Privacy Policy
1) Who we are (Data Controller) Epistemy BV (“we”, “us”) operates [your-domain] and determines the purposes and means of processing personal data under Regulation (EU) 2016/679 (GDPR). Our supervisory authority is the Belgian Data Protection Authority (GBA/APD).
2) What data we collect
3) Sources of data
4) Purposes and legal bases
2) What data we collect
- Identity & contact: name, company, role, email, phone, postal address (if you share it).
- Communications: messages sent via forms or email.
- Marketing preferences: newsletter opt-in/out.
- Technical & usage: IP address, device & browser type, pages viewed, time on site, referring URLs, and cookie identifiers (see Cookies).
- Transactions (if applicable): orders, invoices, VAT number (payment card data is handled by the payment provider, not stored by us).
- Recruitment (if applicable): CV/résumé, cover letter, qualifications.
3) Sources of data
- Directly from you: when you submit forms, subscribe, or email us.
- Automatically: through your device and cookies/SDKs.
- From processors: hosting, analytics, email delivery, payment services (limited to what’s necessary).
4) Purposes and legal bases
Purpose |
Examples |
Legal Basis |
Operate and secure the website |
Hosting, delivery, uptime, security logs |
Legitimate interests (running a secure site) |
Respond to inquiries |
Contact forms, support emails |
Legitimate interests / pre-contractual steps |
Marketing (with consent) |
Newsletters, updates, events |
Consent (withdraw anytime) |
Analytics and Improvement |
Measure usage, debug, improve UX |
Contract (non-essential cookies only) |
Fulfill transactions (if any) |
Orders, invoicing |
Contract; legal obligation (tax) |
Legal and compliance |
Record-keeping, requests from authorities |
Legal obligation |
Where we rely on consent, you may withdraw it at any time (see Your rights).
5) Cookies and consent (Ketch)
We use Ketch as our consent management platform (CMP). On your first visit, Ketch displays a banner allowing you to Accept all, Reject non-essential, or Customize cookies. Your choices are stored by Ketch to demonstrate consent.
Categories we use:
5) Cookies and consent (Ketch)
We use Ketch as our consent management platform (CMP). On your first visit, Ketch displays a banner allowing you to Accept all, Reject non-essential, or Customize cookies. Your choices are stored by Ketch to demonstrate consent.
Categories we use:
- Strictly necessary (no consent required): core site functions, security, load balancing.
- Performance/analytics (consent): usage measurement, diagnostics.
- Functional (consent): remembering preferences.
- Advertising (consent, only if we use it): ad personalization/retargeting.
Tool |
Purpose |
Data Collected |
Retention |
Controller / Processor |
Lawful Basis |
Weebly host cookies |
Load pages, security, session mgmt. |
Session IDs, security tokens |
Session–1 year |
Processor |
Legitimate interests (strictly necessary) |
[Analytics tool, e.g., Matomo/GA4] |
Site analytics |
IP (masked where possible), events, pages |
13–26 months |
Processor |
Consent |
Ketch CMP |
Record/display consent |
Consent state, timestamp, anon IDs |
Up to 24 months |
Processor |
Legal obligation/Legitimate interests |
6) Our processors and disclosuresWe share data with service providers under GDPR-compliant agreements:
7) International data transfersSome processors (including Weebly/Square and Ketch) may process data outside the EEA/UK. Where this occurs, we rely on:
8) RetentionWe keep personal data only as long as needed:
Category and Typical retention
You can request to access, rectify, erase, or port your data, or restrict/object to processing based on legitimate interests, and you can withdraw consent at any time.
To exercise rights, email [email protected] (we may verify your identity).
You also have the right to lodge a complaint with the Belgian Data Protection Authority (GBA/APD) or your local authority.
10) ChildrenOur site is not intended for children under 16. If you believe a child provided data, contact us and we will take appropriate steps.
11) SecurityWe apply appropriate technical and organisational measures (encryption in transit, access controls, least-privilege, vendor due diligence, backups). No system is perfectly secure; we review and improve safeguards regularly.
12) Third-party linksExternal sites we link to are governed by their own privacy policies. Please review those policies before providing any personal data.
13) ChangesWe may update this notice to reflect legal, technical, or business developments. Material changes will be communicated on this page and, where appropriate, by email.
14) Contact
Email: [email protected]
Postal: Epistemy BV | Nieuwland 34 | 9000 Gent | Belgium
- Website hosting & platform: Weebly (provided by Square/Block) for site hosting, themes, forms, and performance.
- Consent management: Ketch for cookie banner, consent logs, and preference management.
- Email/CRM/Newsletters (if used): [e.g., MailerLite/Mailchimp/Sendinblue].
- Analytics (if used): [e.g., Matomo/Google Analytics configured via Ketch].
- Payments/e-commerce (if used): [e.g., Stripe/Mollie/Adyen]. Card data is processed by the provider.
- Professional advisors: legal, accounting, auditors (as necessary).
7) International data transfersSome processors (including Weebly/Square and Ketch) may process data outside the EEA/UK. Where this occurs, we rely on:
- Adequacy decisions (where applicable), and/or
- Standard Contractual Clauses (SCCs) plus transfer impact assessments and additional safeguards.
8) RetentionWe keep personal data only as long as needed:
Category and Typical retention
- Contact/inquiry records - Up to 3 years after last interaction
- Newsletter & consent logs - Until you withdraw; suppression lists kept to honour opt-out
- Analytics (consented) - Per tool settings (typically 14–26 months)
- Security logs - 6–24 months
- Transaction records (if any) - Contract term + up to 10 years for tax/accounting
- Recruitment data (if any) - Up to 6 months after decision (longer if you consent)
You can request to access, rectify, erase, or port your data, or restrict/object to processing based on legitimate interests, and you can withdraw consent at any time.
To exercise rights, email [email protected] (we may verify your identity).
You also have the right to lodge a complaint with the Belgian Data Protection Authority (GBA/APD) or your local authority.
10) ChildrenOur site is not intended for children under 16. If you believe a child provided data, contact us and we will take appropriate steps.
11) SecurityWe apply appropriate technical and organisational measures (encryption in transit, access controls, least-privilege, vendor due diligence, backups). No system is perfectly secure; we review and improve safeguards regularly.
12) Third-party linksExternal sites we link to are governed by their own privacy policies. Please review those policies before providing any personal data.
13) ChangesWe may update this notice to reflect legal, technical, or business developments. Material changes will be communicated on this page and, where appropriate, by email.
14) Contact
Email: [email protected]
Postal: Epistemy BV | Nieuwland 34 | 9000 Gent | Belgium