Privacy Policy
- Version
- 1.1
- In effect from
- 05 October 2026
- Last updated
- 02 October 2026
- Supersedes
- Privacy Policy v1.0 (23 June 2026)
- Controller
- 4Viso BV, Niel, Belgium
On this page
- 1.Who we are
- 2.When this policy applies
- 3.Personal data we collect
- 4.Why we use your data and on what legal basis
- 5.Anonymized and aggregated data
- 6.Public organization profiles
- 7.Invitations sent on a customer's behalf
- 8.Who we share data with
- 9.How long we keep data
- 10.International transfers
- 11.Security
- 12.Your rights
- 13.California residents
- 14.Cookies and similar technologies
- 15.Children
- 16.Changes to this policy
- 17.Contact and supervisory authority
This Privacy Policy explains how 4Viso BV handles personal data when it decides why and how that data is used, that is, when 4Viso acts as a controller. It covers visitors to 4viso.com, people who register for or use the 4Viso platform, business contacts, and people who receive an invitation through the platform. It is the privacy policy referred to in Section 15.4 of the Software Subscription Agreement, the contract customers accept inside the 4Viso platform.
Data that a customer uploads into the platform, such as audit records, supplier data, and the details of people referenced in them, is processed on that customer's instructions under the Data Processing Agreement and the customer's own privacy notice. This policy does not cover that data.
Section 01
Who we are
4Viso BV is a private limited company incorporated under Belgian law, registered with the Crossroads Bank for Enterprises under number 1027.105.086, with its registered office at Science Park Antwerp, Galileilaan 15, 2845 Niel, Belgium. Email: info@4viso.com.
4Viso operates a business-to-business software-as-a-service platform for governance, risk, and compliance management, including shipping-lane risk intelligence, supply-chain audit management, compliance-scheme and guideline management, and certificate management.
Section 02
When this policy applies
4Viso acts in two roles, and which one applies decides which document governs.
| Situation | 4Viso's role | Governing document |
|---|---|---|
| You browse 4viso.com, contact us, or receive marketing from us | Controller | This policy |
| You create or sign in to a user account, including one-time passwords, multi-factor authentication, and security logs | Controller | This policy |
| Your organization's contract with us: Order Forms, invoicing, Credits, support, service and legal notices | Controller | This policy |
| Your organization's public profile on the platform | Controller | This policy (Section 6) |
| You receive an invitation sent by the platform because a customer asked for it | Processor for the customer; controller only for the suppression record | Customer's privacy notice; this policy (Section 7) |
| Data a customer uploads or generates in the platform (audits, checklists, supplier records, people referenced in them) | Processor | Data Processing Agreement and the customer's privacy notice |
If you use the platform under a contract between your employer and 4Viso, your employer's privacy notice also applies to what your employer does with your data.
Section 03
Personal data we collect
3.1 Data you give us
| Category | Examples | When |
|---|---|---|
| Identity | First name, last name, job title | Account registration, Order Forms |
| Contact | Business email address, phone number | Registration, support, invitations you accept |
| Organization | Company name, registered address, registration and VAT numbers, certifications, service locations, service types | Profile creation and maintenance |
| Credentials | Hashed password, one-time passcodes, multi-factor authentication enrollment, SSO identity claims | Authentication |
| Billing | Billing address, subscription plan, Credit purchases, tokenized payment method | Subscription management via Stripe |
| Communications | Support tickets, email correspondence, feedback | Support and account management |
3.2 Data we collect automatically
| Category | Examples | Source |
|---|---|---|
| Technical identifiers | IP address, browser type, operating system, device type | Web server and security logs |
| Usage | Pages visited, features used, click paths, session duration | Mixpanel and Google Analytics 4, subject to your cookie consent |
| Consent choices | Your cookie preferences | Cookie banner (see Section 14) |
| Security and audit logs | Sign-in events, MFA events, permission changes, data exports | Platform audit trail |
3.3 Data we receive from others
- Your organization or a 4Viso customer: your name and business contact details when an administrator adds you as a user or when a customer asks the platform to invite you or your organization (see Section 7).
- Stripe: tokenized payment confirmation and subscription status.
- Zoho CRM: sales and account-relationship data for customers and prospects.
- Single sign-on providers: identity claims (name, email) when your organization uses SSO.
