GDPR Compliance

Last updated: 13 March 2026

This page complements our user-facing Privacy Policy. It provides implementation details for compliance (records of processing, processors, transfers, security, cookies, Data Subject Requests).

1) Roles & entities

Controller: Andrii Trush (self-employed in Belgium)
Registered address: 9200 Dendermonde, Belgium
Enterprise number (KBO/BCE): BE 1016.452.805
Email: contact@isapp.be
DPO: Not appointed.
Website covered: isapp.be (the "Site")

2) Records of processing activities (ROPA)

PurposeData categoriesData subjectsLegal basisLegitimate interestRetentionRecipients/processorsKey security measures
Contact form handlingName, email, message content; optional phone/companyWebsite users, prospectsContract (6(1)(b)) or Legitimate interests (6(1)(f))Efficient handling of enquiriesUp to 12 months after last interaction (unless legal retention applies)Service providers supporting contact handling (if any)HTTPS/TLS; spam filtering; access controls
Project briefing & proposalsIdentity/contact, company, project scope, requirements, timeline, budget, uploaded filesProspects, website usersContract (6(1)(b)) pre-contractual steps; or Legitimate interests (6(1)(f))Efficient scoping and proposal preparationUp to 24 months after last interaction if no contract is formed; longer if legal retention applies once contractedInternal tools (CRM/task/docs, if any)Access controls; avoid special categories; secure file storage
Analytics (opt-in)IP (truncated/aggregated where applicable), device and usage data, pages viewedWebsite usersConsent (6(1)(a)) via Cookiebot2–14 months (per analytics settings)Google Analytics 4, Microsoft Clarity, Cloudflare Web Analytics / RUM, Ahrefs Web AnalyticsConsent gating; retention limits; privacy-friendly modes where available
Security & error monitoringIP, request metadata, error traces/logsWebsite usersLegitimate interests (6(1)(f))Ensure availability, integrity and secure operation of the Site~90 daysCDN/WAF, error monitoringNetwork firewalling, WAF, rate-limiting, RBAC, logging
Marketing & remarketing (opt-in)Cookie IDs, page events, campaign attributionUsers who consentedConsent (6(1)(a))Per vendor policyGoogle Ads, Meta PixelConsent gating, periodic reviews

3) Processors & sub-processors

We maintain DPAs with our processors. They act on our documented instructions and implement appropriate measures. The list below reflects our current stack for the Site.

VendorPurposePrimary locationsTransfer mechanismDPA/TermsNotes
Usercentrics (Cookiebot)Consent Management Platform (CMP)EU/GlobalStandard terms / SCCs where applicableDPABlocks non-essential scripts until consent
Google Tag ManagerTag management and delivery (fires tags per Cookiebot consent)EU/USDPF + SCCsGoogle Ads Data Processing TermsInfrastructure only; no cookies by itself when configured without analytics
Cloudflare (CDN/WAF)CDN, security (WAF, DDoS)GlobalDPF + SCCs where applicableDPAStrictly necessary by default
Cloudflare Web Analytics / RUMWebsite analytics (opt-in)EU/GlobalDPF + SCCs where applicableCovered under Cloudflare DPARuns only after Statistics consent
Ahrefs Web AnalyticsPrivacy-first website analytics (opt-in)EU/GlobalStandard termsServiceCookieless mode supported; gated under Statistics
Google Analytics 4Website analytics (opt-in)EU/USDPF + SCCsProcessor TermsRuns only after consent; IP masking
Microsoft ClaritySession analytics (opt-in)EU/USDPF + SCCsMicrosoft GDPR & DPASession recording/heatmaps only after consent
SentryError monitoringEU/USDPF + SCCsDPALog minimization; personal data limited
Google AdsAdvertising & remarketing (opt-in)EU/USDPF + SCCsAds Processor TermsConsent required
Meta PixelAdvertising & remarketing (opt-in)EU/USDPF + SCCsBusiness Tools TermsConsent required

4) Cookies & Consent Management

We use Cookiebot (Usercentrics) as our CMP. By default, all non-essential tags and scripts are blocked. Tags are managed via Google Tag Manager and will fire only when the corresponding Cookiebot consent category is granted. You can change or withdraw your consent at any time via Change cookie preferences.

