Privacy Statement – Rebillix

Welcome to Rebillix. We take the protection of personal data very seriously. In this privacy statement we explain which data we collect, why we do so, how long we retain it and which rights you have.

Rebillix is an AI-driven platform for collections, payment management and debtor engagement, and processes personal data on behalf of our customers. In many cases we act as processor and follow our customers' instructions. In some situations we are the controller, for example for website visitors, accounts and billing.


1. Who are we?

Rebillix B.V.

We are responsible for the processing of personal data as described in this statement.


2. Who does this privacy statement apply to?

This statement applies to:

  • Rebillix customers (companies and their employees)
  • Debtors of our customers who communicate or pay through Rebillix
  • Visitors to our website (rebillix.com)
  • People who use our AI agents (voice, email, chat, WhatsApp)
  • Applicants & interested parties

3. Which personal data do we process?

Depending on the situation, we process parts of the following categories:

A. For customers (B2B)

  • Naam, e-mailadres, telefoonnummer
  • Bedrijfsnaam, functie, facturatiegegevens
  • Inloggegevens (hashed passwords, MFA tokens)
  • IP-adressen & loggegevens
  • Communication with support

B. For debtors (on behalf of our customers)

We process this data solely on instruction from our customers:

  • Naam, adres, contactgegevens
  • Invoices, payment statuses and payment plans
  • Betalingsinformatie (IBAN, transactiegegevens, betaalhistorie)
  • Communicatiegegevens: e-mail, WhatsApp, SMS, voice calls, AI-agent interacties
  • Score- en risicomodellen
  • Voorkeurskanalen & contactmomenten

Opmerking: Rebillix never independently decides which data is provided; the customer determines this in accordance with the data processing agreement.

C. Website en productgebruik

  • IP-adres, browserinformatie, device-informatie
  • Cookies (functional & analytical)
  • Pagina-interacties en foutmeldingen
  • Sessies en logins

D. Applicants

  • CV, achtergrondinformatie
  • Contactgegevens
  • Referenties (optioneel)

4. Purposes of processing

We process data for the following purposes:

1. Performing collections and payment management

  • Sending payment reminders
  • Setting up payment arrangements
  • Communicatie via AI-agents (WhatsApp, voice, e-mail, chat)
  • Monitoring payment statuses & follow-up

2. Delivery of our SaaS services

  • Creating and managing customer accounts
  • Authorization, security & audit logs
  • Analytics en foutdetectie

3. Processing payments

  • Recording payments
  • Doorsturen naar PSP's
  • Reconciliatie

4. Improving our AI models

  • Alleen meta-data, nooit inhoud die herleidbaar is tot personen
  • Data is always anonymized before it is used for model training

5. Marketing & communicatie

  • Newsletters (only with opt-in)
  • Website-analyse

6. Wettelijke verplichtingen

  • Boekhouding
  • Fraudepreventie
  • AVG-administratie

5. Legal basis for processing

Depending on the situation, we base processing on:

  • Performance of a contract (our SaaS service)
  • Wettelijke verplichting (administratie)
  • Gerechtvaardigd belang (fraudepreventie, security)
  • Consent (newsletter, cookies)
  • Processing as processor (collections/payments on behalf of our customers)

6. How long do we retain data?

Rebillix never retains personal data longer than necessary.

Bewaartermijnen:

  • Debtor data: max. 24 months after contract end, or shorter if the customer requests this
  • Transactiegegevens: 7 jaar (wettelijke verplichting)
  • Customer account data: up to 6 months after cancellation
  • Log- & securitydata: 12 maanden
  • Applicants: 4 weeks, or 12 months with consent

7. Do we share data with third parties?

Only when necessary:

Mogelijke ontvangers:

  • Payment Service Providers (PSP's)
  • Hostingpartners
  • Telecommunicatieproviders
  • E-mailproviders
  • Juridische partijen (bij geschillen)
  • Auditors (for ISO-27001, ISAE-3402)

We conclude a data processing agreement with all these parties.

We never sell personal data.


8. Internationale doorgifte

Data is generally stored within the EU.

If transfer outside the EU is necessary, for example WhatsApp, then:

  • this only happens to countries with an adequacy decision, or
  • zijn er EU-standaardcontractbepalingen (SCC's) afgesloten.

9. Security

We take strong technical and organizational measures:

  • Encryption of data in transit & at rest
  • Audit logging
  • Multi-Factor Authentication
  • Least-privilege access
  • ISO-27001 best-practices
  • Regelmatige penetratietests
  • Hashing & salting of passwords
  • Air-gapped AI training environment for anonymized data

10. Rights of data subjects

Under GDPR, everyone has:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction
  • Right to data portability
  • Right to object
  • Right to withdraw consent

Requests can be sent to privacy@rebillix.com.

If we are the processor, we forward the request to our customer, the controller.


11. AI-agenten en automatische besluitvorming

Rebillix gebruikt AI-modellen om:

  • berichten te genereren
  • gesprekken te voeren
  • risico's in te schatten

But we never make fully automated decisions with legal effects for data subjects.

A human employee of our customer always has final control.


12. Cookies

Our website uses:

  • Functional cookies (required for operation)
  • Analytical cookies (anonymized, no consent required)
  • Marketing cookies (only with consent)

The full cookie statement is available at rebillix.com/cookies.


13. Wijzigingen

We may change this statement. The most recent version is always available on our website.