Privacy policy

This policy explains what personal data My Intelligent Agenda collects, why, and how long we keep it — both when you request access to our product on behalf of a hospital, and once your hospital is a customer and its staff use the product day to day. It does not replace a data processing agreement (DPA); see "Two kinds of data, two roles" below for how the two relate.

1. Who we are

"My Intelligent Agenda" ("we", "us", "our") is the product name under which this rostering service is developed and operated. The service is operated by Ruben Gysemans, acting on behalf of a company in formation under Belgian law. Once the company is incorporated, its name, enterprise number and registered office will be published here.

Questions about this policy or about your personal data can be sent to [email protected].

2. Two kinds of data, two roles

Two very different kinds of personal data flow through this service, and we play a different legal role for each:

3. What we collect

3.1 When you request access

We also process a small amount of technical data automatically — your IP address and standard request metadata — to keep the form secure against automated abuse. See "Cookies" below for how that works in practice.

3.2 When your hospital uses the product

The rostering data your hospital's administrators enter and manage — staff records, schedules, shift preferences, and absences — is your hospital's data. We act as a processor for it, not a controller (see "Two kinds of data, two roles" above). Beyond ordinary application logs needed to run and secure the service, we do not separately collect personal data about your hospital's staff for our own purposes.

4. Why we process it

5. How long we keep it

6. Who we share it with

We use a small number of specialist providers ("processors") to run the service. None of them is authorized to use your data for their own marketing purposes.

7. International transfers

Hetzner's hosting is within the EU (Germany), so hosting itself involves no transfer of personal data outside the European Economic Area. Cloudflare and Postmark are US-headquartered global providers whose infrastructure may process data outside the EEA.

8. Cookies — and why there's no banner

This site does not use advertising or cross-site tracking cookies, and we haven't built a cookie-consent banner. Here's exactly why:

9. Your rights

Under GDPR you have the right to access, correct, or erase your personal data, to restrict or object to its processing, to receive a copy of it in a portable format, and to withdraw consent at any time (withdrawal does not affect processing already carried out).

If your hospital controls the data in question (see "Two kinds of data, two roles" above), please contact your hospital's own administrator first — we support your hospital in fulfilling such requests. For signup data we control directly, contact [email protected].

You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), or with the supervisory authority in your own country.

10. Changes to this policy

We may update this policy as the product or the law changes. We'll update the effective date above, and if a change is material we'll take reasonable steps to let existing customers know.

11. Governing law

This policy is governed by Belgian law. Any dispute that cannot be resolved amicably will be submitted to the competent Belgian courts, to the exclusion of any other forum.

Questions about how we handle your data? Email [email protected].