Privacy Policy

Last updated: September 2026

Introduction

Relevé is committed to protecting personal data and being clear about how we use it. This policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and what rights you have. It is written in plain language rather than legal boilerplate.

Relevé B.V., registered in the Netherlands with KvK number 98697390 ("Relevé", "we", "us"), is the controller for the personal data described in this policy. We operate under the EU General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG).

We have not appointed a data protection officer, because the nature and scale of our processing does not require one. We are established in the EU, so we do not need a representative under Article 27 GDPR. Questions about this policy go to hello@relevee.nl.

Our two roles

Relevé acts in two different roles under data protection law. This policy covers only the first.

  • Controller for people who interact with us directly: visitors to this website, people who request early access, and the individuals who hold accounts on the Relevé platform on behalf of their organisation. This policy describes that processing.
  • Processor for the data that customer organisations load into the platform: operational, staff, artist, volunteer, audience, supplier, and financial data, which may include personal data about the people an organisation works with. The organisation is the controller of that data and decides why and how it is processed. We process it only on the organisation's instructions, under our Data Processing Agreement (DPA), which forms part of our Terms of Service.

If you are a staff member, artist, volunteer, participant, or contact of a Relevé customer and want to exercise your rights over data that organisation has loaded into the platform, please contact that organisation. We will help them respond.

What we collect, why, and on what legal basis

Website visitors

Hosting. This website is hosted by a third-party hosting provider. When you visit, the hosting provider processes your IP address and basic request metadata to deliver the pages to you. Legal basis: our legitimate interest in operating a website (Art. 6(1)(f) GDPR).

Analytics. We use a privacy-focused analytics service to understand how visitors use this website: pages viewed, referring site, country, and device type. It does not use cookies. Visitor identifiers are derived from a daily-rotating hash and are not used for cross-site tracking. We also record which site features are used, and, when the early access form is submitted, the country and organisation type selected. None of this is linked to your name or email. Legal basis: legitimate interest in understanding and improving the website.

Error monitoring. We use an error monitoring service to detect and fix technical errors. When an error occurs, it collects technical information such as your browser type, operating system, the page URL, and details of the error. It also measures page performance for a sample of visits. For a sample of visits, and for visits in which an error occurs, it records a replay of how the page behaved so we can reproduce the problem. Text you see and anything you type are masked in these replays, and images and media are blocked. We have configured IP address anonymisation, and error data is processed in the EU (Frankfurt). Legal basis: legitimate interest in maintaining a functioning website.

Early access requests

When you request early access, we collect your name, email address, organisation name, country, organisation type, and the language you used. We store this in our database, hosted by a third-party database provider in the EU. We use it to assess your request, follow up with you, and arrange an onboarding call. Legal basis: our legitimate interest in responding to a request you made to us (Art. 6(1)(f) GDPR). You can withdraw your request at any time by emailing us, and we will delete your details.

Platform account holders

If you hold an account on the Relevé platform on behalf of your organisation, we process:

  • Account data: your name, work email address, role within your organisation, and login credentials (stored as a hash). Used to provide the service and secure your account. Legal basis: performance of the contract with your organisation (Art. 6(1)(b)) and our legitimate interest in providing the service to the organisation you represent.
  • Security and usage logs: login times, IP address, and actions taken in the platform. Used for security, an audit trail of who changed what, support, and preventing misuse. Legal basis: legitimate interest and, where applicable, legal obligation.
  • Support and service communications: emails and support requests you send us, and the service notices we send you about security, changes to the service, or changes to our terms or this policy. Legal basis: performance of the contract and legitimate interest.
  • Billing contact and invoicing records: the name and email of your organisation's billing contact and the invoices we issue. Legal basis: performance of the contract and our legal obligation to keep financial records.
  • Interactions with Ré: the prompts you enter and the outputs generated, kept so you can return to them. See the section on Ré and AI features below.

We do not send marketing newsletters unless you ask for them, and you can opt out at any time.

