Privacy Policy
Last updated: 24 June 2026. Version 1.0
This Privacy Policy explains how Quivvy Solutions BV ("we", "us", "our") processes personal data in connection with the backup247.app service. We take the protection of your personal data seriously and process it in accordance with the General Data Protection Regulation (GDPR) and applicable Belgian data protection law.
Important distinction. backup247.app creates backups of data from your SaaS applications (such as Airtable, Notion and others). With respect to the data you choose to back up, we act as a processor on your behalf; you remain the controller for that data. With respect to the data we process about you as a customer (account and billing data), we act as a controller. This Policy covers both roles and refers, where relevant, to our Data Processing Agreement (DPA).
1. Who we are
- Controller: Quivvy Solutions BV
- Company number: BE 0783.340.623
- Registered office: Poortakkerstraat 57, 9051 Gent, Belgium
- Privacy contact: hello@backup247.app
For any questions regarding this Policy or the processing of your data, you can reach us at the email address above.
2. What data do we process?
2.1 Account and billing data (we act as controller)
When you create an account or take out a subscription, we process:
- Name
- Email address
- Billing details (billing address, VAT number, payment data processed through Stripe)
2.2 Backup data (we act as processor)
To provide the service, we copy data from your connected SaaS applications to a secure database on your instruction. This data may contain personal data of third parties (for example contacts or customers in your Airtable or Notion). We process this data solely to provide the backup, retention and restore functionality and never for our own purposes. We do not access the content of your backups, except where strictly technically necessary to deliver or restore the service.
2.3 Technical data
For the operation and security of the service, we process limited technical data such as IP address, log files and synchronisation timestamps. We do not use tracking or marketing cookies; only functional cookies that are strictly necessary to log in and operate the application.
3. Why and on what legal basis do we process your data?
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and managing your account | Name, email | Performance of the contract (Art. 6(1)(b)) |
| Providing the backup service | Backup data, technical data | Performance of the contract (Art. 6(1)(b)) |
| Invoicing and accounting | Billing data | Legal obligation (Art. 6(1)(c)) |
| Security and abuse prevention | Logs, IP address | Legitimate interest (Art. 6(1)(f)) |
4. How long do we keep your data?
- Backup data: retained according to the retention settings you configure yourself in your account. You determine the retention period and can adjust it at any time.
- Account and billing data: retained for as long as your account is active. Billing data is retained in accordance with the statutory retention period of seven years.
- Upon termination: when your account is cancelled, your backup data is deleted within 30 days, subject to statutory retention obligations.
5. Who do we share data with?
We never sell your data. We only engage the following sub-processors to deliver the service:
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase (via AWS, eu-central / eu-west) | Hosting of the application and storage of backup data | European Union | Processing within the EEA |
| Stripe | Processing of payments and subscriptions | EU / US | Stripe DPA and EU Standard Contractual Clauses |
We do not transfer your personal data outside the European Economic Area (EEA). The storage of backup data and the application itself take place entirely within the EU. Payment processing through Stripe may involve processing outside the EEA; the EU Standard Contractual Clauses (SCCs) apply to this.
6. How do we secure your data?
We implement appropriate technical and organisational measures to protect your data, including encryption of data in transit and at rest, strict access control, logging and monitoring. Our infrastructure runs on Supabase within the EU.
7. Your rights
Under the GDPR you have the following rights regarding your personal data:
- The right of access to the data we process about you
- The right to rectification of inaccurate data
- The right to erasure ("right to be forgotten")
- The right to restriction of processing
- The right to data portability
- The right to object to processing based on legitimate interest
You can exercise these rights via hello@backup247.app. We will respond within the statutory period of one month. Where your request concerns data held in a backup for which one of our customers is the controller, we will refer you to that customer.
8. Complaints
If you are not satisfied with the way we process your data, you have the right to lodge a complaint with the Belgian Data Protection Authority:
Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), Drukpersstraat 35, 1000 Brussels, contact@apd-gba.be, www.dataprotectionauthority.be
9. Changes to this Policy
We may update this Privacy Policy from time to time. The most recent version is always available at backup247.app. In the event of material changes, we will notify you by email or through the application.
10. Governing law
This Privacy Policy is governed by Belgian law. Any disputes will be submitted to the competent courts of the judicial district of Ghent.
See also our Terms of Service and Cookie Policy.
