Overview & scope¶
This Privacy Policy applies to the JustClose web application available atjustclose.be and any sub-domains operated by Stay Active CommV (the "Service"). It governs how we process personal data of two groups:
- Users — agency administrators and sub-account operators who log into JustClose to manage their CRM.
- End-customers — individuals whose data is captured into JustClose by our Users (via web forms, Facebook Lead Ads, Messenger conversations, etc.).
For end-customers, Stay Active CommV acts as a data processor on behalf of the User (who is the controller). For account-related data of Users themselves, we act as the controller.
Who we are¶
JustClose is operated by:
BE0805615187 · Trading as RenoAd Agency / JustCloseYou can reach us at [email protected] for any privacy-related question, data-subject request, or security report.
Data we collect¶
We collect three categories of data:
From you directly
- Account identity: full name, email address, telephone number, password (stored as a salted hash).
- Business profile: company name, address, BTW/VAT number, logo, time-zone preference.
- Contact records you import: names, emails, phone numbers, addresses, custom field values, tags.
- Communications you send via the Service: SMS, email, WhatsApp, Messenger, and Instagram DM messages, plus any attached media.
Automatically
- Technical metadata: IP address, browser user-agent, OS, screen size.
- Session activity: login times, pages viewed, actions taken inside the dashboard.
- Cookies strictly necessary for authentication and CSRF protection.
From connected third-party platforms
- Meta (Facebook & Instagram) — see § 04 for the dedicated breakdown.
- Stripe — payment events for our subscription billing (event IDs, masked card brand/last-four, not full card details).
- Twilio & Postmark — message-delivery status callbacks for SMS, WhatsApp, and email.
Data received via Meta APIs¶
When a User connects a Facebook Page (and any linked Instagram business account) to JustClose, we use Meta's Graph API + Webhooks to receive and process specific event types. The permissions we request are:
What we store
- Page Access Tokens — encrypted at rest with AES-256-GCM via our
INTEGRATION_ENCRYPTION_KEY. Used only for outbound Graph API calls (fetching leads, sending messages). - Lead form data — every field value submitted by the end-customer, persisted as a Contact in your sub-account.
- Messages — text content, attachments, sender/recipient IDs, and Meta's message_id. Stored against the Conversation thread.
- Webhook payloads — deduplicated by Meta's event ID. Raw payloads retained for 30 days for debugging.
What we do NOT do
- We do not sell or rent any Meta-sourced data to third parties.
- We do not use it for training machine-learning models.
- We do not enrich it with data brokers or external profiling services.
- We do not access Page data outside the explicit permissions listed above.
How we use your data¶
We process the data above for the following purposes:
- Service delivery — operating the CRM, routing leads and messages into the right sub-account, sending workflow-triggered communications.
- Account administration — authentication, billing, support, fraud prevention.
- Service improvement — aggregate usage analytics, error tracking via Sentry (no message bodies, no Meta data).
- Legal compliance — responding to lawful requests, retaining records where statutorily required.
Our legal basis under GDPR Art. 6 is (a) contractual necessity for Users and (b) legitimate interest of our User-controllers for end-customer data, balanced against the rights of the data subject.
Sub-processors¶
We rely on a small number of carefully vetted sub-processors. Each is bound by a data-processing agreement that mirrors our obligations.
SCC = Standard Contractual Clauses. DPF = EU-US Data Privacy Framework certified.
Data retention¶
We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law:
- Account data — for the duration of your active subscription, plus 90 days after termination for export/recovery.
- Contact records & conversations — controlled by you. Deletable at any time from the dashboard. Hard-deleted from backups within 35 days.
- Meta webhook payloads — 30 days, then purged.
- Billing records — 7 years (Belgian tax law).
- Server & security logs — 90 days rolling window.
Your rights (GDPR)¶
Under the General Data Protection Regulation you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion ("right to be forgotten").
- Restriction — limit processing in specific circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Lodge a complaint — with the Belgian Data Protection Authority (gegevensbeschermingsautoriteit.be).
To exercise any of these, email [email protected] from the address registered to your account. We respond within 30 days.
Requesting data deletion¶
You can request that JustClose delete your personal data through two channels:
Via Facebook Settings (for Meta-connected data)
- Open Facebook → Settings & privacy → Settings → Apps and Websites.
- Find JustClose in the list, click Remove.
- Choose Request that the app delete data.
Facebook will forward your request to our /api/webhooks/meta-data-deletion endpoint. We acknowledge with a confirmation code and delete the corresponding data within 30 days. The confirmation URL we return lets you check status at any time.
Directly via email
Email [email protected] with the subject "GDPR deletion request" and include the email address you registered with. We confirm receipt within 5 working days and delete within 30 days.
International transfers¶
Our primary infrastructure is in the EU (Hetzner, Germany). Some sub-processors (Twilio, Postmark, Stripe US-side) may process data outside the EU. Transfers rely on Standard Contractual Clauses (Module Two: Controller-to-Processor) and, where applicable, the EU-US Data Privacy Framework certifications.
Security measures¶
We apply the following technical and organisational measures:
- TLS 1.3 in transit for all customer-facing endpoints.
- AES-256-GCM encryption at rest for secrets (access tokens, API keys, encrypted credentials).
- HMAC-SHA256 signature verification on every inbound Meta webhook.
- Per-project tenant isolation enforced at the database query layer via
withScopedAuth. - Hashed and salted password storage (bcrypt).
- JWT sessions with rotation, CSRF tokens, and rate-limited authentication endpoints.
- Daily encrypted backups, retained 35 days.
- Quarterly internal security audits, vulnerability disclosure at [email protected].
Children's privacy¶
JustClose is not intended for use by individuals under 16. We do not knowingly collect personal data from minors. If you believe a minor has provided data to us, please contact [email protected] and we will delete the record promptly.
Changes to this policy¶
We may update this policy as the Service evolves or regulation changes. Material changes are announced via email to all active account holders at least 14 days before they take effect. The version number and effective date at the top of this page always reflect the current published policy.
Contact¶
For any privacy matter — questions, requests, complaints, or vulnerability reports:
Belgian Data Protection Authority: gegevensbeschermingsautoriteit.be