VIATIC

Legal

Privacy Policy

Last updated: June 7, 2026

1. Who we are

Viatic is a web service published by AthCode, a sole-trader business registered in Belgium (operator: Damien Flasse, Ath, Belgium, email: [email protected]). AthCode acts as the data controller for all personal data processed through viatic.eu.

2. Our privacy-by-design commitment

Viatic is built around a single principle: travel data never leaves your browser. Destinations, travel dates, and per diem amounts are computed locally in your session and are never transmitted to or stored on our servers. We collect only what is strictly necessary to provide the service.

3. Data we collect and why

3.1 Free plan (no account)

When you use the calculator without creating an account, we collect no personal data. Calculations are stateless and anonymous.

3.2 Registered accounts (Free and Pro)

DataPurposeLegal basis
Email address Authentication via magic link; transactional emails (billing receipts, password-less login) Contract performance (Art. 6(1)(b) GDPR)
Organisation name Labelling your workspace; PDF headers Contract performance
Organisation configuration (logo, primary colour, custom rules) Persisting your Pro settings so you don't re-enter them Contract performance (Pro plan only)
Billing data (Stripe customer ID, subscription status) Processing and managing your subscription Contract performance; legal obligation

We do not collect names of travellers, trip itineraries, or reimbursement amounts. These are never sent to our servers.

3.3 Server logs

Our servers retain standard HTTP access logs (IP address, timestamp, URL, HTTP status) for up to 30 days for security monitoring and abuse prevention.

4. Sub-processors

We share data with the following third parties only to the extent necessary to deliver the service:

ProviderPurposeLocation
Hetzner Online GmbH Cloud hosting (VPS, database) EU (Helsinki, Finland)
Amazon Web Services EMEA SARL (Amazon SES) Transactional email delivery EU (Frankfurt, Germany); US parent
Stripe Payment processing and subscription management EU (Ireland)
Cloudflare DNS, CDN, bot protection (Turnstile) EU infrastructure available; US parent

All sub-processors operate under standard contractual clauses (SCCs) or an equivalent transfer mechanism where required.

5. Data retention

  • Account data (email, organisation name, configuration): retained for the duration of your subscription and deleted within 90 days of account closure upon request.
  • Billing records: retained for 7 years as required by Belgian accounting law.
  • Magic link tokens: expire after 1 hour and are deleted immediately after use.
  • Server logs: deleted after 30 days.

6. Your rights

Under GDPR you have the right to:

  • Access the data we hold about you
  • Rectify inaccurate data
  • Erase your data (right to be forgotten)
  • Port your data in a machine-readable format
  • Object to processing based on legitimate interest
  • Restrict processing in certain circumstances

To exercise any of these rights, email [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Belgian Data Protection Authority (APD/GBA).

7. Cookies

Viatic uses a single session cookie strictly necessary for authentication (keeping you logged in). We do not use advertising cookies, third-party trackers, or analytics cookies.

8. Changes to this policy

We may update this policy as the service evolves. Material changes will be notified by email to registered users. The "last updated" date at the top of this page always reflects the current version.

9. Contact

For any privacy question, contact us at [email protected].