Privacy Policy
Last updated: March 2026
1. Who is responsible for your data?
Setorio is a service provided by:
Setorio
Charlotte van Pallandtlaan 132
1112 ZL Diemen, The Netherlands
Chamber of Commerce (KvK): 91736838
Email: privacy@setor.io
Setorio is the data controller within the meaning of the General Data Protection Regulation (GDPR).
2. What data do we process and why?
2.1 Waitlist (setor.io)
When you sign up for the waitlist, we process:
- Email address
- Date and time of sign-up
- Origin of your visit (UTM parameters, referrer)
Purpose: To inform you about the availability of Setorio.
Legal basis: Consent (GDPR art. 6(1)(a)). You can unsubscribe at any time via the link in every email.
2.2 App usage (app.setor.io)
When you create an account and use Setorio, we process:
- Name and email address
- Company name
- Account details and login history
- Subscriptions, client data, and billing information you enter
- Application usage (actions, session duration, page views)
- IP address and browser type (technical logging)
Purpose: Delivering and improving the service, fulfilling billing obligations, providing support.
Legal basis: Performance of a contract (GDPR art. 6(1)(b)) and legitimate interest (GDPR art. 6(1)(f)) for analytics and security.
2.3 Your clients' data
Data you enter about your own clients (names, email addresses, billing details) is processed by Setorio on your behalf. You are the data controller for this data; Setorio acts as the data processor. See also section 4 (Sub-processors).
3. How long do we retain your data?
| Data | Retention period |
|---|---|
| Waitlist sign-ups | Up to 12 months after the last email, or until unsubscription |
| Account data | Up to 30 days after account deletion |
| Billing data | 7 years (statutory retention obligation) |
| Analytics data | Maximum 12 months |
| Technical logs | Maximum 90 days |
After deleting your account, you have 30 days to export your data.
4. Sub-processors
We never sell your data. We use the following sub-processors, who process your data exclusively on behalf of Setorio:
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Hosting of the application and landing page (EU region) | EU |
| PostHog Inc. | Product analytics (EU instance) | EU |
| Brevo (Sendinblue) | Email communication | EU |
| Stripe Inc. | Payment processing | US (SCCs) |
| Moneybird B.V. | Invoicing and accounting | NL |
Data processing agreements are in place with all sub-processors. For transfers outside the EU, we use Standard Contractual Clauses (SCCs).
5. Cookies and analytics
Setorio uses PostHog for product analytics. PostHog is configured on an EU server and collects anonymized usage data to improve the application.
The landing page (setor.io) places functional cookies that are necessary for the page to function correctly. For analytics cookies, consent is requested via the cookie banner.
6. Your rights
Under the GDPR, you have the following rights:
- Access — you can request an overview of the data we hold about you
- Rectification — you can have incorrect data corrected
- Erasure — you can request that your data be deleted
- Objection — you can object to processing based on legitimate interest
- Data portability — you can request a copy of your data in a common format
- Withdrawal of consent — where processing is based on consent, you can withdraw it at any time
Send a request to privacy@setor.io. We will respond within 30 days.
7. Filing a complaint
If you believe we are not handling your data correctly, you can file a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens
autoriteitpersoonsgegevens.nl
Phone: +31 88 180 5250
8. Changes
This privacy policy may be updated. In the event of significant changes, you will receive an email notification. The date at the top of this document indicates when the latest version was published.
9. Contact
Questions about this privacy policy? Send an email to privacy@setor.io.