Last updated: July 15, 2026
This policy fulfils our information obligations under GDPR Arts. 12–14. It describes how BeCleva ApS ("BeCleva", "we", "us", or "our") processes personal data. The service brand name is BeCleva. It is not a substitute for individual legal advice. Your statutory rights remain unchanged.
BeCleva ApS is the controller for personal data processed in connection with the BeCleva service. Company: BeCleva ApS (BeCleva), CVR 46636538, address: Vejlevej 86, 6000 Kolding, Danmark.
Privacy contact: support@becleva.com.
We have not appointed a Data Protection Officer (DPO), as we assess it is not required (not a public authority; no large-scale systematic monitoring; no large-scale processing of special-category data). Privacy questions: support@becleva.com.
EU representative (Art. 27): Not applicable — we are established in the EU (Denmark). Supervisory authority: Datatilsynet (Danish Data Protection Agency).
Identity and account: Email, username and any name or profile details you provide; technical identifiers related to sign-in. Sign-in via Supabase Auth (email/password or “Sign in with Google”).
Email from us: Necessary and service emails (e.g. welcome, password reset, and — if enabled — subscription or savings reminders) via Resend.
Budget and finances: Budgets, income and expenses; subscriptions; receipts and images/metadata; savings goals; file imports (e.g. CSV/Excel).
Payments: Payment and subscription status via Stripe. We do not store full card numbers on our servers.
Bank (when enabled): Account name/IBAN, bank name, transaction history (amount, date, description, etc.) via Enable Banking Oy — see section 3.
AI: Text/image excerpts needed for the feature you use (typically descriptions and amounts for categorisation; image excerpts for receipt scanning).
Community categorisation: Anonymised merchant tokens, short text samples and category votes to improve categorisation for all users — without exposing your email or account number in the consensus layer.
Technical: With consent, error/performance data (Sentry) and web analytics (Vercel Analytics/Speed Insights). Necessary local storage/cookies for sign-in and preferences.
We do not intentionally process special categories of personal data (Art. 9). We do not make solely automated decisions with legal or similarly significant effects (Art. 22).
Directly from you: When you create an account, enter budget data, upload files/receipts, vote on categories or contact support.
From you via third parties you choose: — Google: if you sign in with Google. — Enable Banking Oy (AISP): if you connect a bank. Explicit PSD2 consent is given to Enable Banking; you typically authorise via MitID or the bank’s secure login. We are not an AISP. We receive forwarded account/transaction data, have read-only access, cannot move money and do not store bank login/MitID. The connection typically renews about every 180 days. — Stripe: payment-related information for Premium.
Automatically generated: Technical log/device data as needed for operations and (with consent) error analysis.
Account, budget, import, receipts, savings, in-app subscriptions and Premium delivery: performance of contract (Art. 6(1)(b)).
Bank data after you connect: contract (b) to deliver the bank-connected service; PSD2 consent to Enable Banking is separate.
AI features you actively use: contract (b).
Community categorisation (anonymised tokens/votes): contract (b) as part of categorisation and/or legitimate interests (f) in improving accurate categories — balanced because email/IBAN are not shared in the consensus layer.
Optional cookies/analytics/error reporting (Sentry, Vercel Analytics): consent (a) via the cookie banner; withdrawable.
Optional reminder emails: consent or contract depending on the setting; you can turn them off in the app.
Security, abuse prevention, operations and rate limiting: legitimate interests (f) in protecting the service and users. You may object — see section 8.
Accounting and mandatory retention of our own sales records (not your bank transactions as an archive): legal obligation (c), typically the Danish Bookkeeping Act.
To create an account and enter into the service agreement you must provide at least a valid email (and password or social login). Without that we cannot provide the account.
Budget, import, receipt and bank data are voluntary in that you choose what to enter or connect — but without them the corresponding features cannot be used fully.
Premium payment requires the information Stripe needs for payment. Cookie consent for analytics is optional; declining does not affect core sign-in.
