Privacy
Partner Privacy Notice
How personal data is used when you apply, operate as a partner, record prospect activity or exercise your data rights.
Version 2026-08-11-v2 · Last updated 11 August 2026
Who controls your data
Quinten Dockx, a natural-person enterprise trading under the establishment name All At Once, is the controller for Partner Network applications, accounts, programme operations and commission administration. Belgian enterprise number 0682.981.750; VAT number BE 0682.981.750; registered establishment Lange Delle 15, 1970 Wezembeek-Oppem, Belgium; [email protected].
This notice supplements the main All At Once Privacy Policy where the main service is involved. Privacy requests can be sent to [email protected].
Information we process
- Account and application data, including identity, contact, business registration, VAT, address, website, work approach and acceptance evidence.
- Prospect and relationship data entered by partners, including business identity, professional contact details, source, outreach history, outcomes, objections and do-not-contact status.
- Attribution, referral, subscription-state, commission, invoice and payment records.
- Security, audit, device, session, support and privacy-request records.
- Limited public website content used only when the separately controlled Partner Prepared Preview is enabled and accepted by a business owner.
Purposes and legal bases
- Assess applications and operate the programme: steps before contract and performance of contract.
- Prevent duplicate contact, resolve attribution and protect the platform: legitimate interests in fair, secure programme operations.
- Administer invoices, accounting and tax records: contract and legal obligations.
- Detect abuse, preserve evidence and defend legal claims: legitimate interests and legal obligations.
- Use optional analytics only after consent. Necessary authentication and security storage operate without analytics consent.
Prospect data and partner responsibilities
All At Once and a partner may each have their own responsibilities for prospect information. A partner must have a lawful basis for collecting and using a contact, provide required information, record the source, and respect an objection. All At Once uses the shared directory to prevent conflicting or repeated outreach and applies access controls so unrelated partners cannot read private contact details or notes.
No automated outreach is sent by the Partner Network. A do-not-contact instruction overrides claims, reactivation and follow-up.
Recipients and international processing
Data is shared only with authorised All At Once personnel and service providers needed for hosting, authentication, security, email, payments, website import and operations. Current core providers include Lovable Cloud, Supabase, Stripe, Firecrawl and infrastructure providers used by the main All At Once service.
Where processing occurs outside the EEA, All At Once relies on an adequacy decision or appropriate safeguards such as Standard Contractual Clauses, as applicable. The provider list and transfer assessment must be reviewed before launch and after material provider changes.
Retention
Data is kept only for the period needed for application review, programme operation, duplicate prevention, accounting, disputes and legal obligations. The technical retention register distinguishes rejected applications, active partner records, prospect contact details, closed opportunities, analytics, audit evidence and financial records.
Automated retention rules remain disabled until their durations are approved by Belgian counsel and the accountant. This avoids deleting legally required records or retaining prospect data on an unreviewed assumption.
Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability or object to processing based on legitimate interests. You can start a request inside your partner account or email [email protected]. Requests are recorded with a target response date of one month.
You may complain to the Belgian Data Protection Authority. Some records may be retained where required for invoices, taxes, fraud prevention or legal claims; any refusal or limitation will be explained.