Privacy Policy
How Kollaborate handles your personal data, in accordance with the GDPR and Belgian data protection law.
Last updated: 15 September 2026
1. Data controller
The data controller for your personal data is SOCIALWORLD CommV, trading name Noble Matter and Kollaborate, KBO 0794.495.920, VAT BE0794.495.920, RPR/RLE Antwerp, registered office Krijgsbaan 11, 2640 Mortsel (office: Frankrijklei 5, 2000 Antwerp).
For questions about data protection, contact us via: info@kollaborate.app.
Kollaborate does not currently have an appointed Data Protection Officer (Functionaris voor Gegevensbescherming, FG/DPO). Questions and requests regarding your personal data are handled via info@kollaborate.app.
2. Which personal data we process
2.1 Account data (all users)
- Name, first name, email address
- Profile picture (optional)
- Telephone number (optional)
- Role on the platform (business or creator)
- Password (stored encrypted via Supabase Auth, never readable by us)
- Login history and session data
2.2 Business data
- Company name and trading name
- KBO/company number (verified via the KBO database)
- VAT number
- Sector and description of activities
- Address of the establishment
- Billing details for the subscription and platform fees
2.3 Creator data
- Instagram and/or TikTok handle (username)
- Public account statistics (follower count, engagement, reach), retrieved via the official API's of Meta and TikTok
- Niche and content style (provided by the creator themselves)
- Location (city/region, provided by the creator themselves)
- Payout details: bank account or Stripe Express account (via Stripe, not stored directly with us)
- Address (street, postcode, municipality) and tax status, needed to make a payout and issue an invoice
- National register number, only for creators without a company number. In Belgium this is the tax identification number of a natural person, and we need it to meet the reporting obligation of Directive (EU) 2021/514 (DAC7). We process it for that purpose only, share it exclusively with the Belgian tax administration, and use it nowhere else in the service. If you have a company number, we do not ask for it.
- Date of birth, likewise only for DAC7 reporting
2.4 Collaboration and transaction data
- Offered and accepted collaborations, including briefs and counter-proposals
- Message exchange via the in-app chat
- Delivered content (links, uploads) and approval status
- Payment data of collaborations: amounts, transaction ID's, statuses (via Stripe, no card details with us)
- Ratings and reviews after a collaboration has ended
2.5 Usage data and platform statistics
- Anonymous pageview statistics via Vercel Web Analytics. It uses no cookies and processes no personal data; no individual identification is possible.
- Limited behaviour analytics via Microsoft Clarity on public website pages, such as scroll behaviour, click patterns, heatmaps and session recordings. Clarity is configured with cookies disabled and sensitive content remains masked. We use this to improve usability, not for ad targeting.
- Technical logs (error messages, performance) for security and stability
2.6 Support and contact communication
- When you ask a question via our support or contact form or by email: your name (optional), email address, the category and content of your message, and limited technical context (the page from which you wrote and your browser type) so that we can handle your question correctly.
- This data is used to help you and to safeguard the quality of our services (legal basis: performance of the contract and/or our legitimate interest in customer support).
3. Purposes and legal bases of the processing
3.1 Performance of the contract (Art. 6(1)(b) GDPR)
- Creating and managing accounts
- Matching between businesses and creators
- Processing payments and payouts
- Communication via in-app chat
- Verification of KBO registration and social media profiles
- Management of subscriptions, trial periods and promotional codes
3.2 Legal obligation (Art. 6(1)(c) GDPR)
- Keeping accounting records (Act of 17 July 1975 on the accounting of undertakings, seven-year retention period)
- KYC and AML checks by Stripe in accordance with the Act of 18 September 2017 on the prevention of money laundering and the financing of terrorism
- DAC7 reporting to the Belgian tax administration (Directive (EU) 2021/514, transposed in articles 321quater and following of the Belgian Income Tax Code). As a platform operator we must report annually who received a payment through Kollaborate, for what amount, and under which identification number. For this we process the national register number or company number, the date of birth, the address and the amounts paid. This is a legal obligation: without this data we cannot pay out.
