1. Who are we?
Finding Solutions (private limited company), company number 1040.797.924, with its registered office at Bosdel 54 box 44, 3600 Genk, Belgium. PreventX is part of Finding Solutions. Finding Solutions is the controller within the meaning of Article 4(7) GDPR. You can contact us about any privacy matter at info@prevent-x.be.
2. What personal data do we collect?
We collect only the information you provide yourself or that is strictly necessary for the website to work:
- Contact form: name, email address, company name, telephone number (optional) and the content of your message.
- Specialised contact requests: only when you select Werfpoort or Managed HSE, we ask for your role, telephone number, region and preferred contact time in addition to the standard contact details. For Werfpoort, we also ask for the construction-site location, estimated project value, planned timing, current attendance registration and composition of the site team. For Managed HSE, we ask what support is missing.
- Data during a Werfpoort pilot: only when a separate assignment begins, we may process a name or badge identifier, employer, role, test IN and OUT times, identification method, registration source and an optional operational note. For security, deduplication and an auditable log, we may also record a one-way hash of the IP address and the browser identifier (User-Agent); we do not store the raw IP address. The precise scope, roles and retention period are set out in advance in the assignment and, where necessary, a data processing agreement.
- Customer portal account: email address, name, company domain and a bcrypt-hashed password.
- Uploaded documents (risk assessments, toolbox reports and photographs): stored on Supabase EU servers and protected by tenant-specific Row-Level Security.
- Technical usage data (only with consent): pages, click paths, screen size, language, and general browser and device category. For our own analytics, we do not retain a raw IP address or full User-Agent. We retain only broad categories and one-way hashes created with our own secret salt.
- Campaign data (only with consent): GCLID, GBRAID or WBRAID, UTM source, medium, campaign, term and content, landing page and capture time. For a contact request, we may also record conversion data without the contact content itself: qualified, meeting scheduled or won, and the assignment value when won. We link those data to the contact request to measure advertising conversions. For a trial account, attribution may also be linked to the associated Stripe objects.
3. Legal bases for processing
We apply a specific legal basis under Article 6 GDPR to each data category:
- Contact form: your explicit consent when you press “Send” (Article 6(1)(a)). Processing continues until you withdraw that consent.
- Portal account: performance of a contract (Article 6(1)(b)). Processing continues until the service is terminated.
- Uploaded documents: performance of a contract and legitimate interests (Article 6(1)(b) and (f)). Retention: while you are a customer plus five years for statutory audit requirements under the Belgian well-being-at-work framework.
- Analytics and advertising measurement: your explicit consent through the cookie banner (Article 6(1)(a) GDPR and the ePrivacy Directive 2002/58/EC). Browser attribution expires after 90 days; linked analytics and conversion records expire no later than after 13 months.
- Pilot assessment and delivery: steps prior to entering into a contract and, once an assignment starts, performance of that contract (Article 6(1)(b)). Where PreventX processes attendance data solely on the customer's behalf, PreventX acts as a processor within the written instructions agreed with that customer.
4. Cookies and tracking
We use Google Consent Mode v2: no non-essential analytics or marketing storage is used before you give explicit consent through the cookie banner. Campaign data from the URL remains only temporarily in the page's working memory before you make a choice. Functional cookies for session management, language selection and CSRF protection are essential for the site to work and fall within the exception in Article 5(3) of the ePrivacy Directive; they do not require consent.
Categories of cookies and storage we use:
- Essential (always active):
preventx-cookie-consent-v2in local browser storage retains your choice for up to 12 months. Secure session cookies are also required for login and CSRF protection. This storage is not used for marketing. - First-party visitor analytics (only with consent): a random session key in session storage. The server retains only a secret-salted hash of that key, together with pages and broad device data. We do not retain a full User-Agent, external IP geolocation or high-entropy device attributes. During setup and deletion, a random purpose-specific deletion key may temporarily remain in local browser storage. It contains no page, campaign or account data and remains available after the tab closes if a network error occurs. Server retention is no more than 13 months.
- Advertising (only with consent): Google Ads may place
_gcl_auand_gcl_aw. PreventX also stores a signed, HttpOnlypx_attributioncookie containing strictly limited campaign data for up to 90 days. After a specialised contact request, this attribution may be linked to conversion data without the contact content itself. When a trial starts, the first click is linked immutably to the account. Attribution and conversion records expire no later than after 13 calendar months. The purpose is to attribute the contact conversion, trial start or first actual payment to the correct campaign. - Apollo.io (only with consent): website visitor measurement and possible B2B company enrichment for the sales team. Apollo is loaded only after you give consent.
