Data Protection Policy
1.
Version
This policy was last updated on 01-10-2025
2.
Short Description – Highlights
Summ.link BV is committed to maximizing the protection of your personal data in compliance with the General Data Protection Regulation (GDPR). We strictly process your data for the intended use and adhere to applicable privacy regulations. You have the right to opt-out of non-essential messages and exercise your data rights by contacting us. For essential communication and legally required purposes, opting out may not be possible. Contact us at support@summ.link or through our website for any inquiries.
3.
Company Identification & Contact
3.1
HQ
Summ.link
Nederkouter 26 0401
B-9000 Gent
Belgium.
Company registration number: BTW BE 0651.734.783
3.2
General contact
Email: support@summ.link
Website: https://summ.link/
4.
Services
We offer the following services that require the processing of personal data:
• Professional Services: Data Platforms & Operations, AI & Data Engineering, Agentic AI Solutions, Governance, Compliance & Security, Web 3.0 Data Spaces and WooCommerce Connected
5.
Website
For information about our website and its data processing practices, please refer to our Cookie Policy available on our website.
6.
Company Internal Operations
If you have any questions as a current or former employee, please contact us at people@summ.link.
7.
Data Collection
When visitors access our website, we collect and process certain data in order to improve user experience, ensure website functionality, and analyze traffic patterns. The following categories of data are collected:
7.1
Technical Information
• IP address (stored in anonymized form)
• Device details, such as browser type, operating system, and screen resolution
• Location data, derived from the IP address (city/country level)
7.2
Analytics and Tracking
We use Google Analytics 4 (GA4), Google Tag Manager, and Microsoft Clarity to monitor and analyze website traffic and visitor behavior. This includes:
• Clickstream data: pages visited, time spent on pages, navigation paths
• Session recordings and heatmaps through Microsoft Clarity to better understand user interactions
• Cookies, managed through Enzuzo, to ensure compliance with EU regulations and to allow visitors to manage their preferences
7.3
Communication & Marketing
• Newsletter sign-ups: when visitors subscribe, we collect their email address (and any optional preferences they provide)
• Contact page: when visitors contact us, we collect their name, email address, and phone number
• Social media pixels: we use tracking pixels from Facebook/Meta, LinkedIn, Twitter, and TikTok for marketing and retargeting purposes
7.4
Excluded Features
• We do not provide account creation or e-commerce services on our website
• We do not integrate WhatsApp chat widgets
7.5
Data Retention and Aggregation
• Data is retained only as long as permitted by European regulations
• After the maximum retention period, data is aggregated and anonymized for statistical and analytical purposes7.
8.
Data Usage
8.1
To Allow You to Use Our Services
• Ensure that our services function properly and securely
• Enable website functionality, including analytics, cookies, and session recordings
• Provide access to newsletters, contact forms, and other service-related features
• Support HR processes such as hiring, applicant tracking, and payroll administration
8.2
To Communicate With You
• Respond to inquiries you submit via our contact page or other channels
• Send newsletters and service updates when you have subscribed or requested them
• Send newsletters and service updates when you have subscribed or requested them
• Provide important service-related announcements and notifications
9.
Website - Tooling
To provide our services, analyze website traffic, and support communication, we use several third-party tools. These tools fall into different categories depending on their purpose.
9.1
Analytics & Tracking
• Google Analytics 4 (GA4) We use Google Analytics to collect information about your interactions with our website, such as the pages you visit, the time spent on each page, and the referring website. This helps us analyze website traffic and improve our website's functionality and user experience. Google Analytics may collect and process your IP address and other browsing data. Please refer to Google's Privacy Policy for more information on how Google Analytics handles your data.
• Google Tag Manager (GTM) We utilize Google Tag Manager to manage and deploy tags on our website. These tags are used to track user interactions, website analytics, and marketing campaigns. GTM does not collect personally identifiable information (PII) and operates in accordance with Google's Privacy Policy.