Ré and AI features

The platform includes Ré, an AI assistant. When you use Ré you are interacting with an AI system, not a person. Section 8 of our Terms of Service sets out the commitments below. This policy repeats them so that they are visible to everyone whose data may be affected.

  • Where processing happens. AI processing takes place within the EU or EEA.
  • No training. We do not use your data or your organisation's data to train AI models, and we require the AI providers we use not to either.
  • Personal data sent to AI providers. We limit the personal data sent to AI providers to what is needed for the feature you are using, and we strip or mask personal data where that can be done without breaking the feature. Because the data an organisation loads into the platform may itself contain personal data, such as the names of staff, artists, suppliers, or counterparties, we cannot guarantee that none reaches an AI provider.
  • No automated decision-making. Ré does not make decisions that produce legal or similarly significant effects on your organisation or on any individual, within the meaning of Article 22 GDPR. It produces suggestions, drafts, and summaries for people to review and act on. AI outputs can be inaccurate, incomplete, or misleading, including when they appear confident.
  • Providers. We will notify customer organisations before adding a new AI provider.

Benchmarking

Benchmarking compares an organisation against a group of comparable organisations using the platform. Section 7 of our Terms of Service describes how it works. For privacy purposes, the points that matter are:

  • An organisation's data is included in the pool used to generate benchmarks shown to other customers, and their data is included in the pool used to generate the organisation's own benchmarks.
  • Other customers see only aggregates across a group. They never see an individual organisation's figures, its name, or anything identifying it.
  • We do not show a benchmark unless the comparison group contains at least five organisations. Below that, the platform reports insufficient data rather than showing a figure, so that no organisation can be identified by working backwards from an average.
  • Benchmarks are calculated from organisation-level figures. We do not include personal data about individuals in benchmark outputs.
  • Inclusion in the benchmark pool is part of the service and is not separately optional, because benchmarks only exist if participants contribute to them.
  • Aggregated, anonymised benchmark data may be retained after an organisation leaves the platform. It cannot be traced back to the organisation or to any individual.

Bank connections and financial data (EU and EEA customers only)

The financial module is available only to organisations established in the EU or EEA. Where an organisation connects a bank account, the connection is provided by Enable Banking Oy, a payment service provider licensed in the EU. Consent is given to Enable Banking Oy directly, on their terms, and can be withdrawn through them or through us at any time. We receive read-only account information through them. We never initiate payments and never have access to move funds.

We use bank transaction data only to provide the service to the organisation that connected the account: bookkeeping, financial reporting, and the reports the organisation chooses to generate. We do not use it for any other purpose. In particular, we do not sell it, use it to build profiles of individuals, share it with third parties for their own purposes, or use it for marketing.

Transaction data can include personal data about the people an organisation pays or receives money from. We process that data as a processor under the DPA. The organisation remains the controller.

Who we share data with

We share personal data with service providers who process it on our behalf under written data processing agreements. They provide website and platform hosting, our database, analytics, error monitoring, and AI processing. For EU and EEA customers who connect a bank account, Enable Banking Oy, a payment service provider licensed in the EU, provides the connection, and you consent to them directly. These providers process data in the EU or EEA. Where a supporting service processes data outside the EEA, the safeguards under International transfers apply. We do not publish our subprocessor list, but a current list, naming each provider and where it processes data, is available on request by emailing hello@relevee.nl. Customer organisations receive it as part of the DPA.

We also disclose personal data:

  • To funders and other recipients you choose. Where the platform lets an account holder share a report or data with a funder or other third party, the account holder chooses what to share and with whom. Once shared, the recipient handles that data under their own responsibilities under data protection law.
  • When the law requires it. To comply with a legal obligation, court order, or request from a competent authority, or to establish, exercise, or defend legal claims.
  • If our business changes hands. In a merger, acquisition, or sale of our business, personal data may be transferred to a successor who takes on our obligations under this policy and our agreements with customers. We will notify account holders before their data is transferred to a successor.

