Privacy Policy
Last updated: 29 August 2026
Mondivio Solutions builds software in more than one shape. Some of it runs entirely on your own servers and never reaches us. Some of it we host and operate on a client’s behalf. Some of it is our own platform. What happens to personal data is genuinely different in each case — so this page says which is which, rather than pretending one answer covers all three.
Who we are
| Controller | Mondivio Solutions (“Mondivio”, “we”, “us”) |
|---|---|
| Address | Rotterdam, the Netherlands |
| Chamber of Commerce | KvK 90316630 |
| General contact | info@mondivio.com |
| Privacy questions | info@mondivio.com |
We are established in the Netherlands, so the EU General Data Protection Regulation (GDPR) applies to everything described below.
The three shapes, and our role in each
Before the detail, the part that decides everything else — what we actually are, legally, for a given piece of software:
| Software that runs on your own infrastructure | You install it, it stores data in your own database, and it is never transmitted to us. You are the controller and we are not a processor, because the data does not reach us. Example: the AI Support Chat plugin for WooCommerce. |
|---|---|
| Systems we host and operate for a client | We run the service, so personal data does pass through infrastructure we control. The client is the controller and we are their processor, under a written data-processing agreement that names the sub-processors, where the data is stored and how long it is kept. |
| Our own platforms | Products we operate and sell under our own name. We are the controller for the service itself. Each carries its own privacy notice, because the sub-processors and the retention differ per product. |
We do not claim that everything we build stays on your own server. Much of it does not. Where we hold data, we say so on this page, and a data-processing agreement governs it.
1. This website
mondivio.com is a static website. We run no analytics, no tracking pixels, no advertising tags and no contact forms. We do not build visitor profiles, and we do not sell or share data with advertisers.
Our hosting provider keeps standard server logs (IP address, timestamp, requested URL, user agent) for security and troubleshooting. These are ordinary technical records kept on our behalf, retained for a short period, and used for no other purpose. Legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).
One page — /ai-support-chat/ — loads the Freemius checkout script so you can buy without leaving the page. See our cookie statement for what that means.
2. When you contact us
If you write to info@mondivio.com or support@mondivio.com, or call us, we keep your message and our reply so we can help you and refer back to the conversation later. If a conversation turns into a proposal, we keep that correspondence and the quote as part of the record of the engagement. We use it for nothing else, and we do not add you to a mailing list.
Legal basis: our legitimate interest in answering the people who contact us, or the steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR).
3. When you buy software from us
How a purchase is handled depends on which product you are buying, because we do not sell them the same way. In neither case do we see or store your full payment card details.
| The WooCommerce plugin | Sold through Freemius, Inc. as Merchant of Record. Freemius — not Mondivio — is the seller named on your invoice, takes the payment and accounts for EU VAT. Through the Freemius vendor dashboard we can see your licence, your billing email address and your purchase history, which we use to provide support, honour refunds and deliver updates. Freemius has its own privacy policy at freemius.com/privacy. |
|---|---|
| IntellyPilot | Sold as a subscription on its own site, under its own terms. Card payments are processed by Stripe, which holds the card details so that we do not. Stripe is a payment processor rather than the seller, so unlike the arrangement above the invoice comes from us. What IntellyPilot itself records about you is set out in its own notice at intellypilot.com/legal/privacy. |
Legal basis in both cases: performance of our contract with you (Art. 6(1)(b) GDPR).
4. When we build or run something for you
In advisory, integration and custom-build work we regularly encounter personal data that belongs to our client — in a database we are migrating, a system we are debugging, or a service we operate on their behalf. In all of that work the client is the controller and we act on their documented instructions.
- Before we touch production data, a data-processing agreement is put in place. It names the purpose, the categories of data, the sub-processors, where the data is stored, and how long we keep it.
- Access is limited to the people doing the work, and withdrawn when the engagement ends.
- Where we host a system, the hosting region is agreed in writing.
- At the end of an engagement we return or delete the data, at the client’s choice, except where the law requires us to keep a record.
If you are an employee, customer or contact of one of our clients and you want to exercise a right over your data, please contact that client directly — they are the controller, and we may not act on your request without their instruction. We will always help them respond.
5. Our products
Each product has its own privacy notice, because what happens to data differs per product. This page covers Mondivio as a company; the notices below cover the products themselves.
| AI Support Chat for WooCommerce | A WordPress plugin that runs on the shop’s own server. Conversations, customer emails and order data stay on that server and never reach us. Read the AI Support Chat privacy notice → |
|---|---|
| IntellyPilot | A marketing platform we operate ourselves, so here we are the controller for the service. It has its own privacy notice covering accounts, content and the providers it relies on. Read the IntellyPilot privacy notice → |
When further products launch, their notices will be listed here before they are available to buy.
6. How long we keep things
| Server logs | Short-term, as kept by our hosting provider for security purposes |
|---|---|
| Support and sales correspondence | As long as needed to help you, and afterwards while a dispute could reasonably arise |
| Purchase and licence records | Seven years, to meet Dutch tax and accounting obligations |
| Client data we process on instruction | As set out in the data-processing agreement for that engagement |
| Data inside software installed on your own server | Controlled entirely by you, on your own infrastructure |
7. Sharing
We do not sell personal data and we do not share it for advertising. We share it only with the service providers we need in order to run the business — our hosting provider, Freemius for plugin sales and licensing, and Stripe for subscription payments — with the sub-processors named in a client’s data-processing agreement, and where the law requires it.
8. Your rights
Under the GDPR you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or hand it over in a portable format. Where we rely on your consent, you can withdraw it at any time.
Email info@mondivio.com and we will respond within one month. If you are not satisfied, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority where you live.
Two practical notes. For data held inside software installed on somebody else’s server, we cannot act on your request, because we have no access to it — please contact that organisation. For data we process on a client’s instruction, we will pass your request to that client and support them in answering it.
9. Changes
If we change this policy, we will update the date at the top of the page. Material changes to how we handle customer or client data will be announced by email to those affected.