Attenova Attenova

Privacy policy

Version 1.0 · last updated 30 August 2026

1. Who is responsible?

ATTENOVA ("Attenova"; company details will be added after registration) is the controller for the data of visitors to this website and of account holders. For the personnel data an organisation enters into the platform (rosters, leave, employees' time records), that organisation is the controller and Attenova acts as processor; we arrange this in the data processing agreement.

2. Which data do we process?

  • Account data: name, email address, password (stored encrypted), language preference.
  • Organisation data: what your organisation enters: teams, rosters, leave and absences, time records (including any location check if your organisation switches it on), and internal messages.
  • Sign in with Google (optional): if you choose this, we only receive your name, email address and a technical linking ID from Google. We never receive your Google password and read nothing else from your Google account.
  • Technical data: limited log files (such as IP address at sign-in) for security (e.g. protection against intrusion attempts), and error reports to solve problems.
  • Website statistics: anonymised and without cookies (see the cookie policy).

3. For what and on which basis?

  • To provide the service and manage your account (performance of the contract).
  • To secure, prevent abuse and fix errors (legitimate interest).
  • To send you necessary service emails, such as verification, invitations and notifications you configure yourself (performance of the contract; you manage notification preferences in the app).
  • To invoice and comply with our legal obligations (legal obligation).

We do not sell data and do not use it for advertising.

4. Who receives data?

Only service providers we need to make the platform work, each under a data processing agreement:

  • Brevo (email delivery, EU) for service emails.
  • Stripe (payments) for paid subscriptions; Attenova does not store card details itself.
  • Backblaze (encrypted backups, EU region).
  • Google, only if you use "Sign in with Google".

All data is hosted on servers within the European Union.

5. How long do we keep data?

  • Account data: as long as your account exists. Organisation data: as long as the organisation is a customer; after an organisation is deleted, its data is permanently erased (backups rotate out automatically within the backup retention period).
  • We keep billing data for as long as the law requires. Security logs are cleaned up automatically after a short time.

6. Your rights

You have the right to access, rectify, erase, restrict, object to and port your data. Email us at info@attenova.eu; we respond within the legal term. If it concerns personnel data that your employer or club manages in Attenova, address your request (also) to that organisation; we help them with it. You can also lodge a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be).

7. Security

Connections are encrypted (https), passwords are stored hashed, access is restricted by roles and permissions, time records can only be corrected with a verifiable trail, and we make encrypted backups daily.

8. Changes

In case of important changes to this policy we inform you via the app or email.

← Back to the home page