Informative Version – Reference Language: French
This document is a courtesy translation of the Privacy Policy of DS Solutions SRL, provided solely for the user's comfort and reading convenience. Only the original French version has binding legal value and binds the parties. In the event of any contradiction, dispute, or ambiguity in interpretation between this translation and the French version, the French version shall exclusively prevail.
1. PREAMBLE
This Privacy Policy (the "Policy") describes the conditions under which DS Solutions SRL (hereinafter the "Data Controller", "DS Solutions", "we" or "us") collects, uses, retains, protects and processes personal data within the framework of providing the Mellio SaaS platform (the "Services").
The protection of personal data is a priority for DS Solutions.
We are committed to processing personal data in accordance with:
- Regulation (EU) 2016/679 of 27 April 2016 (GDPR);
- applicable Belgian legislation;
- as well as the recommendations of the Data Protection Authority (DPA).
This Policy is an integral part of our contractual environment but does not replace the SaaS Agreement or the Data Processing Agreement (DPA), which govern the processing carried out on behalf of our professional Clients.
2. SCOPE OF APPLICATION
This Policy applies to the processing of personal data carried out by DS Solutions when acting as Data Controller, particularly concerning:
- website visitors;
- prospects;
- client agencies;
- their representatives;
- platform administrator users;
- individuals contacting our support.
Conversely, when data is processed in the platform on behalf of an Agency (for example, data relating to merchants, end customers, loyalty cards, or loyalty programs), DS Solutions acts primarily as a Data Processor within the meaning of Article 28 of the GDPR.
These processing activities are governed by the Data Processing Agreement (DPA) concluded with each Agency.
3. DEFINITIONS
For the purposes of this Policy:
-
Agency
The professional client who has subscribed to the Services.
-
Merchant
The client of the Agency using a sub-account of the platform.
-
User
Any natural person using the Services.
-
Personal Data
Any information relating to an identified or identifiable natural person.
-
Processing
Any operation performed on personal data (collection, consultation, retention, modification, deletion, etc.).
-
GDPR
Regulation (EU) 2016/679 of the European Parliament and of the Council.
4. DATA CONTROLLER
The Data Controller is:
DS Solutions SRL
Registered office: [to be completed]
Belgium
CBE: [to be completed]
Email: privacy@...
Website: https://...
For any questions relating to the processing of personal data, you can contact us at this address.
If a Data Protection Officer (DPO) is subsequently appointed, their contact details will be published on our website.
5. WHEN ARE WE THE DATA CONTROLLER?
DS Solutions acts as Data Controller particularly for:
- creating Agency accounts;
- managing subscriptions;
- invoicing;
- accounting;
- managing payments;
- managing prospects;
- demonstration requests;
- requests addressed to support;
- platform security;
- technical logs;
- legal obligations.
In these situations, DS Solutions determines the purposes and means of the processing itself.
6. WHEN DO WE ACT AS A DATA PROCESSOR?
When Agencies use Mellio to manage their own merchants and the end users of their loyalty programs, DS Solutions acts primarily as a Data Processor.
This particularly concerns:
- merchant data;
- merchant customer data;
- digital loyalty cards;
- point histories;
- rewards;
- loyalty campaigns;
- information imported by the Agency.
In these processing activities:
- the Agency remains the Data Controller;
- DS Solutions acts exclusively on the documented instructions of the Agency, in accordance with the DPA.
DS Solutions never uses this data for its own commercial purposes.
7. OUR PROCESSING PRINCIPLES
DS Solutions applies the following principles to all of its processing activities:
lawfulness, fairness, transparency, data minimization, accuracy, purpose limitation, storage limitation, integrity, confidentiality, and accountability.
We only collect data that is strictly necessary for the purposes pursued.
8. CATEGORIES OF DATA COLLECTED
Depending on the Services used, we may process the following categories of data.
8.1 Identification data
- last name;
- first name;
- function/title;
- company;
- company number;
- VAT number;
- professional contact details.
8.2 Contact details
- professional email address;
- phone number;
- professional postal address.
8.3 Contractual data
- subscription;
- order history;
- quotes;
- contracts;
- invoices;
- payments.
8.4 Connection data
We notably record:
- IP address;
- date and time of connection;
- browser;
- operating system;
- user ID;
- security logs;
- administration logs;
- technical information necessary for securing the Services.
This information is primarily used to:
- ensure security;
- detect fraud;
- analyze incidents;
- guarantee the stability of the Services.
8.5 Support data
When you contact our support, we may retain:
- email exchanges;
- transmitted screenshots;
- diagnostic files;
- information allowing us to resolve your request.
8.6 Payment data
Payments are processed by our specialized service provider.
DS Solutions never stores full bank card numbers.
