Back

Privacy policy

This policy describes how Prosio collects, uses, retains and protects personal data, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the "GDPR") and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.

Last updated · September 12, 2026

1. Data controller

The controller of the data collected through the Prosio website and application is: Salama Forever SRL (commercial brand "Prosio"), registered office at rue du Bon Pasteur 54/1, 1140 Evere (Brussels), Belgium, registered with the CBE under number BE 0711.688.802.

When Prosio acts as a processor on behalf of a customer (dealership, automotive group), that customer is the controller for the prospect data they import and use in the application. The respective obligations are then governed by the data processing agreement (DPA) entered into with the customer.

2. Data protection contact

Single contact point for any request relating to personal data: contact@prosio.be.

Any request is handled within one month in accordance with Article 12 of the GDPR, extendable by two months in case of a complex request (with reasoned notification to the data subject).

3. Scope

This policy applies:

— to the prosio.be marketing website (public pages and contact forms) ; — to the Prosio application accessible upon authentication ; — to exchanges with the Prosio teams (sales, support, security, DPO).

It does not cover third-party websites to which Prosio may refer through hyperlinks.

4. Categories of data collected

Professional identification data: name, title, role, employer, business email address and phone number.

Account and authentication data: identifier, authentication managed by Supabase, language preference and time zone. Tokens for linked Google or Microsoft accounts are encrypted by the application with AES-256-GCM before storage.

Technical data: session information and logs produced by configured services.

Entered or imported business data: companies, contacts, quotes, drafts, messages, notes, appointments and files. When the user requests a Google preview, the application retrieves authorised Gmail metadata and Calendar events.

Prosio is intended for professional commercial information. Do not enter sensitive data without agreeing an appropriate processing framework with your organisation.

5. Sources of the data

Directly from the user: account creation, data entry, CSV/XLSX imports and linking a Google or Microsoft account.

From the employer customer: account provisioning, imported data and configured access.

From connected services: authorised data during Google previews and events delivered by configured business workflows. Linking an account does not by itself start mailbox synchronisation.

Hosting and authentication services also produce technical session information and logs.

6. Processing purposes

Provide the service: authentication, sales data, conversation follow-up, tasks, appointments and connected-account previews. Configured workflows may draft and send messages; their access and purposes must be reviewed for the customer.

Manage sales enquiries, the contractual relationship and support; protect the service and meet applicable obligations. Customer data must not be reused for a new purpose without an appropriate legal basis and information.

7. Legal bases (Article 6 GDPR)

The legal basis must match each purpose and data subject: performance of a contract where that person is a party, a legal obligation, an assessed legitimate interest, or consent where required. The customer employer determines and documents the basis for processing its CRM contacts.

Technical OAuth authorization from Google or Microsoft is not, by itself, GDPR consent for every email processing activity. The customer must inform users and affected contacts and check the rules for commercial communications. A contact being B2B does not remove these obligations.

8. Retention periods

Account data is retained to provide the service during the active relationship, then only for purposes and periods justified by applicable obligations or the defence of rights. Exact periods must be provided in the service documents before use with real data.

For CRM data, the customer defines archiving and deletion rules in its instructions and DPA. Log and backup retention depends on enabled services. This page does not attest to automatic deletion or a complete end-of-contract export.

Removing a Google or Microsoft connection deletes the tokens stored in Prosio; it does not delete data already imported into the CRM or messages held by the provider. Also revoke authorization with that provider.

9. Recipients

Within Salama Forever SRL: product, support, security, accounting teams, on a need-to-know basis.

Within the employer customer: authorised administrators and users access data according to their role and dealership scope. Access relies on application controls and database rules.

From sub-processors: see section 10.

From public authorities: upon Belgian or European judicial requisition based on a legal ground.

Prosio does not sell or rent personal data to third parties.

10. Sub-processors

Supabase provides the database and authentication services used by the application. The Next.js host and any file, transactional email and orchestration services depend on the deployment.

Depending on enabled connections, Google may provide authentication and Gmail/Calendar previews on request. Microsoft may provide SSO and an OAuth link to an Outlook account. This link does not constitute synchronisation or connect CRM delivery to Microsoft Graph.

Configured n8n workflows may use a delivery service and an AI provider, such as Anthropic, to prepare a draft. The transmitted context may include professional contact details and message content. The providers’ processing, retention and data-use terms must be checked for the service actually subscribed to; no zero-retention arrangement is assumed.

