Last updated: 8 September 2026
This Privacy Policy explains how Rollo collects, uses, and protects personal data when you visit our website (rollo.ai), contact us, apply for a job with us, or otherwise interact with us outside of an existing client engagement. It does not cover personal data we process on behalf of our clients as part of delivering AI engineering, training, or consultancy services: that processing is governed by the data processing agreement (DPA) in place with each client.
1. Who we are
Rollo (BV/SRL), a private limited company under Belgian law, is the data controller for the personal data described in this policy.
- Registered address: Tavernierkaai 2/18, 2000 Antwerp, Belgium
- Enterprise/VAT number: BE 0770.392.212
- Contact e-mail for privacy questions: privacy@rollo.ai
Rollo has not appointed a statutory Data Protection Officer, as this is not required given the scale and nature of our processing activities. All privacy questions and requests are handled by the contact above.
2. What personal data we collect
We keep the personal data we collect to what is necessary for the purpose it is collected for. Depending on how you interact with us, this may include:
- Contact and enquiry data: name, e-mail address, company name, and the content of any message you send us (for example, when you e-mail us to schedule a conversation about our services).
- Recruitment data: if you apply for a role at Rollo by e-mail, we receive your name, contact details, CV/resume, cover letter, and any other information you choose to include (such as a LinkedIn profile or portfolio).
- Website usage data: technical and analytics information generated by your use of our website, such as IP address, browser and device type, pages visited, and referral source. See our Cookie Policy for details on the specific technologies used and the choices available to you.
We do not knowingly collect special categories of personal data (such as health, religious belief, or biometric data) through our website, and we ask that you do not include such information in messages or job applications to us unless it is strictly relevant (for example, in the context of a reasonable accommodation request during recruitment).
3. Why we process your data and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Responding to enquiries and scheduling conversations about our services | Legitimate interest in engaging with prospective clients and partners (Art. 6(1)(f)); performance of pre-contractual steps where you are considering entering a contract with us (Art. 6(1)(b)) |
| Assessing job applications and managing recruitment | Necessary for pre-contractual steps taken at your request (Art. 6(1)(b)); legitimate interest in evaluating candidates (Art. 6(1)(f)) |
| Operating, securing, and improving our website; measuring audience and traffic sources | Consent (Art. 6(1)(a)) for non-essential analytics/marketing cookies; legitimate interest (Art. 6(1)(f)) for strictly necessary functionality and security |
| Complying with legal, accounting, and tax obligations | Legal obligation (Art. 6(1)(c)) |
4. Who we share your data with
We do not sell personal data. We may share personal data with:
- Service providers who support our website and business operations (for example, hosting and infrastructure providers, e-mail providers, and Google as the operator of Google Tag Manager, which we use for website tag management: see our Cookie Policy). These providers act as our processors and are contractually bound to protect your data and use it only for the purposes we instruct.
- Professional advisers (such as accountants or lawyers) where necessary for our legitimate business purposes.
- Public authorities, where we are legally required to disclose personal data (for example, to a tax authority or in response to a lawful request from the Belgian Data Protection Authority or a court).
5. International data transfers
Some of our service providers (for example, Google) may process personal data on servers located outside the European Economic Area, including in the United States. Where this occurs, we rely on appropriate safeguards recognised under GDPR, such as the European Commission's Standard Contractual Clauses, and we select providers that offer equivalent guarantees for the protection of your data. You can request more information about these safeguards by contacting us using the details in Section 1.
6. How long we keep your data
- Enquiry and contact correspondence: kept for as long as needed to handle the enquiry and for a reasonable period afterwards (typically up to 3 years) in case of follow-up, unless you ask us to delete it sooner.
- Job applications: kept for up to 12 months after the recruitment process ends, so we can consider you for future roles, unless you ask us to delete your application sooner or object to this retention.
- Website analytics data: retained according to the retention periods described in our Cookie Policy.
- Data we must keep for legal, accounting, or tax reasons is retained for the statutory period required under Belgian law (generally up to 7 years for accounting records).
7. Automated decision-making
We do not use your personal data to make decisions about you that are based solely on automated processing (including profiling) and that produce legal effects or similarly significantly affect you.
8. Your rights
Under the GDPR, you have the right to:
- request access to the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request erasure of your data, subject to legal exceptions;
- request restriction of processing in certain circumstances;
- object to processing based on our legitimate interest;
- request portability of data you provided to us, where technically feasible;
- withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal; and
- lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at privacy@rollo.ai. We will respond within one month, as required by the GDPR.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels, www.autoriteprotectiondonnees.be, or with the supervisory authority in your own EU member state.
9. Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse, proportionate to the sensitivity of the data involved.
10. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "last updated" date at the top of this page shows when it was last revised. We encourage you to review this page periodically.
11. Contact
Questions about this Privacy Policy or how we handle your personal data can be sent to privacy@rollo.ai or by post to Rollo, Tavernierkaai 2/18, 2000 Antwerp, Belgium.
