasure, restriction, objection or portability and withdraw consent where consent is the legal basis. A response is normally provided within one month, with a possible extension for complex requests. Proportionate identity verification may be required.
11
Requests and complaints
Email contact@limuvo.com and identify the request and relevant company. Where Limuvo acts as processor, the request is coordinated with the controller. A complaint may also be made to the Belgian Data Protection Authority or the competent authority where the person lives or works.
12
Updates
This page is updated when processing, providers or applicable requirements change. The date at the top identifies the current version. Additional notice is provided when a change materially alters how data is used.