Privacy Policy

Last updated: 23 August 2026

This policy explains how Hivexel processes personal data in Hivexel Compliance (https://comply.hivexel.com) and on https://hivexel.com. It complements the Terms of Service, the DPA and the Cookie Policy. Contact: [email protected].

1. Who we are

The controller for account, billing, support and marketing data of the Service is Hivexel, identifiable via https://hivexel.com and https://comply.hivexel.com and the email [email protected].

We do not publish a tax identification number or registered office in this document. Those details, where the law requires them (including so you can exercise your rights or for invoicing), are provided on request to the email above and appear on invoices. You may also lodge a complaint with the CNPD.

We have not appointed a data protection officer (DPO). The contact for exercising your rights is the email above.

2. Two roles: controller and processor

Account and commercial data. When we process name, email, credentials, plan, payments, language, security logs and communications with us, Hivexel acts as controller (GDPR Art. 4(7)).

Customer Data. When the organisation uploads or enters data about employees, contractors, suppliers, equipment and evidence files, the customer organisation is the controller and Hivexel is a processor (Art. 28). That processing is described in the DPA, which forms part of the contract.

3. Data we process as controller

We process only what we need to provide and improve the Service:

  • account identity: name, email, password (stored irreversibly by the authentication provider), organisation and permissions;
  • use of the Service: role, language, last active date, product events (for example “account created”, “document uploaded”) without file contents;
  • billing: email, organisation identity, plan, subscription status and Stripe identifiers;
  • campaign attribution, only with advertising-cookie consent: click identifiers (gclid/gbraid/wbraid) and UTM parameters linked to the account;
  • security: IP address, timestamps, session tokens and anti-bot verification (Cloudflare Turnstile);
  • communications: transactional email (account confirmation, invites, password reset, deadline alerts you configured, weekly digest if enabled) and support replies.

4. Customer Data (we act as processor)

The organisation may record, among other things: names, contacts, internal numbers, job titles, dates, notes, supplier tax IDs, and files (PDF, images, DOCX) linked to obligations. The legal basis for that processing is the customer organisation’s, not ours.

The Service includes templates such as occupational medical-fitness certificates. If the customer uses them, it may be processing health data (special category, GDPR Art. 9). Only the customer can decide whether to do so and on what ground. We do not use those files to train AI models or for advertising.

5. Purposes and legal bases (when we are controller)

  • Providing the Service, authentication, hosting account data and performing the contract — Art. 6(1)(b);
  • Invoicing, accounting and tax duties — Art. 6(1)(c);
  • Security, abuse prevention and product improvement (usage events without document contents) — legitimate interest, Art. 6(1)(f);
  • Analytics and advertising cookies, and sending ad click identifiers to Google — consent, Art. 6(1)(a) and Portuguese ePrivacy law; you may withdraw consent at any time (see Cookies);
  • Responding to support and GDPR rights requests — Art. 6(1)(c) and 6(1)(b).

You may object to legitimate-interest processing by writing to [email protected]. Legitimate interest does not apply to Customer Data: there we follow the organisation’s instructions under the DPA.

6. Recipients and subprocessors

We use providers strictly needed to run the Service. The current list is in the DPA. In short: hosting and database, authentication and files, payments (Stripe), email (Brevo), background jobs, anti-bot protection, product analytics, and — only with consent — Google Analytics and Google Ads.

We do not sell personal data. We may disclose data if the law requires it or to defend rights in legal proceedings.

7. International transfers

Some providers (including Google, Stripe, Supabase or Cloudflare) may process data outside the EEA. Where that happens we require appropriate safeguards, typically the European Commission’s standard contractual clauses, plus supplementary measures the provider offers. We request EU regions when the supplier allows it.

8. Retention

  • Account data and Customer Data: while the organisation is active and, after a closure request, any residual time needed for backups and legal duties;
  • Billing: the statutory retention period for accounting records in Portugal (typically 10 years);
  • Security logs: as needed to investigate incidents (typically up to 12 months);
  • Cookie preference: 180 days;
  • Campaign attribution (with consent): 90 days;
  • Google Analytics: according to the property settings (no longer than needed).

To delete an organisation or exercise the right to erasure, write to [email protected]. Some data may have to be kept if the law requires it (for example invoices).

9. Your rights

When Hivexel is the controller, you may request access, rectification, erasure, restriction, portability and objection, and withdraw consent without affecting the lawfulness of prior processing. Write to [email protected]. We will respond within the legal time limit (typically one month).

If the data sits in Customer Data (for example an employee record in your employer’s organisation), address the request to the customer organisation. If you contact us, we will forward it to the organisation under the DPA, unless the law prevents us.

You have the right to lodge a complaint with the Portuguese supervisory authority (cnpd.pt).

10. Cookies

We use cookies that are necessary for the Service to work and, only if you accept, analytics and advertising cookies. Details, the list and how to change your choice are in the Cookie Policy. Declining is as easy as accepting.

11. Security

We apply measures appropriate to the risk: encrypted transport (HTTPS), isolation between organisations in the database (RLS policies), role-based access, and file access through the authenticated Service. No system is infallible; if we become aware of an incident that affects you, we will notify you as required by law and the DPA.

12. Children

The Service is intended for adult professional users. We do not knowingly collect data from children to create accounts. If an organisation uploads children’s data as Customer Data, the lawfulness of that processing is the organisation’s responsibility.

13. Changes

We may update this policy. The date at the top and version 2026-08-23.2 change when the text changes. Material changes will be announced by email or in the product.