Privacy policy

This policy describes the processing of personal data by Espero-Soft Informatiques SRL in connection with the Wobelio platform, in accordance with Regulation (EU) 2016/679 (GDPR) and the Belgian Act of 30 July 2018.

Last updated: August 6, 2026

1. Controller

Controller
Espero-Soft Informatiques SRL, Rue de la Colonne 1A, 1080 Molenbeek-Saint-Jean, Belgique
Company number
1033.022.383
Supervisory authority
Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels

No data protection officer has been appointed: our processing falls under none of the cases in which Article 37 GDPR requires one. Privacy requests are handled at the address above.

2. Data processed

We process only what the service requires:

  • Account: email address, name if you provide one, profile picture where you sign in with a Google account, interface language, theme preference, creation and last sign-in dates.
  • Websites: the content you publish, uploaded files, domain name, subdomain, website settings.
  • Billing: plan taken, billing period, due dates, payment history, invoices, identification details and VAT number where you supply them.
  • Messages received through your forms: what your visitors enter, a hash of their IP address (never the address itself) and their browser type, solely in order to filter automated submissions.
  • Audit tools: address of the website analysed, results of the analysis, and email address where you ask for the report to be sent.
  • Technical logs: IP address, timestamp, page requested and response code, kept for security and incident diagnosis.
  • Prospecting: business contact details of company representatives, where we build such a list (see section 8).

We collect no special category data within the meaning of Article 9 GDPR, carry out no advertising profiling, and neither sell nor transfer any data for third-party marketing purposes.

3. Purposes, legal bases and retention

Creating and managing your account
Legal basis: performance of the contract. Retention: for as long as the account exists, then deletion from live systems within thirty days of its closure.
Signing you in
Legal basis: performance of the contract. One-time codes expire after ten minutes and are then deleted; the session cookie lasts thirty days at most.
Publishing and hosting your websites
Legal basis: performance of the contract. Retention: for as long as the website exists in your account.
Billing the subscription and keeping accounts
Legal basis: performance of the contract and legal obligation. Retention of accounting records: seven years, as required by the Code of Economic Law.
Sending you service messages
Renewal reminders, security alerts, notice of changes to the terms. Legal basis: performance of the contract and legal obligation. These messages cannot be opted out of while the account exists.
Producing an audit report
Legal basis: performance of the contract, or legitimate interest for a report requested without an account. Retention: thirty days for a report not attached to an account, then automatic deletion.
Keeping the platform secure
Abuse prevention, filtering of automated submissions, incident diagnosis. Legal basis: legitimate interest. Retention of logs: twelve months at most.
Answering your support requests
Legal basis: performance of the contract. Retention: three years from the last exchange.
Handling reports of illegal content
Legal basis: legal obligation (Regulation (EU) 2022/2065). Retention: five years, the decision having to remain justifiable.

4. The data of your website's visitors

Where your website collects data (contact form, order, sign-up), you are the controller and we act as processor, on your behalf and on your instructions.

On that basis we undertake to:

  • process that data only in order to provide you with the service, never for our own purposes;
  • protect it with appropriate technical and organisational measures;
  • engage another processor only under the conditions described in section 5;
  • assist you in handling data subject requests and notify you without undue delay in the event of a data breach;
  • delete that data at the end of the service, save where the law requires it to be kept.

On your side, it is up to you to inform your visitors, obtain their consent where required, publish your own legal notice and collect no more than you need. The platform provides templates for legal pages: they are texts to be reviewed and completed, not legal advice.

5. Recipients and processors

Your data is accessible only to those people at Espero-Soft Informatiques SRL who need it, all bound by confidentiality. It is shared with the following third parties, each bound by a processing agreement:

Stripe Payments Europe, Limited
Payment processing and storage of payment methods. 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Irlande.
Domain registrar
Registration and renewal of a domain name in your name, where you ask for one. Registrant data is passed on to the competent registry, as its rules require.
Hosting
Espero-Soft Informatiques SRL, à l’adresse de son siège social. The servers are located within the European Union.
Email delivery
Our own mail relay. Sign-in codes and notifications pass through no third-party service.

Your data may further be disclosed to a judicial or administrative authority where the law requires it, and to our advisers in the event of a dispute. Should the business be transferred, it would pass to the acquirer, bound by this policy; you would be informed beforehand.

6. Transfers outside the European Union

Processing and storage take place within the European Union. Our payment provider may, for fraud prevention and support purposes, access certain data from a third country: such transfers are governed by the standard contractual clauses adopted by the European Commission.

A copy of the applicable safeguards may be requested at info@espero-soft.com.

7. Your rights

You have the following rights at any time:

  • access: obtain confirmation that data concerning you is processed, and a copy of it;
  • rectification: have inaccurate or incomplete data corrected;
  • erasure: have your data deleted, apart from what we are required to keep;
  • restriction: ask for processing to be frozen while a challenge is resolved;
  • objection: object to processing based on our legitimate interest, including prospecting, to which you may object without giving reasons;
  • portability: receive in a machine-readable format the data you have provided to us, or ask for it to be transmitted directly to another provider;
  • withdrawal of consent: where processing is based on your consent, withdraw it at any time, without affecting what was done beforehand.

These rights are exercised by simple request to info@espero-soft.com. We answer within one month, extendable by two months where the request is complex, in which case you are informed. Proof of identity will be asked for only where there is reasonable doubt as to your identity, and destroyed once verified.

You may lodge a complaint with the Belgian Data Protection Authority, https://www.autoriteprotectiondonnees.be, or with the supervisory authority of your country of residence, and seek a judicial remedy.

8. Commercial prospecting

We send messages presenting the platform to business contacts (managers, self-employed professionals, associations), at their business address and for an offer that relates to their activity. That processing rests on our legitimate interest in making the service known.

Every message states who sends it and includes an immediate opt-out, including from your mail client. An objection is recorded permanently: the address is kept on a suppression list so that it is never contacted again. Failing any interaction, contact details are erased after three years.

No prospecting message is sent to the personal addresses of platform users without their prior consent.

9. Security

Exchanges with the platform are encrypted (HTTPS). Access to systems is limited to those who need it and is logged. Sign-in codes are stored hashed, the IP addresses of form submissions as a hash, and regular backups allow recovery after an incident.

In the event of a data breach likely to result in a high risk to your rights, we inform you without undue delay and notify the supervisory authority within seventy-two hours.

10. Automated decisions

No decision producing legal effects concerning you is taken solely on the basis of automated processing. Anti-fraud and anti-spam filters may flag a submission, but any measure taken against an account is subject to human review and to a statement of reasons, which may be contested under the terms of use.

11. Cookies

The platform uses only cookies necessary for it to work. Their list, purpose and lifetime are set out in the cookie policy.

12. Changes to this policy

This policy may change with the service or with the applicable rules. The date of the last revision appears at the top of the page. Any substantial change is announced by email at least thirty days before it takes effect, and earlier versions may be requested at info@espero-soft.com.