Legal
Privacy Policy
Last updated: June 7, 2026
1. Who we are
Viatic is a web service published by AthCode, a sole-trader business registered in Belgium (operator: Damien Flasse, Ath, Belgium, email: [email protected]). AthCode acts as the data controller for all personal data processed through viatic.eu.
2. Our privacy-by-design commitment
Viatic is built around a single principle: travel data never leaves your browser. Destinations, travel dates, and per diem amounts are computed locally in your session and are never transmitted to or stored on our servers. We collect only what is strictly necessary to provide the service.
3. Data we collect and why
3.1 Free plan (no account)
When you use the calculator without creating an account, we collect no personal data. Calculations are stateless and anonymous.
3.2 Registered accounts (Free and Pro)
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Authentication via magic link; transactional emails (billing receipts, password-less login) | Contract performance (Art. 6(1)(b) GDPR) |
| Organisation name | Labelling your workspace; PDF headers | Contract performance |
| Organisation configuration (logo, primary colour, custom rules) | Persisting your Pro settings so you don't re-enter them | Contract performance (Pro plan only) |
| Billing data (Stripe customer ID, subscription status) | Processing and managing your subscription | Contract performance; legal obligation |
We do not collect names of travellers, trip itineraries, or reimbursement amounts. These are never sent to our servers.
3.3 Server logs
Our servers retain standard HTTP access logs (IP address, timestamp, URL, HTTP status) for up to 30 days for security monitoring and abuse prevention.
4. Sub-processors
We share data with the following third parties only to the extent necessary to deliver the service:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting (VPS, database) | EU (Helsinki, Finland) |
| Amazon Web Services EMEA SARL (Amazon SES) | Transactional email delivery | EU (Frankfurt, Germany); US parent |
| Stripe | Payment processing and subscription management | EU (Ireland) |
| Cloudflare | DNS, CDN, bot protection (Turnstile) | EU infrastructure available; US parent |
All sub-processors operate under standard contractual clauses (SCCs) or an equivalent transfer mechanism where required.
5. Data retention
- Account data (email, organisation name, configuration): retained for the duration of your subscription and deleted within 90 days of account closure upon request.
- Billing records: retained for 7 years as required by Belgian accounting law.
- Magic link tokens: expire after 1 hour and are deleted immediately after use.
- Server logs: deleted after 30 days.
6. Your rights
Under GDPR you have the right to:
- Access the data we hold about you
- Rectify inaccurate data
- Erase your data (right to be forgotten)
- Port your data in a machine-readable format
- Object to processing based on legitimate interest
- Restrict processing in certain circumstances
To exercise any of these rights, email [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (APD/GBA).
7. Cookies
Viatic uses a single session cookie strictly necessary for authentication (keeping you logged in). We do not use advertising cookies, third-party trackers, or analytics cookies.
8. Changes to this policy
We may update this policy as the service evolves. Material changes will be notified by email to registered users. The "last updated" date at the top of this page always reflects the current version.
9. Contact
For any privacy question, contact us at [email protected].