Privacy Policy
How Kollaborate handles your personal data, in accordance with the GDPR and Belgian data protection law.
Last updated: 18 July 2026
1. Data controller
The data controller for your personal data is SOCIALWORLD CommV, trading name Creative Hero and Kollaborate, KBO 0794.495.920, VAT BE0794.495.920, RPR/RLE Antwerp, registered office Krijgsbaan 11, 2640 Mortsel (office: Frankrijklei 5, 2000 Antwerp).
For questions about data protection, contact us via: info@kollaborate.app.
Kollaborate does not currently have an appointed Data Protection Officer (Functionaris voor Gegevensbescherming, FG/DPO). Questions and requests regarding your personal data are handled via info@kollaborate.app.
2. Which personal data we process
2.1 Account data (all users)
- Name, first name, email address
- Profile picture (optional)
- Telephone number (optional)
- Role on the platform (business or creator)
- Password (stored encrypted via Supabase Auth, never readable by us)
- Login history and session data
2.2 Business data
- Company name and trading name
- KBO/company number (verified via the KBO database)
- VAT number
- Sector and description of activities
- Address of the establishment
- Billing details for the subscription and platform fees
2.3 Creator data
- Instagram and/or TikTok handle (username)
- Public account statistics (follower count, engagement, reach), retrieved via the official API's of Meta and TikTok
- Niche and content style (provided by the creator themselves)
- Location (city/region, provided by the creator themselves)
- Payout details: bank account or Stripe Express account (via Stripe, not stored directly with us)
2.4 Collaboration and transaction data
- Offered and accepted collaborations, including briefs and counter-proposals
- Message exchange via the in-app chat
- Delivered content (links, uploads) and approval status
- Payment data of collaborations: amounts, transaction ID's, statuses (via Stripe, no card details with us)
- Ratings and reviews after a collaboration has ended
2.5 Usage data and platform statistics
- Anonymous pageview statistics via Vercel Web Analytics. It uses no cookies and processes no personal data; no individual identification is possible.
- Technical logs (error messages, performance) for security and stability
2.6 Support and contact communication
- When you ask a question via our support or contact form or by email: your name (optional), email address, the category and content of your message, and limited technical context (the page from which you wrote and your browser type) so that we can handle your question correctly.
- This data is used to help you and to safeguard the quality of our services (legal basis: performance of the contract and/or our legitimate interest in customer support).
3. Purposes and legal bases of the processing
3.1 Performance of the contract (Art. 6(1)(b) GDPR)
- Creating and managing accounts
- Matching between businesses and creators
- Processing payments and payouts
- Communication via in-app chat
- Verification of KBO registration and social media profiles
- Management of subscriptions, trial periods and promotional codes
3.2 Legal obligation (Art. 6(1)(c) GDPR)
- Keeping accounting records (Act of 17 July 1975 on the accounting of undertakings, seven-year retention period)
- KYC and AML checks by Stripe in accordance with the Act of 18 September 2017 on the prevention of money laundering and the financing of terrorism
- Cooperation with competent authorities under a legal order
3.3 Legitimate interest (Art. 6(1)(f) GDPR)
- Detection and prevention of fraud, fake accounts and abuse (interest: integrity of the platform and protection of other users)
- Security monitoring and audit logs (interest: security of the platform and users' data)
- Technical improvement of the platform on the basis of anonymised usage statistics
3.4 Consent (Art. 6(1)(a) GDPR)
- Newsletters and marketing communications by email are only sent after express, separate consent. You can withdraw this consent at any time via the unsubscribe link at the bottom of every email or by contacting us via info@kollaborate.app.
4. Recipients and processors
We work with the following processors that process personal data on our behalf. A data processing agreement has been concluded with each processor in accordance with Art. 28 GDPR:
4.1 Processors within the EU/EEA
- Supabase Inc. (database hosting, EU-Central-1 / Frankfurt, Germany): storage of account data, transactions and chat messages. Supabase uses AWS as its underlying infrastructure in the EU.
