Legal
Privacy policy
How this service handles personal data. Last updated 28 September 2026.
Who is responsible
Subsido is an independent information service operated by a company established in Belgium. It is not affiliated with, endorsed by, or operated by any government or public authority. The operator is the controller of the personal data described here. For anything on this page, including requests to access or delete data, write to hello@subsido.be.
What the data is about
The measures this service carries (grants, loans, tax measures and their conditions) are published by public authorities and describe schemes, not people. Where a publication names a contact person, that part is not imported. The personal data this service holds is about its own account holders, and whatever account holders choose to send about the companies they match, below.
If you hold an account
An account exists so you can hold an API key, see your usage and pay for a plan. What is stored is what those three things need and nothing beyond them.
- Name and email address
- From your Google sign-in, with the fact that Google has verified the address. To identify the account, address you in the dashboard, and write to you about your keys, your plan or a change to our terms or this policy.
- Google account identifier
- The permanent identifier Google gives your account. See the section below.
- Password
- None: you sign in with Google.
- Session records
- A SHA-256 hash of the session token, and when it was created, last used and expires. Sessions last 30 days. The token itself is not stored.
- API keys
- A SHA-256 hash of the key, its first characters, whether it is live or test, the name you gave it, and when it was last used. The key itself is shown once and never stored, which is why we cannot recover a lost one.
- API usage
- Requests, errors, rate-limited requests and the volume of data sent, per account, per endpoint, per day, and match evaluations per month. Counts only: never the parameters you sent or the data you received. They drive your quota, the usage chart in the dashboard and billing.
- Technical logs
- The proxy in front of the website and the API, and the servers behind it, log what they need to run and secure the service: for each request the time, the address requested, the status, the request id, the browser or client software (user agent) and the visitor’s IP address, and errors. They are not joined to your account in any report. Addresses used to limit the rate of requests are held in memory only, for a day at most.
- Refused capabilities
- Per day, which gated feature an account asked for without its plan including it, and how often. So we know what people need.
- Billing identifiers
- A Stripe customer and subscription id, the price and plan you are on, its renewal date and whether it is set to end, and the record of what each Stripe notification changed.
- Webhook endpoints
- Only if you create one: the URL, its filters, the signing secret, and each delivery’s status and the HTTP status your server answered.
- Operator flag and last sign-in
- Whether the account can reach the operator dashboard, and when it last signed in.
There is no advertising and no profiling. Nothing about you is sold or shared for anyone else’s marketing.
Company facts you send us
Matching needs facts about a company: a postcode, a headcount, a turnover, NACE codes, a legal form, a founding date, an enterprise number, a project budget. For most companies these are business data. For a sole proprietor they can be personal data, so they are handled as such.
- POST /v1/match, bulk match, the MCP tools and the check on this website
- The facts are used only to compute the answer. They are evaluated in memory and are not stored, not logged and not used for anything else; what remains is the count of match evaluations on the account that made the call. An enterprise number is checked for its check digits and echoed back; no register is consulted with it. The check on this website passes what you type in its form to the API in the same way, under the site’s own account, and keeps nothing either.
- Watchlists
- When you put a company on a watchlist, we store your reference for it, the company and project facts you sent, and its current matches, so it can be re-evaluated whenever a measure changes. They are kept until you remove the company or delete the watchlist, or the account is deleted. We ask for facts, not names: use a reference that means something to you and nothing to anyone else.
For the companies you send, you decide what is sent and why; we process it on your behalf, to answer your request. Do not send names, addresses of people or anything the matcher does not ask for: it has no field for them, and a property it does not know is refused.
Signing in with Google
Accounts are created and signed in with Google: Google hands your browser a signed token, which our API checks against Google’s published keys. The token names a permanent identifier for your Google account, your email address and whether Google has verified it, and your name. We keep the identifier, the address, the fact that it is verified, and the name, and nothing else: no contacts, no calendar, no access to anything in your Google account.