We do not sell personal data. We do not share it with third parties for their own marketing.

International transfers

We host and store data within the EU or EEA. Some of the supporting services we use to operate the website and platform currently process data outside the EEA. Where that happens, we rely on the European Commission's Standard Contractual Clauses under Article 46(2)(c) GDPR, supplemented where necessary by additional safeguards identified in a transfer impact assessment. Where the destination country has an EU adequacy decision, we may rely on that instead. We do not rely on your consent or acknowledgement as a basis for transfers.

AI processing takes place within the EU or EEA. We are working to bring all processing within the EEA, and we will update this policy as services move.

How long we keep data

Data Retention period
Early access requestsUntil we have handled your request. If you do not become a customer, deleted 12 months after our last contact with you.
Account dataFor the term of your organisation's subscription and for 30 days after it ends, during which your organisation can export its data. After that we delete it, except where we are required to keep it or where it exists only in aggregated, anonymised form in benchmarks.
Data your organisation loads into the platformThe same 30-day export window applies. Your organisation's own retention obligations, including the seven-year Dutch bookkeeping retention period (bewaarplicht), remain its responsibility. Export before the window closes.
Invoicing and billing recordsSeven years, as required by Dutch law (art. 2:10 BW and art. 52 AWR).
Security and access logs12 months.
Web server logs30 days.
Error reports and replays90 days.
Support correspondence24 months after our last contact with you.
Ré conversation historyFor the life of your account, or until you delete it.

Where we delete data, copies in backups are overwritten within 30 days.

Security and data breaches

We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, role-based access controls, logging, and regular review of our security practices.

If a personal data breach is likely to result in a risk to individuals, we notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of it, as Article 33 GDPR requires. If a breach is likely to result in a high risk to you, we will tell you directly without undue delay, as Article 34 requires. If a breach affects data we process for a customer organisation, we notify that organisation without undue delay and give it the information it needs to meet its own obligations, as set out in section 14 of our Terms of Service and in the DPA.

Children

Our website and platform are intended for organisations and the adults who represent them. We do not knowingly collect personal data from anyone under 16 for our own purposes, and we do not offer accounts to them. If you believe a child has given us personal data, contact us and we will delete it.

Customer organisations may run youth programmes and load participant, volunteer, or audience data that includes information about minors. In that case the organisation is the controller, is responsible for the legal basis and for any parental consent required, and we process the data only on its instructions under the DPA.

Cookies and similar technologies

This website does not set any non-essential cookies, so no consent banner is required under article 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet). Our analytics service does not use cookies. Our error monitoring service does not use cookies, but uses browser session storage to link the pages of a single visit when a replay is being recorded.

The platform sets strictly necessary cookies to keep you logged in and to secure your session. These do not require consent. If we ever introduce cookies or similar technologies that require consent, we will ask for it before setting them.

Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy
  • Correct inaccurate or incomplete information
  • Request deletion of your data
  • Restrict how we process your data
  • Object to processing based on our legitimate interests
  • Data portability: receive the data you gave us in a machine-readable format
  • Withdraw consent at any time, where processing is based on consent
  • Not be subject to automated decision-making that produces legal or similarly significant effects on you

To exercise any of these rights, email hello@relevee.nl. We may ask you to confirm your identity before we act on a request, so that we do not disclose or delete data at the request of the wrong person. We respond within one month. For complex or multiple requests we may take up to two further months, and we will tell you within the first month if we need that time. Exercising your rights is free of charge.

If your request concerns data a customer organisation has loaded into the platform, we will forward it to that organisation, because it is the controller of that data, and we will help it respond.

If you are unsatisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens. You may also complain to the supervisory authority in the EU country where you live or work.

Changes to this policy

We may update this policy as the platform and our data practices evolve. If a change is material, we will notify account holders by email or within the platform at least 30 days before it takes effect. For other changes, we will update the "last updated" date at the top of this page. Previous versions are available on request.

Contact

Relevé B.V.
KvK 98697390
hello@relevee.nl