This page explains what Beloplan records about you, where it is kept, who can reach it and how long it stays. It covers the Beloplan web application and the Beloplan app on your phone. What your employer then does with those records is covered by their own privacy notice, not by this one.
Responsibility
Who is responsible for your data#
Your employer. You have a Beloplan account because the company you work for uses Beloplan, and the working records in it — your hours, your tasks, your photographs — are that company’s business records. They decide what is collected, who may see it, and how long it is kept.
In the language of the GDPR, your employer is the controller and we are a processor: we run the software and look after the servers on their written instructions, and we do not use what is in their account for any purpose of our own.
Data
What Beloplan stores#
Everything below is stored because the product needs it to work. None of it is collected for advertising, none of it is sold, and none of it is combined with your activity in other apps or on other websites.
About you
- Your name, your work e-mail address and, where your company records one, your phone number.
- The language you chose and the settings you set for yourself.
- Your password — never as you typed it. What is stored is an Argon2 hash, which is a one-way calculation: it can check a password you type again, and it cannot be turned back into your password.
- Your signed-in devices. Each one is a row holding when it signed in, the browser or app it identified itself as, and the network address it came from. You can see this list, and end any session on it, under Settings.
The work you do
- Hours clocked, tasks moved, materials used, stock movements, notes and reasons you type, site-journal entries, problems you report.
- Photographs taken for the work — task photos, receipts, delivery notes, site pictures — and the documents you open, attach or sign.
- Expense claims, which are your own money until you are reimbursed. No card number, no bank account and no payment is ever collected, on the web or on the phone.
- Messages and comments you write to colleagues or to a customer through the product.
- Your company’s commercial records: customers, suppliers, quotes, invoices, prices. These are the company’s, not yours, and your account reaches only the part of them your employer granted you.
What the system records about what was done
Beloplan keeps an audit trail: which account changed which record, when, what changed from and to, the network address the change came from and the browser or app it was made with. It exists so that "who approved this hour, and when" has an answer that nobody can quietly edit.
Photographs
Photographs, and the location hidden inside them#
Cameras write things into a photograph that you cannot see, and on most phones that includes the exact coordinates where it was taken. Beloplan handles that deliberately, and the two halves of the product handle it differently — so both are written here rather than the flattering one.
On the phone app
Before a picture leaves the app, it is rebuilt keeping only which way up it is and when it was taken. Everything else goes — the location above all, including the copies some camera makers and some editing apps hide elsewhere in the file. The server never receives a coordinate from the phone app, whichever camera took the picture.
On the web application
A photograph uploaded through a browser is read by the server first: if the file carries a capture time or a position, those two values are kept as data on the record, marked with where they came from — the camera, or typed in by the person uploading. That is the point of them. A site photograph whose time and place are known is evidence in a dispute about hidden work; one without them is a picture.
The file that is then stored carries none of it. Every metadata container is removed — EXIF, XMP and IPTC alike — without re-encoding a single pixel, so the image you download later is the image that arrived, and it no longer says where it was taken. Where a position was kept, it is visible in the gallery to the colleagues who can already open the record, and it is deleted with the record.
Location
Where you are#
The phone app does not know where you are. It holds no location permission on either Android or iPhone, and no screen reads a position. When you tap "navigate there", it hands your maps app an address the server gave it — never a coordinate the app measured.
Beloplan can record where somebody was standing when they clocked in, and that is switched off for every company until two separate things are true: the company has turned it on in its own settings, and you have given your consent. Either one missing and no position is written — not stored-but-hidden, not written.
Consent here is a real consent, which means it costs nothing to refuse: refusing records your hours exactly as consenting does. Withdrawing it is one action, and it erases the positions it covered rather than merely stopping the next one. A position on an entry that has been approved is erased at that point too.
Storage & security
Where it is kept, and how it is protected#
Records live in a PostgreSQL database. Files and photographs live in object storage, separately from the database, which holds only the key that points at them. We run no hardware of our own: both are operated for us by specialist providers under contract.
One company cannot see another
Every row in the database carries the company it belongs to, and the database itself enforces the boundary through row-level security — the account the application connects with is not permitted to bypass it. This matters more than a promise: it means a mistake in application code shows up as no rows rather than as somebody else’s rows.
Getting it there
- Everything the app and the browser send travels over an encrypted connection.
- The phone app additionally checks that the server is the one it expects, so a connection intercepted on a public network fails rather than succeeding quietly.
