Privacy and Cookie Policy
Last updated: 21 September 2026
This Privacy Policy describes how Novadesko collects, uses, shares and protects your personal data when you use our mobile application, our web application, our accountant portal or related services. We apply the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the Belgian Act of 30 July 2018 and, for our artificial-intelligence features, Regulation (EU) 2024/1689 on artificial intelligence (AI Act).
1. Data controller
- Novadesko SRL
- Rue de Boussoit 4, 7110 Maurage, Belgium
- BE 1018.192.568
- E-mail: privacy@novadesko.com (privacy questions) or support@novadesko.com
- Phone: +32 64 78 00 87
For the data of your own customers, suppliers and employees that you enter in Novadesko, you remain the controller and Novadesko acts as processor (art. 28 GDPR), in accordance with the Terms of Service.
2. Personal data collected
- Identification data: name, first name, e-mail address, phone number, company and VAT number.
- Authentication data: login, password (encrypted), session tokens.
- Technical data: IP address, device, operating system, unique identifier, country and browsing rhythm.
- Usage data: actions in the application, technical logs, statistics.
- Business and financial data: invoices, quotes, customers, suppliers, products, synchronised bank transactions, CODA statements, supporting documents and imported files.
- Cookies and similar technologies (application and website).
3. Processors and technical providers
Novadesko relies on the following providers, bound by contract and by the obligations of article 28 GDPR:
- Hosting: servers located in the European Union (OVH).
- Electronic invoicing: B2Brouter (Peppol access point), Peppol network.
- Payments: Stripe, Mollie (Novadesko stores no card data).
- Bank synchronisation (open banking, PSD2): Enable Banking, Ponto (Ibanity), only with your explicit, periodically renewed consent.
- Artificial intelligence: Anthropic (Claude models) and OpenAI, see section 4.
- Communications: transactional e-mail services, SMS Factor (SMS), Twilio (voice assistance).
- Measurement and diagnostics: Firebase (Google) for crash reports and anonymised statistics, Apple iOS Diagnostics, IPinfo (approximate IP geolocation for security purposes).
- Company verification: Crossroads Bank for Enterprises, VIES and CompanySearch (public company data).
- Public data source for prospecting: Crossroads Bank for Enterprises (CBE) (see "Commercial prospecting").
No advertising SDK or third-party tracker is integrated without your explicit consent.
4. Artificial-intelligence features
Novadesko includes artificial-intelligence (AI) features to save you time:
- Document recognition (OCR): extraction of data from imported invoices, receipts and statements.
- AI assistants (NovaAI, document-creation assistant, marketing assistant): answers to accounting questions, drafting of documents and texts, categorisation suggestions.
- Automated assistance and support: first replies to support requests, always reviewed by a human before any commitment.
In accordance with the AI Act, we inform you transparently:
- You are interacting with an AI: every assistant is clearly identified as such in the interface. Generated content (texts, extractions, suggestions) is flagged as AI-produced.
- No fully automated decision with legal effect is taken about you (art. 22 GDPR): every extraction or suggestion remains a proposal that you validate, edit or reject before it takes effect (accounting entry, document sending, tax return).
- Results may contain errors: the AI replaces neither your judgement nor your accountant's. Always check amounts, VAT rates and legal information before use.
- Providers: AI requests are processed by Anthropic (Claude) or OpenAI, established in the United States, under their business (API) terms. Your data is not used to train their models and is deleted by these providers after a limited period. Transfers are covered by the EU-US Data Privacy Framework and standard contractual clauses.
- Minimisation: only the data needed for the requested feature is sent (the document to read, the question asked and its accounting context). No credentials or passwords are ever sent.
- Choice: AI features are optional; you may not use them or ask support to disable them for your account.
AI Act classification: Novadesko's features are limited-risk AI systems subject to transparency obligations (art. 50). Novadesko operates no high-risk AI system within the meaning of Annex III, no biometric recognition and no scoring of individuals.
5. Purposes of processing
- managing your user account and files;
- providing the application's services and features (invoicing, Peppol, accounting, point of sale, bank synchronisation, AI);
- improving our services (aggregated statistics, experience optimisation);
- ensuring security, fraud and outage prevention;
- complying with our legal obligations (accounting, tax, anti-money laundering);
- important communications (support, technical notifications) and commercial communications (see "Commercial prospecting" below).
6. Legal basis
- Performance of the contract (art. 6.1.b): account creation, use of the application.
