Privacy notice

Draft for review. This describes what the service actually does with your data today, written to be checked rather than to look reassuring. It has not been reviewed by a privacy lawyer and will be replaced before commercial launch.

Last updated: not yet published.

Controller

Qmino BV, Belgium (VAT BE 0000.000.000 — placeholder). Questions and requests: support@nbb-mcp.be.

What we collect

Data Why Legal basis Kept
Your email address It is your account identity and the only way to sign in. Performance of the contract Until you ask for deletion
Sign-in tokens (hashed) To verify a magic link once and only once. Performance of the contract Deleted shortly after expiry
API keys (hashed) To authenticate tool calls. We cannot recover a key, only replace it. Performance of the contract Until revoked, then as usage history
Usage metadata — which tool, when, whether it was billable Quota enforcement, billing, and diagnosing failures. Performance of the contract; legitimate interest in preventing abuse Retained as billing records
Billing data (name, address, VAT number, payment method) Invoicing and tax. Held by Stripe; we see the invoice, not your card. Legal obligation (accounting) and contract 7 years, as Belgian bookkeeping law requires
Server logs, including IP address Security, rate limiting and debugging. Legitimate interest Short-lived; not used to profile you

We do not use tracking cookies, analytics or advertising. The only cookie the site sets is the session cookie created when you sign in, and it exists to keep you signed in.

The company data the service returns is public register data about legal entities. It is not personal data about you, and we do not record which companies you looked up beyond the tool name needed for metering.

Processors we use

Processor What for What it sees
Contabo (Germany) Hosting the application and its database Everything the service stores
Brevo (France) Sending sign-in mails Your email address and the mail content
Stripe (Ireland / United States) Subscription payments, invoices and tax Your billing details; only for paid accounts
OpenAI (United States) Reading PDF-only filings into structured data The public filing document only — never your email address, key or usage. Paid plan only, and only for filings the National Bank publishes as PDF.

Transfers outside the EEA (Stripe, OpenAI) rely on the European Commission's standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.

Your rights

Under the GDPR you can ask for access to your data, correction, erasure, restriction, a portable copy, or object to processing based on legitimate interest. Mail support@nbb-mcp.be from the address on the account and we will act within one month.

Deletion removes your account, your keys and your sign-in tokens. Invoices and the usage rows they are based on are kept for the statutory bookkeeping period — we are not allowed to delete accounting records on request, and we will tell you exactly what remains.

You can also complain to the Belgian Data Protection Authority (gegevensbeschermingsautoriteit.be), or to the authority where you live.

How we protect it

If we ever discover a breach affecting your data, we will notify you and the supervisory authority as the GDPR requires.