Skip to content
Websexpert logo
Legal

Privacy Policy

Last updated on August 6, 2026

This privacy policy is a template built on standard GDPR principles. It is not legal advice — have it reviewed by a lawyer after filling in your business details, especially when reusing it for a client's website.

1. Who are we?

This website is operated by Websexpert [FILL IN: full company name, legal form, and company registration number — set via dashboard → Business details]. For any questions about this privacy policy, you can reach us at:

2. What data do we collect?

a) Contact form

When you fill in our contact form, we process your name, email address, and message content. We use this data solely to respond to your enquiry, based on our legitimate interest in replying to questions you send us directly.

b) Visitor statistics

We keep anonymised visitor statistics (pages visited, approximate device type, referring website, country, and how long certain page sections are viewed) to understand how our site is used. In doing so:

  • We never store your IP address. Instead, a one-way hash is calculated that changes daily, so visits cannot be traced back to an IP address or person.
  • Your country is only determined via a header from our reverse proxy (Cloudflare, if used) — an IP address is never sent to an external location service.
  • We measure how long parts of the page are visible (e.g. "Services" or "Projects") to see what interests visitors — this is fully anonymised, linked to the same daily hash.
  • We only recognise returning visitors when you have given consent via the cookie notice (see the "visitor_uuid" cookie below) — without consent this isn't possible, and your visit simply counts anonymously.
  • We do not use Google Analytics unless we have explicitly enabled it (see below), and never without your consent.

c) Cookies

Our website uses the following types of cookies:

Cookie Purpose Retention Consent required?
Session cookie (Laravel) Required for the contact form and, where applicable, the admin dashboard to function. Session / max. 2 hours No — strictly necessary
cookie_consent Remembers your choice in the cookie notice. 12 months No — strictly necessary
visitor_uuid Recognises returning visitors for our own, anonymous statistics — contains no name, email, or other identifiable data. 12 months Yes — only after your consent
Google reCAPTCHA Protects our contact form against spam and automated abuse. Up to 6 months (set by Google) No — security purpose
Google Analytics (if active) Anonymous visit statistics, only if we have enabled it. Up to 14 months Yes — only after your consent
Microsoft Clarity (if active) Heatmaps and session recordings to improve the website, only if we have enabled it. Up to 12 months Yes — only after your consent

We currently [FILL IN: "do/do not"] use Google Analytics and [FILL IN: "do/do not"] use Microsoft Clarity to collect anonymous visit statistics. If active, these scripts are only loaded after you give consent via the cookie notice, and we process your IP address in truncated form (IP anonymisation). Google reCAPTCHA is used to protect our contact form from spam; this falls under Google's privacy policy.

d) Security log (login attempts)

To protect our admin dashboard from unauthorised access, we keep a log of login attempts (successful and failed): the email address entered, IP address, country, and time. This is not a visitor statistic but a security measure, based on our legitimate interest (GDPR art. 6.1.f) to detect and prevent abuse. This log is kept for a maximum of [FILL IN: e.g. 90 days].

3. How long do we keep your data?

We keep contact enquiries for [FILL IN: e.g. a maximum of 24 months] after the last contact, unless a longer retention period is legally required. Anonymised visitor statistics are kept for [FILL IN: e.g. a maximum of 26 months].

4. Do we share data with third parties?

We never sell your data. To send emails we use an email provider [FILL IN: provider name, e.g. your hosting partner or transactional email service]. This party processes data solely on our instructions and in line with the GDPR.

5. How do we secure your data?

We take appropriate technical and organisational measures: encrypted passwords, secure (HTTPS) connections, restricted access to the admin dashboard, and protection against automated abuse (rate limiting, spam filters) on our forms.

6. What are your rights?

Under the GDPR you have the right to:

  • Access the data we hold about you
  • Correct inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing

You can exercise these rights by contacting us at info@websexpert.be. You also have the right to lodge a complaint with the Belgian Data Protection Authority via gegevensbeschermingsautoriteit.be.

7. Changes

We may update this privacy policy from time to time. The date at the top of this page indicates when it was last changed.

8. Contact

Questions about this privacy policy? Contact us at info@websexpert.be or 0493 54 17 17.