Privacy policy
Document ID VADA-PRIV · Version 2.1 · Effective 1 September 2026 · In force
Supersedes v2.0.1 (14 August 2026)
This policy explains how we collect and use personal data when you use the vada website and services. We are committed to processing your data lawfully and transparently under the EU General Data Protection Regulation (GDPR).
1. Who is responsible for your data
The data controller is:
- Bernage BV
- Emile Zola laan 62, Schaarbeek, Belgium
- BE1032576282
- privacy@bernage.be
2. What data we collect
- Data you give us when you contact us: your name, email, organisation, country and the content of your message, plus any file you attach. Our form processor also records the IP address the submission came from, and keeps it for 12 months, to filter spam and keep the service secure.
- Access requests (licensed-engineer area): when you ask for access to the engineer area we collect your professional registration details — certification or registration number, issuing authority, country of registration, registration expiry, and whether you hold professional indemnity insurance — together with your name, email, and organisation or practice details, and the declarations you make in support of the request. We use this to assess your eligibility under our Terms of Service, and we verify your registration before granting access. Requests that do not lead to an account are kept for 12 months.
- Engineer account and project data (licensed-engineer area): when you register and use the engineer area we store your sign-in email and engineer profile — your name, professional certification number, country/jurisdiction, licence status and expiry, and the record of your acceptance of our terms and professional-responsibility declaration. For each project you create we store the project and programme names, the location and coordinates, the designer and approver names and certification numbers, the client name and address, the bridge configuration, the generated drawing packs and their revision history. Approver and client details are personal data of third parties that you, as the engineer, provide.
- Purchase, billing and tax-status data: when you buy a design pack, a costing pack or a licence, we collect the details needed to take payment and issue an invoice: your billing name and address, VAT/TIN, country and preferred currency, and the email address we deliver to. For business buyers we use your country and VAT number to determine the correct tax treatment of the sale (for example VAT reverse-charge for a VAT-registered business, and any applicable local digital-services tax).
- Payment data: we offer three payment methods — bank transfer (Wise invoice), card (Mollie) and, in mobile-money markets, pawaPay. The payment itself is completed on the provider's own secure systems: we never see or store your full payment-card number or your mobile-money credentials. We receive a payment confirmation and a transaction reference, and — for delivery and support — your email and the minimal buyer details above.
- Technical data: basic server logs kept by our hosting provider (e.g. IP address, browser type) for security and to run the site.
- Cookieless analytics: our public pages record first-party page views — the page path, the referrer domain, a coarse country code, a timestamp and named interactions with the page (for example that the pricing section was scrolled to, or a sign-in button was clicked) — stored in the EU on our own backend. No cookies are set, no IP address is stored and no personal data is collected, so no consent banner is required.
- Beta feedback (engineer area): if you use the Feedback button, we store your message, the page you sent it from and your browser's user agent — and, only when you tick "include my current design", the bridge configuration you attached — in the EU, for product improvement.
- Operational events (engineer area): the platform logs operational events (design attempts, issuance of drawing packs, errors and abuse signals) for security, abuse prevention and service improvement. These logs reference your engineer profile and minimal technical facts about the event; they are stored in the EU and retained for 12 months.
3. Why we use your data, and our legal basis
| Purpose | Legal basis |
|---|---|
| Deliver the drawings / packs / services you order and respond to your enquiry | Performance of a contract |
| Operate the licensed-engineer area (accounts, projects, issuing drawing packs) | Performance of a contract |
| Take payment for the packs or licences you order, and issue invoices and keep accounts | Performance of a contract; Legal obligation (Belgian tax & accounting law) |
| Determine the correct tax treatment of a sale (e.g. VAT reverse-charge, local digital-services tax) from the country and VAT/TIN you provide | Legal obligation; Performance of a contract |
| Assess a request for access to the licensed-engineer area, including verifying professional registration | Steps taken at your request prior to entering into a contract |
| Contact you about your project or quote | Legitimate interest / your consent |
| Keep the site and service secure and prevent abuse and payment fraud | Legitimate interest |
Where we rely on consent, you can withdraw it at any time.
