1. Who is responsible
AZ Technologies SRL is the controller for Renovae's website, pilot applications, business contacts, administration, security, billing, and service-account data. Contact: hello@aztechnologies.be. Full company details are in the Legal Notice.
For photographs, panoramas, property information, and other content uploaded by a customer on behalf of its agency, seller, landlord, developer, or client, the customer normally decides why that data is used and acts as controller. AZ Technologies SRL then acts as processor under the Data Processing Addendum.
2. Data we process
- Business contacts: name, agency, business email, telephone number, messages, and pilot or sales history.
- Workspace data: company, invitation, project, property, room, access, publication, and configuration information.
- Customer content: uploaded photographs and panoramas, prompts, renovation preferences, AI outputs, thumbnails, and exported tours.
- Technical and security data: IP address, request and error logs, device/browser information, authentication and session identifiers, and Turnstile anti-abuse signals.
- Usage and commercial data: generation requests, model/provider, token or credit consumption, estimated provider cost, timestamps, status, and billing or VAT information where applicable.
- Support data: communications, issue reports, and material voluntarily supplied to diagnose a problem.
3. Purposes and legal bases
- To review pilot applications and take steps requested before a contract: pre-contractual measures.
- To provide workspaces, generations, storage, publication, support, and billing: performance of a contract.
- To secure the service, prevent abuse, measure provider costs, improve reliability, and manage B2B relationships: our legitimate interests, balanced against affected rights.
- To keep accounting, tax, compliance, and dispute records: legal obligations and establishment, exercise, or defence of legal claims.
- To send optional marketing where legally required: consent, which can be withdrawn. We do not treat a pilot application as consent to unrelated marketing.
4. Providers and transfers
We disclose data only where needed to operate the service, comply with law, protect rights, or complete a business transaction subject to appropriate safeguards. Current service providers may include Vercel for hosting, Neon for PostgreSQL, Cloudflare for R2 storage and Turnstile security, Clerk for administrator authentication, Resend for email delivery, and OpenAI for AI image processing.
Some providers may process data outside the European Economic Area. We rely on an adequacy decision where available or contractual safeguards such as the European Commission's standard contractual clauses and the provider's data-processing terms. Provider locations and subprocessors may change; the DPA explains the notice process for material changes.
OpenAI states that API data is not used to train its models by default. Depending on the endpoint and account controls, provider abuse-monitoring logs may retain submitted content for up to 30 days. Customers should therefore avoid unnecessary personal or confidential information in images and prompts.
5. Retention schedule
We keep personal data only as long as needed for the stated purpose, then delete or irreversibly anonymize it unless law or an active dispute requires longer retention.
- Unsuccessful or inactive pilot applications: up to 12 months after the last meaningful contact.
- Business relationship and support records: for the relationship and up to 24 months afterward, unless needed longer for a claim.
- Workspace content and AI outputs: while the workspace or invitation is active; normally deleted from active storage within 30 days after expiry, revocation, termination, or a valid deletion request.
- Deleted or expired content in encrypted backups: overwritten through the backup cycle, normally within 90 days.
- Session and invitation data: until expiry or revocation, then retained only where necessary for security and audit records, normally no longer than 12 months.
- Security, request, and error logs: normally up to 12 months, or longer where required to investigate an incident.
- Generation usage and cost records: normally 24 months; aggregated records that no longer identify a person may be kept longer.
- Invoices, accounting, VAT, and legally required records: for the applicable Belgian statutory retention period.
- OpenAI processing copies: subject to the provider controls described above, potentially up to 30 days after an API request.
6. Your rights
Depending on the circumstances, an individual may ask for access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Consent can be withdrawn without affecting earlier lawful processing. We may need to verify identity and may direct a request to the customer where that customer is the controller.
Send requests to hello@aztechnologies.be. You may also complain to the Belgian Data Protection Authority at dataprotectionauthority.be. We do not use Renovae data for solely automated decisions that produce legal or similarly significant effects on individuals.
7. Security and incidents
We use measures intended to protect data, including scoped access, hashed invitation/session tokens in the database, secure cookies, provider access controls, and separated storage. No internet service is risk-free. Customers must control who receives invitation and publication links and notify us promptly of suspected compromise.
8. B2B service and changes
Renovae is intended for professional users and not for children. We may update this policy when the service, providers, or law changes. The current version and effective date will remain available here.