Privacy policy

Document ID VADA-PRIV · Version 2.1 · Effective 1 September 2026 · In force

Supersedes v2.0.1 (14 August 2026)

This policy explains how we collect and use personal data when you use the vada website and services. We are committed to processing your data lawfully and transparently under the EU General Data Protection Regulation (GDPR).

1. Who is responsible for your data

The data controller is:

2. What data we collect

3. Why we use your data, and our legal basis

PurposeLegal basis
Deliver the drawings / packs / services you order and respond to your enquiryPerformance of a contract
Operate the licensed-engineer area (accounts, projects, issuing drawing packs)Performance of a contract
Take payment for the packs or licences you order, and issue invoices and keep accountsPerformance of a contract; Legal obligation (Belgian tax & accounting law)
Determine the correct tax treatment of a sale (e.g. VAT reverse-charge, local digital-services tax) from the country and VAT/TIN you provideLegal obligation; Performance of a contract
Assess a request for access to the licensed-engineer area, including verifying professional registrationSteps taken at your request prior to entering into a contract
Contact you about your project or quoteLegitimate interest / your consent
Keep the site and service secure and prevent abuse and payment fraudLegitimate interest

Where we rely on consent, you can withdraw it at any time.

4. Who we share your data with

We do not sell your data. We use a small number of processors that handle data on our behalf:

ProviderPurposeLocation
NhostOur own backend: authentication, database, file storage and serverless functions (the licensed-engineer area, generated drawing packs, operational logs, beta feedback) and the cookieless page-view analytics on the public pagesEU (Frankfurt, Germany)
FormsparkReceives and forwards contact-form submissionsTrampoline Software SRL, Belgium; data stored in Ireland and Germany
BotpoisonInvisible spam protection on our contact formTrampoline Software SRL, Belgium; data stored in Ireland
MollieCard payment processing for design packs, costing packs and licencesEU (Netherlands)
pawaPay (Payments Techco OÜ)Mobile-money payment collection and settlement in African markets. pawaPay uses locally licensed payment providers as its sub-processors to collect mobile money in each market (for Tanzania, Madina-Tech Group Limited). Its current sub-processor list is published at pawapay.io/payment-providers.Contracting entity in Estonia (EU); collection via local providers in the payer's country
WiseIssues our invoices and receives payment settlementEU / EEA
InfomaniakWebsite hostingSwitzerland (EU adequacy)

We may also disclose data where legally required.

5. International transfers

Most of our providers store data within the EU/EEA or in a country recognised by the EU as providing adequate protection (Switzerland; the United Kingdom and Isle of Man for entities in pawaPay's group). Collecting mobile money necessarily involves a payment provider located in the market where the payer is (for example, Tanzania). Where personal data is transferred outside the EEA to pawaPay's local payment providers, that transfer is covered by the EU Standard Contractual Clauses under pawaPay's data-processing agreement. Where any other transfer outside the EEA occurs, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

6. How long we keep your data

Our payment providers also retain transaction records under their own data-processing agreements to meet their legal, tax and anti-money-laundering obligations.

7. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict or object to the processing of your data, to data portability, and to withdraw consent. To exercise any of these, contact us at privacy@bernage.be. We will respond within two weeks.

8. Complaints

If you believe we have not handled your data properly, you can lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Rue de la Presse 35, 1000 Brussels — gegevensbeschermingsautoriteit.be.

9. Cookies and tracking

This website uses no advertising or analytics cookies and no third-party trackers. Fonts, icons, images and all JavaScript — including the 3D bridge configurator, which runs entirely in your browser — are served from our own domain. The requests the site makes beyond the page itself all go to our own backend (Nhost, in the EU): a cookieless page-view ping on the public pages (page path, referrer domain, coarse country and timestamp — no cookies, no stored IP), and, in the licensed-engineer area, sign-in, data and drawing generation. When you choose to pay, you are handed off to your selected payment provider (Mollie or pawaPay) to complete the payment on their own page or app, subject to that provider's privacy terms; we set no tracking cookies. The one third-party script on our own pages is an invisible anti-spam check (Botpoison, loaded from unpkg.com) on pages that contain a contact form.

On the public pages we measure usage first-party, cookieless and in aggregate only: our own EU-hosted server records the page path, the referrer domain, a coarse country code, a timestamp, and named interactions on this site (for example that the pricing section was scrolled to, or a sign-in button was clicked). We store no visitor identifier of any kind — no cookie, no fingerprint, no visitor key, no hashed IP: your IP address is never stored, and nothing is stored on or read from your device — no cookies, no local storage, no fingerprinting scripts. What we keep are plain counters that cannot be linked to you, on this site or any other. That is why this site needs no cookie/consent banner: the ePrivacy consent requirement applies to storing or reading information on your device, and the measurement described here does neither; the aggregate, non-identifying measurement described here is carried out under legitimate interest (Art. 6(1)(f) GDPR).

The one exception is the invisible anti-spam check on pages that carry a contact form. It holds a short-lived identifier in your browser for as long as the tab is open, solely to link the checks made during a single visit. That is storage strictly necessary to provide the form you asked to use, which the ePrivacy rules exempt from the consent requirement, and it is not used to measure, profile or identify you.

10. Changes to this policy

We may update this policy from time to time. The version and effective date at the top show the current version; material changes take effect on the stated effective date.