Skip to main content

Privacy Policy

How we protect your personal data

Client file being secured in storage beside a closed computer

Privacy Policy

This page has to be clear and reliable.

A privacy policy only works if it is readable, concrete and up to date. You should quickly understand how CertiDocs operates and which rules apply.

Who

Who runs the service and which parties handle data or infrastructure.

What

Which rules, data or responsibilities actually matter here.

When

Which version applies and when it was last updated.

Next

Which other page you need if you actually have to do something.

1. Data controller
CertiDocs is a service operated by Hebora. Data controller: Hebora Enterprise and VAT number: BE 0801.683.521 Email: info@certidocs.be Website: https://www.certidocs.be
2. Data collected
We collect the following data: • Guided form: name, email address, phone number (optional), service type, any document type, source and target languages, urgency level, details provided, any address or timing for interpretation, optional city/province, source page and useful request context • Vercel Analytics: browsing and technical audience-measurement data • Google Analytics, only if GA4 is enabled: aggregated browsing data (pages visited, session duration, device) • CertiDocs technical anti-spam cookie, validated through Cloudflare Turnstile • Origin of the visit: referring site and any campaign parameters (utm_source, utm_medium, utm_campaign), kept in your browser's session storage and attached to the request you send
3. Purpose of processing
Your data is processed to: • Respond to your connection requests, certified translation enquiries or interpretation enquiries • Qualify your need and route it to the right handling path • Improve our services through anonymised traffic analysis • Ensure site security (anti-spam protection via Cloudflare Turnstile)
4. Legal basis
The processing of your data is based on: • Your consent (guided form and optional audience measurement) • Our legitimate interest (site security) • Performance of a contract or pre-contractual measures (connection request)
5. Cookies and audience measurement
Vercel Analytics and Google Analytics (GA4, only when configured) are loaded only after you agree to audience measurement. You can refuse this option or change your choice at any time through “Manage cookies” in the footer. A strictly necessary cookie stores that choice for 6 months, so the question does not return on every page. After a successful Cloudflare Turnstile validation, CertiDocs may also set a secure anti-spam cookie that remains valid for 30 minutes. The site does not create a language-preference cookie. The site also records, in your browser's session storage, the referring site and campaign parameters of the first page you visited. This is used only to know through which channel a request reached us. It is not a cookie, it does not follow your browsing on other sites, and it disappears when you close the tab. Without consent, no audience-measurement script is loaded. Without a valid configured GA4 ID, no Google Analytics script is loaded.
6. Sub-processors
We use the following sub-processors: • Vercel Inc. (USA) - Website hosting and audience measurement • Supabase Inc. (USA) - Database • Resend Inc. (USA) - Transactional email delivery • Cloudflare Inc. (USA) - Security and CDN • Google LLC (USA) - Analytics, only if GA4 is enabled These sub-processors have appropriate safeguards (standard contractual clauses, certifications) to ensure the protection of your data in accordance with GDPR.
7. Data retention
• Request and contact data: kept for as long as needed to process and follow up your request, then reviewed for manual deletion or archiving • Cookie choice: 6 months • Vercel Analytics: retention determined by the provider's active configuration, only after consent • Google Analytics: 14 months, only if GA4 is enabled and after consent • CertiDocs anti-spam cookie: 30 minutes There is currently no automated purge tied to a fixed deadline for request and contact data.
8. Your rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights: • Right of access: obtain a copy of your personal data • Right of rectification: correct inaccurate data • Right to erasure: request deletion of your data • Right to portability: receive your data in a structured format • Right to object: object to the processing of your data • Right to restriction: restrict the processing of your data To exercise your rights, contact us at info@certidocs.be. We will respond within 30 days. You also have the right to lodge a complaint with the Belgian Data Protection Authority (DPA): https://www.dataprotectionauthority.be
9. Changes
This privacy policy may be updated. The version published on the site is the version in force. Last updated: September 2026

National register data

National register — FPS Justice · . Registered translation qualifications on active profiles. Registration periods and availability need checking; these figures do not count CertiDocs partners.

Official source

Official sources used

These institutional references support the regulatory information on this page. Each link opens the public source directly.

CertiDocs analysis: CertiDocs summarises them in practical language. This summary is not legal advice, and CertiDocs is not affiliated with any authority.

Related pages that usually belong with this one

A privacy or legal page rarely stands alone. These are the logical next stops.