• Microsoft Clarity We employ Microsoft Clarity to gain insights into user behavior and improve website performance. Microsoft Clarity may record and analyze actions and interactions on our website, including mouse movements, clicks, scrolling, and non-personally identifiable information. Refer to Microsoft's Privacy Policy for further details on how Microsoft Clarity handles your data.
• Semrush We use Semrush to monitor website performance, track search engine optimization (SEO) metrics, and analyze online visibility. This helps us optimize our digital presence and improve discoverability.
9.2
Marketing & Communication
• Brevo We use Brevo to manage and send newsletters, email campaigns, and other communications to our subscribers. This includes storing email addresses and communication preferences.
• Wistia Wistia is used for hosting and delivering video content on our website. Wistia may collect viewing statistics (e.g., which videos are played, duration of viewing) to help us improve video content and engagement.
• YouTube We link to our podcast channel hosted on YouTube. YouTube may collect viewing data, engagement metrics, and usage statistics when you interact with our content. Please see YouTube’s Privacy Policy for details on how data is handled.
• Social Media Pixels (Meta/Facebook, LinkedIn, X/Twitter, TikTok) We employ social media tracking pixels to deliver targeted advertisements and measure the effectiveness of our campaigns. These pixels may track interactions with our website and link them to your social media profiles.
9.3
Privacy & Compliance
• Enzuzo We use Enzuzo to manage cookies and consent preferences in compliance with European privacy regulations. Visitors can adjust their cookie settings and exercise privacy rights through this tool.
9.4
Recruitment & HR
• Greenhouse Greenhouse is used to manage our hiring processes. This includes applicant tracking, storing CVs, and processing candidate information necessary for recruitment and talent management.
9.5
Website Development & Hosting
Framer
Our website is built and hosted using Framer. This platform provides the technical infrastructure for delivering content to visitors. Framer may collect basic usage and performance data to ensure website availability and reliability
10.
Legal Basis for the Processing of Your Data
We process your personal data in strict accordance with applicable European privacy legislation, including the General Data Protection Regulation (GDPR), and on the basis of the following legal grounds:
Performance of the agreement
We process certain personal data to provide you with access to and allow you to use our services. For example, when you contact us via our contact form, we use your details (such as name, email address, and phone number) to respond to your inquiry.
Legal obligation
In some cases, we are legally required to retain and process specific data, such as administrative records for accounting and tax compliance.
Legitimate interest
We may process data such as anonymized IP addresses, device information, and clickstream data to ensure the security and proper functioning of our website, to analyze website usage, and to improve our services. If you are an existing customer or in an established professional relationship with us, we may also send you information about our services on the basis of our legitimate interest, unless you object or unsubscribe.
Consent
For specific data processing activities, we will only act based on your consent. This includes, for example, the use of certain cookies and similar tracking technologies (via Google Analytics, Microsoft Clarity, or social media pixels), and sending you newsletters if you sign up for them. You may withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
11.
Data Sharing
We take your privacy seriously and only share personal data under specific, necessary circumstances.
11.1
Internal Sharing
• Within Summ.link, access to personal data is limited to the teams and individuals who require it to perform their specific duties.
• This ensures that employees, HR, accounting, or project teams only see data relevant to their department or role.
11.2
Sharing with Clients
• In certain cases, client projects may require specific personal data for operational purposes.
• This may include email address, mobile number, date of birth, address, birth location, and identification documents.
• Data is shared only when necessary and in compliance with privacy regulations.
11.3
Sharing with Service Providers
When you are hired or engage in our services, we may share data with trusted service providers to support HR, payroll, mobility, and healthcare:
• Besox – payroll provider, to process salary payments and related HR administration
• Mbrella – mobility planning service, to assist with transportation-related services
• Officient – HCM (Human Capital Management) tool, to streamline HR processes and employee management
• Alan – healthcare planning service provider, to offer healthcare-related benefits and support
11.4
Analytics & Reporting
• We may share anonymized or aggregated data with analytics and marketing platforms (e.g., Google Analytics, Microsoft Clarity, Semrush) for reporting and website performance analysis.
