Last updated: June 1, 2026
Expivi B.V. values the privacy and security of personal data. This Privacy Policy explains how we collect, use, store, protect and share personal data when you visit our website, interact with us, use our services, or when personal data is processed through the Expivi platform.
We process personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR). We only process personal data for specific, explicit and legitimate purposes, and we do not retain personal data for longer than necessary for those purposes, unless a longer retention period is required or permitted by law.
1. Who we are
Expivi B.V.
Fellenoord 350
5611 ZJ Eindhoven
The Netherlands
Chamber of Commerce number: 75779951
Website: www.expivi.com
Email: [email protected]
For questions about this Privacy Policy, the processing of personal data, or the exercise of privacy rights, please contact us at [email protected].
2. Our role as controller or processor
Expivi may process personal data in different roles, depending on the situation.
When Expivi determines the purposes and means of processing personal data, Expivi acts as the data controller. This applies, for example, when we process personal data in relation to our website, marketing, sales, customer communication, contract management, invoicing, support, security and general business operations.
When Expivi processes personal data on behalf of a customer through the Expivi platform, Expivi may act as a data processor. In those cases, the customer determines the purposes and means of the processing, and Expivi processes personal data in accordance with the customer’s instructions and the applicable contractual agreements.
The personal data processed through the Expivi platform depends on the customer’s implementation and configuration. In many cases, personal data processed in the platform is controlled and used by the customer and is not visible to Expivi, unless access is necessary for support, security, maintenance, troubleshooting, contractual performance or another agreed purpose.
Privacy and data processing terms are addressed as part of Expivi’s contractual agreements with its customers.
3. Personal data we process
The personal data we process depends on your relationship with Expivi and how you interact with our website, services or platform.
Website visitors
When you visit our website, we may process:
- IP address
- Browser type and version
- Device information
- Internet Service Provider
- Date and time of visit
- Referring and exit pages
- Pages visited
- Cookie identifiers
- Click and usage data
- Website preferences and interaction data
Contacts, prospects and customers
When you contact us, request information, request a demo, become a customer or communicate with us, we may process:
- Name
- Business email address
- Telephone number
- Job title
- Company name
- Business address
- Billing details
- Contract information
- Communication history
- Information submitted through contact forms, demo requests, emails or other
- communication channels
Users and end users of the Expivi platform
Depending on the customer’s setup and use of the Expivi platform, the following categories of personal data may be processed:
- Names
- Email addresses
- Customer IDs
- Order data
- Uploaded images or files
- Product configuration data
- Account and login data
- Platform usage data
- Support-related information
- Technical log data
- Other data entered into or processed through the platform by or on behalf of a customer
Support and service communication
When we provide support or communicate about our services, we may process:
- Name and contact details
- Support tickets
- Email or chat correspondence
- Technical information needed to investigate issues
- Information about the relevant customer account, configuration or service environment
- Communication preferences
We only process personal data that is necessary for the purposes described in this Privacy Policy.
4. Why we process personal data and legal bases
We process personal data for the purposes and legal bases described below.
Website operation and security
We process technical data, such as IP addresses, browser data, device data and log files, to operate our website, keep it secure, prevent misuse, detect bots or spam, troubleshoot issues and investigate security incidents.
Legal basis: legitimate interest.
Website analytics and improvement
We may process website usage data to understand how visitors interact with our website and to improve our website, content, services and user experience.
Legal basis: consent where required, or legitimate interest where analytics are configured in a limited and privacy-conscious manner.
Contact, sales and demo requests
When you contact us, request a demo or ask for information, we process your personal data to respond to your request, communicate with you and follow up on potential business opportunities.
Legal basis: pre-contractual steps, legitimate interest or consent, depending on the context.
Customer relationship and service delivery
We process personal data to provide our services, manage customer relationships, create and manage accounts, perform contracts, provide support, process invoices and communicate about our services.
Legal basis: performance of a contract and legitimate interest.
Platform processing on behalf of customers
Where personal data is processed through the Expivi platform on behalf of a customer, Expivi processes such data for the purpose of delivering, maintaining, securing and supporting the platform, and only in accordance with the applicable customer instructions and contractual agreements.
Legal basis: the customer determines the applicable legal basis as controller. Expivi processes such data as processor where applicable.
