Privacy policy
How Custilo collects, uses and protects personal data: the data of the people who use Custilo, and the data of the customers our clients survey.
Version 2026-10-03, last updated 3 October 2026. Permanent link to this version
Draft
This text is a draft that is being reviewed and may still change. Values in square brackets are still to be completed. Questions: hello@custilo.com.
1. Who we are
Custilo is a customer feedback platform operated by:
[Legal company name], [Legal form, e.g. BV/SRL], registered office at [Registered office address, Belgium], enterprise number [KBO/BCE enterprise number], RPR/RPM [Enterprise court of the registered office, e.g. Ghent, division Ghent], VAT [VAT number], email hello@custilo.com.
For anything about your personal data, write to privacy@custilo.com. Based on our assessment of our activities, we are not required to appoint a data protection officer; this address reaches the person responsible for data protection.
This policy applies the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
2. Two roles: controller and processor
Custilo handles personal data in two different capacities.
- As a controller for the data of the people who use Custilo (account holders and team members, and people invited to join a workspace), billing data, the data of visitors of this website and of people who contact us. Sections 3 to 9 describe this processing.
- As a processor for the businesses that use Custilo (our clients). When a business sends its own customers a feedback request through Custilo, that business is the controller of its customers’ data and decides why and how it is used. We only process that data on its instructions, under our data processing agreement. The same applies to the people a business chooses to receive alerts about low scores. Section 10 explains what this means if you received such an email.
3. Data we process as a controller
- Account data: your email address, your password (stored only as a one way hash by our authentication provider), the workspaces you belong to and your role in each, and the date you accepted our terms.
- Workspace and campaign settings you enter: the workspace name, the sender name and reply-to address of each campaign, alert settings and similar configuration.
- Billing data: the email address of the person who subscribes, and the name, billing address and VAT number of the paying business, entered at checkout with our payment provider (Stripe); the Stripe customer and subscription identifiers, the plan, invoices and payment status. Card details are entered directly with Stripe and never reach our servers.
- Invitations: the email address of a person a workspace member invites, and the role offered. We receive this address from the member who sends the invitation.
- Technical and security data: IP addresses and request details in our hosting provider’s logs, a pseudonymised (hashed) form of the IP address used to limit abusive requests to public pages, and, when error monitoring is enabled, error reports with the address of the page (without secret links or search terms) and the browser, but no IP address.
- Correspondence: the messages you send us and our replies.
4. Why we use it, and on which legal basis
- To provide the service you signed up for (create and secure your account, run your workspace, send the emails you set up, invite team members, send alerts, answer support questions): necessary for the performance of our contract with you or your business (GDPR art. 6(1)(b)). Where you act for a business, our legitimate interest in performing the contract with that business (art. 6(1)(f)).
- To bill and keep accounts: necessary for the contract (art. 6(1)(b)) and to meet our legal obligations under Belgian accounting and tax law (art. 6(1)(c)).
- To keep the service secure and working (limit abuse, detect fraud, find and fix errors, keep logs): our legitimate interest in a secure and reliable service (art. 6(1)(f)).
- To send you service messages (usage notices, billing notices, security messages, changes to our terms): necessary for the contract (art. 6(1)(b)). We do not send newsletters or advertising without your consent (art. 6(1)(a)). The only exception is information about our own similar services to existing clients, which the Belgian Royal Decree of 4 April 2003 allows and which relies on our legitimate interest (art. 6(1)(f)); every such message lets you opt out.
- To establish, exercise or defend legal claims: our legitimate interest (art. 6(1)(f)).
Providing account and billing data is necessary to use Custilo; without it we cannot create an account or provide a paid plan. We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you, and we do not sell personal data.
5. Who receives the data
We use carefully selected service providers that process data on our behalf, under a contract with confidentiality and security obligations. They are listed, with what each does and where it processes data, on our sub-processors page. The same providers also process account and technical data for us. Our payment provider Stripe also processes payment data for its own legal obligations (for example fraud prevention and anti money laundering rules), as an independent controller under its own privacy policy.
Other members of your workspace see your email address and role. We may disclose data to authorities when the law requires it, and to professional advisers bound by confidentiality. If our business is transferred, the data may pass to the acquirer, who may only use it as described in this policy unless it informs you first.
