hey squad
shall we settle in?

legal · privacy

Privacy
policy.

Your data is your business. Here's what we collect, why, how we protect it, and the rights you have over all of it.

Last updated · September 21, 2026

01

Who is responsible for your data

The data controller is HeySquad under Elan Invest management, company number BE 0839.904.588, registered office at Rue Hodiamont 24, 4802 Verviers, Belgium, operating office at Rue des Nouvelles Technologies 10, 4821 Dison, Belgium.

For any question about your data: hello@heysquad.be. You can also write to us by post at the operating office.

02

Why we collect this data

We collect data for a very limited set of reasons:

  • Reply when you write to us. An email to hello@heysquad.be, a contact form — we need your name + email to reply.
  • Understand what works on the site. Measure the most-read pages, time spent, traffic sources — to adjust what we publish and drop what doesn't serve.
  • Improve your journey. Remember your preferences (language, cookie choices) so the site stays consistent on your next visit.
  • Distribute our content. When you consent, we may reach you on LinkedIn, Meta or Google with relevant content — never more often than necessary.
  • Meet our legal obligations. Invoicing, accounting, retention of commercial emails — obligations under the Belgian Code of Economic Law.
03

On what legal basis

The GDPR requires a legal basis for each processing activity. Here are ours:

  • Consent (GDPR art. 6.1.a) — for measurement, marketing, and preference cookies. You give consent via the cookie banner and can withdraw it anytime.
  • Legitimate interest (GDPR art. 6.1.f) — to respond to your messages and ensure site security (anti-fraud, anti-spam, error logs).
  • Contract execution (GDPR art. 6.1.b) — if you become a client, to run our collaboration (invoices, deliverables, project exchanges).
  • Legal obligation (GDPR art. 6.1.c) — accounting, invoicing, retention of pre-contractual exchanges when required by law.
04

What data exactly

  • Identification & contact — last name, first name, email, company, phone. Collected only if you provide them.
  • Navigation — pages visited, duration, traffic source, device type, browser, country. Only if you accept analytics cookies.
  • Technical — IP address (anonymized for analytics), session identifiers. Required for the site to function.
  • Content of your messages — when you write to us, the email content is kept for the time strictly necessary to follow up on the conversation.

We collect no sensitive data (health, orientation, origin, political opinions, religion) — our work doesn't require it.

05

Cookies & trackers

A cookie is a small text file placed on your browser. We use four categories. By default everything is refused except strictly necessary cookies — we wait for your explicit consent to activate the rest.

Necessary · always on

Essential for the site to work (session, security, language preference, consent choice). They cannot be turned off.

Tools
Application session, CSRF, hs_consent cookie (13 months)
Legal basis
Legitimate interest
Duration
Session or 13 months max

Analytics · optional

Measure audience and journeys so we can improve the site. Anonymised IPs, aggregated data. No personal identification.

Tools
Google Analytics 4, Vercel Analytics, Vercel Speed Insights
Legal basis
Consent
Duration
14 months (GA4) · 90 days (Vercel)

Marketing · optional

Let us reach you with relevant content on other platforms and measure our campaigns. For ChatGPT Ads, if you contact us or sign up after accepting this category, we also send OpenAI your email in hashed form (SHA-256, never in clear) to tie the conversion to the campaign.

Tools
Meta Pixel, LinkedIn Insight Tag, Google Ads remarketing (via Google Tag Manager), OpenAI's ChatGPT Ads pixel (cookies __oppref, __obref, __oaiq_consent)
Legal basis
Consent
Duration
13 months max

Preferences · optional

Remember your non-essential choices (theme, last section visited) for a consistent experience next time.

Tools
Application localStorage
Legal basis
Consent
Duration
6 months

change your mind

You can change your consent anytime. Takes 10 seconds.

06

How long we keep it

  • Cookies — 13 months max (CNIL/APD recommendation). The consent cookie expires after 13 months → we ask again.
  • Email exchanges — 3 years after the last contact, unless a specific legal obligation applies.
  • Client data — duration of the relationship + 10 years (accounting obligation, Belgian Code of Economic Law art. III.86).
  • Anonymized navigation data — 14 months in GA4 (default setting).
  • Technical logs — 90 days (Vercel, Neon).
07

Who we share it with

We never sell your data. We work with certified sub-processors who only handle it on our behalf, under a strict contractual framework (signed DPA).

