Skip to main content
Black Pixel

Privacy

Privacy policy

· v1.1

Draft. Not legal advice. Review by security-specialist and founder before launch.

The short version

We collect as little as possible. This site uses no tracking cookies and no advertising pixels. If you send us a project brief, we store it so we can reply and so it does not get lost. We host in the EU. You can ask us what we hold about you, and ask us to delete it.

Who is responsible

The controller for personal data processed through this website is:

[PLACEHOLDER-LEGAL-NAME] [PLACEHOLDER-STREET-ADDRESS] [PLACEHOLDER-POSTCODE] [PLACEHOLDER-CITY], Belgium Enterprise number: [PLACEHOLDER-ENTERPRISE-NUMBER] Email: hello@[PLACEHOLDER-DOMAIN]

We do not have a designated data protection officer; we are not required to appoint one. Privacy questions go to the email address above.

What we collect and why

Contact form

When you send a project brief, we process the data you enter: your name, work email, company (optional), service interest, budget range (optional), timeline (optional), your message, and the time you gave consent. We also record the page the form was sent from and, where present, campaign parameters in the URL.

To protect the form against abuse we process your IP address in hashed form and your browser family. We do not store the full IP address.

Purpose: to answer your request and, if you decide to work with us, to prepare a proposal. Legal basis: your consent (Article 6(1)(a) GDPR) when you tick the consent box, and our legitimate interest in responding to business enquiries and preventing abuse (Article 6(1)(f) GDPR).

Support requests

When you open a support request through the support form or reply to one from its status page, we process: your name, work email, company (optional), phone number (optional), the subject, category and priority you select, the messages you write, any files you attach (images or PDF), the time you gave consent and, once we reply, our replies and the ticket timeline (opened, first response, resolved, closed). To protect the form against abuse we process your IP address in hashed form and your browser family; the full IP address is not stored.

Each request receives a reference number and a personal status link that is valid for 30 days. The link is an access key: anyone who has it can read the conversation, so please do not forward it. Internal notes we keep while working on a request are never shown on the status page.

Purpose: to handle your request, keep a record of what was agreed and, for clients with a care plan, to report on response times. Legal basis: performance of a contract or steps prior to one (Article 6(1)(b) GDPR), our legitimate interest in running a support desk and preventing abuse (Article 6(1)(f) GDPR), and your consent for the optional fields (Article 6(1)(a) GDPR).

Emails about a request (confirmation, replies, status changes) are sent through our email provider listed below, which acts as a processor.

Analytics

We use self-hosted, cookie-less analytics ([PLACEHOLDER: Umami or Plausible]) running on our own EU infrastructure. It records page views, referrers, device type and country, without cookies, without persistent identifiers, and without sharing data with third parties. It cannot identify you as an individual.

Legal basis: our legitimate interest in understanding how the site is used (Article 6(1)(f) GDPR).

Email

If you email us directly, we process your email address and the content of your message to reply. Legal basis: legitimate interest (Article 6(1)(f) GDPR) or, where relevant, steps prior to entering into a contract (Article 6(1)(b) GDPR).

Server logs

Our web server keeps short-lived technical logs (request path, status, timestamp, truncated IP) for security and error handling. They are rotated automatically and are not used to profile visitors.

Who processes data on our behalf

We use a small number of service providers, all under data-processing agreements:

| Provider | Purpose | Location |
|---|---|---|
| [PLACEHOLDER-HOSTING-PROVIDER] | Hosting of the website, database and analytics | EU ([PLACEHOLDER-COUNTRY]) |
| Resend | Sending confirmation emails, internal notifications and support-request emails (replies, status changes) | EU (Ireland) sending region; US parent company under standard contractual clauses |
| [PLACEHOLDER-ERROR-TRACKING] | Error monitoring, no personal data intended | EU |

We do not sell personal data, and we do not share it with anyone else unless the law requires it.

Transfers outside the EU

Data is hosted in the EU. If a provider processes data outside the EU (for example transactional email delivery), it does so under the European Commission's standard contractual clauses or an adequacy decision. [PLACEHOLDER: confirm per provider.]

How long we keep data

  • Contact form submissions: 24 months after the last contact, then deleted. If the enquiry becomes a project, the relevant data moves to the project and contract records and follows their retention rules.
  • Support requests: 24 months after the request was closed (or after the last activity if it was never closed), then deleted together with the messages and attachments. If a request concerns a project, the relevant conclusions move to the project records and follow their retention rules.
  • Emails: as long as needed to handle the conversation and any resulting contract, then deleted or archived under legal retention rules.
  • Analytics: aggregated data only; no personal data is retained.
  • Server logs: [PLACEHOLDER: 14] days.

Your rights

Under the GDPR you can ask us to:

  • tell you what personal data we hold about you and give you a copy;
  • correct data that is wrong;
  • delete your data;
  • restrict or object to processing;
  • give you your data in a portable format;
  • withdraw consent at any time, without affecting what was done before.

Email hello@[PLACEHOLDER-DOMAIN]. We respond within one month. We may ask you to confirm your identity first.

If you are not satisfied, you can complain to the Belgian Data Protection Authority: Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels, www.dataprotectionauthority.be.

You can ask us to erase a support request by emailing us from the address the request was made from, quoting its reference number; we anonymise the request and its messages and delete the attachments within 30 days.

Security

Data is transmitted over TLS, stored on encrypted infrastructure in the EU, backed up nightly with encryption, and accessible only to the people who need it. Personal data is never written to application logs.

Changes

We update this policy when our processing changes. The version and date at the top tell you which version you are reading. Each contact form submission records the policy version in force at the time.