Privacy Policy
Last updated: 28 August 2026
Mondivio builds software that runs on your own server. For most of what we make, we never see your data at all — and this page explains exactly where that line sits.
Who we are
| Controller | Mondivio IT & Agriculture (“Mondivio”, “we”, “us”) |
|---|---|
| Address | Spangesekade, Rotterdam, the Netherlands |
| Chamber of Commerce | KvK 90316630 |
| General contact | info@mondivio.com |
| Privacy questions | info@mondivio.com |
We are established in the Netherlands, so the EU General Data Protection Regulation (GDPR) applies to everything described below.
1. This website
mondivio.com is a static website. We run no analytics, no tracking pixels, no advertising tags and no contact forms. We do not build visitor profiles, and we do not sell or share data with advertisers.
Our hosting provider keeps standard server logs (IP address, timestamp, requested URL, user agent) for security and troubleshooting. These are ordinary technical records kept on our behalf, retained for a short period, and used for no other purpose. Legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).
One page — /support-copilot/ — loads the Freemius checkout script so you can buy without leaving the page. See our cookie statement for what that means.
2. When you buy Support Copilot
Purchases are handled by Freemius, Inc., acting as the Merchant of Record. That means Freemius — not Mondivio — is the seller on the invoice, and Freemius collects and processes your payment and billing details, including the data needed to charge EU VAT correctly.
We never see or store your full payment card details. Through the Freemius vendor dashboard we can see your licence, your billing email address and your purchase history, which we use to provide support, honour refunds and deliver updates. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
Freemius maintains its own privacy policy at freemius.com/privacy.
3. The Support Copilot plugin
Support Copilot runs entirely on your own WordPress server. Conversations, customer emails and order data are stored in your own database. They are never sent to Mondivio, and we have no way to read them.
What the plugin stores on your server
The plugin creates three database tables in your WordPress installation:
- Conversations — session key, start and last-activity time, language, visitor IP address, WordPress user ID (if logged in), message count, and the email address used for a hand-off, if any.
- Messages — the text of each message in the conversation, with its role and timestamp.
- Tickets — ticket reference, customer email address, a summary, and the conversation transcript.
If you install the plugin on your store, you are the controller of that data under the GDPR, and it is your own privacy policy that must describe it to your customers. Mondivio is not a processor of it, because it never reaches us.
AI providers
To answer a question, the plugin sends the conversation and the relevant store context to the AI provider you select, using your own API key. Supported providers are OpenAI, Anthropic and Google. Your relationship with that provider is direct: their terms, their data-processing agreement, their retention policy. Mondivio is not a party to it and receives no copy.
Because you bring your own key, you can pick a provider whose terms and region suit your business, and you can switch provider at any time.
Optional integrations
If you configure the optional webhook, ticket data is sent to the Zapier endpoint you supply. This is off by default and only ever goes where you point it.
Licence checks and product analytics
The plugin bundles the Freemius SDK to validate your licence and deliver updates. On activation, Freemius asks whether you want to share basic environment and usage data. This is opt-in — you can decline and keep using the plugin. If you accept, that data goes to Freemius under their privacy policy. Licence validation itself contacts Freemius so we can confirm your subscription is active.
4. When you email us
If you write to info@mondivio.com or support@mondivio.com, we keep your message and our reply so we can help you and refer back to the conversation later. We use it for nothing else. Legal basis: our legitimate interest in answering the people who contact us, or performance of our contract where you are a customer.
5. How long we keep things
| Server logs | Short-term, as kept by our hosting provider for security purposes |
|---|---|
| Support correspondence | As long as needed to support you, and afterwards while a dispute could reasonably arise |
| Purchase and licence records | Seven years, to meet Dutch tax and accounting obligations |
| Data inside the plugin | Controlled entirely by you, on your own server |
6. Sharing
We do not sell personal data and we do not share it for advertising. We share it only with the service providers we need in order to run the business — our hosting provider, and Freemius for payments and licensing — and where the law requires it.
7. Your rights
Under the GDPR you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or hand it over in a portable format. Where we rely on your consent, you can withdraw it at any time.
Email info@mondivio.com and we will respond within one month. If you are not satisfied, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority where you live.
One practical note: for data held inside a Support Copilot installation on somebody else’s store, we cannot act on your request, because we have no access to it. Please contact that store directly.
8. Changes
If we change this policy, we will update the date at the top of the page. Material changes to how we handle customer data will be announced by email to affected customers.