- The web application is served from a single origin with a policy that forbids embedding it in another site and sends no referrer anywhere.
- Passwords are hashed with Argon2. Sign-in tokens are stored only as a hash, never in a form that could be replayed.
- On the phone, the financial screens block screenshots and screen recording, and your sign-in is kept in the phone’s own protected storage.
The servers, the database and the file storage are located in the European Union — Amsterdam, the Netherlands.
Access
Who at Beloplan can see your company’s data#
This is the question every honest privacy page should answer plainly, so: a small number of named people, one company at a time, with every look written down.
- There is no account at Beloplan that can read across all customers at once. Support work is done by binding to one company deliberately, and everything read inside that is checked by the same rules that apply to the company’s own staff.
- A Beloplan operator signs in with a password and a passkey on a physical device. A stolen password on its own yields a session that is authorised for nothing.
- Every operator action — every sign-in, successful or not — is written to a separate audit log that the operator cannot edit.
- We deliberately did not build the ability to sign in as one of your employees and use the product as them. It is the feature support teams reach for first, and it is the one with no honest audit trail on the customer’s side. It stays unbuilt until it can be put in a signed data-processing agreement and shown to the customer whose account it touches.
Third parties
Who else is involved#
Nothing about you is sold, and nothing is shared with anybody for their own purposes. A short list of specialist companies process data on our instructions so that the product can work at all:
- Hosting and database — the servers and the database are run for us by our hosting provider.
- File storage — photographs and documents are held with an object-storage provider.
- E-mail — invitations, password resets and notifications are delivered through a transactional e-mail provider. Nothing is sent to you for marketing.
- E-invoicing — when your company sends an invoice over the Peppol network, that invoice passes through the network’s access point, as e-invoicing requires.
- Crash reports (phone app only) — see below.
Crash reports
When the phone app crashes, it sends a technical report so the fault can be fixed. Those reports are stripped before they leave the phone: no names, no e-mail addresses, no money figures, no coordinates, and no identifier that says which phone or which person it came from. They are diagnostics, not a record of you, and they cannot be tied back to you.
The web application sends no error reports to anybody. There is no analytics tool, no advertising identifier, no tracking pixel and no third-party script on any screen of it.
Retention
How long it is kept#
Business records — hours, invoices, projects, photographs — are kept for as long as your employer keeps them. They are their records, and Belgian bookkeeping law has more to say about how long an invoice lives than we do.
What we do decide is how long the machinery around those records keeps its own traces. These sweeps run nightly and are not optional:
| What | Kept for |
|---|---|
| Audit trail — who changed what | 24 months |
| Record of an e-mail we sent you | 24 months |
| Notifications in the bell | 12 months |
| Expired sign-in tokens | 30 days past expiry |
| Queued outbound messages | 90 days |
| An upload nobody confirmed | 24 hours |
When your employer deletes your account, your name is blanked and your e-mail address, phone number and credentials are removed. The identifier stays, so that the hours you clocked and the deliveries you signed for still resolve to a person on the records that legally have to name one — but that identifier no longer leads to you.
Permissions
What the phone app asks your phone for#
- Camera — for the barcode scanner and for work photographs. Asked for the first time you use one.
- Notifications — for the running-timer notification. Asked once; the app works without it.
- Face ID / fingerprint — to unlock the app again without retyping your password.
That is all it asks a person for. It does not read your contacts, your calendar, your messages, your call history, your browsing, your health data or the other apps on your phone. It can add one calendar entry, when you ask it to, for leave that was approved — and it reads nothing back.
Your rights
Seeing, correcting and deleting your data#
Under the GDPR you can ask to see what is held about you, to have it corrected, to have it erased where the law allows, to restrict or object to how it is used, and to receive it in a portable form.
Ask your employer. The account is theirs, the records in it are theirs, and they are the ones who can act on your request. If they need us to do something technical to satisfy it, they ask us and we do it.
Two things you can do yourself, today, without asking anybody: see every device your account is signed in on and end any of those sessions, under Settings; and change your own password.
If you believe your data has been handled wrongly and your employer has not resolved it, you can complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels.
Changes & contact
Changes to this page, and how to reach us#
When this page changes materially, the version and date at the top change with it and your employer is told. The current version is always the one published here.
For anything about your own records, your hours or your account: ask your employer first — they hold the account and they can act on it. For a question about the software itself, or a privacy question your employer cannot answer, write to us.
Contact
Beloplan BV
Dilbeek, Belgium