MSOIT

Legal

Privacy Policy

Last updated: June 2026

1. Who we are

MSOIT ("Making Sense of IT") is an IT consultancy based in Belgium, providing technology services to small and medium-sized businesses across Belgium and the EU.

Data controller: MSOIT
Contact: hello@msoit.eu
Website: msoit.eu

2. What data we collect

When you submit the contact form on this website, we collect:

  • Contact details: name, email address, phone number (optional), company name (optional)
  • Enquiry details: area of interest, your message
  • Technical data: IP address, browser user agent, page URL, referring URL
  • Marketing attribution: UTM parameters (source, medium, campaign) if present in the URL
  • Language preference: which language you selected on the site

We also retain email correspondence when you reply to messages from us.

We do not collect payment information, sensitive personal data, or any data from minors.

3. Why we collect it and our legal basis

Purpose Legal basis (GDPR Art. 6)
Responding to your enquiry and booking a review Legitimate interest / pre-contractual steps
Following up on our conversation by email Legitimate interest
IP address & browser data — spam and fraud prevention Legitimate interest
Marketing attribution (UTM parameters) — understanding which channels bring enquiries Legitimate interest
Analytics cookies (if you have consented) Consent

We do not send marketing newsletters or add you to mailing lists without your separate, explicit consent.

4. How long we keep your data

Enquiry records (contact form submissions and email correspondence) are retained for 2 years from the date of the last communication. After that period they are permanently deleted from our systems.

If we enter into a commercial relationship, we may retain relevant records for the period required by Belgian accounting and tax law (currently 7 years).

5. Who we share your data with

We use the following third-party services to operate the website:

  • Supabase — cloud database where enquiry data is stored (servers in EU)
  • Resend — transactional email delivery service
  • Railway — website hosting platform
  • Cookiebot / Cybot A/S — cookie consent management

We do not sell, rent, or share your personal data with third parties for marketing purposes.

6. Cookies

This site uses a cookie consent tool (Cookiebot) that lets you choose which categories of cookies to allow. Essential cookies are always active as they are necessary for the site to function. Non-essential cookies (analytics, marketing) are only set after you give consent.

You can change or withdraw your consent at any time by clicking the cookie icon at the bottom of the page, or by clearing your browser cookies.

7. Your rights

Under GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — ask us to correct inaccurate data
  • Deletion — ask us to delete your data (subject to legal retention requirements)
  • Restriction — ask us to restrict processing of your data
  • Objection — object to processing based on legitimate interest
  • Portability — receive your data in a portable format

To exercise any of these rights, email us at hello@msoit.eu. We will respond within 30 days.

You also have the right to lodge a complaint with the Belgian Data Protection Authority (APD/GBA): dataprotectionauthority.be.

8. Security

All data is transmitted over HTTPS. Access to enquiry records is restricted to authorised personnel only and protected by authentication. We review our security practices regularly.

9. Data breach notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Belgian Data Protection Authority (APD/GBA) within 72 hours of becoming aware of it, in accordance with Article 33 GDPR.

If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, describing the nature of the breach, the likely consequences, and the measures taken or proposed to address it.

10. Changes to this policy

We may update this policy from time to time. The date at the top of the page shows when it was last revised. Material changes will be noted here.

11. Record of processing activities

Our full Record of Processing Activities (ROPA) is published separately. It lists every processing activity, the legal basis, data categories, processors, third-country transfers, and retention periods in detail, as required by Article 30 GDPR.

12. Contact

For any privacy-related questions or requests, contact us at:
hello@msoit.eu