Data Protection Policy (GDPR)

Last updated: April 2026

1. Data Controller

APP3 BV acts as the data controller for personal data processed through Billit Connect.

Contact: privacy@app3.be

2. Data Processing Overview

Data CategoryPurposeLegal BasisRetention
Shopify order data (name, email, address, amounts)Invoice creation in BillitContract performanceDuration of installation + 30 days
VAT numbersB2B classification & reverse chargeContract performanceDuration of installation + 30 days
Admin credentials (email, hashed password)Platform access controlContract performanceUntil account deletion
Session tokensAuthenticationContract performance7 days (auto-pruned)
IP addresses, browser infoSecurity & error loggingLegitimate interest90 days
Language preference cookieUser experienceConsent1 year

3. Sub-Processors

Sub-ProcessorPurposeLocation
Billit (Silverfin NV)Invoice creation & e-invoicingBelgium (EU)
Shopify Inc.E-commerce platform (data source)Canada / EU
Server hosting providerApplication & database hostingEU

4. Data Subject Rights

Under the GDPR (and the Belgian equivalent, the Data Protection Act), you have the following rights:

To exercise any right, email privacy@app3.be. We will respond within 30 days.

5. Data Breach Procedure

In the event of a personal data breach, we will:

6. International Transfers

Your data is primarily processed within the EU/EEA. When Shopify processes data in Canada, this is covered by the EU adequacy decision for Canada. We do not transfer data to countries without adequate protection unless appropriate safeguards (such as Standard Contractual Clauses) are in place.

7. Security Measures

8. Data Protection Officer

For data protection inquiries, contact:
APP3 BV — Data Protection
Email: privacy@app3.be

9. Supervisory Authority

You have the right to lodge a complaint with the Belgian Data Protection Authority:
Gegevensbeschermingsautoriteit (GBA)
Drukpersstraat 35, 1000 Brussels
www.gegevensbeschermingsautoriteit.be