4.2 Processors outside the EU/EEA
The processors below are established in the United States or process data outside the EU. The transfer takes place on the basis of the Standard Contractual Clauses (SCCs) adopted by the European Commission (Implementing Decision (EU) 2021/914), unless stated otherwise:
- Stripe Payments Europe Ltd.(payment processing and KYC/AML, Ireland/US): processes payment data and payouts via Stripe Connect Express. Stripe is certified as a PCI DSS Level 1 processor. Stripe's own privacy policy is available at stripe.com/be/privacy. For transfers outside the EEA, we rely on the appropriate safeguards applied by this processor (EU Standard Contractual Clauses, SCC's).
- Vercel Inc. (US): hosting of the website and the Next.js application. Vercel generally does not store user content, but does process request logs that may contain IP addresses. Appropriate safeguards apply to this transfer (Standard Contractual Clauses, SCC's).
- Resend Inc. (US): sending of transactional emails (account activation, password reset, payment confirmations). Email addresses and the content of transactional mails are processed by Resend. Appropriate safeguards apply to this transfer (Standard Contractual Clauses, SCC's).
- Meta Platforms Ireland Ltd.(Instagram Graph API): retrieving public profile statistics of creator accounts. Publicly available data only. Meta's privacy policy applies to the API interaction on Meta's side.
- TikTok Technology Ltd. (TikTok API): retrieving public profile statistics of creator accounts. Publicly available data only. For transfers outside the EEA, appropriate safeguards apply (Standard Contractual Clauses, SCC's).
We never sell your personal data to third parties for marketing purposes.
5. Retention periods
| Category | Retention period | Basis |
|---|---|---|
| Account data (active) | As long as the account is active | Contract |
| Account data after deletion | 90 days (for fraud investigation) | Legitimate interest |
| Transaction data and accounting records | 7 years | Legal obligation (BE accounting legislation) |
| Chat messages and collaboration data | 2 years after last activity | Legitimate interest (dispute resolution) |
| Security and audit logs | 12 months | Legitimate interest (security) |
| Support and contact messages | 2 years after handling | Legitimate interest (follow-up and quality) |
| Newsletter consent | Until consent is withdrawn + 1 year (proof) | Consent |
6. Your rights as a data subject
Under the GDPR (General Data Protection Regulation, Regulation (EU) 2016/679) you have the following rights:
- Right of access (Art. 15 GDPR): you may request which personal data we process about you and receive a copy.
- Right to rectification (Art. 16 GDPR): have incomplete or inaccurate data corrected.
- Right to erasure (Art. 17 GDPR):have your personal data deleted (“right to be forgotten”), unless statutory retention periods apply.
- Right to restriction of processing (Art. 18 GDPR): have processing temporarily suspended while a dispute is being investigated.
- Right to data portability (Art. 20 GDPR): receive your data in a machine-readable format or have it transferred to another service provider.
- Right to object (Art. 21 GDPR): object to processing based on legitimate interest, in particular for marketing purposes.
- Right to withdraw consent (Art. 7(3) GDPR): withdraw consent given (e.g. marketing) at any time without affecting the lawfulness of the processing up to the withdrawal.
Send your request to info@kollaborate.app. We answer your request within thirty (30) calendar days of receipt. We may verify your identity before responding.
7. Complaint to the Data Protection Authority
If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority. In Belgium this is the Data Protection Authority (Gegevensbeschermingsautoriteit, GBA):
- Website: gegevensbeschermingsautoriteit.be
- Address: Drukpersstraat 35, 1000 Brussels
- Email: contact@apd-gba.be
- Telephone: +32 2 274 48 00
You can also lodge a complaint with the supervisory authority of the EU member state where you usually reside or work.
8. Security of personal data
We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction or disclosure, including:
- Encryption of data transmission via TLS (HTTPS)
- Encryption of data at rest (AES-256, via Supabase/AWS)
- Role-based access control (no employee has broader access than necessary)
- Hashed and salted password storage via Supabase Auth (bcrypt)
- Security and access logs with a retention period of 12 months
- Data centres in the EU (Frankfurt) for the primary database
9. Cookies and tracking technologies
We use a limited number of strictly necessary cookies for login management. We do not use advertising cookies or third-party tracking pixels. More information can be found in our Cookie Policy.
10. Changes to this privacy policy
We may amend this privacy policy to reflect current processing practices or legal requirements. In the event of significant changes, we will send you a notice by email. The date of the last amendment is stated at the top of this page. We recommend that you consult this policy periodically.