- Cooperation with competent authorities under a legal order
3.3 Legitimate interest (Art. 6(1)(f) GDPR)
- Detection and prevention of fraud, fake accounts and abuse (interest: integrity of the platform and protection of other users)
- Security monitoring and audit logs (interest: security of the platform and users' data)
- Technical improvement of the platform on the basis of anonymised usage statistics
3.4 Consent (Art. 6(1)(a) GDPR)
- Newsletters and marketing communications by email are only sent after express, separate consent. You can withdraw this consent at any time via the unsubscribe link at the bottom of every email or by contacting us via info@kollaborate.app.
4. Recipients and processors
We work with the following processors that process personal data on our behalf. A data processing agreement has been concluded with each processor in accordance with Art. 28 GDPR:
4.1 Processors storing data within the EU/EEA
- Supabase (database, AWS eu-central-1 / Frankfurt, Germany): storage of account data, collaborations, chat messages and uploaded files. The data sits in the EU. The data processing agreement is concluded with Supabase Pte. Ltd., established in Singapore, and access by the company itself is covered by the standard contractual clauses (module 2) in that agreement.
- Upstash (AWS eu-central-1 / Frankfurt, Germany): rate limiting on our public forms and APIs, to prevent abuse and automated querying. Briefly stores a counter per IP address, for no more than a few minutes. Legal basis: legitimate interest (security), art. 6.1.f GDPR.
- Sentry (Germany region, de.sentry.io): error reporting from the app. Only with your consent, configurable via Profile › Measurement preferences. Configured without personal data (sendDefaultPii: false).
4.2 Processors outside the EU/EEA
For transfers outside the EEA we rely on the appropriate safeguards in each party's data processing agreement: the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914) and, where the processor is additionally certified under the EU-US Data Privacy Framework, on adequacy decision (EU) 2023/1795. You can request a copy of the applicable safeguards via info@kollaborate.app.
- Vercel Inc. (US): hosting of the website and the web app. Processes request logs that may contain IP addresses, and provides cookieless visitor statistics without individual identification.
- Plus Five Five, Inc. (Resend, US): sending transactional email (confirmation, password reset, notifications). Processes email addresses and the contents of those messages.
- PostHog Inc. (US, with storage on the EU host eu.i.posthog.com): product analytics in the web app. Measures which steps users take and links that to a user id. Only with your consent, configurable via Profile › Measurement preferences.
- Microsoft Ireland Operations Ltd. (Microsoft Clarity): measures how visitors scroll and click through the public website pages, including recordings of those movements. Only after your consent via the cookie banner; if you refuse, the script is not loaded.
- RevenueCat Inc. (US): management of subscriptions purchased via the App Store or Google Play. Processes an app user id and your subscription status, no payment data.
- Apple Inc. and Google Ireland Ltd.: in-app purchases. For a purchase through the store, the store itself is the seller; we only receive your subscription status, never your payment details.
- Expo (650 Industries, Inc.) (US): building and delivering app updates. Processes technical data about the device and app version when an update is fetched.
- Meta Platforms Ireland Ltd. (Instagram Graph API) and TikTok Technology Ltd. (TikTok API): retrieving public profile statistics of creator accounts, only when a creator connects their own account.
4.3 Stripe: processor and independent controller
Stripe Payments Europe Ltd. (Ireland) processes the payments between businesses and creators and the payouts via Stripe Connect Express. Stripe is PCI DSS Level 1 certified. We store no card details ourselves.
Worth knowing: Stripe is not our processor for everything. For a number of purposes Stripe determines the purposes and means itself, and therefore acts as an independent controller: the choice of banks and payment method providers, fraud prevention, anti-money-laundering and identity checks (KYC), its own invoicing and product improvement. For those processing activities Stripe's own privacy terms apply, not ours.
Stripe's privacy policy is available at stripe.com/be/privacy.
We never sell your personal data to third parties for marketing purposes.
5. Retention periods
| Category | Retention period | Basis |
|---|---|---|
| Account data (active) | As long as the account is active | Contract |
| Account data after deletion | Within 30 days at the latest | Legal obligation (art. 17 GDPR) |
| Transaction data and accounting records | 7 years | Legal obligation (BE accounting legislation) |
| Chat messages and collaboration data | 2 years after last activity | Legitimate interest (dispute resolution) |
| Security and audit logs | 12 months | Legitimate interest (security) |
| Support and contact messages | 2 years after handling | Legitimate interest (follow-up and quality) |
| Newsletter consent | Until consent is withdrawn + 1 year (proof) | Consent |
6. Your rights as a data subject
Under the GDPR (General Data Protection Regulation, Regulation (EU) 2016/679) you have the following rights:
- Right of access (Art. 15 GDPR): you may request which personal data we process about you and receive a copy.
