Skip to Content

Privacy Policy

Website Privacy Policy


Who we are and how this policy applies

This policy explains how Replasia NV processes personal data when you visit or interact with our public websites and online pages available at https://replasia.com and any subdomains that link to this notice. It applies to site browsing, contact forms, newsletter subscriptions, analytics, and related website operations only.

It does not apply to clinical, research, imaging, usability testing, or AI-related processing of health data. Those activities are covered by the Replasia Privacy Policy for Clinical, Research, and AI Data Processing.

Contact: Miguel Azevedo (Qity BV)

Email: dpo@qity.be

What we collect on the website

We collect only what we need to operate and improve the site and to provide content you request.

  • Technical and usage data: IP address, date and time, pages viewed, referrer URL, browser and device information, operating system, and similar log data.

  • Analytics data: page views, sessions, bounce rate, events, and aggregated audience metrics.

  • Communication data: details you submit via contact forms or email, such as your name, email address, company, message content, and preferences.

  • Newsletter data: your email address and subscription preferences.

  • Consent records: your cookie and marketing preferences, timestamps, and related metadata.

We do not ask for special category data on the website. Please do not include health information or other sensitive data in web forms. If such information is received inadvertently, we will delete or redact it unless a lawful reason requires retention.

Why we process your data and our legal bases

We process website personal data for the following purposes, using the legal bases set out in Articles 6 and 7 GDPR.

  • Site operation and security: to deliver pages, maintain availability, prevent abuse, and detect incidents. Legal basis: our legitimate interests (Art. 6(1)(f)).

  • Analytics and performance: to understand site usage and improve content, based on your choices in the consent banner. Legal basis: consent (Art. 6(1)(a)).

  • Newsletter and marketing emails: to send updates you request and manage your subscription with double opt-in and easy unsubscribe. Legal basis: consent (Art. 6(1)(a)) and e-privacy rules where applicable.

  • Responding to enquiries: to answer questions and manage follow-up. Legal basis: pre-contractual steps or legitimate interests (Art. 6(1)(b) or 6(1)(f)).

  • Compliance: to meet legal obligations and handle rights requests. Legal basis: legal obligation (Art. 6(1)(c)).

You may withdraw consent at any time using the cookie banner link in the footer or the unsubscribe link in emails. Withdrawal does not affect processing carried out before withdrawal.

Cookies and similar technologies

We use a consent management tool to record and honour your choices. Non-essential cookies and similar technologies are used only with your consent. You can change or withdraw consent at any time via Cookie settings.

Analytics and consent management

We use Piwik PRO Analytics Suite for web analytics and consent management. Piwik PRO uses cookies to collect usage data such as IP address, browser and operating system, visited pages, and interactions. We use these data to calculate metrics and improve the site.

Data are retained for 14 or 25 months depending on configuration. We configure Piwik PRO to store data in the European Economic Area where possible.

If a transfer outside the EEA is required for hosting or support, we rely on appropriate safeguards such as Standard Contractual Clauses and provider data-processing terms. Piwik PRO does not use your data for its own purposes and does not pass it to unauthorised third parties. For details, see Piwik PRO’s privacy documentation.

Newsletter subscriptions and tracking

If you subscribe, we collect your email address, record double opt-in, and send the newsletter until you unsubscribe. We may use privacy-respecting measurement such as unique links or minimal open tracking to understand whether emails are delivered and useful. You can unsubscribe at any time using the link in each email or by contacting us.

Recipients and international transfers

Personal data are shared only as needed with trusted service providers acting under contract to host the site, deliver emails, provide analytics and consent tools, and secure our infrastructure. We require processors to follow Article 28 GDPR and implement appropriate technical and organisational measures.

If personal data are transferred outside the EEA, we use recognised safeguards such as European Commission adequacy decisions or Standard Contractual Clauses, and we assess any additional measures needed to protect the data.

Retention

  • Server logs: typically up to 12 months, shorter where feasible.

  • Analytics: 14 or 25 months as configured.

  • Contact enquiries: for as long as needed to handle your request and for a limited period thereafter for audit and compliance.

  • Newsletter data: until you unsubscribe or your address bounces, plus a short suppression period to honour your choice.

We delete or anonymise data when retention ends, keeping minimal records where required by law.

Your rights

You have the rights of access, rectification, erasure, restriction, objection, and data portability, and the right to withdraw consent at any time. You also have the right to lodge a complaint with your supervisory authority. In Belgium, this is the Gegevensbeschermingsautoriteit / Autorité de protection des données (GBA/APD), http://www.dataprotectionauthority.be/ .

To exercise your rights, contact us at info@replasia.com or the postal address above. We will respond within one month, extendable where permitted for complexity.

Children’s data

Our website is not directed to children.

We do not knowingly collect children’s personal data through the site.

Security

We protect personal data using appropriate technical and organisational measures, including TLS encryption, access controls, logging, vulnerability management, and processor due diligence. Internet transmission is never entirely risk-free, so if you prefer, you may contact us by telephone or post.

Automated decision-making

We do not use the website to carry out decisions based solely on automated processing that produce legal or similarly significant effects.

Changes to this policy

We may update this policy from time to time to reflect changes in law, services, or providers. Material changes will be highlighted on the site. The effective date above shows when this version took effect.

How this website policy differs from our clinical and research policy

This website policy covers visitors, cookies, analytics, newsletters, and online forms. It is not intended for processing of medical images, clinical records, or other special category data. If you interact with Replasia in a clinical, research, usability, or AI context, please refer to the Replasia Privacy Policy for Clinical, Research, and AI Data Processing, which addresses Article 9 GDPR safeguards, retention, and participant rights for those activities.