We only retain the necessary information:
- payment status;
- transaction reference;
- billing history.
8.7 Technical data
Depending on the features used:
- technical identifiers;
- configuration settings;
- activity logs;
- user preferences.
9. DATA WE DO NOT COLLECT
DS Solutions does not voluntarily collect:
- any sensitive data within the meaning of Article 9 of the GDPR;
- any biometric data;
- any health data;
- any data relating to criminal convictions.
The Services are exclusively intended for professionals.
They are not designed to be used by minors under 18 years of age.
10. PURPOSES OF THE PROCESSING
DS Solutions processes personal data only for specified, explicit and legitimate purposes.
The main purposes pursued are as follows:
| Purpose |
Legal basis |
| Creation and management of accounts |
Performance of the contract |
| Provision of SaaS Services |
Performance of the contract |
| Subscription management |
Performance of the contract |
| Payment management |
Performance of the contract |
| Billing management |
Legal obligation |
| Technical support |
Performance of the contract |
| Platform security |
Legitimate interest |
| Fraud detection |
Legitimate interest |
| Access logging |
Legitimate interest |
| Backups |
Legitimate interest |
| Compliance with accounting obligations |
Legal obligation |
| Management of contact requests |
Pre-contractual measures |
| Response to competent authorities |
Legal obligation |
| Defense of our legal rights |
Legitimate interest |
We never process personal data for a purpose incompatible with those described above.
11. LEGAL BASES
In accordance with Article 6 of the GDPR, processing activities are based on one or more of the following legal bases.
11.1 Performance of the contract
The majority of the processing is necessary in order to:
- create the Client account;
- provide the Services;
- provide support;
- manage payments;
- administer the subscription.
Without these processing activities, the Services could not be provided.
11.2 Legal obligations
Certain data is retained in order to satisfy in particular:
- accounting obligations;
- tax obligations;
- obligations imposed by public authorities.
11.3 Legitimate interest
DS Solutions pursues several legitimate interests, including:
- protecting the security of the Services;
- preventing fraud;
- ensuring platform stability;
- detecting cyber attacks;
- improving performance;
- ensuring the continuity of the Services;
- defending its rights in court.
When this legal basis is used, we ensure that we safeguard the rights and freedoms of the data subjects.
11.4 Consent
When consent is required by regulations, particularly for certain non-essential cookies or certain marketing communications, it is obtained beforehand.
Consent can be withdrawn at any time.
12. DATA RECIPIENTS
Personal data is only accessible to persons who need to know it as part of their duties.
This may include in particular:
- authorized employees of DS Solutions;
- subcontractors acting on our behalf;
- public authorities when required by law;
- legal or accounting advisors in the context of their missions.
We never sell, rent, or market personal data.
13. SUBCONTRACTORS
To ensure the operation of the Services, DS Solutions uses several specialized subcontractors.
As of the publication date of this Policy, the main subcontractors are as follows:
| Subcontractor |
Main purpose |
| Clever Cloud |
Platform hosting |
| Mollie |
Payment processing |
| Brevo |
Sending transactional emails |
| Google reCAPTCHA |
Protection against automated abuse |
| Apple Wallet |
Generation and management of Wallet cards |
| Google Wallet |
Generation and management of Wallet cards |
This list may evolve to reflect the evolution of the Services.
Any new subcontractor is selected with the level of diligence reasonably expected of a professional service provider.
When required by the GDPR, a contract compliant with Article 28 is concluded with each of them.
14. INTERNATIONAL TRANSFERS
The main production infrastructures are hosted within the European Union.
However, some of our subcontractors may be required to carry out processing involving a transfer of data outside the European Economic Area.
When such transfers exist, DS Solutions ensures that they are based on one of the mechanisms provided for by Chapter V of the GDPR, notably:
- an adequacy decision by the European Commission;
- Standard Contractual Clauses;
- any other appropriate safeguard provided by the GDPR.
We ensure that these transfers offer a level of protection substantially equivalent to that guaranteed within the European Union.
15. SECURITY MEASURES
DS Solutions implements technical and organizational measures designed to protect personal data against:
- accidental or unlawful destruction;
- loss;
- alteration;
- unauthorized disclosure;
- unauthorized access.
These measures include in particular:
- encryption of communications via HTTPS and TLS 1.3;
- encryption of storage volumes by AES-256 (LUKS2) or equivalent technology;
- user authentication;
- access control based on the principle of least privilege;
- logging of administrator accesses;
- daily backups;
- infrastructure monitoring;
- regular updates of software components;
- limiting access to authorized persons only.
Security measures are regularly re-evaluated to account for changes in risks and the state of the art.