Support and troubleshooting
We process personal data to handle support requests, investigate technical issues, maintain service quality, resolve incidents and improve reliability.
Legal basis: performance of a contract and legitimate interest.
Marketing communication
We use HubSpot to manage marketing communications and related customer or prospect interactions. We may use contact details to send information about Expivi, our services, product updates, events or relevant content. Marketing emails include an unsubscribe option.
Legal basis: consent or legitimate interest, depending on the communication, the relationship with the recipient and applicable law.
Lead identification, advertising and campaign measurement
Subject to cookie consent where required, we may use website and cookie data for marketing, lead identification, account-based marketing, advertising, retargeting and campaign measurement. This may involve providers such as HubSpot, Google, LinkedIn, Meta, Microsoft, Leadinfo, Leadfeeder and Albacross.
Legal basis: consent where required, and legitimate interest where permitted by applicable law.
Legal, tax and compliance obligations
We process certain personal data to comply with legal, tax, accounting, regulatory and compliance obligations.
Legal basis: legal obligation.
5. Cookies and similar technologies
Expivi uses cookies and similar technologies to make the website function properly, protect the website, remember preferences, analyze website usage, support marketing activities and measure advertising performance.
When visiting our website, a cookie pop-up is shown. Through this pop-up, visitors can manage their cookie choices where required by law.
We use the following categories of cookies and similar technologies.
Necessary cookies
Necessary cookies help make the website usable by enabling basic functions such as page navigation, security, bot detection, cookie consent management and access to secure areas of the website. The website cannot function properly without these cookies.
These cookies may be provided by, among others:
- Cloudflare
- Google reCAPTCHA
- HubSpot
- Cookiebot
- Vimeo
- Expivi’s own website domain
Examples include cookies and local storage items used for bot detection, spam prevention, load balancing, cookie consent storage, security and website presentation.
Preference cookies
Preference cookies enable the website to remember information that changes how the website behaves or looks, such as chat session continuity, language preferences or regional settings.
These cookies may be provided by, among others:
- HubSpot
Analytics, marketing and tracking cookies
Marketing and tracking cookies may be used to track visitors across websites, identify business interest, measure campaigns, deliver relevant advertisements, limit ad frequency and understand how visitors reached or interacted with the website.
These cookies and similar technologies may be provided by, among others:
- Google, including Google Analytics, Google Ads and Google DoubleClick
- Meta Platforms
- Microsoft
- HubSpot
- Leadinfo
- Albacross
- Vimeo
- Server-side Google Tag Manager
Examples of such cookies and technologies include identifiers and pixels used for analytics, conversion tracking, advertising effectiveness measurement, retargeting, lead identification and account-based marketing.
Unclassified cookies
Some cookies or similar technologies may still be in the process of classification. Expivi aims to classify cookies appropriately and keep cookie information up to date in cooperation with the relevant providers.
6. Cookie retention
Cookies and similar technologies may be stored for different periods depending on their purpose and provider. Some cookies are session-based and expire when the browser session ends. Others may be stored for a defined period, such as 1 day, 180 days, 1 year, 400 days or 2 years. Some local storage items may remain persistent until removed or reset.
The exact retention period depends on the specific cookie, technology and provider. Where required, non-essential cookies are only placed after consent has been given through the cookie pop-up.
7. Log files
Expivi uses log files for website administration, security, troubleshooting, monitoring and analytics. Log files may include IP addresses, browser type, device information, Internet Service Provider, date and time stamps, referring and exit pages and click activity.
IP addresses and similar online identifiers may constitute personal data. We process this information carefully and retain it only for as long as necessary for security, operational, troubleshooting, legal or compliance purposes.
8. Third parties and recipients of personal data
We only share personal data where necessary for our services, business operations, security, marketing activities, customer support, contractual performance or legal obligations.
We may share personal data with the following categories of recipients:
- Hosting and cloud service providers
- IT and security providers
- Website infrastructure providers
- Analytics and cookie providers
- CRM, marketing and email automation providers, including HubSpot
- Advertising and campaign measurement providers
- Lead identification and account-based marketing providers
- Communication providers
- Support and ticketing systems
- Payment, invoicing and accounting providers
- Professional advisers, such as accountants, lawyers, consultants or auditors
- Public authorities, regulators or courts where required by law
Where we engage third-party processors, we take appropriate contractual, technical and organizational measures to protect personal data. Information about subprocessors is available upon request via [email protected].