• Individual-level personal data is never shared externally for analytics purposes.
11.5
Legal & Regulatory Requests
• Personal data may only be disclosed to government authorities upon their request and after consent from the individual concerned (visitor, employee, or freelancer), unless otherwise required by law.
11.6
Cross-Border Transfers
• All external partners and service providers operate within the European Union, ensuring compliance with EU data protection laws.
11.7
Purpose Limitation
• Data is shared only for operational purposes such as payroll, HR management, client project execution, analytics, or legal compliance.
• Personal data is never used for unrelated marketing or commercial purposes without explicit consent.
12.
Security Measures
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures are in line with the recommendations of the General Data Protection Regulation (GDPR) and ISO 27001 standards.
13.
Your Rights
You have the following rights regarding your personal data:
• Right to access: You can request access to the personal data we hold about you.
• Right to rectification: You can request the correction or update of your personal data if it is inaccurate or incomplete.
• Right to erasure: You can request the deletion of your personal data under certain circumstances.
• Right to restrict processing: You can request the restriction of processing your personal data under certain circumstances.
• Right to data portability: You can request a copy of your personal data in a structured, commonly used, and machine-readable format.
• Right to object: You can object to the processing of your personal data under certain circumstances, such as for direct marketing purposes.
• Right to withdraw consent: If we process your personal data based on your consent, you have the right to withdraw your consent at any time.
To exercise your rights or for any privacy-related inquiries, please contact us at privacy@summ.link.
14.
Changes to the Policy
We may update this Data Protection Policy from time to time. The latest version will be published on our website, and any substantial changes will be communicated to you
15.
Your Right to Submit a Complaint regarding Data Usage
We value your trust and take your data privacy seriously. If you believe that we have mishandled your data in any way, we encourage you to bring your concerns to our attention. By informing us of your objections, we can thoroughly investigate the matter and take appropriate steps to address and resolve any issues that may arise.
In addition to contacting us directly, you also have the right to lodge a complaint with the relevant data protection authorities. The following bodies can receive and assess complaints related to data protection:
• De Gegevensbeschermingsautoriteit (BE)
• De Autoriteit Persoonsgegevens (NL)
• Der Bundesbeauftragte für den Datenschutz (DE)
• CNIL, La Commission Nationale de l'Informatique et des Libertés (FR)
• La Commission nationale pour la protection des données (LU)
• Garante per la Protezione dei Dati Personali (IT)
• The Information Commissioner's Office (UK)
These authorities are responsible for safeguarding data protection rights and ensuring compliance with relevant regulations in their respective jurisdictions. Please note that we strive to address any concerns internally and resolve them to your satisfaction. However, should you choose to escalate the matter to a data protection authority, we respect your right to do so and will cooperate fully during any investigation.
It is important to us that your data is handled in accordance with applicable laws and regulations, and we appreciate your feedback and engagement in helping us maintain a high standard of data protection.
16.
Compliance with Data Protection Legislation
Our commitment to protecting your data is in accordance with the relevant "Data Protection Regulations," which encompass international, European (such as GDPR), and national legislation, as well as binding recommendations and regulations issued by privacy authorities. To ensure transparency and alignment with evolving privacy requirements, we reserve the right to update this Data Protection Policy periodically. Any changes will be reflected in a new version posted on our website. We strongly encourage you to regularly review this page to stay informed about any modifications. In the event of significant changes to this policy that may impact your rights or how we handle your data, we will notify you through postings on our website or, where applicable, by directly contacting prospects and customers. Additionally, we maintain an archive of previous policy versions, which you can access by contacting us. By adhering to applicable data protection legislation and keeping you informed of any policy updates, we aim to maintain the highest standards of privacy protection and ensure our practices align with your expectations.