If you withdraw consent, we set Google storage back to denied, stop our visitor tracker and Apollo, delete the active anonymous visitor session and its page views, and remove the attribution cookie. We make a best-effort attempt to remove an already loaded Apollo tracker from browser storage, after which the page reloads once to terminate executable tracker state. Linked conversions that have not yet been sent are withdrawn. Deletion of attribution metadata that belongs to us at Stripe takes place in the background and is retried after a temporary failure. Measurements already lawfully sent to an external recipient are not retrospectively deleted by this action.
Change cookie preferences
Current status: Not decided yet
5. With whom do we share personal data?
Only with expressly appointed processors, each subject to a data processing agreement under Article 28 GDPR:
- Supabase (database and storage): EU region, Frankfurt. Data processing agreement compliant with the GDPR.
- Vercel (hosting and edge): EU region, Paris CDG. Standard Contractual Clauses for any transfer to the US.
- Anthropic Claude (AI content generation for the blog and portal assistant): customer opt-in through the customer portal. Standard Contractual Clauses for data outside the EEA.
- Google Ads: only with consent, for browser conversions, specialised contact stages and the later first-payment conversion. PreventX does not send a name, email address, telephone number, company name, message or other contact content. It sends only the relevant click and conversion action identifier, unique transaction key, time and, for a won assignment or payment, currency and value.
- Stripe: for card registration, subscriptions and payments. The temporary Checkout Session and Customer may receive an internal attribution key and, when present, the type and limited Google click identifier. The Subscription is linked to the same attribution only through our secure internal administration and receives no campaign, click-identifier or consent metadata.
- Apollo.io: only with consent, for website visitor measurement and B2B company enrichment.
We never sell personal data to third parties.
6. Your rights under the GDPR
Under Chapter III GDPR (Articles 12–23), you have the right to:
- Access (Article 15): receive a copy of your data in a readable format within 30 days.
- Rectification (Article 16): have inaccurate data corrected.
- Erasure (Article 17, the “right to be forgotten”): have all data erased unless a statutory retention obligation applies, including the five-year audit retention period.
- Restriction (Article 18): temporarily pause processing.
- Data portability (Article 20): receive your data in a machine-readable format, including a JSON export of portal data.
- Object (Article 21): object to processing based on legitimate interests.
- Withdraw consent (Article 7(3)): at any time, without affecting processing lawfully carried out before withdrawal.
To submit a request, email info@prevent-x.be with the subject “GDPR request”. We respond within 30 days, free of charge unless a request is manifestly unfounded or excessive.
7. Security
We use technical and organisational measures under Article 32 GDPR, including:
- HTTPS-only with HSTS, with a two-year max-age, on all subdomains.
- Passwords hashed with bcrypt cost factor 12.
- Tenant-specific Row-Level Security (RLS) on the database.
- Logging of access to sensitive data; optional two-factor authentication.
- An incident-response plan, including notification to the Belgian Data Protection Authority within 72 hours where a personal-data breach is notifiable under Article 33 GDPR.
8. Retention periods
- Contact-form leads: 12 calendar months after the last substantive change, after which the name, email address, telephone number, company name, message, qualification fields and internal note are anonymised.
- Werfpoort pilot data: for the agreed pilot and only until the deletion or return date set out in advance in the assignment or data processing agreement. Shadow-test data is not reused for another purpose and is deleted or returned to the customer by that contractually agreed date.
- Customer portal data: while you are a customer plus the statutory five-year audit retention period under the Belgian Code on Well-being at Work.
- Consent choice: up to 12 months.
- Attribution cookie: up to 90 days.
- Attribution and conversion records linked to contact requests: no later than 13 calendar months after the respective capture and conversion time. First-party visitor analytics and trial-account attribution also expire no later than 13 calendar months after their original collection.
- After that deletion, a detached, hashed technical locator may be kept for up to 30 additional days solely to erase remaining attribution metadata at Stripe. The locator contains no user, tenant, campaign data or click identifier and is not used for measurement.
- Server logs for HTTPS access and errors: 30 days, then anonymised.
9. Complaints
If you believe we are infringing your rights, you may lodge a complaint with the Belgian Data Protection Authority (GBA/APD), Rue de la Presse 35, 1000 Brussels, Belgium, at contact@apd-gba.be.
10. Changes
We update this policy when material changes occur. The “last updated” date above shows the most recent revision. For significant changes, we increase the cookie-consent version so that you are asked to confirm your choice again.
Questions? Email info@prevent-x.be. We respond within five business days.