9. Hosting and international transfers
Expivi hosts its website and platform data in the European Union or European Economic Area.
However, some third-party providers used for cookies, analytics, marketing, advertising, communication or other business purposes may process personal data outside the European Economic Area, depending on their infrastructure and processing locations.
Where personal data is transferred outside the European Economic Area, Expivi seeks to ensure that appropriate safeguards are in place. These may include an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism under applicable data protection law.
10. Security of personal data
Expivi takes appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration and destruction.
These measures may include:
- Access controls and authorization procedures
- Authentication and password policies
- Encryption where appropriate
- Logging and monitoring
- Backup and recovery procedures
- Security patching and vulnerability management
- Supplier security assessments
- Incident management procedures
- Periodic risk assessments
- Employee awareness and training
- Data minimization and need-to-know access principles
Expivi works according to ISO/IEC 27001 principles and is in the process of obtaining official ISO/IEC 27001 certification, expected in July 2026. Until certification is formally obtained, Expivi does not claim to be ISO/IEC 27001 certified.
11. Retention of personal data
Expivi retains personal data only for as long as necessary for the purposes for which it was collected or otherwise processed. We also take into account contractual obligations, legal obligations, limitation periods, security requirements and legitimate business needs.
We do not retain personal data longer than necessary. When personal data is no longer required, it is deleted, anonymized or otherwise securely disposed of.
Retention periods may differ per category of data, for example:
- Website and technical log data is retained only as long as necessary for security, troubleshooting, monitoring and operational purposes.
- Contact and demo request data is retained only as long as necessary to respond to the request, manage the relationship and follow up on relevant business communication.
- Customer and contract data is retained for the duration of the customer relationship and thereafter only as long as necessary for contractual, legal, tax, accounting or compliance purposes.
- Billing and accounting data is retained in accordance with applicable statutory retention obligations.
- Support data is retained only as long as necessary to provide support, maintain service quality, resolve issues, document communications and meet contractual or legal obligations.
- Platform data processed on behalf of customers is retained in accordance with the relevant customer agreement, customer instructions and applicable legal requirements.
- Marketing data is retained until consent is withdrawn, an unsubscribe request is made, an objection is submitted, or the data is no longer necessary for the relevant marketing purpose.
Where applicable, Expivi applies the maximum retention periods permitted or required by applicable laws only when such retention is necessary and lawful. In all other cases, Expivi applies shorter retention periods based on the purpose of processing and the principle of storage limitation.
12. Rights of individuals
Depending on the circumstances and applicable law, individuals may have the following rights in relation to their personal data:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object to certain processing activities
- Right to withdraw consent at any time, where processing is based on consent
- Right to lodge a complaint with a supervisory authority
Requests can be submitted via [email protected]. We may request additional information to verify your identity before handling your request.
Where Expivi processes personal data as a processor on behalf of a customer, we may need to refer your request to the relevant customer, as that customer is responsible for determining how the personal data is processed.
13. Complaints
If you believe that Expivi has not handled your personal data properly, please contact us at [email protected].
You also have the right to lodge a complaint with a competent data protection supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.
If you are located in another EU member state, you may also contact your local data protection authority.
14. Children
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children without consent from a parent or legal guardian. If you believe that we have processed personal data of a child, please contact us at [email protected] so that we can take appropriate action.
15. Links to third-party websites
Our website may contain links to third-party websites or services. Expivi is not responsible for the privacy practices of these third parties. We recommend that you review the privacy policies of any third-party websites or services you visit.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example when our services, processing activities, legal obligations, cookie use or security practices change.
The most recent version of this Privacy Policy will be available on our website. Where changes are material, we will take appropriate steps to inform affected individuals.
17. Contact
For questions about this Privacy Policy, the processing of personal data, or the exercise of privacy rights, please contact:
Expivi B.V.
Fellenoord 350
5611 ZJ Eindhoven
The Netherlands
Chamber of Commerce number: 75779951
Email: [email protected]
Website: www.expivi.com