Privacy Policy
Version 2.4
Last updated: 22 September 2026
1. Who is responsible for your data?
Setorio is a service provided by:
Setorio, a trade name of Mayelow
A sole proprietorship (eenmanszaak)
Charlotte van Pallandthof 132
1112 ZL Diemen, the Netherlands
Chamber of Commerce (KvK): 91736838
VAT number: NL004912213B40
Email: privacy@setor.io
Setorio is the data controller within the meaning of the General Data Protection Regulation (GDPR).
2. What data do we process and why?
2.1 App usage (app.setor.io)
When you create an account and use Setorio, we process:
- Name and email address
- Company name
- Account details and login history
- Subscriptions, client data, and billing information you enter
- Application usage (actions, session duration, page views)
- IP address and browser type (technical logging)
Purpose: Delivering and improving the service, fulfilling billing obligations, providing support.
Legal basis: Performance of a contract (GDPR art. 6(1)(b)) and legitimate interest (GDPR art. 6(1)(f)) for analytics and security.
Billing data is retained to comply with our tax obligations (GDPR art. 6(1)(c); art. 52 Algemene wet inzake rijksbelastingen).
2.2 Your clients' data
Data you enter about your own clients (names, email addresses, billing details) is processed by Setorio on your behalf. You are the data controller for this data; Setorio acts as the data processor. See also section 4 (Sub-processors).
3. How long do we retain your data?
| Data | Retention period |
|---|---|
| Account and workspace data | Deleted immediately when you delete your workspace; otherwise 30 days after your access ends |
| Backup copies | Overwritten within 7 days |
| Billing records | 7 years, where the law requires this |
| Analytics data | Maximum 12 months |
| Technical logs | Maximum 90 days |
You can delete your workspace at any time in Settings. Deletion is immediate and permanent, so request an export via support@setor.io first. If your access ends for another reason, you have 30 days to request an export, after which Setorio deletes your data. Backup copies are overwritten within 7 days. Billing records are kept for 7 years where the law requires this.
4. Sub-processors
We never sell your data. We use the following sub-processors, who process your data exclusively on behalf of Setorio:
| Sub-processor | Purpose | Data location | Transfer mechanism |
|---|---|---|---|
| Vercel Inc. | Hosting of setor.io and app.setor.io | EU (Frankfurt) | EU hosting; SCCs for incidental access |
| Supabase Inc. | Database, authentication, file storage | United Kingdom (London) | UK adequacy decision |
| Resend Inc. | Transactional email | EU and US | Standard Contractual Clauses |
| PostHog Inc. | Product analytics | EU | EU hosting |
| Functional Software Inc. (Sentry) | Error monitoring, including masked session replays | EU (Frankfurt) | EU hosting |
| Cloudflare, Inc. | Bot protection (Turnstile) on signup and public forms | Global | SCCs / EU-US Data Privacy Framework |
| Stripe Payments Europe Ltd. | Payment of Setorio subscriptions | EU (Ireland) and US | SCCs / EU-US Data Privacy Framework |
Data processing agreements are in place with all sub-processors. The canonical version of this list is the sub-processor list in our Data Processing Agreement, which is also where changes to it are notified.
We also use Google Ireland Ltd. (Google Ads) and Reddit, Inc. (Reddit Ads) to measure our advertising. They act as independent controllers. They receive data from the application only after you accept marketing cookies, and from our public website unless you reject them. Browser push notifications, if you enable them, are delivered through your browser vendor's push service (Google, Mozilla or Apple).
For business customers processing client data through Setorio, see our Data Processing Agreement.
5. Cookies and analytics
The first time you visit setor.io or app.setor.io you are asked to accept or reject analytics cookies. We would rather say plainly what happens before you answer than leave you to find out: analytics cookies are set when you arrive, on both the website and the application. If you reject, they are removed again, the recording of how pages are used stops, and nothing further is stored.
We do that because most visitors arrive from an advertisement, read one page and leave without answering the banner at all, and because the website and the application are two addresses for one product: measuring them separately told us almost nothing about whether the thing works. It is a deliberate choice, and rejecting is the way to opt out of it. You can change your answer at any time through the Cookie settings link in the footer.
Advertising cookies follow the same rule on both, with one exception. The advertising pixel that tells us which advertisement led to a sign-up is set on arrival on the website and in the application, because a sign-up that cannot be traced back to the advertisement that paid for it is the one thing we are measuring. Google's advertising storage in the application still waits until you accept.
5.1 Always on (strictly necessary)
These are needed for the site and the application to work at all, so they are not part of the choice:
- Your sign-in session, so you stay logged in between pages.
- Your cookie choice itself, so we do not ask again on every page.
- Interface preferences you set yourself, such as light or dark mode, stored in your browser and never sent to us.
5.2 Analytics and advertising
- PostHog (product analytics, EU servers), to see which parts of Setorio are used, and session replays of how pages are used, with all text you type and all uploaded media masked. Once you are signed in, your account's email address and name are attached to your analytics profile, so that a question you ask us can be matched to what actually happened. If you reject, PostHog sets no cookies and no browser storage at all, stops replaying, deletes what it had stored, and cannot recognise you between visits. It still counts the visit itself, anonymously.
- Google Ads and Reddit Ads, to measure whether our advertising works. If you reject, the Reddit pixel is unloaded and the identifier it stored is deleted, and Google is told to drop to cookieless signals through Google Consent Mode and its cookies are deleted too. In the application neither is loaded at all until you accept.
- Sentry error reports, so a page that breaks tells us it broke. Personal data is scrubbed before it is sent.
Your choice is stored in one cookie on setor.io for twelve months and applies to both the website and the application.
5.3 Client portals
The client portals our customers run on their own domains carry no analytics, no advertising and no third-party requests of any kind. Fonts, images and scripts there are served from our own servers.
Questions about any of this, or a request to be removed from our analytics entirely, can go to privacy@setor.io.
6. Your rights
Under the GDPR, you have the following rights:
- Access: you can request an overview of the data we hold about you
- Rectification: you can have incorrect data corrected
- Erasure: you can request that your data be deleted
- Objection: you can object to processing based on legitimate interest
- Data portability: you can request a copy of your data in a common format
- Withdrawal of consent: where processing is based on consent, you can withdraw it at any time
Send a request to privacy@setor.io. We will respond within one month.
7. Filing a complaint
If you believe we are not handling your data correctly, you can file a complaint with the Dutch Data Protection Authority:
8. Changes
This privacy policy may be updated. In the event of significant changes, you will receive an email notification. The date at the top of this document indicates when the latest version was published.
9. Contact
Questions about this privacy policy? Send an email to privacy@setor.io.