Who is responsible
Webdevamin, trading as Postiva, is the data controller for account administration, service security, product analytics, customer communication, and business records. The controller can be reached at [email protected] or at Eigen-Haardstraat 39, 8400 Oostende, Belgium.
A customer that imports or uploads personal data obtained from clients, public webpages, or other people is responsible for the lawful basis and, where Article 14 GDPR applies, for giving those people the required privacy information. This includes identifying Postiva or its service-provider categories where the law requires it.
Data we process
- Account and security data, including name, email, password hash, email verification, sessions, IP address, user agent, passkeys, two-factor details, and API tokens.
- Team and client workspace data, including team names, roles, invitations, member details, and client notes.
- Content data, including URLs, pasted source text, extracted webpage text, prompts, generated copy, images, audio, video, PDFs, schedules, brand kits, reference images, review comments, and approval links.
- Billing data received from Paddle, including plan, subscription, transaction, invoice, status, currency, and limited customer details. Full payment card details are not stored by Postiva.
- Google profile name and email when Google sign-in is chosen.
- Server-side product events, such as registration, project creation, generation outcomes, and feature use. Postiva does not currently use third-party analytics cookies.
- Support, legal, and content report correspondence.
Data comes from you, a team owner or inviter, Google when you choose social login, Paddle when a purchase is made, public webpages imported at a customer's request, people whose data a customer uploads, and technical events generated through service use.
Processing details
| Category and source | Purpose and legal basis | Required? | Recipients | Retention |
|---|---|---|---|---|
| Name, email, credentials, verification, sessions and security events from you or a team administrator | Account delivery under the contract; security and abuse prevention under legitimate interests | Core account data is required. Without it, Postiva cannot provide or secure an account. | Hosting, email and optional Google authentication providers | Account life, then 30 days for recoverable account data. Authentication records follow session or credential expiry. |
| Source text, public pages imported on request, prompts, uploads, customer/client data, generated output and review comments | Generate, store, share and deliver customer-requested output under the contract or the customer controller's instructions | Optional, but the selected feature cannot run without the submitted material. | OpenAI, hosting and private storage providers | Until customer deletion or account termination, followed by stated recovery and backup rotation. Public review links expire after 30 days by default. |
| Plan, transaction, invoice and customer details from Paddle | Subscription delivery under the contract and tax, accounting and fraud duties under legal obligation or legitimate interests | Required for a paid plan | Paddle as Merchant of Record and independent controller; professional advisers where needed | For applicable Belgian tax and accounting periods, generally at least seven years |
| Feature events and technical diagnostics generated through use | Reliability, capacity, security and limited product understanding under legitimate interests | Generated automatically. Core security collection cannot be disabled. | Hosting and infrastructure providers | Product analytics up to 24 months. Production application logs are configured for 14 days. |
| Support, rights requests and content reports from correspondents and affected users | Respond, meet legal duties, moderate the marketplace and establish or defend claims | Usually optional, but enough detail is required to assess the request. Anonymous CSAM reporting remains available. | Email provider, advisers and competent authorities when required | Resolved moderation evidence for 3 years unless a legal hold or legal duty requires longer. Other correspondence is kept only while needed for the request and related claims. |
Purposes and legal bases
- Contract: create accounts, provide team workspaces, generate and store content, deliver files, manage subscriptions, and provide support.
- Legitimate interests: secure the service, prevent abuse, diagnose failures, understand product use with limited server-side analytics, improve reliability, and establish or defend legal claims.
- Legal obligation: keep tax, accounting, transaction, and legally required platform records, respond to lawful requests, and process valid content notices.
- Consent: only where a feature or applicable law specifically requires it. Google sign-in is optional and can be avoided by using email and password.
Postiva does not sell personal data and does not use it for third-party advertising.
AI processing
Selected source content, prompts, brand context, uploaded references, and requested output settings are sent to OpenAI to generate text, images, style analysis, or speech. OpenAI processes this data as a service provider under its business terms. OpenAI states that API inputs and outputs are not used to train its models by default. Limited abuse-monitoring logs may be retained by OpenAI for up to 30 days unless a different approved control applies.
