Privacy Notice
me-os — a private administrative tool. Version of 19 August 2026.
me-os is not a service offered to anyone. It is private software operated by the company named below for its own administrative records and those of its legal representative. There are no users, no customers, and no accounts other than the operator's own. This notice is published because service providers reasonably require a controller to state what an application does.
Controller
THE SANCTUARY SRLRue de Masnuy-Saint-Jean 40A, 7020 Mons, Belgium
Enterprise number (BCE/KBO) 0742.742.559 — VAT BE 0742.742.559
yolo@thesanctuary.dev
No Data Protection Officer is designated: the conditions of Article 37 GDPR are not met, as the controller carries out no large-scale processing and no large-scale processing of special categories of data.
Whose personal data is processed
Only the operator's own records and those of its legal representative. Where an incoming invoice names a supplier's employee, that data is processed solely as part of the accounting record it belongs to. No personal data is collected from visitors to this website, which serves two static pages, sets no cookies and runs no analytics.
Purposes and legal bases (Art. 6 GDPR)
- Keeping accounting and tax records
- Art. 6(1)(c) — compliance with a legal obligation, under Book III of the Belgian Code of Economic Law and the Belgian VAT Code.
- Tracking payment deadlines and reconciling payments
- Art. 6(1)(f) — the controller's legitimate interest in meeting its own obligations on time.
- Reading the controller's own bank accounts
- Art. 6(1)(a) — consent, given to each bank directly and revocable there at any time.
Bank account access
- Access is read-only: account details and transaction history. Payment initiation is neither used nor possible.
- It runs through Enable Banking Oy (Otakaari 5, 02150 Espoo, Finland), an Account Information Service Provider authorised and supervised by the Finnish Financial Supervisory Authority (FIN-FSA), over the banks' official PSD2 interfaces.
- Only accounts held by the controller or its legal representative are connected, each by explicit consent given at the bank, revocable at the bank.
Recipients
None, beyond what the law requires. Data is not sold, not published, not used for advertising, and not used to train any model. The controller's accountant receives accounting records in the ordinary course, as it must. Belgian tax and social-security authorities receive what statute requires.
Storage and transfers
Retrieved data is held locally, on equipment controlled by the controller in Belgium. There is no hosted backend holding personal data. Enable Banking Oy is established in Finland; the banks are established in Belgium and the EEA. The controller does not transfer personal data outside the EEA. This site is served as static files by Cloudflare and holds no personal data.
Retention
Accounting records and supporting documents are retained for seven years from the close of the financial year to which they relate, as required by Belgian accounting law, and for ten years where the VAT Code imposes a longer period. Records outside those obligations are deleted once the purpose above no longer applies.
Rights
Under Articles 15 to 22 GDPR: access, rectification, erasure, restriction, portability, and objection — exercisable against this controller at the address above, and separately against each bank and against Enable Banking Oy for the processing each carries out.
Complaints may be lodged with the Belgian supervisory authority: Autorité de protection des données / Gegevensbeschermingsautoriteit, Rue de la Presse 35 / Drukpersstraat 35, 1000 Brussels — autoriteprotectiondonnees.be · gegevensbeschermingsautoriteit.be.