Legal
Privacy Policy
Last updated: June 2026
1. Who we are
MSOIT ("Making Sense of IT") is an IT consultancy based in Belgium, providing technology services to small and medium-sized businesses across Belgium and the EU.
Data controller: MSOIT
Contact: hello@msoit.eu
Website: msoit.eu
2. What data we collect
When you submit the contact form on this website, we collect:
- Contact details: name, email address, phone number (optional), company name (optional)
- Enquiry details: area of interest, your message
- Technical data: IP address, browser user agent, page URL, referring URL
- Marketing attribution: UTM parameters (source, medium, campaign) if present in the URL
- Language preference: which language you selected on the site
We also retain email correspondence when you reply to messages from us.
We do not collect payment information, sensitive personal data, or any data from minors.
3. Why we collect it and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Responding to your enquiry and booking a review | Legitimate interest / pre-contractual steps |
| Following up on our conversation by email | Legitimate interest |
| IP address & browser data — spam and fraud prevention | Legitimate interest |
| Marketing attribution (UTM parameters) — understanding which channels bring enquiries | Legitimate interest |
| Analytics cookies (if you have consented) | Consent |
We do not send marketing newsletters or add you to mailing lists without your separate, explicit consent.
4. How long we keep your data
Enquiry records (contact form submissions and email correspondence) are retained for 2 years from the date of the last communication. After that period they are permanently deleted from our systems.
If we enter into a commercial relationship, we may retain relevant records for the period required by Belgian accounting and tax law (currently 7 years).
5. Who we share your data with
We use the following third-party services to operate the website:
- Supabase — cloud database where enquiry data is stored (servers in EU)
- Resend — transactional email delivery service
- Railway — website hosting platform
- Cookiebot / Cybot A/S — cookie consent management
We do not sell, rent, or share your personal data with third parties for marketing purposes.
6. Cookies
This site uses a cookie consent tool (Cookiebot) that lets you choose which categories of cookies to allow. Essential cookies are always active as they are necessary for the site to function. Non-essential cookies (analytics, marketing) are only set after you give consent.
You can change or withdraw your consent at any time by clicking the cookie icon at the bottom of the page, or by clearing your browser cookies.
7. Your rights
Under GDPR you have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — ask us to correct inaccurate data
- Deletion — ask us to delete your data (subject to legal retention requirements)
- Restriction — ask us to restrict processing of your data
- Objection — object to processing based on legitimate interest
- Portability — receive your data in a portable format
To exercise any of these rights, email us at hello@msoit.eu. We will respond within 30 days.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (APD/GBA): dataprotectionauthority.be.
8. Security
All data is transmitted over HTTPS. Access to enquiry records is restricted to authorised personnel only and protected by authentication. We review our security practices regularly.
9. Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Belgian Data Protection Authority (APD/GBA) within 72 hours of becoming aware of it, in accordance with Article 33 GDPR.
If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, describing the nature of the breach, the likely consequences, and the measures taken or proposed to address it.
10. Changes to this policy
We may update this policy from time to time. The date at the top of the page shows when it was last revised. Material changes will be noted here.
11. Record of processing activities
Our full Record of Processing Activities (ROPA) is published separately. It lists every processing activity, the legal basis, data categories, processors, third-country transfers, and retention periods in detail, as required by Article 30 GDPR.
12. Contact
For any privacy-related questions or requests, contact us at:
hello@msoit.eu