Third Party Index

Snapshot 36552

Document
Privacy policy
URL
https://eazbook.acsft.com/privacy
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
16028 bytes
SHA-256 (raw)
b8f2708a3a9ed05fddeecce82e4571ceff35ccf980de07d8f181ec99704bf62e
SHA-256 (normalized text)
8fcae269ee1734cc28b6a04cfc3d6e0b5b965a791f509126d1ad5b8fd4fe991b

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Privacy Policy
Last updated 1 March 2026 · Applies to every ACL Software BV product
This policy explains what personal data ACL Software BV collects when you use any of our products, why we collect it, and what you can do about it. It covers every product in our catalogue, because they all run on the same platform — though each one holds its accounts and its customer data separately.
1. Who we are
ACL Software BV, Chaussée de Nivelles 315, 5020 Namur, Belgium, is the data controller for the account data described below. For the content you store inside our products on behalf of your company, your company is the controller and we act as processor — see our Data Processing Agreement.
2. What we collect
Account data
Your name and email address, so we can identify you and your colleagues can recognise you.
A salted hash of your password. We never store the password itself and cannot recover it.
Session records: an opaque token hash, the approximate time of last use, your browser's user agent and IP address. These let you see and revoke your active sessions.
Company data
The companies you belong to, your role in each, and which products each company has enabled.
Invitations you send or receive, including the invited email address.
Product content
Whatever you and your colleagues put into the products — tasks, bookings, notes and similar. We treat this as your company's data, not ours.
What we deliberately do not collect
No third-party advertising or analytics trackers.
No selling, renting or sharing of personal data with advertisers. Ever.
No profiling and no automated decision-making with legal effects.
3. Why we are allowed to use it
We process account and company data to perform the contract we have with you (Article 6(1)(b) GDPR). We process security-related data such as session and login records on the basis of our legitimate interest in keeping accounts safe (Article 6(1)(f)). Where we rely on consent, you can withdraw it at any time.
4. Cookies
We set exactly one cookie: a signed session cookie on the .acsft.com domain. It identifies one account, on the product that account belongs to. It is HTTP-only, restricted to same-site requests, and it expires after 30 days or when you sign out. We do not use tracking cookies, so we do not show a cookie banner.
5. Who else sees your data
Our hosting and database providers, operating within the European Union, process data on our behalf under written agreements. We do not transfer personal data outside the EEA. We disclose data to authorities only when legally compelled, and we will tell you unless we are forbidden from doing so.
6. How long we keep it
Account data: for as long as your account exists, then deleted within 30 days.
Company content: until your company deletes it or closes the company, then within 30 days.
Session records: until expiry or revocation, whichever comes first.
Backups: rolling 30-day retention, after which deletions become irreversible.
7. Your rights
You have the right to access, correct, erase, restrict and port your personal data, and to object to processing based on legitimate interests. Email privacy@acsft.com and we will respond within one month. You may also complain to the Belgian Data Protection Authority.
8. Security
Passwords are hashed with bcrypt. Session tokens are stored only as HMAC hashes, so a database leak does not hand over live sessions. Access between companies is refused at the API layer rather than the UI layer. Traffic is encrypted in transit. Changing your password signs out every other device.
9. Changes
If we change this policy in a way that materially affects you, we will email account owners at least 30 days before it takes effect.
Questions about this document? Write to privacy@acsft.com. See also our Terms of Service, Privacy Policy and Data Processing Agreement.