Cookie categories & tag mapping

CategoryPurposeToolsConsent required?Release condition (Cookiebot)
NecessarySecurity, load balancing, consent storage, tag delivery infrastructureCloudflare (CDN/WAF), Google Tag Manager, Cookiebot coreNo (legitimate interest)Always on (infrastructure only; no analytics/marketing code)
PreferencesRemember language/UX choicesSite settingsYespreferences = true
StatisticsMeasure usage and performanceGoogle Analytics 4, Microsoft Clarity, Cloudflare Web Analytics / RUM, Ahrefs Web AnalyticsYesstatistics = true (tags released via GTM)
MarketingRemarketing, ad performanceGoogle Ads, Meta PixelYesmarketing = true (tags released via GTM)

5) SEO crawlers (not cookies; not under CMP)

We use Ahrefs Webmaster Tools for technical SEO and link analysis. Its bot (AhrefsBot) crawls publicly available pages to evaluate site health and links. It does not set cookies or track visitors and does not depend on your cookie consent.

6) International data transfers

Some of our processors are located outside the European Economic Area (EEA), primarily in the United States. For US-based processors that are certified under the EU-US Data Privacy Framework (DPF), transfers rely on the European Commission's adequacy decision (Implementing Decision (EU) 2023/1795). Where a processor is not DPF-certified or is located in another non-EEA country, we rely on the European Commission's Standard Contractual Clauses (SCCs) and implement supplementary measures where necessary. We periodically review transfer frameworks and vendor certifications. The processor table above indicates the applicable transfer mechanism for each vendor.

7) Security measures (overview)

  • Encryption in transit (TLS) and at rest where available
  • Role-based access control, least privilege, 2FA for admin access
  • Regular patching and dependency management
  • Backups and restore testing
  • Network protections (WAF, rate limiting, DDoS mitigation)
  • Logging/monitoring and alerting for anomalies
  • Secrets management and environment segregation

8) Data breach notification

In the event of a personal data breach, we follow a structured response process in accordance with GDPR Articles 33 and 34:

  1. Detection and containment. We take immediate steps to contain the breach and assess its scope.
  2. Risk assessment. We evaluate the likelihood and severity of risk to the rights and freedoms of affected individuals.
  3. Notification to the supervisory authority. If the breach is likely to result in a risk to individuals' rights and freedoms, we notify the Belgian Data Protection Authority (APD/GBA) without undue delay and, where feasible, within 72 hours of becoming aware of the breach. If notification is delayed beyond 72 hours, we provide reasons for the delay.
  4. Notification to data subjects. If the breach is likely to result in a high risk to individuals' rights and freedoms, we inform the affected individuals without undue delay, describing the nature of the breach, likely consequences, and measures taken or proposed.
  5. Documentation. We document all breaches, including facts, effects, and remedial actions taken, regardless of whether notification to the DPA was required.

9) Data Protection Impact Assessment (DPIA)

We have assessed our processing activities against the criteria in GDPR Article 35 and the Belgian DPA's list of processing operations that require a DPIA. Based on the nature, scope, context, and purposes of our processing — which is limited to standard business operations (contact handling, analytics with consent, security logging) — we have concluded that a DPIA is not required at this time. We will reassess if our processing activities change materially.

10) Data Subject Request (DSR) workflow

  1. Submit: Email contact@isapp.be from the address you used on our Site and describe your request.
  2. Verify: We may ask for limited information to confirm your identity.
  3. Assess: We locate relevant data and assess any legal restrictions (e.g., legal obligations, third-party rights).
  4. Respond: We respond within 30 days (extendable where permitted for complex requests).
  5. Escalate: If you are not satisfied, you can complain to the Belgian Data Protection Authority (APD/GBA).

APD/GBA: Rue de la Presse 35, 1000 Brussels, contact@apd-gba.be, www.dataprotectionauthority.be.