Privacy Policy
Cohively
Last updated: 12 August 2026
This Privacy Policy explains how Vulpo BV (Brusselsesteenweg 81, 9230 Wetteren, Belgium, company number 0749.617.582, VAT BE 0749.617.582) — operator of the Cohively platform — collects, uses and protects personal data. Vulpo BV is the data controller for the personal data described below. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Belgium law.
For questions about this policy or to exercise your rights, contact us at info@cohively.com.
Who this policy covers
Cohively is a workspace tool sold to businesses. For personal data that a customer company enters about its own team members, clients and contacts, that company is the controller and Vulpo BV acts as its processor under the Terms & Conditions. For account, billing and platform-operation data, Vulpo BV is the controller. This policy describes both roles.
Personal data we process
- Account data — first and last name, email address, phone number, date of birth (optional), password (stored only as a secure one-way hash), locale, notification and marketing preferences, and profile/cover images you choose to upload.
- Company & billing data — company name, VAT number, address and billing email used to create your workspace and process subscriptions.
- Client & contact data — names, emails, phone numbers, VAT numbers and addresses your company records about its clients.
- Content you create — tickets, comments, documents, projects, time entries, polls, calendar entries, assets and support messages. These free-text fields may contain personal data you choose to enter.
- Vault data — credentials and secure notes stored in the password vault. Secret values are encrypted (see “Security”); only non-secret metadata (labels, URLs) is indexed for search.
- Special-category data — where you record sick or family leave, the reason field may reveal health information. It is stored encrypted and used only to manage leave.
- Usage & security data — IP address, browser/user-agent, sign-in history and an audit trail of security-relevant actions, kept to protect your account and the platform.
Why we process it, and our legal bases
- To provide the service (Art. 6(1)(b) — contract): creating and running your workspace, authentication, and the features you use.
- To bill you (Art. 6(1)(b) and (c) — contract and legal obligation): processing subscriptions and keeping the invoicing records tax law requires.
- To keep the platform secure (Art. 6(1)(f) — legitimate interests): audit logging, sign-in history, breached-password checks and abuse prevention.
- To send product news (Art. 6(1)(a) — consent): only if you opt in; you can withdraw at any time.
- Special-category data (Art. 9(2)(b)): leave-management data is processed to meet employment-law obligations of the customer company.
Service providers (processors) we share data with
We use a small number of vetted providers to run Cohively. Except for Paddle, our Merchant of Record (see below), each processes personal data only on our instructions under a data-processing agreement:
- Paddle — payments and subscription billing as reseller and Merchant of Record; receives billing name, email and address. For payment processing, tax and fraud prevention Paddle acts as an independent controller under its own privacy policy, not as our processor.
- Google Cloud — hosting of encryption keys (Cloud KMS, EU region), file/media storage, and address geocoding (Maps).
- Our email provider — delivery of transactional and, if opted in, product emails.
- Sentry — error monitoring, configured not to send personal data by default.
- Search infrastructure — full-text search over your workspace content; run within our own infrastructure unless a hosted engine is configured, in which case it is covered by a processing agreement.
- Have I Been Pwned — checks whether a chosen password has appeared in a breach, using k-anonymity so no password or identifiable data leaves our servers.
We do not sell personal data. Where a provider processes data outside the EEA, we rely on adequacy decisions or Standard Contractual Clauses as appropriate.
How long we keep it
We keep personal data for as long as your account or workspace is active. Security logs (audit trail and sign-in history, including IP addresses) are retained for a limited period and then automatically deleted. Invoicing records are kept for the period required by tax law. When an account or client is erased, its personal data is anonymised (see “Your rights”).
Your rights
Subject to the conditions in the GDPR, you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and to data portability. You can:
- Access & portability — download a machine-readable export of your personal data from your profile page.
- Rectification — edit your profile details at any time.
- Erasure — request account deletion from your profile; your administrators action it and your personal data is then irreversibly anonymised.
- Withdraw consent — turn off marketing emails at any time.
To exercise any right, contact info@cohively.com. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données). Where a customer company is the controller (its team, client and content data), we will forward your request to that company.
Security
Passwords are stored as one-way hashes and two-factor secrets are encrypted. Vault secrets are encrypted with a dedicated per-company key using Google Cloud KMS. Access is restricted per company and per permission, transport is encrypted with TLS, and access to secrets is audited. Despite these measures, no online service can be guaranteed perfectly secure.
Cookies
We use only strictly necessary cookies to keep you signed in and secure your session. We do not use advertising or third-party tracking cookies.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the platform, and the “last updated” date above will change.
Contact
Vulpo BV, Brusselsesteenweg 81, 9230 Wetteren, Belgium — info@cohively.com. Data-protection enquiries: info@cohively.com.