- Consent (art. 6.1.a): non-essential cookies, electronic commercial communications where the law requires it, bank connection.
- Legitimate interest (art. 6.1.f): security, internal statistics, product improvement, commercial prospecting of businesses based on publicly accessible data (see "Commercial prospecting" below).
- Legal obligations (art. 6.1.c): accounting and tax retention.
Commercial prospecting
When we use publicly accessible data, in particular from the Crossroads Bank for Enterprises (CBE), we may use it to send you commercial communications about our services, by post and, under the conditions set by law, electronically, on the basis of our legitimate interest (art. 6.1.f) in promoting our services to businesses. For this purpose we only process public business data: company name, registered office address, company number, legal form and date of incorporation. You may object at any time, free of charge and without justification, to the use of your data for direct marketing, through our opt-out form or by e-mail to privacy@novadesko.com; your request is applied immediately to all our channels (post, e-mail, text messages, calls), with no further balancing test. After an objection we keep only the data strictly needed to prevent any further prospecting (suppression list: e-mail address, phone number or company number). When your data was not collected from you, the information required by Article 14 GDPR (controller identity, purpose, legal basis, source, rights) appears on our first communication and refers to this policy.
7. Storage and security
- hosting in the European Union;
- encryption of data in transit (HTTPS/TLS);
- encryption of sensitive data at rest (passwords, tokens, access keys);
- secure daily backups and restore tests;
- access strictly limited to authorised staff, access logging;
- continuous security monitoring (intrusion and attack detection).
8. Transfers outside the European Economic Area
Your data is hosted in the European Union. Some providers (Anthropic, OpenAI, Stripe, Google, Twilio) may process data from the United States. These transfers rely on the adequacy decision for the EU-US Data Privacy Framework or on the European Commission's standard contractual clauses, supplemented by technical measures (encryption, minimisation).
9. Retention period
- as long as the user account is active;
- accounting documents and invoices: statutory retention period (7 years in Belgium, 10 years in France);
- archiving or deletion after 36 months of inactivity, or earlier on request;
- technical and security logs: 12 months maximum;
- prospecting data from public sources (CBE): 12 months maximum after our last communication, or until you object; the suppression list (data strictly needed to stop contacting you) is kept without time limit;
- data sent to AI providers: deleted by them after a limited period (30 days maximum) and never used for training.
10. Your rights
- right of access and rectification;
- right to erasure and to restriction of processing;
- right to portability (export of your data from the application);
- right to object, in particular to prospecting and direct marketing, at any time, free of charge and without justification, through our opt-out form;
- right to withdraw your consent at any time;
- right not to be subject to a fully automated decision and to obtain human intervention on any AI-produced result;
- right to lodge a complaint with the Data Protection Authority.
To exercise your rights: privacy@novadesko.com. We reply within one month; proof of identity may be requested.
11. Cookies (application and website)
- necessary cookies: authentication and security;
- analytics cookies: usage measurement, only with your consent;
- preference cookies: language, theme and configuration.
You can manage your preferences through the cookie banner or your browser settings.
12. Data sharing
Novadesko neither sells nor rents any personal data. Data is shared only with the processors listed in section 3, with your accountant or accounting firm when you grant them access to your file, and with legally competent authorities when the law requires it.
13. Requests from public authorities
- prior review of the lawfulness of every request received;
- challenge of requests deemed excessive or unlawful;
- minimisation of the data disclosed to what is strictly necessary;
- documentation and traceability of requests, replies and legal bases.
Where the law allows it, the users concerned are informed of these requests.
14. Data breaches
In the event of a personal-data breach presenting a risk to your rights, Novadesko notifies the Data Protection Authority within 72 hours and informs you without delay when the risk is high, together with the measures taken.
15. Account and data deletion
You may request the complete deletion of your account and personal data at any time from the application settings or by e-mail: support@novadesko.com. Documents subject to a statutory retention obligation are kept for the required period, then deleted.
16. Supervisory authority
Data Protection Authority (Belgium), Rue de la Presse 35, 1000 Brussels, www.dataprotectionauthority.be. Users established in another EU country may contact their national authority (CNIL in France, Autoriteit Persoonsgegevens in the Netherlands, CNPD in Luxembourg, BfDI in Germany).
17. Changes to this policy
Novadesko may amend this policy. The version in force is the one published in the application and on the website; significant changes are notified in the application or by e-mail.