4. Who we share your data with
We do not sell your data. We use a small number of processors that handle data on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Nhost | Our own backend: authentication, database, file storage and serverless functions (the licensed-engineer area, generated drawing packs, operational logs, beta feedback) and the cookieless page-view analytics on the public pages | EU (Frankfurt, Germany) |
| Formspark | Receives and forwards contact-form submissions | Trampoline Software SRL, Belgium; data stored in Ireland and Germany |
| Botpoison | Invisible spam protection on our contact form | Trampoline Software SRL, Belgium; data stored in Ireland |
| Mollie | Card payment processing for design packs, costing packs and licences | EU (Netherlands) |
| pawaPay (Payments Techco OÜ) | Mobile-money payment collection and settlement in African markets. pawaPay uses locally licensed payment providers as its sub-processors to collect mobile money in each market (for Tanzania, Madina-Tech Group Limited). Its current sub-processor list is published at pawapay.io/payment-providers. | Contracting entity in Estonia (EU); collection via local providers in the payer's country |
| Wise | Issues our invoices and receives payment settlement | EU / EEA |
| Infomaniak | Website hosting | Switzerland (EU adequacy) |
We may also disclose data where legally required.
5. International transfers
Most of our providers store data within the EU/EEA or in a country recognised by the EU as providing adequate protection (Switzerland; the United Kingdom and Isle of Man for entities in pawaPay's group). Collecting mobile money necessarily involves a payment provider located in the market where the payer is (for example, Tanzania). Where personal data is transferred outside the EEA to pawaPay's local payment providers, that transfer is covered by the EU Standard Contractual Clauses under pawaPay's data-processing agreement. Where any other transfer outside the EEA occurs, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
6. How long we keep your data
- Enquiries that do not lead to an order: 12 months.
- Operational event logs (engineer area): 12 months.
- Beta feedback: up to 24 months.
- Cookieless analytics: kept as aggregate figures only; the records contain no personal data.
- Engineer account and project records: for as long as your account is active and as required to keep our accounts.
- Order, invoice, payment and accounting records: retained for the period required by Belgian law (currently 7 years).
- Marketing consent records: until you withdraw consent.
Our payment providers also retain transaction records under their own data-processing agreements to meet their legal, tax and anti-money-laundering obligations.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict or object to the processing of your data, to data portability, and to withdraw consent. To exercise any of these, contact us at privacy@bernage.be. We will respond within two weeks.
8. Complaints
If you believe we have not handled your data properly, you can lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Rue de la Presse 35, 1000 Brussels — gegevensbeschermingsautoriteit.be.
9. Cookies and tracking
This website uses no advertising or analytics cookies and no third-party trackers. Fonts, icons, images and all JavaScript — including the 3D bridge configurator, which runs entirely in your browser — are served from our own domain. The requests the site makes beyond the page itself all go to our own backend (Nhost, in the EU): a cookieless page-view ping on the public pages (page path, referrer domain, coarse country and timestamp — no cookies, no stored IP), and, in the licensed-engineer area, sign-in, data and drawing generation. When you choose to pay, you are handed off to your selected payment provider (Mollie or pawaPay) to complete the payment on their own page or app, subject to that provider's privacy terms; we set no tracking cookies. The one third-party script on our own pages is an invisible anti-spam check (Botpoison, loaded from unpkg.com) on pages that contain a contact form.
On the public pages we measure usage first-party, cookieless and in aggregate only: our own EU-hosted server records the page path, the referrer domain, a coarse country code, a timestamp, and named interactions on this site (for example that the pricing section was scrolled to, or a sign-in button was clicked). We store no visitor identifier of any kind — no cookie, no fingerprint, no visitor key, no hashed IP: your IP address is never stored, and nothing is stored on or read from your device — no cookies, no local storage, no fingerprinting scripts. What we keep are plain counters that cannot be linked to you, on this site or any other. That is why this site needs no cookie/consent banner: the ePrivacy consent requirement applies to storing or reading information on your device, and the measurement described here does neither; the aggregate, non-identifying measurement described here is carried out under legitimate interest (Art. 6(1)(f) GDPR).
The one exception is the invisible anti-spam check on pages that carry a contact form. It holds a short-lived identifier in your browser for as long as the tab is open, solely to link the checks made during a single visit. That is storage strictly necessary to provide the form you asked to use, which the ePrivacy rules exempt from the consent requirement, and it is not used to measure, profile or identify you.
10. Changes to this policy
We may update this policy from time to time. The version and effective date at the top show the current version; material changes take effect on the stated effective date.