Data controller
DéliNatie bv, registered in Belgium under BCE/KBO number [to be confirmed in Phase 0]. Registered office: [address to be confirmed]. This policy applies to all personal data processed via delinatie.be and its sub-paths.
Data Protection Officer
For any data protection inquiry or to exercise your rights, contact our DPO at privacy@delinatie.be. We respond within 30 calendar days as required under Article 12(3) GDPR.
Categories of personal data we process
Contact details you submit via quote-request, contact, and brochure-by-email forms: name, business email, phone, company name, VAT/BTW number, and any free-text message.
Portal account credentials for customers and suppliers: email, hashed password, linked Customer or Supplier record in our ERP.
Order, invoice, and quotation history accessible to the portal account holder.
Technical data: a transient IP address held in-memory for up to one hour for rate-limiting the brochure-email endpoint. Not persisted.
Legal bases for processing
Quote requests: Art. 6(1)(b) — steps prior to entering a contract.
Contact forms: Art. 6(1)(f) — legitimate interest in responding to inquiries.
Brochure-by-email follow-up: Art. 6(1)(f) — legitimate interest in B2B marketing follow-up. You can opt out at any time via the unsubscribe mechanism (planned).
Newsletter signup: Art. 6(1)(a) — explicit, freely-given consent. Double opt-in is required and consent can be withdrawn at any time.
Portal account and order history: Art. 6(1)(b) — contract performance.
Session cookie (sid): functional, strictly-necessary cookie under the EU Cookie Law exemption.
Recipients and processors
Mailjet (EU region) — transactional email delivery for confirmations and brochure attachments. Data Processing Agreement on file.
Hetzner via Coolify — application and database hosting (Falkenstein, Germany).
WORQABLE BV — operator of our self-hosted ERPNext instance which stores Leads, Customers, Suppliers, orders, invoices, and quotations. Data Processing Agreement on file.
We do not share personal data with any other third party. We use no marketing pixels, advertising cookies, or third-party trackers.
International transfers
All personal data is processed and stored within the European Union. We do not transfer data outside the EU.
Retention periods
Leads: retained for 3 years from the last interaction unless converted to a Customer record.
Customer records: retained per Belgian commercial law (typically 10 years for invoice records).
Mailjet send logs: approximately 6 months under Mailjet's policy.
Server and application logs: 30-day rolling retention on Coolify.
Rate-limit memory: cleared on container restart (typically daily).
Your rights
Under GDPR, you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. Exercise these rights by emailing privacy@delinatie.be — we respond within 30 calendar days.
You have the right to lodge a complaint with the Belgian Data Protection Authority (Autoriteit Persoonsgegevens / Autorité de Protection des Données — APD/GBA): https://www.autoriteprotectiondonnees.be/.
Cookies and tracking
We use no marketing cookies, advertising cookies, or third-party trackers.
Strictly-necessary cookies: portal session cookie (sid) for authenticated users, and a NEXT_LOCALE preference cookie for language selection.
Analytics: we run self-hosted Umami in cookieless mode with daily-rotating anonymized visitor hashes. No cookies, no localStorage, no IP storage. This configuration is exempt from consent requirements under CNIL/APD guidance for audience-measurement analytics.
Security
We apply technical and organizational measures appropriate to the risk under Art. 32 GDPR: TLS everywhere, scoped API credentials, in-process rate limiting, server-side input validation, and quarterly rotation of service-account secrets. Detailed measures are documented internally and available to data subjects on request.
Changes to this policy
We will post the date of the most recent revision at the top of this page. Material changes will be communicated via the portal and, where applicable, by email.