GDPR Information

Last updated: 26 September 2025

This page complements our user-facing Privacy Policy. It provides implementation details for compliance (records of processing, processors, transfers, security, cookies, Data Subject Requests).

1) Roles & entities

Controller: Andrii Trush (self-employed in Belgium)
Registered address: 9200 Dendermonde, Belgium
Enterprise number (KBO/BCE): BE 1016.452.805
Email:contact@isapp.be
DPO: Not appointed.
Websites covered: isapp.be, isap.me, isap.dev

2) Records of processing activities (ROPA)

PurposeData categoriesData subjectsLegal basisLegitimate interest (if 6(1)(f))RetentionRecipients / processorsKey security measures
Contact form handlingName, email, message content; optional phone/companyWebsite users, prospectsContract (6(1)(b)) or Legitimate interests (6(1)(f))Efficient handling of enquiriesUp to 12 months after last interaction (unless legal retention applies)Service providers supporting contact handling (if any)HTTPS/TLS; spam filtering; access controls
Project briefing & proposalsIdentity/contact, company, project scope, requirements, timeline, budget, uploaded filesProspects, website usersContract (6(1)(b)) pre-contractual steps; or Legitimate interests (6(1)(f))Efficient scoping and proposal preparationUp to 24 months after last interaction if no contract is formed; longer if legal retention applies once contractedInternal tools (CRM/task/docs, if any)Access controls; avoid special categories; secure file storage
Analytics (opt-in)IP (truncated/aggregated where applicable), device and usage data, pages viewedWebsite usersConsent (6(1)(a)) via Cookiebot2–14 months (per analytics settings)Google Analytics 4, Microsoft Clarity, Cloudflare Web Analytics / RUM, Ahrefs Web AnalyticsConsent gating; retention limits; privacy-friendly modes where available
Security & error monitoringIP, request metadata, error traces/logsWebsite usersLegitimate interests (6(1)(f))Ensure availability, integrity and secure operation of the Sites~90 daysCDN/WAF, error monitoringNetwork firewalling, WAF, rate-limiting, RBAC, logging
Marketing & remarketing (opt-in)Cookie IDs, page events, campaign attributionUsers who consentedConsent (6(1)(a))Per vendor policyGoogle Ads, Meta PixelConsent gating, periodic reviews

3) Processors & sub-processors

We maintain DPAs with our processors. They act on our documented instructions and implement appropriate measures. The list below reflects our current stack for the Sites.

VendorPurposePrimary locationsTransfer mechanismDPA/TermsNotes
Usercentrics (Cookiebot)Consent Management Platform (CMP)EU/GlobalStandard terms / SCCs where applicableDPABlocks non-essential scripts until consent
Cloudflare Gateway Tag ManagerTag delivery/routing (fires only per Cookiebot consent)GlobalStandard terms; SCCs where applicableServiceInfrastructure only; no cookies by itself
Cloudflare (CDN/WAF)CDN, security (WAF, DDoS)GlobalStandard terms; SCCs where applicableDPAStrictly necessary by default
Cloudflare Web Analytics / RUMWebsite analytics (opt-in)EU/GlobalStandard terms; SCCs where applicableServiceRuns only after Statistics consent
Ahrefs Web AnalyticsPrivacy-first website analytics (opt-in)EU/GlobalStandard termsServiceCookieless mode supported; gated under Statistics
Google Analytics 4Website analytics (opt-in)EU/USSCCsProcessor TermsRuns only after consent; IP masking
Microsoft ClaritySession analytics (opt-in)EU/USSCCsMicrosoft GDPR & DPASession recording/heatmaps only after consent
SentryError monitoringEU/USSCCsDPALog minimization; personal data limited
Google AdsAdvertising & remarketing (opt-in)EU/USSCCsAds Processor TermsConsent required
Meta PixelAdvertising & remarketing (opt-in)EU/USSCCsBusiness Tools TermsConsent required

4) Cookies & Consent Management

We use Cookiebot (Usercentrics) as our CMP. By default, all non-essential tags and scripts are blocked. Tags are delivered via Cloudflare Gateway Tag Manager and will fire only when the corresponding Cookiebot category is granted. You can change or withdraw your consent at any time via Change cookie preferences.

Cookie categories & tag mapping

CategoryPurposeToolsConsent required?Release condition (Cookiebot)
NecessarySecurity, load balancing, consent storage, tag delivery infrastructureCloudflare (CDN/WAF), Cloudflare Gateway Tag Manager, Cookiebot coreNo (legitimate interest)Always on (infrastructure only; no analytics/marketing code)
PreferencesRemember language/UX choicesSite settingsYespreferences = true
StatisticsMeasure usage and performanceGoogle Analytics 4, Microsoft Clarity, Cloudflare Web Analytics / RUM, Ahrefs Web AnalyticsYesstatistics = true (tags released via CF Gateway TM)
MarketingRemarketing, ad performanceGoogle Ads, Meta PixelYesmarketing = true (tags released via CF Gateway TM)

5) SEO crawlers (not cookies; not under CMP)

We use Ahrefs Webmaster Tools for technical SEO and link analysis. Its bot (AhrefsBot) crawls publicly available pages to evaluate site health and links. It does not set cookies or track visitors and does not depend on your cookie consent.

6) International data transfers

Where a processor is outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) and implement supplementary measures if needed. We periodically review transfer frameworks and vendor documentation.

7) Security measures (overview)

  • Encryption in transit (TLS) and at rest where available
  • Role-based access control, least privilege, 2FA for admin access
  • Regular patching and dependency management
  • Backups and restore testing
  • Network protections (WAF, rate limiting, DDoS mitigation)
  • Logging/monitoring and alerting for anomalies
  • Secrets management and environment segregation

8) Data Subject Request (DSR) workflow

  1. Submit: Email contact@isapp.be from the address you used on our Sites and describe your request.
  2. Verify: We may ask for limited information to confirm your identity.
  3. Assess: We locate relevant data and assess any legal restrictions (e.g., legal obligations, third-party rights).
  4. Respond: We respond within 30 days (extendable where permitted for complex requests).
  5. Escalate: If you are not satisfied, you can complain to the Belgian Data Protection Authority (APD/GBA).

APD/GBA: Rue de la Presse 35, 1000 Brussels, contact@apd-gba.be, www.dataprotectionauthority.be.