Avasto Logo

Privacy Policy & Data Processing

Last updated: 20 September 2026

1. Introduction

Welcome to Avasto Planner. This privacy policy explains how we (AVASTO B.V.) collect, use, secure, and share personal data when you use our SaaS application for personnel and equipment planning (the "Service"). We attach great value to your privacy and process personal data strictly in accordance with the General Data Protection Regulation (GDPR).

2. Our Role: Data Controller vs. Data Processor

To be transparent about our obligations, we distinguish between the roles we fulfill:

As Data Controller

For the account and payment details of the company purchasing the Service, we determine the purpose and means of the processing. This includes your subscription management and administration.

As Data Processor

For all employee, project, and planning data you enter into the application, you act as the Data Controller and we solely as the Data Processor. We process this data exclusively on your behalf to operate the application.

3. Data Collection and Application Usage

We only collect data strictly necessary for providing and securing the application:

  • Account and Billing Data:

    Company name, contact person, email address, and payment history. Necessary for contract execution and legal administrative obligations.

  • Planning and Employee Data:

    Names, schedules, qualifications, and linked company resources. This data is managed by the customer and exclusively used for the core functionality of Avasto Planner.

  • System and Security Logs:

    IP addresses, login timestamps, and audit logs (who made what change). Necessary based on legitimate interest to guarantee the integrity and security of the system.

4. How We Secure Your Data

The security of your company and employee data is fundamental to our Service. Our security measures include:

Encryption: All data is transmitted encrypted (via TLS/HTTPS) and stored securely encrypted (encryption-at-rest) in secure European data centers.

Access Control (RBAC): The application uses strict role-based access rights. Employees only see their own schedules and public project information, while administrators can manage the full administration.

Isolation: Data from different customers (tenants) is logically separated within the database, making unauthorized access between different company accounts impossible.

Monitoring & Backups: We actively monitor for suspicious login attempts and make secure daily backups to prevent data loss due to technical failures.

5. Subprocessors and Third Parties

We never sell or rent your data never. Data is only shared with strictly selected subprocessors necessary for the technical execution of the Service, such as:

  • Hosting (EU): For secure cloud infrastructure and storage.
  • Mollie B.V.: For secure, PCI-DSS certified processing of your subscription payments.
  • Email Providers: Exclusively for delivering transactional messages (such as employee invitations or password recovery).

6. Third-Party Integrations (Google API & AI)

Google API Services (Calendar Integration)

If you choose to connect Avasto Planner with Google Calendar, we securely store authorization tokens. Our use and transfer to any other app of information received from Google APIs will adhere strictly to the Google API Services User Data Policy, including the Limited Use requirements.

Artificial Intelligence (Google Gemini)

Our planning assistant uses Google Gemini. When you use this functionality, only the directly relevant context (such as availability for a specific project) is processed. Your company data is never used to train public Google AI models.

7. Cookies and Storage on your Device

Our application is functionally designed and makes no use of marketing, tracking, or advertising cookies. We exclusively use locally stored functional data (such as session cookies and localStorage) technically necessary to keep you logged in and display the user interface (like theme preferences) correctly.

8. Retention Periods (Data Retention)

  • Active Subscriptions: Your data is retained as long as your account is active.
  • Upon Cancellation: After termination of your subscription, you have the option to export your data, after which it is deleted from our active systems. Backups rotate out after a maximum of 30 days.
  • Fiscal Obligations: Invoices and payment history are retained for 7 years in accordance with Dutch Tax Administration legislation.

9. Your GDPR Rights

You (and your employees) always retain control over personal data. You have the right to:

  • Access & Rectification: Viewing or correcting incorrect data.
  • Data Portability: Exporting data in a structured format.
  • Right to be Forgotten: The request for complete deletion of data.
  • Restriction & Objection: Temporarily stopping or objecting to specific processing operations.

Note: Because Avasto Planner is often used on behalf of an employer (our customer), employees should initially submit privacy requests to their employer. We provide technical support to the employer in executing these requests.

10. Contact Information

Do you have questions about the security of our application or want to exercise your rights? Please contact us:

AVASTO B.V.

Populierenweg 41
3421 TX Oudewater
The Netherlands

mail@avasto.nl

CoC: 73351938

Are you dissatisfied with how we handle your data? You also have the right to file a complaint with the Data Protection Authority (DPA).

© 2026 Avasto. All rights reserved.