16. CONFIDENTIALITY
DS Solutions' employees and persons authorized to access personal data are subject to a confidentiality obligation.
Access to data is limited strictly to those persons whose duties require such access.
The subcontractors we use are also subject to contractual confidentiality obligations.
17. DATA BREACHES
In the event of a personal data breach likely to result in a risk to the rights and freedoms of the data subjects, DS Solutions implements the procedures provided by the GDPR.
When DS Solutions acts as Data Controller, it notifies, if applicable:
- the competent Data Protection Authority within legal deadlines;
- the data subjects when required by regulations.
When DS Solutions acts as a Data Processor, it informs the Data Controller as soon as possible after becoming aware of the breach, to enable them to comply with their own legal obligations.
18. AUTOMATED DECISION-MAKING
DS Solutions does not make any decisions producing legal effects based solely on automated processing within the meaning of Article 22 of the GDPR.
19. DATA RETENTION PERIOD
DS Solutions retains personal data only for the time necessary to fulfill the purposes pursued and comply with its legal obligations.
The main retention periods are as follows:
| Category |
Duration |
| Agency account |
For the entire duration of the contract |
| Billing data |
7 years (Belgian legal obligation) |
| Payments |
7 years |
| Contracts and quotes |
10 years after the end of the contractual relationship |
| Support tickets |
3 years after closure |
| Technical logs |
12 months maximum, unless required for security or legal obligations |
| Backups |
Rotation up to 30 days maximum, except for exceptional technical necessity |
| Prospect data |
3 years after last contact, unless opposed or requested for deletion |
When legal periods expire, the data is securely deleted or anonymized.
20. END OF CONTRACT
At the end of the contractual relationship:
- accounts are deactivated in accordance with the SaaS Agreement;
- data is retained during the contractual reversibility period (30 days), to allow the Client to organize the migration or deletion of their data;
- at the end of this period, the data is deleted or anonymized, unless retention is required by law or necessary for the defense of DS Solutions' rights.
The modalities applicable to data processed on behalf of Agencies are detailed in the Data Processing Agreement (DPA).
21. YOUR RIGHTS
In accordance with the GDPR, you have the following rights.
21.1 Right of access
Obtain confirmation that personal data concerning you is processed and a copy of it.
21.2 Right to rectification
Have any inaccurate or incomplete data corrected.
21.3 Right to erasure
Obtain the erasure of your data when the conditions provided by the GDPR are met.
However, this right is not absolute and may be limited by legal or contractual obligations.
21.4 Right to restriction of processing
Request the temporary suspension of certain processing in the cases provided by regulations.
21.5 Right to object
Object to certain processing based on our legitimate interest.
We will review each request in accordance with the GDPR.
21.6 Right to data portability
Receive the data you have provided to us in a structured, commonly used and machine-readable format when the conditions provided by the GDPR are met.
21.7 Withdrawal of consent
When the processing is based on your consent, it can be withdrawn at any time.
This withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
22. EXERCISING YOUR RIGHTS
Requests related to the exercise of your rights can be sent to:
DS Solutions SRL
Email: privacy@...
To protect personal data, DS Solutions may request additional information when reasonably necessary to verify the identity of the requester.
No systematic copy of an identity document is required.
Requests are processed within the time limits provided by the GDPR.
23. COMPLAINTS
If you believe that your personal data is not being processed in accordance with applicable regulations, you can file a complaint with the competent authority.
In Belgium:
Data Protection Authority (DPA)
Rue de la Presse 35
1000 Brussels
Belgium
https://www.autoriteprotectiondonnees.be
However, we invite you to contact us first in order to seek an amicable solution.
24. COOKIES AND SIMILAR TECHNOLOGIES
The website and platform may use cookies or similar technologies notably to:
- ensure the technical functioning of the Services;
- secure forms (Google reCAPTCHA);
- maintain user sessions;
- remember certain preferences.
Processing related to cookies is described in our , available on our website.
When regulations require it, your consent is obtained before depositing non-essential cookies.
25. ACCOUNT SECURITY
Each user is responsible for the confidentiality of their login credentials.
Voluntary sharing of a user account is not recommended and may engage the Client's responsibility.
Any suspicion of fraudulent use must be reported immediately to DS Solutions.
26. CHANGES TO THIS POLICY
DS Solutions may modify this Policy notably to:
- take into account legislative changes;
- integrate new Services;
- reflect changes in its processing activities;
- improve its compliance.
The applicable version is the one published on our website on the date of consultation.
In the event of a substantial modification, affected Clients will be informed by an appropriate means.
27. APPLICABLE LAW
This Policy is governed by Belgian law.
Any dispute relating to its interpretation or execution falls under the jurisdiction of the Belgian courts, subject to applicable mandatory rules on data protection.