We do not sell your personal data. We share it with processors who process it on our instructions under DPAs where required:
— Supabase: database, Auth, Edge Functions, storage. — Stripe: payments. — Resend: email. — Google: only for “Sign in with Google” (independent controller for its login flow). — OpenAI: AI input when you use AI features. — Sentry: errors/performance (only with cookie consent). — Vercel: hosting; Analytics/Speed Insights only with consent. — Trigger.dev: background jobs. — Upstash: cache/rate limiting. — Enable Banking Oy: AISP when you connect a bank (PSD2 consent to them).
Privacy policies: Supabase (https://supabase.com/privacy), Stripe (https://stripe.com/privacy), Resend (https://resend.com/legal/privacy-notice), Google (https://policies.google.com/privacy), OpenAI (https://openai.com/policies/privacy-policy), Sentry (https://sentry.io/privacy/), Vercel (https://vercel.com/legal/privacy-policy), Trigger.dev (https://trigger.dev/legal/privacy), Upstash (https://upstash.com/trust/privacy), Enable Banking (https://tilisy.enablebanking.com/privacy).
Transfers to third countries (e.g. USA for OpenAI, Stripe, Sentry, Vercel): we rely on the EU Commission’s standard contractual clauses (SCCs) or other approved mechanisms under GDPR Chapter V. Contact us for more information on the safeguards.
Account and app data (budget, receipts, import, bank data in our systems): for as long as the account is active. After account deletion we aim to delete from active systems within 30 days; temporary backups may briefly retain residues.
Supabase Auth login: deleted as part of the account-deletion flow. Contact support@becleva.com if you want confirmation.
Stripe/payment and accounting records for us or Stripe: as long as the law requires (typically up to 5 years under the Bookkeeping Act) — not your bank transactions as a budget archive.
Sentry error data: typically up to about 90 days, only with consent.
Vercel Analytics: per provider standard (typically 30–90 days), only with consent.
Trigger.dev/Upstash logs/cache: short-lived (minutes to about 30 days for logs).
Community consensus (token/sample/category): retained while relevant for categorisation; vote linkage follows your account and is deleted/anonymised on account deletion to the extent the system supports.
AI input at OpenAI: processed to deliver the response; we aim for no-retention/API settings where possible — see also OpenAI’s terms.
Under the GDPR you have rights including: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21) — including objection to processing based on legitimate interests (f).
Where processing is based on consent, you may withdraw consent at any time (cookies via cookie settings; optional emails in the app; PSD2 bank access via app/Enable Banking/your bank). Withdrawal does not affect the lawfulness of processing before withdrawal.
You can export data and delete your account in settings, or contact support@becleva.com. We respond without undue delay and within 1 month (extendable by up to 2 months for complex cases — we will inform you).
You may lodge a complaint with Datatilsynet: Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark. Phone +45 33 19 32 00. Email dt@datatilsynet.dk. Web: www.datatilsynet.dk. We encourage you to contact us first so we can try to resolve the matter.
We use appropriate technical and organisational measures: TLS in transit, access control, Row Level Security (RLS) on user data, service-role keys only in serverless/backend — never in the client. No online service is 100% risk-free; we work continuously to reduce risk. In the event of a serious breach we notify Datatilsynet and affected users when the law requires.
Necessary local storage/cookies: sign-in and preferences (theme, language, currency, selected budget, cookie consent). Strictly necessary — no consent required under the cookie rules.
Optional: With accept in the cookie banner, Sentry may load and Vercel Analytics/Speed Insights may be used. You can change choices via cookie settings in the site footer.
Under our terms of service you must generally be at least 18 to create an account and enter a Premium agreement. The service is not directed at children. We do not knowingly collect personal data from persons under 15 without parental/guardian consent under applicable rules. Contact us if you believe we have processed a child’s data without a lawful basis — we will delete it.
We may update this policy. For material changes we endeavour to give reasonable notice (typically at least 14 days) by email and/or in the app, unless faster effect is required by law or security. The “Last updated” date changes when the policy is revised. The current version is always on this page.
Have questions about our privacy policy? Email support@becleva.com.