Snapshot 19845
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to content
Privacy Policy
Last updated: September 26, 2026
Organize IT SRL ("we", "our"), publisher of the UpBoard.ai platform, is committed to protecting the privacy of its users in accordance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679).
1. Data Controller
Organize IT SRL
Rue du Mont-Lassy 54, 1380 Lasne, Belgium
Company number: 0650.555.046
Email: [email protected]
2. Data Collected
2.1 Registration Data
First and last name
Professional email address
Company name
Password (stored in hashed form)
2.2 Usage Data
Conversations with AI agents
Preferences and settings
Technical logs (sign-ins, errors): email addresses, phone numbers, IBANs and national ID numbers are masked in them
Usage metrics (number of messages, tokens consumed)
2.3 ERP Data
Data from your ERP (Odoo) is queried in real time: we do not copy your database. We only keep analysis results (alerts, scores), your agents' contextual memory and your ERP connection credentials, encrypted (Fernet). Retention periods are listed in section 7.
2.4 Public diagnostic (free scan)
The free diagnostic can be run without creating an account. To run it, you give us your Odoo address, the database name, the login used and an API key (or a password). We keep:
the resulting score and its breakdown by module;
the list of detected anomalies, with the reference of the document concerned, the amount and the related party (for example the name of a customer or a salesperson), deleted 30 days after the diagnostic;
your Odoo address, the database name and the login used, deleted 30 days after the diagnostic unless you create an account;
your contact details (name, email, company) if you choose to leave them, the date and time of your agreement to receive the result, and, separately, the date and time of your agreement to receive commercial updates.
The API key or password is never saved to our database during the diagnostic: it only lives in an encrypted token that becomes unusable after 30 minutes. After a successful diagnostic, your Odoo access stays encrypted for 30 minutes at most after launch, to connect your account if you create and connect it within that time; otherwise it is erased. If you connect your account this way, this access becomes that account's Odoo connection, kept encrypted like any connection.
The form offers two separate boxes. The first one, required to receive your report, allows us to process your contact details and send you the diagnostic result. The second one, optional and unticked by default, allows us to send commercial updates about UpBoard. You receive your report even if you only tick the first one.
If you leave your contact details, they are sent, with your score and the main anomalies, to our sales management tool (Odoo, installed on a server we run ourselves, with no third party involved) so we can follow up on your request. We only send commercial follow-ups if you ticked the second box: at most three emails (1, 3 and 7 days after the diagnostic). Each follow-up contains a one-click unsubscribe link that takes effect immediately: no further follow-up is sent to you.
If you started a trial without subscribing, we write to you at most three times after it ends (3, 14 and 30 days later), to remind you of what the trial found and to present our plans. Each of these emails contains a one-click unsubscribe link. One week before your data is deleted, we also send you a notice giving the date: that notice is about your data, so it is sent to you even after an unsubscribe.
3. Legal Basis for Processing
Contract performance: processing necessary for service delivery, and for the diagnostic you request (pre-contractual steps taken at your request)
Legitimate interest: service improvement, security, and follow-ups after a trial that ended without a subscription (an existing business relationship, with an unsubscribe available at any time)
Consent: sending the diagnostic result to your contact details, commercial follow-up emails (a separate, optional consent), and website audience measurement (Google Analytics). You can withdraw your consent at any time, as easily as you gave it.
4. Processing Purposes
Providing and improving the UpBoard.ai service
Authentication and user account management
Secure connection to ERP systems
Running the free diagnostic and following up on your request
Billing and subscription management
Website audience measurement, with your consent
Technical support
5. Sub-processors
Service Provider Location Purpose
Hosting Infomaniak Switzerland Server and database hosting
AI Anthropic United States AI Agents (Claude)
AI OpenAI United States Semantic indexing of agent memory (embeddings)
Payment Stripe United States Payment processing and retention of billing data
Email Brevo France Transactional emails and diagnostic follow-ups
Monitoring Sentry United States Error tracking
Backups Google (Google Drive) United States Off-site copy of backups, encrypted before upload
Audience measurement Google Ireland Limited (Google Tag Manager, Google Analytics) Ireland, possible transfers to the United States Website traffic statistics, only after your consent
Bot protection Cloudflare (Turnstile) United States Protecting the contact and partner forms, and the free diagnostic, against bots
Transfers to the United States are governed by Standard Contractual Clauses (SCCs) approved by the European Commission.
For the personal data you process through the service, in particular data from your ERP, we act as a processor within the meaning of Article 28 of the GDPR. Our commitments in that capacity, and how this sub-processor list ties into them, are set out in the data processing agreement (DPA).
6. Cookies and trackers
The website only sets the cookies below. Audience measurement cookies are set, and Google Tag Manager is loaded, only after your consent ("Accept all" or the "Audience measurement" category). Without your consent, no request is sent to Google. We use no advertising cookies.
Cookie Purpose Type Duration
cookie_consent Remember your cookie choices Necessary 13 months
NEXT_LOCALE Remember your language (French or English) Necessary 12 months
refresh_token Keep your session alive while you are signed in to your account Necessary 7 days
_ga, _ga_<identifier> Google Analytics: distinguish visitors and sessions Audience measurement, subject to consent 2 years
For signed-in users, your browser's local storage also keeps the session token and display preferences. No third party reads it.
You can change or withdraw your consent at any time with the "Cookie settings" link in the footer, or with this button. On withdrawal, the Google Analytics cookies are deleted and Google Tag Manager is no longer loaded.
7. Data Retention
Public diagnostic that stayed anonymous (no contact details left): deleted 30 days after the diagnostic.
Public diagnostic with contact details, no account created: deleted 12 months after the diagnostic, or 30 days after you unsubscribe from the follow-ups if that comes first.
Diagnostic from which you created an account: attached to the account and deleted with it.
Active account: account data is kept while the subscription or trial is running.
Subscription ended or trial expired without subscribing: all account data (users, ERP connections, conversations, analysis results, agent memory) is deleted 90 days after the end of the subscription or trial, unless you subscribed in the meantime.
Sign-up never completed (no trial started, no subscription): deleted 90 days after it was created.
Contact details sent to our sales management tool: kept while the business relationship is active, and deleted on request at [email protected]. They are not covered by the automatic deletions above.
Billing data: the data the law requires to be kept is kept by Stripe, our payment provider, not by us.
You can also ask for your data to be deleted at any time (section 8). Deleted data then disappears from our encrypted backups as they rotate.
8. Your Rights
Under the GDPR, you have the following rights:
Access: obtain a copy of your personal data
Rectification: correct inaccurate data
Erasure: request deletion of your data
Portability: receive your data in a structured format
Objection: object to the processing of your data
Restriction: restrict the processing of your data
Withdrawal of consent: at any time, for follow-up emails (unsubscribe link) and for cookies ("Cookie settings")
To exercise your rights, contact us at: [email protected]
9. Security
We implement the following security measures:
TLS encryption for all communications
Fernet encryption of ERP credentials
bcrypt hashing of passwords
Two-factor authentication with a code sent by email, off by default: each user can turn it on, and an admin can require it for the whole organisation
Data isolation by tenant (multi-tenancy)
Access and action logging
10. Supervisory Authority
You have the right to lodge a complaint with the Belgian Data Protection Authority (DPA): www.autoriteprotectiondonnees.be
11. Contact
For any questions regarding this policy: [email protected]