Vercel Inc.

Site hosting and private storage of job application CVs + Analytics

United States (EU-US Data Privacy Framework certified)

Neon Inc.

Postgres database (editorial content)

European Union (Frankfurt)

Google Ireland Ltd.

Google Tag Manager + Google Analytics 4 (subject to your consent)

Ireland + United States (DPF)

Meta Platforms Ireland Ltd.

Meta Pixel (subject to your marketing consent)

Ireland + United States (DPF)

LinkedIn Ireland Unlimited Company

LinkedIn Insight Tag (subject to your marketing consent)

Ireland + United States (DPF)

The Rocket Science Group LLC (Mailchimp)

Transactional and marketing emails (where applicable)

United States (DPF)

Plus Five Five, Inc. (Resend)

Emails sent by the site: contact form messages and job applications (with a link to the CV, never the file)

Ireland (sending) + United States (DPF and standard contractual clauses)

OpenAI Ireland Ltd.

ChatGPT Ads pixel and conversions API (subject to your marketing consent): attribution cookies and hashed email

Ireland + United States (standard contractual clauses)

08

Transfers outside the European Union

Some sub-processors (Vercel, Google, Meta, LinkedIn) are based in the United States. Transfers are made under the EU-U.S. Data Privacy Framework (DPF), a transfer mechanism adopted by the European Commission in July 2023.

For sub-processors not certified under DPF, transfers are governed by standard contractual clauses adopted by the European Commission (Decision 2021/914).

09

How we secure it

  • Encrypted exchanges over HTTPS (TLS 1.3).
  • Database hosted in the EU, encrypted at rest (AES-256).
  • Tool access secured by multi-factor authentication (2FA).
  • Access logs kept for 90 days for intrusion detection.
  • Minimization principle — we store only what serves a purpose.
  • Annual review of the security policy.

In case of a data breach affecting us that is likely to result in a high risk to your rights, we notify you without delay (GDPR art. 34).

10

Your rights

The GDPR gives you a set of rights over your personal data. We respect them without question, and free of charge.

  • Right of access — know what data we hold about you and get a copy.
  • Right to rectification — correct inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten") — request deletion of your data, unless a legal obligation applies.
  • Right to restriction — request that we freeze the processing of your data in certain cases.
  • Right to object — oppose processing based on our legitimate interest.
  • Right to portability — retrieve your data in a structured, machine-readable format.
  • Right to withdraw consent — anytime, without affecting the lawfulness of prior processing.
  • Right not to be subject to automated decisions — we make none about you, but the right is preserved.

To exercise one of these rights, write to us at hello@heysquad.be. We reply within one month (extendable by 2 months for complex requests, GDPR art. 12).

11

Recruitment

When you apply through our jobs page, here is what happens to your application:

  • Purpose. Process your application: read it, organise the conversations that follow and reply to you.
  • Data. Your identity, your contact details (email, phone, LinkedIn profile), the story of the project you led, a link to your portfolio or an online project, and your CV if you attach one. The CV is kept in a private space of the website, with our hosting provider (Vercel, section 7), under an anonymous name: only the people hiring open it, from our back office or through a restricted link that expires at the end of the retention period. The email that notifies us of your application contains that link, never the file. We also keep the date and IP address of your consent.
  • Discretion. Only the people hiring at HeySquad read your application. We share it with no one else and use it for nothing else, neither prospecting nor newsletters.
  • Legal basis. Pre-contractual measures taken at your request (GDPR art. 6.1.b).
  • Retention. Six months after the last interaction, then your application and your CV are deleted.
  • Your rights. Access, rectification, erasure, by simple email to jerome@heysquad.be.
12

Contact us & APD complaint

For any question or request related to your personal data:

  • By email: hello@heysquad.be
  • By post: HeySquad, Rue des Nouvelles Technologies 10, 4821 Dison, Belgium

If you believe we're not respecting your rights, you can file a complaint with the Belgian Data Protection Authority (APD), Rue de la Presse 35, 1000 Brussels — autoriteprotectiondonnees.be.

This policy may change — the last updated date is shown at the top of the page. Major changes are notified via the cookie banner.

← Back to home

HeySquad · Dison · Belgium