Privacy policy
Effective: July 7, 2026
This policy explains what personal data My Intelligent Agenda collects, why, and how long we keep it — both when you request access to our product on behalf of a hospital, and once your hospital is a customer and its staff use the product day to day. It does not replace a data processing agreement (DPA); see "Two kinds of data, two roles" below for how the two relate.
1. Who we are
"My Intelligent Agenda" ("we", "us", "our") is the product name under which this rostering service is developed and operated. The service is operated by Ruben Gysemans, acting on behalf of a company in formation under Belgian law. Once the company is incorporated, its name, enterprise number and registered office will be published here.
Questions about this policy or about your personal data can be sent to [email protected].
2. Two kinds of data, two roles
Two very different kinds of personal data flow through this service, and we play a different legal role for each:
- Access-request data. When you or a colleague submits the signup form, we are the controller of the information submitted — we decide why and how it's processed.
- Rostering data. Once your hospital is a customer, the staff records, schedules, absences, and preferences your hospital's administrators enter belong to and are controlled by your hospital. We process that data only as a processor, on your hospital's documented instructions, under a separate data processing agreement.
3. What we collect
3.1 When you request access
- Hospital name
- Contact person's name
- Work email address
- Phone number — optional
- Preferred language (Dutch or English)
- The date and time you gave consent to be contacted (see the consent checkbox on the form)
We also process a small amount of technical data automatically — your IP address and standard request metadata — to keep the form secure against automated abuse. See "Cookies" below for how that works in practice.
3.2 When your hospital uses the product
The rostering data your hospital's administrators enter and manage — staff records, schedules, shift preferences, and absences — is your hospital's data. We act as a processor for it, not a controller (see "Two kinds of data, two roles" above). Beyond ordinary application logs needed to run and secure the service, we do not separately collect personal data about your hospital's staff for our own purposes.
4. Why we process it
- To review and respond to your access request
- To create and provision your hospital's account once a request is approved
- To send the small number of operational emails the signup process requires (a verification link, a confirmation)
- To keep the signup form and the product secure against automated abuse and fraud
- To comply with our own legal obligations, for example responding to a data-subject request
5. How long we keep it
- An access request that is never approved — rejected, withdrawn, or simply never confirmed — is deleted 12 months after the last activity on it.
- An approved request's information is kept as part of your hospital's account record for as long as the account is active.
- The record of when consent was given is kept for as long as your hospital's account is active, plus 5 years afterward, as evidence that consent was obtained.
- Rostering data is kept for as long as your hospital's account is active; see the Terms of Use for what happens when an account ends.
6. Who we share it with
We use a small number of specialist providers ("processors") to run the service. None of them is authorized to use your data for their own marketing purposes.
- Hetzner Online GmbH
- Infrastructure hosting — our servers and database run on Hetzner's infrastructure in Germany.
- Cloudflare, Inc.
- Content delivery, TLS/HTTPS, and bot/abuse protection (Turnstile) for the public site and signup form.
- Postmark
- Transactional email delivery for the verification and account emails described above.
7. International transfers
Hetzner's hosting is within the EU (Germany), so hosting itself involves no transfer of personal data outside the European Economic Area. Cloudflare and Postmark are US-headquartered global providers whose infrastructure may process data outside the EEA.
9. Your rights
Under GDPR you have the right to access, correct, or erase your personal data, to restrict or object to its processing, to receive a copy of it in a portable format, and to withdraw consent at any time (withdrawal does not affect processing already carried out).
If your hospital controls the data in question (see "Two kinds of data, two roles" above), please contact your hospital's own administrator first — we support your hospital in fulfilling such requests. For signup data we control directly, contact [email protected].
You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), or with the supervisory authority in your own country.
10. Changes to this policy
We may update this policy as the product or the law changes. We'll update the effective date above, and if a change is material we'll take reasonable steps to let existing customers know.
11. Governing law
This policy is governed by Belgian law. Any dispute that cannot be resolved amicably will be submitted to the competent Belgian courts, to the exclusion of any other forum.
Questions about how we handle your data? Email [email protected].