Version 1.0 · last updated 10 July 2026 · applies to lever.lu and the Lever platform
This notice explains how Lever collects, uses, shares and protects personal data, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Belgian Data Protection Act of 30 July 2018. It is written to be read — plain language first, detail where it matters.
Lever is a financial-diagnostic platform operated by MAYDA SRL (“Lever”, “we”, “us”), a company incorporated in Belgium under enterprise number BE 0763.584.691. For account, marketing and analytics data, we act as the data controller.
When an accounting firm uses Lever to process its own clients’ data — entering enterprise numbers, running scans, generating dossiers — Lever and that firm act as joint controllers under Article 26 GDPR. A Joint Controllership Agreement sets out who is responsible for informing data subjects and for handling their requests.
| Category | Where it comes from | Why we process it |
|---|---|---|
| Waitlist & account data — name, work email, firm, role | You | Create and manage your account; contact you about the beta |
| Public company data — filings, annual accounts, sector, headcount | Public registers (BCE/KBO, NBB) | Run the diagnostic engine and sector benchmarks |
| Sole-trader indicators — where a registration is a natural person | BCE/KBO | Flagged; automated pre-scoring is suppressed until a professional relationship is confirmed |
| Usage & device data — pages, events, approximate location | Analytics (with consent) | Understand and improve the product |
| Support communications | You | Respond to your requests |
We do not seek special-category data. Company financial data is business data; where it identifies a natural person (for example a sole trader), we treat it as personal data under this notice. Scans use public filings only — no client passwords or portal logins are ever required.
Lever computes opportunity scores from company data. These are decision-support outputs reviewed by a licensed professional — not decisions that produce legal or similarly significant effects by automated means alone within the meaning of Article 22 GDPR. Pre-scoring of sole traders is suppressed by default. In line with the EU AI Act transparency principle, platform outputs are labelled as AI-assisted estimates that require professional validation. A DPIA is completed before any large-scale processing begins.
We do not sell personal data. We use a small set of vetted processors, each bound by a data processing agreement under Article 28 GDPR:
| Processor | Purpose | Location |
|---|---|---|
| Neon / Databricks | Primary database (the data engine) | EU — Frankfurt |
| Cloudflare | Hosting, content delivery, operational data | EU region |
| Anthropic | AI edge-case interpretation & narratives | US — under EU Standard Contractual Clauses |
| Brevo | Transactional & waitlist email | EU — Paris / AWS Frankfurt |
| PostHog | Product analytics (with consent) | EU Cloud |
Personal data is stored in the EU/EEA. The only transfer outside the EEA is to Anthropic (United States) for AI processing, governed by Standard Contractual Clauses and a Transfer Impact Assessment. Data sent to that service carries internal identifiers only — never raw enterprise numbers or company records.
Data is hosted on EU infrastructure in Frankfurt. We apply encryption in transit and at rest, role-based access controls, IP-restricted database access, audit logging, and least-privilege management of secrets. Where a record is erased, we use logical deletion (a deleted_at marker) so that audit-defence integrity is preserved while the record is excluded from all further processing.
| Data | Retention |
|---|---|
| Waitlist (no account created) | Until you unsubscribe — maximum 24 months |
| Account & billing data | Duration of the relationship, plus statutory retention (up to 7 years for accounting records) |
| Scan & dossier audit logs | Retained for audit defence; logically deleted on a valid erasure request |
| Benchmark dataset | Anonymised / aggregated — no longer personal data |
Subject to the conditions in the GDPR, you have the right to access, rectification, erasure, restriction, data portability and objection, and to withdraw consent at any time. To exercise a right, email privacy@lever.lu; we respond within one month (extendable by two months for complex requests, in which case we will tell you). You may also lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels.
We use strictly-necessary storage to make the site work and, only with your consent, privacy-first analytics. Full detail and controls are in our Cookie Notice.
We update this notice as the platform develops and will revise the version and date at the top. For any question, contact privacy@lever.lu.