Kollaborate
Download on the App StoreGet it on Google Play
Legal

Privacy Policy

How Kollaborate handles your personal data, in accordance with the GDPR and Belgian data protection law.

Last updated: 15 September 2026

This is an English courtesy translation. In case of any discrepancy, the Dutch version prevails and is the legally binding version (switch language via NL/EN at the top).

1. Data controller

The data controller for your personal data is SOCIALWORLD CommV, trading name Noble Matter and Kollaborate, KBO 0794.495.920, VAT BE0794.495.920, RPR/RLE Antwerp, registered office Krijgsbaan 11, 2640 Mortsel (office: Frankrijklei 5, 2000 Antwerp).

For questions about data protection, contact us via: info@kollaborate.app.

Kollaborate does not currently have an appointed Data Protection Officer (Functionaris voor Gegevensbescherming, FG/DPO). Questions and requests regarding your personal data are handled via info@kollaborate.app.

2. Which personal data we process

2.1 Account data (all users)

2.2 Business data

2.3 Creator data

2.4 Collaboration and transaction data

2.5 Usage data and platform statistics

2.6 Support and contact communication

3. Purposes and legal bases of the processing

3.1 Performance of the contract (Art. 6(1)(b) GDPR)

3.2 Legal obligation (Art. 6(1)(c) GDPR)

3.3 Legitimate interest (Art. 6(1)(f) GDPR)

3.4 Consent (Art. 6(1)(a) GDPR)

4. Recipients and processors

We work with the following processors that process personal data on our behalf. A data processing agreement has been concluded with each processor in accordance with Art. 28 GDPR:

4.1 Processors storing data within the EU/EEA

4.2 Processors outside the EU/EEA

For transfers outside the EEA we rely on the appropriate safeguards in each party's data processing agreement: the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914) and, where the processor is additionally certified under the EU-US Data Privacy Framework, on adequacy decision (EU) 2023/1795. You can request a copy of the applicable safeguards via info@kollaborate.app.

4.3 Stripe: processor and independent controller

Stripe Payments Europe Ltd. (Ireland) processes the payments between businesses and creators and the payouts via Stripe Connect Express. Stripe is PCI DSS Level 1 certified. We store no card details ourselves.

Worth knowing: Stripe is not our processor for everything. For a number of purposes Stripe determines the purposes and means itself, and therefore acts as an independent controller: the choice of banks and payment method providers, fraud prevention, anti-money-laundering and identity checks (KYC), its own invoicing and product improvement. For those processing activities Stripe's own privacy terms apply, not ours.

Stripe's privacy policy is available at stripe.com/be/privacy.

We never sell your personal data to third parties for marketing purposes.

5. Retention periods

CategoryRetention periodBasis
Account data (active)As long as the account is activeContract
Account data after deletionWithin 30 days at the latestLegal obligation (art. 17 GDPR)
Transaction data and accounting records7 yearsLegal obligation (BE accounting legislation)
Chat messages and collaboration data2 years after last activityLegitimate interest (dispute resolution)
Security and audit logs12 monthsLegitimate interest (security)
Support and contact messages2 years after handlingLegitimate interest (follow-up and quality)
Newsletter consentUntil consent is withdrawn + 1 year (proof)Consent

6. Your rights as a data subject

Under the GDPR (General Data Protection Regulation, Regulation (EU) 2016/679) you have the following rights:

Send your request to info@kollaborate.app. We answer your request within thirty (30) calendar days of receipt. We may verify your identity before responding.

7. Complaint to the Data Protection Authority

If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority. In Belgium this is the Data Protection Authority (Gegevensbeschermingsautoriteit, GBA):

You can also lodge a complaint with the supervisory authority of the EU member state where you usually reside or work.

8. Security of personal data

We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction or disclosure, including:

9. Cookies and tracking technologies

We use a limited number of strictly necessary cookies for login management. For public website analytics we use Vercel Web Analytics and Microsoft Clarity. Clarity cookies are disabled. We do not use advertising cookies or remarketing pixels. More information can be found in our Cookie Policy.

10. Automated decision-making and profiling

Article 13(2)(f) GDPR requires us to state whether we take decisions about you by automated means alone. We do not. There is no automated decision-making within the meaning of Article 22 GDPR: no decision producing legal effects or similarly significant effects for you is taken without a human being involved.

In concrete terms:

Some things do happen automatically. Because "no automated decision-making" can easily read as "nothing happens automatically", here is what does:

If you disagree with something that happened automatically, you can always have a person look at it via info@kollaborate.app. Where it concerns a decision about content we removed or refused, the appeal procedure in our DSA policy applies as well.

11. Changes to this privacy policy

We may amend this privacy policy to reflect current processing practices or legal requirements. In the event of significant changes, we will send you a notice by email. The date of the last amendment is stated at the top of this page. We recommend that you consult this policy periodically.

PrivacyTermsCookiesContact