Section 04
Why we use your data and on what legal basis
The purposes below are those for which 4Viso is the controller. They correspond to Section 15.4 of the Software Subscription Agreement.
| Purpose | Data used | Legal basis (GDPR Article 6) |
|---|---|---|
| Create, authenticate, and secure user accounts, including sign-in credentials, one-time passwords, MFA, and security and access logs; detect and prevent fraud, abuse, and breaches of the acceptable-use rules | Identity, contact, credentials, technical identifiers, security logs | Contract (6(1)(b)) for account operation; legitimate interests (6(1)(f)) in keeping the platform, our customers, and third parties safe from unauthorized access and abuse |
| Provide and operate the platform for your organization | Identity, contact, organization, usage | Contract (6(1)(b)) |
| Manage the customer relationship: Order Forms, invoicing, payment collection, Credits, support | Identity, contact, organization, billing, communications | Contract (6(1)(b)); legal obligation (6(1)(c)) for accounting and tax records |
| Send service and legal notices, including renewal reminders, price-change and sub-processor notices, security notices, and notices under the Agreement | Contact, account-administrator role | Contract (6(1)(b)); legal obligation (6(1)(c)) where a notice is required by law |
| Publish organization profiles so that organizations can be found and audited (Section 6) | Organization data, primary business contact details | Legitimate interests (6(1)(f)) of customers and their counterparties in verifying and contacting organizations; contract (6(1)(b)) with the organization |
| Keep a suppression record of people who have asked not to receive further invitations (Section 7) | Email address, date of request | Legitimate interests (6(1)(f)) in honoring your choice; legal obligation (6(1)(c)) under direct-marketing rules where applicable |
| Marketing and business development: product updates to existing customers; outreach to prospects | Identity, contact, organization | Legitimate interests (6(1)(f)) for existing customers (Recital 47); consent (6(1)(a)) for prospects. You may object or withdraw at any time. |
| Analytics and product improvement, including generating anonymized and aggregated data that no longer identifies anyone | Usage, technical identifiers | Consent (6(1)(a)) for analytics cookies; legitimate interests (6(1)(f)) in measuring and improving the platform |
| Comply with legal obligations | Whatever the obligation requires | Legal obligation (6(1)(c)) |
| Establish, exercise, or defend legal claims, including debt recovery and regulatory inquiries | Identity, contact, contract records, communications | Legitimate interests (6(1)(f)) |
Where we rely on legitimate interests we have carried out a balancing test and concluded that our interests do not override your rights and freedoms. You can ask for a summary of a balancing test at info@4viso.com. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
Section 05
Anonymized and aggregated data
4Viso generates anonymized, aggregated, and de-identified data from use of the platform and uses it for security, product improvement, research, and benchmarking. That data does not identify any customer, user, or other individual, and we do not disclose it in a form that identifies a customer (Section 7.4 of the Agreement). Once data is anonymized it is no longer personal data.
Section 06
Public organization profiles
The platform is designed so that organizations can be discovered and audited. By default, part of an organization's profile is visible to other platform users, may appear in search results within the platform and on 4Viso's public pages, and may be indexed by external search engines. 4Viso cannot control reuse of that information once it has been indexed externally.
Visible by default
- Organization name, registered address, and primary contact information. Where the primary contact is a named person, their business name, role, business email address, and business phone number are part of the public profile.
- Organization type, industry sectors, and service locations.
- Certifications and compliance schemes held.
- Logistics service types.
Private by default
Everything else, including audit records, risk assessments, internal notes, and non-public documents, is private and governed by the customer's role-based access control settings. The platform's shareability settings let a customer decide which items of its private information are shared, and with which other users or organizations. 4Viso acts on that configuration and does not decide what a customer shares.
Your choices
The organization's administrator controls which optional profile information is published and can nominate a role-based mailbox rather than a named individual as the primary contact. If your personal details appear on a profile and you believe they should not, ask your administrator or contact info@4viso.com. You can object to this processing under Article 21 GDPR.
Section 07
Invitations sent on a customer's behalf
The platform sends invitations and notifications when a customer or one of its users asks it to, for example inviting you to join that customer's account, inviting your organization to become a subsidiary in the customer's group, or inviting your organization to join an ecosystem or compliance scheme that the customer operates, using a member or contact list the customer maintains.
- Who is responsible. The customer decided to contact you and is the controller of your contact details. 4Viso sends the message as the customer's processor under the Data Processing Agreement. The customer's privacy notice applies.
- What the message tells you. The message may say that it is sent on the customer's behalf, identify the customer, state where your contact details came from, and include 4Viso's company identification.
- Refusing further invitations. The message offers a way to refuse further invitations. If you use it, 4Viso records your email address and the date on a suppression list and will not send you further invitations. 4Viso keeps that suppression record as controller, because it is the only way to honor your choice across customers.