The providers actually used, their regions and applicable safeguards must be described in the service documents and DPA for the environment concerned. Contractual notification and objection terms remain those of the applicable DPA.

11. International transfers

Processing regions and any transfers depend on the providers actually enabled and their service terms. They must be identified for the Customer’s environment; a provider having a European presence does not by itself guarantee the absence of transfers.

Where a transfer to a third country is unavoidable, it is necessarily based on:

— an adequacy decision of the European Commission (Article 45 GDPR) ; — failing that, the standard contractual clauses adopted by the Commission on 4 June 2021 (Article 46 GDPR) ; — or any other appropriate safeguard provided for in Chapter V of the GDPR.

The documentation of these safeguards is provided to the customer upon reasoned request.

12. Security measures

Prosio uses authentication and access controls based on roles and dealership scope. Connection tokens for email services are encrypted by the application before storage. The Security page explains these mechanisms and the elements that depend on hosting configuration. Applicable contractual guarantees are set out in the documents agreed with the customer.

13. Your rights

In accordance with Articles 15 to 22 of the GDPR, you have the following rights:

— access to your data and obtaining a copy ; — rectification of inaccurate data ; — erasure ("right to be forgotten") where the conditions are met ; — restriction of processing in the event of contestation of the accuracy of the data ; — portability of the data provided in a structured and machine-readable format ; — objection to processing based on legitimate interest or prospecting ; — withdrawal of consent at any time when the processing is based thereon ; — not to be subject to a decision based solely on automated processing producing legal effects.

14. Exercise of your rights

Any request may be addressed to contact@prosio.be or by post to Salama Forever SRL, rue du Bon Pasteur 54/1, 1140 Evere (Brussels).

Prosio may request reasonable proof of identity to handle the request, in accordance with Article 12.6 of the GDPR.

A response is provided within one month of receipt. This period may be extended by two months in case of a complex request or multiple requests, with reasoned notification to the data subject.

The exercise of these rights is free of charge, except for manifestly unfounded or excessive requests which may give rise to reasonable fees or a reasoned refusal.

15. Complaint with a supervisory authority

You have the right to lodge a complaint with the Belgian Data Protection Authority:

Data Protection Authority (DPA) Rue de la Presse 35, 1000 Brussels Tel.: +32 (0)2 274 48 00 contact@apd-gba.be autoriteprotectiondonnees.be

You may also refer the matter to the supervisory authority of your habitual place of residence or work.

16. Automated decisions and profiling

Prosio uses available sales information to suggest priorities and next actions. Configured AI workflows may receive sales context, including conversation content, to prepare drafts. Results can be inaccurate; users must check them before relying on them or sending a message.

These features must not be used on their own to make decisions with legal or similarly significant effects on a person. The AI provider, transmitted data and retention conditions must be documented. A logo, signature or public figure alone does not confirm a contact’s identity, authority or creditworthiness.

Connected accounts: Microsoft Entra and Google

Signing in to Prosio through Microsoft Entra or Google identifies the user through Supabase. It does not automatically grant access to read the mailbox.

The separate Outlook connection requests delegated openid, profile, email, offline_access and Mail.Send permissions. Mail.Send technically allows sending as the connected account; offline_access allows access to be renewed. The current connection does not activate the CRM delivery workflow and does not request mail or calendar read access. Tenant policy may require IT approval.

Depending on the user’s choice, the Google connection requests gmail.metadata and/or calendar.events.readonly, with openid and email. The on-demand preview shows up to 10 messages (subject, sender, date) and 10 primary-calendar events (title, location, date). These items are not copied into the CRM.

The account, granted permissions and encrypted tokens are stored for the connection. Removal in Prosio and revocation at the provider are separate actions. The guide and draft email for IT are available in Connections.

17. Protection of minors

Prosio is a B2B service exclusively intended for adult professionals acting in the exercise of their commercial activity. The service is not directed at minors and does not knowingly collect any data concerning a minor. Any report of unintentional collection will result in the immediate deletion of the data concerned.

18. Changes to the policy

This policy may be amended to reflect legal, regulatory, technical or organisational developments. Any substantial change is notified to users by email and/or by banner in the application at least 30 days before entering into force. The applicable version is that indicated by the date of last update at the top of this page.