Welcome to Rebillix. We take the protection of personal data very seriously. In this privacy statement we explain which data we collect, why we do so, how long we retain it and which rights you have.
Rebillix is an AI-driven platform for collections, payment management and debtor engagement, and processes personal data on behalf of our customers. In many cases we act as processor and follow our customers' instructions. In some situations we are the controller, for example for website visitors, accounts and billing.
1. Who are we?
Rebillix B.V.
We are responsible for the processing of personal data as described in this statement.
2. Who does this privacy statement apply to?
This statement applies to:
- Rebillix customers (companies and their employees)
- Debtors of our customers who communicate or pay through Rebillix
- Visitors to our website (rebillix.com)
- People who use our AI agents (voice, email, chat, WhatsApp)
- Applicants & interested parties
3. Which personal data do we process?
Depending on the situation, we process parts of the following categories:
A. For customers (B2B)
- Naam, e-mailadres, telefoonnummer
- Bedrijfsnaam, functie, facturatiegegevens
- Inloggegevens (hashed passwords, MFA tokens)
- IP-adressen & loggegevens
- Communication with support
B. For debtors (on behalf of our customers)
We process this data solely on instruction from our customers:
- Naam, adres, contactgegevens
- Invoices, payment statuses and payment plans
- Betalingsinformatie (IBAN, transactiegegevens, betaalhistorie)
- Communicatiegegevens: e-mail, WhatsApp, SMS, voice calls, AI-agent interacties
- Score- en risicomodellen
- Voorkeurskanalen & contactmomenten
Opmerking: Rebillix never independently decides which data is provided; the customer determines this in accordance with the data processing agreement.
C. Website en productgebruik
- IP-adres, browserinformatie, device-informatie
- Cookies (functional & analytical)
- Pagina-interacties en foutmeldingen
- Sessies en logins
D. Applicants
- CV, achtergrondinformatie
- Contactgegevens
- Referenties (optioneel)
4. Purposes of processing
We process data for the following purposes:
1. Performing collections and payment management
- Sending payment reminders
- Setting up payment arrangements
- Communicatie via AI-agents (WhatsApp, voice, e-mail, chat)
- Monitoring payment statuses & follow-up
2. Delivery of our SaaS services
- Creating and managing customer accounts
- Authorization, security & audit logs
- Analytics en foutdetectie
3. Processing payments
- Recording payments
- Doorsturen naar PSP's
- Reconciliatie
4. Improving our AI models
- Alleen meta-data, nooit inhoud die herleidbaar is tot personen
- Data is always anonymized before it is used for model training
5. Marketing & communicatie
- Newsletters (only with opt-in)
- Website-analyse
6. Wettelijke verplichtingen
- Boekhouding
- Fraudepreventie
- AVG-administratie
5. Legal basis for processing
Depending on the situation, we base processing on:
- Performance of a contract (our SaaS service)
- Wettelijke verplichting (administratie)
- Gerechtvaardigd belang (fraudepreventie, security)
- Consent (newsletter, cookies)
- Processing as processor (collections/payments on behalf of our customers)
6. How long do we retain data?
Rebillix never retains personal data longer than necessary.
Bewaartermijnen:
- Debtor data: max. 24 months after contract end, or shorter if the customer requests this
- Transactiegegevens: 7 jaar (wettelijke verplichting)
- Customer account data: up to 6 months after cancellation
- Log- & securitydata: 12 maanden
- Applicants: 4 weeks, or 12 months with consent
7. Do we share data with third parties?
Only when necessary:
Mogelijke ontvangers:
- Payment Service Providers (PSP's)
- Hostingpartners
- Telecommunicatieproviders
- E-mailproviders
- Juridische partijen (bij geschillen)
- Auditors (for ISO-27001, ISAE-3402)
We conclude a data processing agreement with all these parties.
We never sell personal data.
8. Internationale doorgifte
Data is generally stored within the EU.
If transfer outside the EU is necessary, for example WhatsApp, then:
- this only happens to countries with an adequacy decision, or
- zijn er EU-standaardcontractbepalingen (SCC's) afgesloten.
9. Security
We take strong technical and organizational measures:
- Encryption of data in transit & at rest
- Audit logging
- Multi-Factor Authentication
- Least-privilege access
- ISO-27001 best-practices
- Regelmatige penetratietests
- Hashing & salting of passwords
- Air-gapped AI training environment for anonymized data
10. Rights of data subjects
Under GDPR, everyone has:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction
- Right to data portability
- Right to object
- Right to withdraw consent
Requests can be sent to privacy@rebillix.com.
If we are the processor, we forward the request to our customer, the controller.
11. AI-agenten en automatische besluitvorming
Rebillix gebruikt AI-modellen om:
- berichten te genereren
- gesprekken te voeren
- risico's in te schatten
But we never make fully automated decisions with legal effects for data subjects.
A human employee of our customer always has final control.
12. Cookies
Our website uses:
- Functional cookies (required for operation)
- Analytical cookies (anonymized, no consent required)
- Marketing cookies (only with consent)
The full cookie statement is available at rebillix.com/cookies.
13. Wijzigingen
We may change this statement. The most recent version is always available on our website.