Section 09
How long we keep data
| Data | Retention | Why |
|---|---|---|
| Account and profile data | Duration of the subscription plus 90 days | Platform operation and the customer's data-export window (Section 22.2 of the Agreement) |
| Contract records: Order Forms, acceptance records, notices, renewal reminders | Duration of the contract plus 10 years | Belgian limitation period for contractual claims |
| Billing and invoice records | 10 years from invoice date | Belgian VAT and accounting retention rules (VAT Code art. 60; Code of Economic Law art. III.86) |
| Security and audit logs | 12 months | Incident investigation and compliance |
| Support communications | 3 years from resolution | Dispute resolution and service improvement |
| Marketing contact data | Until you object or withdraw consent, or 2 years of inactivity | Consent, or legitimate interest for existing customers |
| Invitation suppression record | Until you ask to be removed | Needed to keep honoring your refusal |
| Analytics data (GA4, Mixpanel) | 14 months (GA4); 12 months (Mixpanel) | Trend analysis; data minimization |
| Backups | 30-day rolling window | Disaster recovery; then overwritten |
Data that is no longer required is deleted or irreversibly anonymized. On termination of a subscription, the customer may ask for earlier deletion of platform content, except where retention is required by law.
Section 10
International transfers
The platform is hosted on Amazon Web Services in a single region within the European Union. Where personal data is transferred outside the European Economic Area, for example when our development partner in India maintains and supports the platform, or to Stripe's US infrastructure or Zoho's India infrastructure, we rely on one or more of the following:
- the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914);
- an adequacy decision of the European Commission; or
- approved Binding Corporate Rules.
A copy of the applicable safeguards is available on written request to info@4viso.com.
Section 11
Security
We apply technical and organizational measures proportionate to the risk, including encryption in transit (TLS 1.2 or higher) and at rest (AES-256), role-based access control, multi-factor authentication, security testing integrated into our development pipeline, logging of access to the platform, and an ISO 27001-aligned management system (certification in progress). Customers can request more detail on these measures at info@4viso.com.
Section 12
Your rights
Under the GDPR you have the following rights. To exercise them, email info@4viso.com with the subject "Privacy / DPO Request". We respond within one month, extendable by two further months for complex requests, in which case we will tell you.
| Access (Art. 15) | Confirmation of whether we process your data and a copy of it. |
|---|---|
| Rectification (Art. 16) | Correction of inaccurate or incomplete data. |
| Erasure (Art. 17) | Deletion where no overriding legal basis or retention duty exists. |
| Restriction (Art. 18) | Limiting processing in specific circumstances. |
| Portability (Art. 20) | Your data in a structured, machine-readable format. |
| Objection (Art. 21) | To processing based on legitimate interests, including public profiles, and to direct marketing at any time. |
| Withdraw consent | At any time, without affecting earlier processing. |
| Complain | To the Belgian Data Protection Authority or the authority where you live or work. |
If your request concerns data that a customer uploaded into the platform, we will pass it to that customer, who is the controller, and help them respond.
Section 13
California residents
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the right to know what personal information we collect, use, and disclose, to delete it, to correct it, and not to be discriminated against for exercising these rights. 4Viso does not sell personal information or share it for cross-context behavioral advertising, and we honor the Global Privacy Control signal. We do not collect sensitive personal information for purposes other than those the law permits.
In the preceding 12 months we collected these categories of personal information: identifiers, commercial information, internet or other electronic network activity, and professional or employment-related information. To submit a verifiable request, email info@4viso.com. We respond within 45 days, extendable by a further 45 days with notice.
Section 15
Children
The platform is a professional business service and is not directed at anyone under 18. We do not knowingly collect personal data from minors. If you believe we have done so, contact info@4viso.com and we will delete it.
Section 16
Changes to this policy
We may update this policy to reflect changes in our practices, technology, or legal requirements. The "Last updated" date at the top changes each time. For material changes we notify account administrators by email, or by a prominent notice in the platform, at least 14 days before the change takes effect. This policy is a notice about our own processing. It does not change the Software Subscription Agreement, which is amended only as that Agreement provides.
Section 17
Contact and supervisory authority
Data Protection Officer
4Viso BV, Science Park Antwerp, Galileilaan 15, 2845 Niel, Belgium
Email: info@4viso.com (subject: "Privacy / DPO Request")
Belgian Data Protection Authority
Gegevensbeschermingsautoriteit / Autorité de protection des données
Rue de la Presse 35, 1000 Brussels
www.dataprotectionauthority.be