hey squad
shall we settle in?

legal · privacy

Privacy
policy.

Your data is your business. Here's what we collect, why, how we protect it, and the rights you have over all of it.

Last updated · April 24, 2026

01

Who is responsible for your data

The data controller is HeySquad under Elan Invest management, company number BE 0839.904.588, registered office at Rue des Nouvelles Technologies 10, 4821 Thimister-Clermont, Belgium.

For any question about your data: hello@heysquad.be. You can also write to us by post at the address above.

02

Why we collect this data

We collect data for a very limited set of reasons:

  • Reply when you write to us. An email to hello@heysquad.be, a contact form — we need your name + email to reply.
  • Understand what works on the site. Measure the most-read pages, time spent, traffic sources — to adjust what we publish and drop what doesn't serve.
  • Improve your journey. Remember your preferences (language, cookie choices) so the site stays consistent on your next visit.
  • Distribute our content. When you consent, we may reach you on LinkedIn, Meta or Google with relevant content — never more often than necessary.
  • Meet our legal obligations. Invoicing, accounting, retention of commercial emails — obligations under the Belgian Code of Economic Law.
03

On what legal basis

The GDPR requires a legal basis for each processing activity. Here are ours:

  • Consent (GDPR art. 6.1.a) — for measurement, marketing, and preference cookies. You give consent via the cookie banner and can withdraw it anytime.
  • Legitimate interest (GDPR art. 6.1.f) — to respond to your messages and ensure site security (anti-fraud, anti-spam, error logs).
  • Contract execution (GDPR art. 6.1.b) — if you become a client, to run our collaboration (invoices, deliverables, project exchanges).
  • Legal obligation (GDPR art. 6.1.c) — accounting, invoicing, retention of pre-contractual exchanges when required by law.
04

What data exactly

  • Identification & contact — last name, first name, email, company, phone. Collected only if you provide them.
  • Navigation — pages visited, duration, traffic source, device type, browser, country. Only if you accept analytics cookies.
  • Technical — IP address (anonymized for analytics), session identifiers. Required for the site to function.
  • Content of your messages — when you write to us, the email content is kept for the time strictly necessary to follow up on the conversation.

We collect no sensitive data (health, orientation, origin, political opinions, religion) — our work doesn't require it.

05

Cookies & trackers

A cookie is a small text file placed on your browser. We use four categories. By default everything is refused except strictly necessary cookies — we wait for your explicit consent to activate the rest.

Necessary · always on

Essential for the site to work (session, security, language preference, consent choice). They cannot be turned off.

Tools
Application session, CSRF, hs_consent cookie (13 months)
Legal basis
Legitimate interest
Duration
Session or 13 months max

Analytics · optional

Measure audience and journeys so we can improve the site. Anonymised IPs, aggregated data. No personal identification.

Tools
Google Analytics 4, Vercel Analytics, Vercel Speed Insights
Legal basis
Consent
Duration
14 months (GA4) · 90 days (Vercel)

Marketing · optional

Let us reach you with relevant content on other platforms and measure our campaigns.

Tools
Meta Pixel, LinkedIn Insight Tag, Google Ads remarketing (via Google Tag Manager)
Legal basis
Consent
Duration
13 months max

Preferences · optional

Remember your non-essential choices (theme, last section visited) for a consistent experience next time.

Tools
Application localStorage
Legal basis
Consent
Duration
6 months

change your mind

You can change your consent anytime. Takes 10 seconds.

06

How long we keep it

  • Cookies — 13 months max (CNIL/APD recommendation). The consent cookie expires after 13 months → we ask again.
  • Email exchanges — 3 years after the last contact, unless a specific legal obligation applies.
  • Client data — duration of the relationship + 10 years (accounting obligation, Belgian Code of Economic Law art. III.86).
  • Anonymized navigation data — 14 months in GA4 (default setting).
  • Technical logs — 90 days (Vercel, Neon).
07

Who we share it with

We never sell your data. We work with certified sub-processors who only handle it on our behalf, under a strict contractual framework (signed DPA).

Vercel Inc.

Site hosting + Analytics + Speed Insights

United States (EU-US Data Privacy Framework certified)

Neon Inc.

Postgres database (editorial content)

European Union (Frankfurt)

Google Ireland Ltd.

Google Tag Manager + Google Analytics 4 (subject to your consent)

Ireland + United States (DPF)

Meta Platforms Ireland Ltd.

Meta Pixel (subject to your marketing consent)

Ireland + United States (DPF)

LinkedIn Ireland Unlimited Company

LinkedIn Insight Tag (subject to your marketing consent)

Ireland + United States (DPF)

The Rocket Science Group LLC (Mailchimp)

Transactional and marketing emails (where applicable)

United States (DPF)

08

Transfers outside the European Union

Some sub-processors (Vercel, Google, Meta, LinkedIn) are based in the United States. Transfers are made under the EU-U.S. Data Privacy Framework (DPF), a transfer mechanism adopted by the European Commission in July 2023.

For sub-processors not certified under DPF, transfers are governed by standard contractual clauses adopted by the European Commission (Decision 2021/914).

09

How we secure it

  • Encrypted exchanges over HTTPS (TLS 1.3).
  • Database hosted in the EU, encrypted at rest (AES-256).
  • Tool access secured by multi-factor authentication (2FA).
  • Access logs kept for 90 days for intrusion detection.
  • Minimization principle — we store only what serves a purpose.
  • Annual review of the security policy.

In case of a data breach affecting us that is likely to result in a high risk to your rights, we notify you without delay (GDPR art. 34).

10

Your rights

The GDPR gives you a set of rights over your personal data. We respect them without question, and free of charge.

  • Right of access — know what data we hold about you and get a copy.
  • Right to rectification — correct inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten") — request deletion of your data, unless a legal obligation applies.
  • Right to restriction — request that we freeze the processing of your data in certain cases.
  • Right to object — oppose processing based on our legitimate interest.
  • Right to portability — retrieve your data in a structured, machine-readable format.
  • Right to withdraw consent — anytime, without affecting the lawfulness of prior processing.
  • Right not to be subject to automated decisions — we make none about you, but the right is preserved.

To exercise one of these rights, write to us at hello@heysquad.be. We reply within one month (extendable by 2 months for complex requests, GDPR art. 12).

11

Contact us & APD complaint

For any question or request related to your personal data:

  • By email: hello@heysquad.be
  • By post: HeySquad, Rue des Nouvelles Technologies 10, 4821 Thimister-Clermont, Belgium

If you believe we're not respecting your rights, you can file a complaint with the Belgian Data Protection Authority (APD), Rue de la Presse 35, 1000 Brussels — autoriteprotectiondonnees.be.

This policy may change — the last updated date is shown at the top of the page. Major changes are notified via the cookie banner.

← Back to home

HeySquad · Thimister-Clermont · Belgium