Privacy notice
What we collect, and what we do not
Who is responsible
The controller for the personal data described on this page is:
This website collects nothing
No cookies, no analytics, no tag managers, no embedded third-party scripts, no contact forms. Nothing on these pages profiles you or follows you elsewhere, which is also why you were never asked to accept anything.
Server logs
Our hosting provider, and the content delivery network in front of it, record ordinary technical request data, including IP address, timestamp, requested URL and user agent, to serve pages and to defend against abuse. We do not link those records to individuals and we do not use them for analytics.
When you email us
You reach us by mail, so we process your address, your name if you give it, and whatever you choose to write. The basis is our legitimate interest in answering you and, once we are discussing an engagement, the steps taken before a contract (GDPR article 6(1)(f) and 6(1)(b)).
How long we keep it
Correspondence is kept for as long as the conversation or the client relationship is live, and archived afterwards only where an administrative or legal obligation requires it. Ask us to delete a thread and we will, unless we are obliged to keep it.
Who else can see it
Our hosting, content delivery and email providers process data on our behalf under data-processing agreements: Cloudflare, which serves this site and therefore sees every request to it, and Microsoft, which carries our mail. Both are configured for European data residency, so the data is stored and processed inside the European Economic Area. Both have US parent companies, and for the exceptional case where access from outside the EEA does occur, it is covered by the European Commission's standard contractual clauses. We do not sell personal data, we do not share it for advertising, and we do not enrich it from third-party sources.
Your rights
You can ask for access, correction, erasure, restriction or portability, and you can object to processing. Mail us and a person will handle it. You can also lodge a complaint with the Belgian Data Protection Authority at gegevensbeschermingsautoriteit.be.
Found a vulnerability?
We run coordinated disclosure on our own systems too. Our contact address and terms are published where researchers expect to find them.
Last updated: 14 September 2026