RRenovae

B2B legal information

Privacy and retention policy

How AZ Technologies SRL handles website, business-contact, account, workspace, property, referral, and service-usage data.

Effective and last updated: 17 September 2026

1. Who is responsible

AZ Technologies SRL is the controller for Renovae's website, pilot applications, account registration, business contacts, referral programme, administration, security, billing, and service-account data. Contact: hello@aztechnologies.be. Full company details are in the Legal Notice.

For photographs, panoramas, property information, and other content uploaded by a customer on behalf of its agency, seller, landlord, developer, or client, the customer normally decides why that data is used and acts as controller. AZ Technologies SRL then acts as processor under the Data Processing Addendum.

2. Data we process

  • Business contacts: name, agency, business email, telephone number, messages, and pilot or sales history.
  • Account registration: first and last name, email address, password (stored only as a one-way hash), optional telephone number, professional role, the versions of the terms and privacy policy accepted and when, a keyed hash of the IP address and the browser user agent at acceptance, whether the email address is confirmed, and records of any product-email consent and its withdrawal.
  • Referral data: the referral link through which an organization registered, when that link was first opened, and the referring partner or customer, so that the referral programme can be administered and commissions calculated.
  • Workspace data: company, invitation, project, property, room, access, publication, and configuration information.
  • Customer content: uploaded photographs and panoramas, prompts, renovation preferences, AI outputs, thumbnails, and exported tours.
  • Technical and security data: IP address, request and error logs, device/browser information, authentication and session identifiers, and Turnstile anti-abuse signals. The public website also uses Vercel Web Analytics to collect cookie-free, anonymized page-view, referrer, approximate location, browser, device, and operating-system statistics.
  • Usage and commercial data: visited workspace areas, use of key product actions, generation requests and edit categories, model/provider, token or credit consumption, estimated provider cost, timestamps, status, and billing or VAT information where applicable. Product analytics do not contain prompts, images, IP addresses, or browser fingerprints.
  • Support data: chat messages, a pseudonymous support-session identifier, technical connection data, issue reports, and material voluntarily supplied to diagnose a problem. Renovae does not automatically send the signed-in user's name, email address, or company name to the chat provider.

3. Purposes and legal bases

  • To review pilot applications and take steps requested before a contract: pre-contractual measures.
  • To register accounts, run trials, confirm email addresses, provide workspaces, generations, storage, publication, support, and billing: performance of a contract or steps requested before one.
  • To keep proof of the terms accepted, prevent abusive or automated registrations, and administer the referral programme and its commissions: our legitimate interests and, for commissions, performance of the contract with the referrer.
  • To secure the service, prevent abuse, measure provider costs, understand which product functions are useful, improve reliability and usability, and manage B2B relationships: our legitimate interests, balanced against affected rights.
  • To keep accounting, tax, compliance, and dispute records: legal obligations and establishment, exercise, or defence of legal claims.
  • To send optional product news and tips: consent given with the unticked box at registration, which can be withdrawn at any time. We do not treat a pilot application or a registration as consent to marketing. An email address that has not been confirmed receives only the confirmation email and the password-reset or account notices it triggers.

4. Providers and transfers

We disclose data only where needed to operate the service, comply with law, protect rights, or complete a business transaction subject to appropriate safeguards. Current service providers may include Vercel for hosting, Neon for PostgreSQL, Cloudflare for R2 storage and Turnstile security, Clerk for administrator authentication, Zoho Mail and Resend for email delivery, Crisp for user-initiated support chat, and OpenAI and fal.ai for AI image and video processing.

Some providers may process data outside the European Economic Area. We rely on an adequacy decision where available or contractual safeguards such as the European Commission's standard contractual clauses and the provider's data-processing terms. Provider locations and subprocessors may change; the DPA explains the notice process for material changes.

OpenAI states that API data is not used to train its models by default. Depending on the endpoint and account controls, provider abuse-monitoring logs may retain submitted content for up to 30 days. Customers should therefore avoid unnecessary personal or confidential information in images and prompts.

5. Retention schedule

We keep personal data only as long as needed for the stated purpose, then delete or irreversibly anonymize it unless law or an active dispute requires longer retention.

  • Unsuccessful or inactive pilot applications: up to 12 months after the last meaningful contact.
  • Business relationship and support records: for the relationship and up to 24 months afterward, unless needed longer for a claim.
  • Workspace content and AI outputs: while the workspace or invitation is active; normally deleted from active storage within 30 days after expiry, revocation, termination, or a valid deletion request.
  • Self-serve trial content: if an organization that registered online never subscribes, its uploaded and generated content is deleted 90 days after the end of its trial without activity, after a warning where its email address is confirmed. The account itself is kept until it is deleted.
  • Account registration and consent records: for the life of the account and up to 24 months after its deletion, to prove what was accepted or consented to.
  • Signup statistics: up to 180 days; they contain no name, email address or raw IP address.
  • Referral records: for the referral relationship and the commission period, and longer where a commission was paid, for the accounting retention period below.
  • Deleted or expired content in encrypted backups: overwritten through the backup cycle, normally within 90 days.
  • Session and invitation data: until expiry or revocation, then retained only where necessary for security and audit records, normally no longer than 12 months.
  • Security, request, and error logs: normally up to 12 months, or longer where required to investigate an incident.
  • Generation usage and cost records: normally 24 months; aggregated records that no longer identify a person may be kept longer.
  • Workspace page and feature-use events: up to 180 days; they use fixed categories and are not linked to prompts or media content.
  • Invoices, accounting, VAT, and legally required records: for the applicable Belgian statutory retention period, currently ten years. Invoice records are kept even when the related account or organization is deleted.
  • OpenAI processing copies: subject to the provider controls described above, potentially up to 30 days after an API request.

6. Your rights

Depending on the circumstances, an individual may ask for access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Consent can be withdrawn without affecting earlier lawful processing. We may need to verify identity and may direct a request to the customer where that customer is the controller.

Send requests to hello@aztechnologies.be. You may also complain to the Belgian Data Protection Authority at dataprotectionauthority.be. We do not use Renovae data for solely automated decisions that produce legal or similarly significant effects on individuals.

7. Security and incidents

We use measures intended to protect data, including scoped access, hashed invitation/session tokens in the database, secure cookies, provider access controls, and separated storage. No internet service is risk-free. Customers must control who receives invitation and publication links and notify us promptly of suspected compromise.

8. B2B service and changes

Renovae is intended for professional users and not for children. We may update this policy when the service, providers, or law changes. The current version and effective date will remain available here.

All legal documentsContact AZ Technologies SRL
Renovae

Operated by AZ Technologies SRL · BE 0789.659.380 · B2B only

TermsPrivacyCookiesAI & acceptable useDPALegal notice