Legal

Privacy Policy

Last updated: 29 August 2026

Mondivio Solutions builds software in more than one shape. Some of it runs entirely on your own servers and never reaches us. Some of it we host and operate on a client’s behalf. Some of it is our own platform. What happens to personal data is genuinely different in each case — so this page says which is which, rather than pretending one answer covers all three.

Who we are

ControllerMondivio Solutions (“Mondivio”, “we”, “us”)
AddressRotterdam, the Netherlands
Chamber of CommerceKvK 90316630
General contactinfo@mondivio.com
Privacy questionsinfo@mondivio.com

We are established in the Netherlands, so the EU General Data Protection Regulation (GDPR) applies to everything described below.

The three shapes, and our role in each

Before the detail, the part that decides everything else — what we actually are, legally, for a given piece of software:

Software that runs on your own infrastructure You install it, it stores data in your own database, and it is never transmitted to us. You are the controller and we are not a processor, because the data does not reach us. Example: the AI Support Chat plugin for WooCommerce.
Systems we host and operate for a client We run the service, so personal data does pass through infrastructure we control. The client is the controller and we are their processor, under a written data-processing agreement that names the sub-processors, where the data is stored and how long it is kept.
Our own platforms Products we operate and sell under our own name. We are the controller for the service itself. Each carries its own privacy notice, because the sub-processors and the retention differ per product.

We do not claim that everything we build stays on your own server. Much of it does not. Where we hold data, we say so on this page, and a data-processing agreement governs it.

1. This website

mondivio.com is a static website. We run no analytics, no tracking pixels, no advertising tags and no contact forms. We do not build visitor profiles, and we do not sell or share data with advertisers.

Our hosting provider keeps standard server logs (IP address, timestamp, requested URL, user agent) for security and troubleshooting. These are ordinary technical records kept on our behalf, retained for a short period, and used for no other purpose. Legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).

One page — /ai-support-chat/ — loads the Freemius checkout script so you can buy without leaving the page. See our cookie statement for what that means.

2. When you contact us

If you write to info@mondivio.com or support@mondivio.com, or call us, we keep your message and our reply so we can help you and refer back to the conversation later. If a conversation turns into a proposal, we keep that correspondence and the quote as part of the record of the engagement. We use it for nothing else, and we do not add you to a mailing list.

Legal basis: our legitimate interest in answering the people who contact us, or the steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR).

3. When you buy software from us

How a purchase is handled depends on which product you are buying, because we do not sell them the same way. In neither case do we see or store your full payment card details.

The WooCommerce plugin Sold through Freemius, Inc. as Merchant of Record. Freemius — not Mondivio — is the seller named on your invoice, takes the payment and accounts for EU VAT. Through the Freemius vendor dashboard we can see your licence, your billing email address and your purchase history, which we use to provide support, honour refunds and deliver updates. Freemius has its own privacy policy at freemius.com/privacy.
IntellyPilot Sold as a subscription on its own site, under its own terms. Card payments are processed by Stripe, which holds the card details so that we do not. Stripe is a payment processor rather than the seller, so unlike the arrangement above the invoice comes from us. What IntellyPilot itself records about you is set out in its own notice at intellypilot.com/legal/privacy.

Legal basis in both cases: performance of our contract with you (Art. 6(1)(b) GDPR).

4. When we build or run something for you

In advisory, integration and custom-build work we regularly encounter personal data that belongs to our client — in a database we are migrating, a system we are debugging, or a service we operate on their behalf. In all of that work the client is the controller and we act on their documented instructions.

If you are an employee, customer or contact of one of our clients and you want to exercise a right over your data, please contact that client directly — they are the controller, and we may not act on your request without their instruction. We will always help them respond.

5. Our products

Each product has its own privacy notice, because what happens to data differs per product. This page covers Mondivio as a company; the notices below cover the products themselves.

AI Support Chat for WooCommerce A WordPress plugin that runs on the shop’s own server. Conversations, customer emails and order data stay on that server and never reach us.
Read the AI Support Chat privacy notice →
IntellyPilot A marketing platform we operate ourselves, so here we are the controller for the service. It has its own privacy notice covering accounts, content and the providers it relies on.
Read the IntellyPilot privacy notice →

When further products launch, their notices will be listed here before they are available to buy.

6. How long we keep things

Server logsShort-term, as kept by our hosting provider for security purposes
Support and sales correspondenceAs long as needed to help you, and afterwards while a dispute could reasonably arise
Purchase and licence recordsSeven years, to meet Dutch tax and accounting obligations
Client data we process on instructionAs set out in the data-processing agreement for that engagement
Data inside software installed on your own serverControlled entirely by you, on your own infrastructure

7. Sharing

We do not sell personal data and we do not share it for advertising. We share it only with the service providers we need in order to run the business — our hosting provider, Freemius for plugin sales and licensing, and Stripe for subscription payments — with the sub-processors named in a client’s data-processing agreement, and where the law requires it.

8. Your rights

Under the GDPR you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or hand it over in a portable format. Where we rely on your consent, you can withdraw it at any time.

Email info@mondivio.com and we will respond within one month. If you are not satisfied, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority where you live.

Two practical notes. For data held inside software installed on somebody else’s server, we cannot act on your request, because we have no access to it — please contact that organisation. For data we process on a client’s instruction, we will pass your request to that client and support them in answering it.

9. Changes

If we change this policy, we will update the date at the top of the page. Material changes to how we handle customer or client data will be announced by email to those affected.