6. Transfers outside the European Economic Area
Our main database is hosted in the European Union. Some of our providers are based in, or use infrastructure in, countries outside the European Economic Area, such as the United States. Where data is transferred there, we rely on an adequacy decision of the European Commission (for the United States, the EU-U.S. Data Privacy Framework, for providers certified under it) or on the Standard Contractual Clauses adopted by the European Commission, with additional measures where needed. You can ask us for a copy of the relevant safeguards.
7. How long we keep it
- Account data: as long as you have an account. You can ask us to delete your account at any time by email. A deleted workspace is locked for a 30 day grace period (during which an owner can restore it) and then permanently deleted with everything in it. Deleting a workspace does not delete the user accounts of its members; ask us if you also want your account deleted.
- Billing data and invoices: as long as Belgian accounting and tax law requires: in general 7 years from 1 January following the end of the financial year concerned (Code of Economic Law, art. III.88), or longer where tax law requires it or while a tax audit or dispute is pending.
- Invitations: 90 days after they are accepted, cancelled or expire.
- Rate limit records (a pseudonymised form of the IP address): 2 days.
- Hosting logs: at most [X] days. Error reports: at most [90] days. Both are then deleted automatically by the providers.
- Correspondence: as long as needed to handle your question, and afterwards as long as it may be needed as evidence, within the legal limitation periods.
8. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy;
- have inaccurate data corrected;
- have your data erased, where the law allows;
- restrict the processing in certain cases;
- receive the data you gave us in a structured, machine readable format, and have it sent to another provider (portability);
- object at any time to processing based on our legitimate interest, for reasons relating to your situation, and at any time and without reason to direct marketing;
- withdraw a consent at any time, without affecting processing before the withdrawal.
To use these rights, write to privacy@custilo.com. We answer within one month, which can be extended by two months for complex requests (we will tell you if so). We may ask you to confirm your identity.
You can also lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35 / Rue de la Presse 35, 1000 Brussels, contact@apd-gba.be, www.dataprotectionauthority.be, +32 2 274 48 00, using the complaint form, or with the authority of the EU country where you live or work.
9. Cookies
Custilo only uses cookies that are strictly necessary: when you sign in, our authentication provider sets cookies that keep you signed in and protect your session. Without them you cannot use your account. Belgian law (article 10/2 of the Act of 30 July 2018) does not require consent for strictly necessary cookies, so we do not show a cookie banner. We do not use analytics, advertising or social media cookies. If that ever changes, we will ask for your consent first.
10. If you received a feedback email through Custilo
Businesses use Custilo to ask their customers for feedback, for example after a purchase, a delivery or a service visit. If you received such an email, the business that sent it is the controller of your data and Custilo acts as its processor. For questions about why you were contacted, or to exercise your rights, contact that business first; its name is in the email. If you write to us instead, we pass your request on to that business without delay.
For these emails, Custilo processes on behalf of the business:
- your email address, and if the business provides them, your name, its own customer reference and your language;
- details of the interaction the business wants feedback on (for example the store, the date or the type of service), as the business chooses to send them;
- whether the email was delivered, your score and any comment you leave;
- technical data when you open the response or unsubscribe page (your IP address and browser in our hosting provider’s logs, and a pseudonymised form of the IP address used to limit abuse);
- for some businesses and during free trials, a check of whether your email address exists before sending, done by our email validation provider, to avoid emails that bounce. The result is kept for that business only, so it is not checked again, and is deleted with your data or at the latest 120 days after the check (210 days if the address was invalid).
Every feedback email has an unsubscribe link. Using it stops all further feedback emails from that business (in that Custilo workspace). If the business later deletes your data, we keep, on its instructions, only a hash of your email address and the fact that you unsubscribed (or that the address bounced, reported spam, or that the business stopped emails to you), so that you are not emailed again if the business imports your address again. The hash does not contain your address in readable form and is only used to recognise it if it is imported again; it is still personal data and is deleted with the business’s workspace.
11. Security
We protect personal data with technical and organisational measures appropriate to the risk, including encrypted connections, strict separation of each workspace’s data enforced in the database, role based access for team members, passwords, API keys, invitation tokens and confirmation tokens stored only as hashes, and limits on repeated requests. The measures are described in more detail in our data processing agreement.
12. Changes to this policy
We may update this policy, for example when we add a feature or a provider. The date at the top shows the latest version. We inform account holders by email of important changes before they take effect.