Privacy policy
What happens to your details when you visit this website or send us a request.
Last updated: September 2026
Who is responsible
- Controller
- Vema Projects BV
- Address
- Venecolaan 10/00029880 AALTERBelgium
- Enterprise number
- 0464.024.937
- Contact
- sales@vemaprojects.be
Write to that address for anything to do with this policy or with the details we hold about you. It reaches the people who handle enquiries, and it is the address to use for the rights described further down.
What this policy covers
This policy covers this website: the pages you are reading and the contact form on them.
It does not describe the VeMatics products themselves. Accounts in the TikWash app, VemaCard card systems, payment transactions at a terminal, and the management of an installation we have delivered are separate systems with their own arrangements, usually agreed with the operator of the site. If you use a VeMatics system as a customer of one of our clients, that operator is the first point of contact for your data.
What we process, and when
When you contact us directly
If you email or call us, we process what you choose to tell us — your name, your contact details, and the content of your message — in order to answer you.
When you use the contact form
The form asks for the following, and nothing more:
- Request type — general question, quote request or demo request
- Name
- Company — optional
- Phone — optional
- Application — optional, the kind of site the request is about
- Message
When you submit the form, that information is sent to us as an email to sales@vemaprojects.be, with your email address set as the reply address so we can answer you directly. The page also records the moment of submission and which version of the form you used (general, quote or demo). We do not add anything else to it, and the form asks for no special categories of data — please do not send us any.
Protecting the form against automated abuse
The contact form is protected by Cloudflare Turnstile, which checks whether a submission comes from a person rather than from a bot. Cloudflare documents the signals Turnstile collects for this check as your IP address, a TLS fingerprint, your browser's user-agent string, and the site key together with the website it is used on. Cloudflare states that these signals are strictly necessary for detecting and blocking bots, and that it cannot directly identify individuals from them.
Turnstile checks the browser, not the message. What you type into the form is not part of the signals Cloudflare lists for Turnstile: the form content is sent to us, and the widget returns only a token, which our server then asks Cloudflare to verify. If that verification fails, the message is not sent.
Delivering the website
This website is delivered through Cloudflare's network. To serve a page and to protect the site against attacks and abuse, Cloudflare processes connection data such as your IP address, the address you requested and your browser's user-agent string, and keeps short technical logs of requests. Our own contact handler writes a brief technical line when a message fails to send — it records the failure, not your message.
Remembering your language
If you choose a language with the language switcher, this website stores that choice in your browser as vematics_locale. It stores only the selected language code — one of en, nl or fr. It does not store a name, email address or account identifier. It is used only to open the right language when you return to the site's entry page. The cookie policy describes it in full.
What we do not do
This website carries no analytics, no advertising, no marketing pixels, no behavioural tracking, no newsletter tooling and no visitor accounts. We do not build profiles of visitors and we do not sell personal data. The cookie policy describes what is stored in your browser, which is very little.
Why we process it
- General enquiries — to answer your question and to communicate with you about the subject you raised.
- Quote requests — to assess your request, to prepare and send a quotation, and to take the steps you asked for before a possible business relationship.
- Demo requests — to arrange or respond to the demonstration you asked for and the communication around it.
- Security and abuse prevention — to protect the website and the contact form against automated abuse, spam and malicious traffic.
- Language preference — to show the website in the language you chose.
The legal basis
Which basis applies depends on the nature of your request.
- If you ask for a quotation or a demonstration, we process your details in order to take steps at your request before entering into a contract.
- If you send us a general business enquiry, we rely on our legitimate interest in answering questions that are addressed to us, and on yours in receiving an answer.
- For the spam protection on the form and for the security of the website, we rely on our legitimate interest in keeping both available and free of abuse.
- Where we have to keep something because the law requires it — an invoice, for example — the basis is that legal obligation.
We do not treat consent as the default. You are not asked to accept anything in order to send us a message; if we ever needed consent for something else, we would ask for it separately and you could withdraw it.
What you have to provide
Only the fields marked as required on the contact page are needed, and they are needed for a practical reason: without a name, an email address and a description of your request we cannot understand it or reply to it. The fields marked optional are genuinely optional — they usually help us answer more precisely, and leaving them empty does not stop your message.
There is no statutory obligation to give us any of this. You can also simply call or email us instead.
How long we keep it
We keep contact, quote and demo requests for a maximum of 24 months after the last meaningful contact about them, and then delete them.
There is an exception that matters. If your enquiry develops into a customer relationship, a contract, an invoice, a dispute or another business record, the relevant information becomes part of that record and is kept for as long as that separate purpose requires — accounting and contractual retention periods are set by law or by the nature of the record, and they are longer than 24 months. So it is not the case that everything is deleted after 24 months; it is the enquiry itself that is.
Our email provider keeps its own copy as well, on its own terms. Resend currently states that email and log data is retained for 30 days on its Free, Pro and Scale plans, and that Enterprise plans have flexible retention. Which of those applies to us follows the plan and the settings our production account ends up using; it is a separate period from the 24 months above, which is ours.
Who else processes it
We keep the number of parties involved small. Two providers process personal data on our behalf, as processors, for this website:
- Cloudflare — delivery and security of the website, and the Turnstile check on the contact form.
- Resend — delivery of the email that the contact form generates. The content of your message passes through Resend in order to reach our mailbox.
Inside our company, your request is seen by the people who handle enquiries and, if it becomes a project, by the colleagues working on it. Beyond that, we share personal data only where we are legally required to.
Where your data is processed
Both providers may process data outside the European Economic Area, and we would rather say so plainly than imply everything stays in Belgium.
Resend states that it stores customer data — including message content, delivery logs and account records — in the United States. It covers transfers out of the EEA with the European Commission's standard contractual clauses, which are part of its data processing addendum, and with its participation in the EU–U.S. Data Privacy Framework.
Cloudflare operates a global network, so the technical data involved in delivering and protecting the website may be processed outside the EEA. Cloudflare relies on the standard contractual clauses and on its certifications under the EU–U.S. Data Privacy Framework for those transfers.
Automated decision-making
We do not use the information from this website to make automated decisions that produce legal effects for you or that affect you in a similarly significant way. The Turnstile check is a security measure about the browser making the request; it is not a decision about you as a customer, and a person reads every enquiry that reaches us.
Your rights
Under the GDPR you can ask us to:
- tell you what personal data we hold about you, and give you a copy;
- correct it if it is wrong or incomplete;
- delete it;
- restrict what we do with it while something is being checked;
- stop processing it where we rely on a legitimate interest, by objecting;
- hand it over in a portable form, where that right applies.
Not every right applies in every situation — for example, we cannot delete something we are legally required to keep. If a request cannot be met in full, we will say which part and why.
Write to sales@vemaprojects.be to exercise any of these. We may ask you for enough information to be sure who you are before we act, so that we do not disclose someone else's data.
If you are not satisfied with how we handle it, you can lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données) — https://www.gegevensbeschermingsautoriteit.be. You may also contact the supervisory authority in the EU country where you live or work.
Changes to this policy
If the website starts doing something different with personal data, this page is updated before that change goes live, and the date at the top changes with it. If we ever add analytics or any other non-essential technology, we will re-check what it stores, update this policy and the cookie policy, and ask for your consent before switching it on.