Do not submit special-category data, confidential third-party information, or personal data that is not needed for the requested output. AI output can be inaccurate and must be reviewed before publication.
Postiva is intended for adults aged 18 or older. Customer content must not contain special-category data, criminal-offence data, or children's personal data.
Recipients and service providers
- OpenAI Ireland for AI text, image, style, and speech processing.
- Hetzner and Ploi for application hosting and server management.
- Cloudflare, including private R2 object storage, for network and file infrastructure.
- Amazon Web Services SES in Ireland for transactional email.
- Paddle as Merchant of Record and an independent controller for checkout, tax, invoicing, payment, and subscription services.
- Google as an independent controller when optional Google sign-in is used.
- Professional advisers, authorities, or counterparties where lawfully required.
International transfers
Postiva prefers European regions where the service allows it. Some providers may process data outside the European Economic Area. Where Postiva is responsible for a transfer, it relies on an adequacy decision, the EU Standard Contractual Clauses, or another lawful safeguard. Copies or information about relevant safeguards can be requested by email, subject to confidentiality limits.
For each provider, the applied mechanism depends on the contracted entity and actual processing location. EEA processing needs no Chapter V mechanism. Transfers to a country covered by an EU adequacy decision rely on that decision. Other restricted transfers use the applicable EU Standard Contractual Clauses, supported where appropriate by encryption, access limitation, data minimisation, and a transfer assessment. The current vendor register is reviewed before a provider or region is introduced.
How long data is kept
- Active account, team, and project data is kept while the service is used.
- Explicitly deleted projects and generated assets are removed from active storage promptly.
- After account deletion, recoverable account and personal-team data is held for up to 30 days, then permanently purged. Contact support during that window to request recovery.
- Server-side product analytics is kept for no more than 24 months. Direct account and personal-team identifiers are removed when an account is deleted.
- Expired invitations are deleted automatically.
- Billing, tax, accounting, fraud, legal claim, and content moderation records may be kept longer where the law or a legitimate legal need requires it.
- Provider backups may retain residual copies for a limited rotation period before overwrite.
Public approval links
A project owner can create a tokenised approval link for a client. Anyone who receives the link can view the shared project and submit a decision without an account, so it must be shared only with intended reviewers. The token is used to locate the project and is recorded in server requests. It is not displayed in public marketplace listings.
Links expire after 30 days by default and can be revoked immediately by the project owner. A reviewer's decision, comment, and response time are recorded to provide the requested review and preserve approval evidence. Standard server request logs may contain an IP address and user agent for security and abuse prevention. Do not place sensitive personal data in a review comment.
Your GDPR rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or objection. You may also withdraw consent where processing relies on consent. These rights can be limited by law, the rights of others, or records Postiva must retain.
Send a request to [email protected]. Postiva normally responds within one month. That period may be extended by two months for complex or numerous requests, with notice during the first month. Identity may be verified before a request is completed. A request can be refused or limited where the GDPR or another law permits, including manifestly unfounded or excessive requests, competing rights, legal duties, or legal claims. The reason and complaint options will be explained. You also have the right to complain to the Belgian Data Protection Authority at dataprotectionauthority.be.
No data protection officer has been appointed because the statutory appointment threshold is not met under the current assessment. Use [email protected] for all privacy contact. Where Postiva acts as processor, a request about customer content is referred to the relevant customer controller.
Security and automated decisions
Postiva uses access controls, password hashing, encrypted connections, private file storage, team authorization, CSRF protection, throttling, and optional passkeys and two-factor authentication. No internet service can promise absolute security. Report a suspected incident immediately to [email protected].
Postiva does not make decisions with legal or similarly significant effects based solely on automated processing. AI generation is a tool controlled by the customer.
Changes to this notice
Material changes will be reflected by a new update date and, where appropriate, an in-product notice or a renewed Terms acceptance request.
Marketing communications
Postiva does not currently send promotional email. It will not start doing so until an appropriate opt-in, preference record, sender identification, and one-step unsubscribe workflow are available. Transactional service, security, billing, and legal notices are not promotional messages.
