Legal
Record of Processing Activities
Last updated: June 2026 — Version 1.0
This page documents all personal data processing activities carried out by MSOIT as data controller, in accordance with Article 30 of the General Data Protection Regulation (EU) 2016/679. It is kept up to date and made available to the Belgian Data Protection Authority (APD/GBA) on request.
Data controller: MSOIT (Making Sense of IT)
Contact: hello@msoit.eu
Establishment: Belgium
Processing Activities
One row per activity. Scroll horizontally on small screens.
| ID | Activity | Purpose | Legal Basis | Personal Data | Processors | 3rd Country? | Retention |
|---|---|---|---|---|---|---|---|
| PA-01 | Contact Form Lead Capture | Receive and store enquiries submitted via the website contact form so we can respond and arrange a free IT review. | Art. 6(1)(b) — Pre-contractual steps Art. 6(1)(f) — Legitimate interest | Name; email address; phone number (optional); company name (optional); area of interest; message; IP address; browser user agent; page URL; referring URL; language preference; UTM attribution parameters | Supabase (EU region); Resend | No | 2 years from last contact, then permanently deleted |
| PA-02 | Email Follow-Up Correspondence | Send follow-up emails to arrange or conduct the free IT review and deliver agreed next steps. | Art. 6(1)(f) — Legitimate interest (following up on an inbound business enquiry; no cold outreach) | Name; email address; email correspondence content | Resend (email delivery) | No | 2 years from last contact, then permanently deleted |
| PA-03 | Inbound Email Reply Logging | Capture replies from prospects who respond to our emails so we can maintain a coherent conversation record. | Art. 6(1)(f) — Legitimate interest | Sender email address; name (from email header); reply content; timestamp | Resend (inbound webhook); Supabase (storage, EU region) | No | 2 years from last contact, then permanently deleted |
| PA-04 | Marketing Attribution (UTM Tracking) | Record UTM parameters to understand which marketing channels generate enquiries, enabling informed budget decisions. | Art. 6(1)(f) — Legitimate interest (channel ROI analysis; not used for individual profiling or re-targeting) | UTM source; UTM medium; UTM campaign; UTM term; UTM content | Supabase (EU region) | No | 2 years, retained with lead record, then deleted |
| PA-05 | Spam & Fraud Prevention | Log IP address and browser user agent to detect and block abusive or automated form submissions. | Art. 6(1)(f) — Legitimate interest (protecting system integrity) | IP address; browser user agent string | Supabase (EU region) | No | 2 years with lead record; spam submissions deleted within 30 days |
| PA-06 | Cookie Consent Records (Cookiebot) | Record each visitor's consent decision so we can demonstrate compliance with GDPR consent requirements. | Art. 6(1)(c) — Legal obligation (Art. 7(1) GDPR — controller must be able to demonstrate consent) | Cookiebot consent UUID; hashed IP address; consent timestamp; consent state per category; browser user agent | Cybot A/S / Cookiebot (Denmark, EU) | No — processor based in Denmark (EU/EEA) | 12 months (aligned with consent renewal cycle) |
| PA-07 | Website Analytics | Collect anonymised usage data (pages viewed, session duration, traffic sources) to understand how visitors use the site and improve content. | Art. 6(1)(a) — Consent (visitor must accept statistics cookies via Cookiebot before any analytics script loads) | Anonymised browsing behaviour; pages visited; session duration; browser & device type; country-level location; traffic source | Analytics provider (see Processors table below) | Depends on provider — see Processors table | 26 months, or shorter per provider settings |
| PA-08 | Admin Panel — Lead Management | Allow authorised MSOIT staff to view, reply to, update and delete lead records for sales pipeline management. | Art. 6(1)(f) — Legitimate interest (internal business operations) | All data categories collected in PA-01 and PA-03 | Supabase (backend & auth, EU region) | No | Per PA-01 / PA-03 retention schedules |
Data Processors (Article 28)
Third-party services that process personal data on our behalf. Data Processing Agreements (DPAs) are in place with each processor.
| Processor | Role | Location | 3rd Country Transfer? | DPA in Place? |
|---|---|---|---|---|
| Supabase Inc. | Database, backend API & authentication hosting | EU data region — eu-west-1 (Dublin, Ireland) | No | Yes |
| Resend.com | Transactional email delivery (outbound and inbound webhook) | US (infrastructure may include EU regions) | Yes — SCCs in place per Resend DPA | Yes |
| Cybot A/S (Cookiebot) | Cookie consent management platform (CMP) | Denmark (EU/EEA) | No | Yes |
| Analytics Provider | Website analytics — aggregated usage statistics (only after consent) | To be confirmed | To be confirmed | To be confirmed |
| Railway | Website hosting platform | EU region | No | Yes |
Technical & Organisational Security Measures
- All data transmitted over HTTPS / TLS
- Supabase row-level security enabled; data stored in EU region (Dublin, Ireland)
- Admin panel access protected by authentication; session tokens expire on inactivity
- Principle of least privilege — staff access limited to what is necessary
- API keys scoped to minimum required permissions; stored as environment variables (not in codebase)
- No personal data sold, rented or shared with third parties for marketing
- Security practices reviewed annually
Your Rights
Under GDPR you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to receive it in a portable format. To exercise any of these rights, email hello@msoit.eu. We will respond within 30 days.
You also have the right to lodge a complaint with the Belgian Data Protection Authority: dataprotectionauthority.be.