Version 3.0 — last updated: 25 August 2026.
1. Data controller
Data controller and publisher: Hebora, a business registered with the Belgian Crossroads Bank for Enterprises under number 0801.683.521, VAT number BE 0801.683.521.
Registered office: Rue Saint-Vincent 117 box 1, 1140 Evere, Belgium.
Verification: Crossroads Bank for Enterprises Public Search.
Data protection contact: contact form.
No data protection officer has been appointed because the processing described here does not require one. The controller handles requests directly.
2. Data processed and source
Data comes from you, your browser or providers needed to perform the requested action:
- Navigation and security: IP address, date and time, requested URL, HTTP headers, browser and technical events that may appear in GitHub Pages, Vercel or service logs;
- Contact and appointments: name, email, topic, message, contact preference, callback number, video-call date and time, optional VAT number, language and any audit, diagnostic or configuration summary you choose to send;
- Requested audit or diagnostic: tested public URL, date, time, test status, PageSpeed measurements and generated report;
- Local storage: privacy choice, language, liked projects, configurator draft and temporary transfers between a tool and the form;
- Optional Google Analytics: pages, sessions, navigation events, device, browser, approximate area and pseudonymous identifiers;
- Optional Microsoft Clarity: URL and referrer, device, browser, approximate area, pseudonymous identifier, clicks, pointer movements, scrolling, page dimensions, heatmaps and masked session replays.
Do not enter sensitive data in free-text fields. The site does not request health, political, biometric or payment-card data.
3. Purposes, legal bases and required data
- Deliver, route and secure the site: legitimate interest in providing a secure service and preventing abuse (GDPR Article 6(1)(f)); storage strictly necessary for a requested action falls within the applicable necessary-storage exemption;
- Run an audit, answer an enquiry, prepare a quote or appointment: pre-contractual steps at your request (Article 6(1)(b));
- Remember language and liked projects: consent (Article 6(1)(a));
- Google Analytics and Microsoft Clarity: prior, specific and separate consent for each tool (Article 6(1)(a) and Belgian tracker rules);
- Meet accounting, tax or legal duties after a contract: legal obligation (Article 6(1)(c)) or defence of legal claims (Article 6(1)(f)).
Fields marked as required are needed to handle the request. Refusing preferences, Google Analytics or Microsoft Clarity never prevents use of the site or form.
4. Audience and behavioural measurement
Google Analytics uses measurement ID G-CYRELLJYMS. It loads only after the Google Analytics choice. Google signals, advertising personalisation, remarketing and advertising storage remain disabled.
Microsoft Clarity uses project y7vsbzycfz. It loads only after the Clarity choice and is used to identify navigation friction through behavioural measurements, heatmaps and replays. Forms, personalised results, audits, diagnostics and configurations are masked before loading. Hebora does not use Microsoft Advertising, Clarity Identify API or these data for advertising.
The choices are independent. Silence, continued browsing and pre-ticked boxes are never treated as consent.
5. Cookies and storage
Legal self-assessment: answers stay in memory on the test page. At your request, hebora.legal-contact holds them in sessionStorage, with browser history as a fallback. The checklist can be reused for at most 24 hours and is cleared when removed or after successful submission. It accompanies your message only when you submit the form.
Necessary for a choice or requested action
hebora.privacy-choice— localStorage, domain/path not applicable, keeps the version and date of choices for six months;hebora:configurateur:v1and variants — localStorage, domain/path not applicable, keep the local configurator draft for 30 days;hebora.audit-contact,hebora.configurateur-contactandhebora.diagnostic-contact— sessionStorage, domain/path not applicable, transfer a requested result in the current tab and are deleted after reading.
Optional preferences
languageandhebora.projets.aimes— localStorage, domain/path not applicable, remain on the device for no more than six months and are erased on refusal or expiry.
Google Analytics, only after consent
_gaand_ga_*— domain.hebora.be, path/, pseudonymously identify a browser and session for no more than six months from creation, without renewal on each page.
Microsoft Clarity, only after consent
_clck— domain.hebora.be, path/, site-specific Clarity identifier, up to one year;_clsk— domain.hebora.be, path/, groups pages into a session, up to one day;CLID,ANONCHK,MR,MUIDandSM— Microsoft domains.clarity.msor.bing.com, path/, third-party cookies documented by Microsoft; duration ranges from the session or a few minutes to one year.
Browsers may block third-party cookies. These are maximum periods; refusal, withdrawal, expiry or browser cleaning can shorten them.
6. Recipients and providers
- GitHub Pages / GitHub: static hosting and security logs, including visitor IP addresses — GitHub privacy;
- Vercel: contact and diagnostic API — Vercel privacy;
- Upstash: temporary diagnostic state — Upstash privacy;
- Resend: email delivery for enquiries — Resend privacy;
- Daily.co: creation, only after booking, of a private video room and separate temporary links for the visitor and Hebora — Daily privacy;
- Google Ireland / Google: PageSpeed Insights at your request and Google Analytics after consent — Google privacy;
- Microsoft Ireland Operations / Microsoft: Clarity after consent — Microsoft privacy.
Hebora does not sell or rent data and does not disclose it to data brokers.
7. Transfers outside the EEA
Some providers or subprocessors may process data in the United States or other countries. Depending on the service, transfers rely on an adequacy decision, the EU–US Data Privacy Framework where it covers the recipient, and/or European Commission Standard Contractual Clauses. Google publishes its transfer mechanisms; Vercel, Upstash, Resend and Daily publish data-processing commitments or agreements; Microsoft states that EU Clarity customers contract with Microsoft Ireland Operations Limited and safeguards transfers to affiliates.
You may request a copy or reference to the applicable safeguards through the contact form, subject to confidential information.
8. Retention
- Enquiries and appointments: 12 months after the last exchange, unless a contract, legal duty or dispute requires longer;
- Audit or diagnostic trace: no more than 90 days;
- Technical logs available to Hebora: as long as needed for security and incident diagnosis, then deletion or aggregation; providers may retain their own logs under their duties and policies;
- Google Analytics user and event data: up to 14 months depending on the property setting; standard aggregate reports may remain longer;
- Clarity: ordinary replays 30 days; click data, heatmaps and labelled or favourite sessions up to nine months;
- On-device storage periods are listed in section 5.
9. Your rights
Subject to the GDPR, you may request access, rectification, erasure, restriction and portability; object to processing based on legitimate interest; withdraw consent at any time without affecting earlier lawful processing; and obtain information about transfer safeguards.
Use the contact form. Hebora normally responds within one month. This may be extended by two months for complex or numerous requests, with notice during the first month. Identity evidence is requested only where reasonable doubt exists and unnecessary details should be masked.
Withdraw trackers at any time through “Cookie settings” in the footer. Cookies accessible to Hebora are then deleted; third-party cookies already created can also be removed in browser settings.
10. Automated decisions and minors
No decision producing legal or similarly significant effects is made solely by automated processing. Audit and diagnostic scores are indicative and make no decision about a person.
Hebora services and this professional site do not target people under 18. If a minor’s data has been submitted, erasure can be requested.
11. Security and changes
The site uses HTTPS, a Content Security Policy, data minimisation, anti-abuse controls, masking of sensitive Clarity surfaces and limited access. No system is infallible; a risky incident is handled under applicable notification duties.
This policy is updated when processing or providers change. Its version and date identify the applicable text.
12. Complaint
You may complain to the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels: dataprotectionauthority.be.