Effective date: 17 March 2026
The data controller for personal data collected through the Expedait platform ("Service") is:
Expedait BV is a private limited company (besloten vennootschap / société à responsabilité limitée) incorporated under Belgian law and registered with the Crossroads Bank for Enterprises (KBO/BCE) under enterprise number 1039.524.056 (VAT: BE 1039.524.056).
This policy is provided in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Belgian Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data ("Belgian Framework Act").
You choose which sign-in methods and integrations to enable. We only receive data from a third party when you actively connect it or sign in with it, and you can disconnect at any time. See the GDPR and Data Processing page for the full list.
Providing your data: Account information (name, email, password) is required to use the Service. If you choose not to provide this data, you will not be able to create an account. All other data collection is either part of normal Service usage or optional.
We process your personal data for the following purposes:
| Purpose | Data Used | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Service delivery (authentication, workspace management, content storage) | Account info, profile, content | Contract performance (Art. 6(1)(b)) |
| AI coaching & scoring (sending content to LLM providers) | Page content, chat messages, page type requirements | Contract performance (Art. 6(1)(b)) -AI features are a core part of the Service |
| Product analytics (PostHog) | Usage data, anonymised identifiers | Consent (Art. 6(1)(a)) -opt-in only |
| Security monitoring & fraud prevention | Technical data, access logs | Legitimate interest (Art. 6(1)(f)) -protecting the Service and users |
| Service notifications (invitations, critical updates) | Email address | Contract performance (Art. 6(1)(b)) |
Legitimate interest balancing test: For security monitoring, we have assessed that our interest in preventing unauthorized access and protecting user data outweighs the minimal impact on your privacy, as we only process technical metadata and do not use it for profiling or marketing.
Expedait uses AI/LLM technology for:
These features do not constitute solely automated decision-making with legal or similarly significant effects as defined in GDPR Article 22, because they do not produce binding decisions -scores are guidance, not gatekeepers. If you have concerns about automated processing of your data, you may contact us at support@expedait.org.
In compliance with the Belgian Law of 13 June 2005 (Article 129, transposing the ePrivacy Directive), we distinguish between essential and non-essential cookies:
Your choices: When you first visit the platform, you will be presented with a consent mechanism that allows you to accept or reject analytics tracking. You may change your preference at any time. We provide an equally prominent "Reject All" option alongside "Accept" in compliance with Belgian DPA guidance.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.Personalised email links: If you follow a personalised link from an email we send and accept analytics cookies on our website, we may associate that visit with your contact record via your email. Without consent, website analytics remain anonymous.
We do not use advertising cookies, marketing trackers, or sell your data to third parties.
We share data with third-party service providers solely to deliver the Service. We have entered into Data Processing Agreements (DPAs) with each sub-processor as required by GDPR Article 28. For the complete list of sub-processors, data shared, retention periods, and international transfer safeguards, see our GDPR & Data Processing page.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.Customer relationship management (CRM): We sync your contact details and the usage and activation metrics described above to our CRM (Attio) under a Data Processing Agreement, to manage the customer relationship and product communications. Attio is listed as a sub-processor on our GDPR & Data Processing page.
Some of these services are integrations you choose to connect (for example Notion, Jira and Confluence, Linear, Google Drive, GitHub and Azure DevOps) or sign-in providers you choose to use. You decide which to enable, and that choice determines what is processed. When you connect a third-party tool, your data is also processed by that provider under its own terms and transfer safeguards. See the GDPR and Data Processing page for details.
AI assistant access (MCP): You can also connect external AI assistants you authorise — such as Claude or ChatGPT — to your workspace through our Model Context Protocol (MCP) endpoint (mcp.expedait.org). Access requires you to sign in and explicitly grant permissions via OAuth, the assistant can then read (and, with your permission, write) workspace content on your behalf, and you can revoke that access at any time.
We implement appropriate technical and organisational measures to protect your data (GDPR Article 32), including:
Several of our sub-processors are based in the United States. When your data is transferred outside the European Economic Area (EEA), we rely on the following safeguards in accordance with GDPR Chapter V:
| Provider | Transfer Safeguard |
|---|---|
| OpenAI | EU-US Data Privacy Framework (DPF certified) |
| Google (Gemini, OAuth) | EU-US Data Privacy Framework (DPF certified) |
| GitHub (Microsoft) | EU-US Data Privacy Framework (DPF certified) |
| Notion | EU-US Data Privacy Framework (DPF certified) |
| Anthropic | Standard Contractual Clauses (SCCs) + Transfer Impact Assessment |
| PostHog | Standard Contractual Clauses (SCCs) + Transfer Impact Assessment |
Where you connect an optional integration (such as Notion, Jira and Confluence, Linear, Google Drive, GitHub or Azure DevOps) or sign in with a third-party provider, any transfer of your data outside the EEA is governed by that provider's own terms and transfer safeguards. Please review the provider's privacy policy before connecting.
We periodically verify that our US-based processors maintain their DPF certifications and review the adequacy of transfer safeguards. You may request a copy of the relevant SCCs by contacting support@expedait.org.
We retain your data only as long as necessary for the purposes described in this policy. For specific retention periods per data category, see our GDPR & Data Processing page.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.Usage and activation metrics and CRM records are retained for the life of your account and deleted or anonymised within 90 days of account closure or an erasure request. Product analytics events are retained in PostHog per our analytics provider's configured retention period.
Expedait is a B2B platform not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@expedait.org and we will take steps to delete it.
Under the GDPR, you have extensive rights regarding your personal data, including the right to access, rectify, erase, restrict, port, and object to processing. For a full description of your rights and how to exercise them, see our GDPR & Data Processing page.
You may lodge a complaint with the Belgian Data Protection Authority (GBA/APD) at any time -see our GDPR page for full contact details.
We may update this Privacy Policy from time to time. We will notify users of material changes at least 30 days in advance via email or through the Service. The "Effective date" at the top of this page indicates when the policy was last revised.
For privacy-related enquiries, please contact us at:
Expedait BV
Walenstraat 35, 3310 Rotselaar, Belgium
Email:support@expedait.org