- Right to rectification (Art. 16 GDPR): have incomplete or inaccurate data corrected.
- Right to erasure (Art. 17 GDPR): have your personal data deleted (“right to be forgotten”), unless statutory retention periods apply.
- Right to restriction of processing (Art. 18 GDPR): have processing temporarily suspended while a dispute is being investigated.
- Right to data portability (Art. 20 GDPR): receive your data in a machine-readable format or have it transferred to another service provider.
- Right to object (Art. 21 GDPR): object to processing based on legitimate interest, in particular for marketing purposes.
- Right to withdraw consent (Art. 7(3) GDPR): withdraw consent given (e.g. marketing) at any time without affecting the lawfulness of the processing up to the withdrawal.
Send your request to info@kollaborate.app. We answer your request within thirty (30) calendar days of receipt. We may verify your identity before responding.
7. Complaint to the Data Protection Authority
If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority. In Belgium this is the Data Protection Authority (Gegevensbeschermingsautoriteit, GBA):
- Website: gegevensbeschermingsautoriteit.be
- Address: Drukpersstraat 35, 1000 Brussels
- Email: contact@apd-gba.be
- Telephone: +32 2 274 48 00
You can also lodge a complaint with the supervisory authority of the EU member state where you usually reside or work.
8. Security of personal data
We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction or disclosure, including:
- Encryption of data transmission via TLS (HTTPS)
- Encryption of data at rest (AES-256, via Supabase/AWS)
- Role-based access control (no employee has broader access than necessary)
- Hashed and salted password storage via Supabase Auth (bcrypt)
- Security and access logs with a retention period of 12 months
- Data centres in the EU (Frankfurt) for the primary database
9. Cookies and tracking technologies
We use a limited number of strictly necessary cookies for login management. For public website analytics we use Vercel Web Analytics and Microsoft Clarity. Clarity cookies are disabled. We do not use advertising cookies or remarketing pixels. More information can be found in our Cookie Policy.
10. Automated decision-making and profiling
Article 13(2)(f) GDPR requires us to state whether we take decisions about you by automated means alone. We do not. There is no automated decision-making within the meaning of Article 22 GDPR: no decision producing legal effects or similarly significant effects for you is taken without a human being involved.
In concrete terms:
- Who is approved as a creator or as a business, who receives a payout, and whose account is restricted or closed: each of those is decided by a person who has looked at the file.
- We do not calculate a trust score, credit score or fraud score about you.
- We do not derive a profile from your behaviour to predict your personality, interests or reliability, and we therefore do not sell such a profile to anyone either.
Some things do happen automatically. Because "no automated decision-making" can easily read as "nothing happens automatically", here is what does:
- The order in which creators and offers appear. It follows fixed rules, not a model that learns from your behaviour. The parameters are set out in the app on the page "How we determine the order", reachable from the list in Discover.
- An automated check on chat messages. A small number of categories are refused at the moment you send: sexual content combined with minors, requests for nude images, and proposing sex in return for something. You see this immediately and the message is not stored. A second, broader group of messages goes through but is flagged for our staff, for example when it contains a bank account number or appears to arrange payment outside the platform. Such a flag attaches to the message, not to you: nothing is noted on your profile and no automatic consequence follows.
- Rate limits. Anyone making an unusual number of requests in a short time temporarily receives an error. This protects the service against abuse and clears by itself.
- Reminders and notifications. Messages about an expiring deadline, a new response or a payout are sent automatically based on what happens in your file.
If you disagree with something that happened automatically, you can always have a person look at it via info@kollaborate.app. Where it concerns a decision about content we removed or refused, the appeal procedure in our DSA policy applies as well.
11. Changes to this privacy policy
We may amend this privacy policy to reflect current processing practices or legal requirements. In the event of significant changes, we will send you a notice by email. The date of the last amendment is stated at the top of this page. We recommend that you consult this policy periodically.