IT Live Privacy Policy
This privacy policy applies to the entire IT Live ecosystem, including the mobile applications, account.itlive.nl, agent.itlive.nl and all associated digital tools, hosting services and AI agents.
Last updated: 2026-04-21
1. Company identity
IT Live is a trade name of Aanbod op Maat.
D-U-N-SĀ® Number: 473783386
Phone: 085 083 5610
Email: info@itlive.nl
2. Data we process
We only process data necessary for delivering, securing and improving our services:
- Account data: Name, email, phone number, company name ā for authentication, billing and support.
- Content you create yourself: Chat messages with Sophie, files in your Drive, notes, CRM contacts, appointments. Ownership stays with you.
- Technical data: IP address, device type, app version, crash logs ā only for troubleshooting and security.
- App usage: Which screens you open and taps you make, anonymous aggregate data ā to improve the app. Never linked to an individual without your consent.
3. Sensitive data you voluntarily enter
This section was added because the app optionally supports storing credentials that you yourself own (API keys, FTP, SMTP). Apple and Google require full transparency about this.
Certain features let you enter credentials or keys belonging to external services where you have your own account. Examples:
- API keys for AI providers (only for premium customers who want to use their own account): OpenAI, Anthropic, Google AI, Groq. In the standard version everything is handled through our own proxy ā you don't need to enter any key.
- FTP / SFTP credentials: only if you ask IT Live to manage your existing website on your own hosting package.
- SMTP / mail server settings: only if you want IT Live to send mail from your own mail server.
- Social / ads tokens: only when you explicitly choose in a dashboard integration to load e.g. Meta Ads or Google Ads statistics.
How we handle this
- Storage is encrypted in our database (AES-256 at rest, TLS 1.3 in transit). Keys are only readable by the specific process that calls the corresponding service ā they are never shown in logs, backups or support queries.
- Keys are used exclusively for the task you provided them for. We don't use your OpenAI key to run our own platform; we don't use your FTP to read other files.
- You can revoke or delete any key at any time via Settings ā Integrations. Deletion is immediate and permanent.
- We do not sell, share or analyze this data. It only leaves our infrastructure towards the external service it was intended for.
4. Placeholder security in AI requests
When you ask the chat for help with sensitive information (such as passwords, customer data or invoices) we automatically apply placeholder replacement before the request goes to the AI:
- Names are replaced with [CLIENT_1], emails with [EMAIL_1], IBAN/tax IDs with [ID_1] etc.
- The AI therefore never sees actual personal data; the original values are only substituted back locally into the reply you see.
- Passwords and API keys are never placed in an AI prompt, period. Not even as a placeholder ā they are blocked.
This approach reduces the risk of sensitive information reaching an external AI provider, and is mandatory for all our AI calls.
5. AI providers and data transit
For AI functionality we use different partners depending on the task type (chat, voice, vision). We always send the minimal context necessary and never more than needed for your request.
- Standard version: everything via IT Live's managed infrastructure. You don't have to configure anything. Data is not used to train AI models.
- Premium / bring-your-own-key: you are the data controller for what goes to your own provider account. We only facilitate the transport.
6. Mobile app permissions
The iOS and Android app only requests permissions when you use a feature that needs them. You can revoke each permission via your phone's settings.
- Microphone: for voice recording in the chat (Whisper STT) ā audio is processed immediately and not stored.
- Camera: for photo upload to your Drive or CRM ā photos only go to your own Drive.
- Location: optional, only for features like "plan meeting on location".
- Push notifications: for invoice updates, ticket responses and Sophie reminders. You can disable this per category.
- Face ID / Touch ID: only locally on your device ā biometrics never leave your phone.
7. Storage, hosting and security
- All servers are in the EU (Netherlands and Germany), GDPR compliant.
- Encryption: TLS 1.3 in transit, AES-256 at rest for sensitive fields (keys, passwords, financial data).
- Offsite backups: encrypted, retention 30 days, accessible only to authorized engineers.
- Access by IT Live staff is logged and limited to operational necessity (support, incident response).
- Penetration tests: annually by an independent party.
8. Your rights (GDPR)
You have the right to access, correct, export and delete your data. Request it via info@itlive.nl ā we respond within 14 days. You can delete your account yourself via Settings ā Account ā Delete; all personal data is permanently deleted within 30 days (except legally required administration such as invoices, retention 7 years).
9. No tracking, no ad networks
The IT Live app contains no advertising SDKs, no third-party tracking, no fingerprinting. We don't implement Apple's AppTrackingTransparency framework because we simply don't track. App usage statistics (which screen, how often) remain anonymous and on our own servers.
10. Children
IT Live is intended for business use by adults. We don't target children under 16. If a child accidentally creates an account and we discover this, we delete it.
11. Changes
For material changes to this policy we will notify you by email and show a banner in the app. Previous versions can be requested via info@itlive.nl.
12. Contact and supervisory authority
Questions? info@itlive.nl or +31 85 8002 035.
Not satisfied? You can file a complaint with the Dutch Data Protection Authority at autoriteitpersoonsgegevens.nl.