The account is keyed on the identifier, not the email address. An address can be changed by its owner or reassigned to someone else entirely, and that person should not inherit your API keys.
Revoking access at your Google account permissions stops future sign-ins. It does not delete the account here; write to us for that.
Payments
Payments are handled by Stripe, as our processor. Card details are entered on Stripe’s own checkout, never on this site, and never reach our servers. Stripe also collects the billing address and VAT number that invoicing needs. We receive only the identifiers and subscription status listed above. Stripe’s handling of your payment details is covered by Stripe’s privacy policy.
Cookies and analytics
Two cookies of our own. sb_session holds your sign-in session, is marked httpOnly so no script can read it, and expires after 30 days or when you sign out. sb_lang remembers for a year which language you read the site in, so the address without a language takes you there. Both serve what you ask for yourself, do nothing else, and are not used to track you.
The website uses Google Analytics 4 to count visits: which pages are read, which sites and searches bring visitors, the type of device and browser, and roughly which country or region visitors are in. It sets the cookies _ga and _ga_* so a returning visitor is not counted twice, and keeps them for up to two years. Google Analytics does not store IP addresses, and what we see are aggregate reports that are never linked to your account. It runs on the website only, never on the API: nothing you send to the API reaches Google.
Google Analytics loads only after you accept it in the banner at the bottom of the page. If you decline, it does not load and Google sets no cookies. Your choice is kept in your browser. You withdraw consent by clearing this site’s data in your browser, after which the banner appears again. Google’s opt-out add-on or a content blocker also stops it.
Where the data lives, and for how long
Everything runs on a rented server at netcup in Germany, in the European Union, with Cloudflare in front of it. The database is not reachable from the internet. Payments go to Stripe, and Google receives a sign-in request only when you choose to sign in; Google Analytics receives the page views described above. Web fonts are loaded from Bunny Fonts, so your browser requests them from that service; we receive nothing from it. There are no other processors, and nothing is transferred outside the EU by us, apart from what Stripe, Google and Cloudflare do under their own safeguards.
- Account records
- Kept while the account exists, and deleted on request, with its keys, usage, watchlists and webhooks.
- Sessions
- 30 days, then deleted.
- Revoked API keys
- The hash is kept so a revoked key stays revoked.
- Usage counters
- Aggregated per day and kept while the account exists; the dashboard shows the last 30 days.
- Technical logs
- Rotated by size and overwritten; they are not archived.
- Match requests
- Not kept.
- Watchlist companies
- Until you remove them or delete the watchlist.
- Billing records
- What each Stripe notification changed, kept for accounting as the law requires.
Legal bases
- Your account, keys, sessions, usage and webhooks: needed to perform the contract you enter into when you create an account and choose a plan (Article 6(1)(b) GDPR).
- Billing records: to meet our accounting and tax obligations (Article 6(1)(c) GDPR).
- Technical logs, rate limiting and refused capabilities: our legitimate interest in running a secure, stable service and in knowing what users need (Article 6(1)(f) GDPR).
- Google Analytics: your consent (Article 6(1)(a) GDPR), which you can withdraw at any time as described above.
- Company facts you send, including on a watchlist: we process them on your behalf. You decide why they are processed, and you need a legal basis of your own for sending them.
Your rights
Under the General Data Protection Regulation (GDPR) you may ask for a copy of what is held about you, ask for it to be corrected or deleted, ask for its processing to be restricted, or receive it in a portable format. You may object to how it is processed, in particular to processing based on our legitimate interest, and complain to a supervisory authority. In Belgium that is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données). Write to hello@subsido.be and you will get an answer within 30 days. There is no charge, and you do not need to give a reason for a deletion request.
Changes
If this policy changes in a way that affects you, the date at the top changes and account holders are emailed. It is never changed silently.
This policy exists in Dutch, French and English. The three versions have the same value; in case of doubt, none prevails over the others.
See also the terms of service and the sources we use.
