← Back to modus-ops.be Privacy Policy · v2.0 · last updated 11.05.2026

Privacy.

Short version: we only collect what we need to help you, we do not sell your data, we do not train AI models on your data, and you can request access or deletion at any time.

1. Who we are

MODUS is a brand of ZESTOLOGY BV.

For the purposes of the GDPR and the EU AI Act, we are the controller for the data you share directly with us through the website, email or calendar platform.

ZESTOLOGY BV
VAT BE 1013.413.339
Brussels, Belgium
hello@modus-ops.be

For assignments where we process personal data on your behalf, for example when building automations on your customer data, we act as processor.

In that case, we sign a separate Data Processing Agreement ("DPA") in advance, as required by article 28 GDPR.

2. What data we collect

When you contact us or book a call

We may collect:

  • your name, company name, email address and phone number, if you share it;
  • the content of your message or intake call;
  • any attachments you send, such as quotes, screenshots or process documents;
  • for paid events, billing and payment data via our payment provider.

When you are a client

We may process:

  • billing and payment data, such as VAT number, billing address and bank details;
  • access to systems needed for the assignment, such as SharePoint, n8n or CRM, preferably through your own accounts or keys in your own tenant;
  • the content of your processes, documents, emails and other materials, only to the extent needed for the agreed scope.

When you visit the website

We collect:

  • anonymised page statistics, such as visits, browser type and country level;
  • no tracking cookies, no profiles, no cross-site tracking and no advertising networks.

Cloudflare temporarily stores IP addresses for security and bot detection, for a maximum of 24 hours.

3. Why we use data — and on what legal basis

We use personal data for the following purposes:

To answer your message and follow up on quotes, based on pre-contractual relationship under article 6.1.b GDPR.

To perform the agreed assignment, based on performance of contract under article 6.1.b GDPR.

To handle billing and accounting, based on legal obligation under article 6.1.c GDPR.

To improve our website, based on legitimate interest under article 6.1.f GDPR, using aggregated data.

To secure our systems, including Cloudflare, MFA and logs, based on legitimate interest under article 6.1.f GDPR.

We do not do direct marketing without your explicit consent. We do not add you to a mailing list unless you choose to subscribe.

4. AI & LLM use

We build AI applications for clients.

For our own operations and client assignments, we use large language models and automation providers. We are explicit about what this means.

We do not train models on your data. We use business API versions, such as OpenAI Platform, Anthropic API or Azure OpenAI, where training on client data is disabled by default, or we configure explicit opt-out flags.

We do not make automated decisions about you. We do not make decisions with legal effects or similarly significant impact about you as a visitor or client within the meaning of article 22 GDPR.

If the solutions we build for your customers do automate such decisions, you are the controller and we help you with the required assessments.

Human validation remains required. LLM output may contain errors or hallucinations. For any decision with substantial impact, a human remains in the loop — with us and in the solutions we deliver.

We are EU AI Act-aware. We classify AI systems we build according to the risk levels of the EU AI Act, Regulation 2024/1689. For systems that may qualify as high-risk under Annex III, we request a joint risk analysis in advance and help with documentation and transparency obligations.

5. How long we keep data

We keep data only as long as needed.

Contact requests that do not lead to an assignment are kept for a maximum of 12 months and then deleted.

Client data is kept during the term of the contract plus 5 years, in line with the Belgian limitation period for contractual liability under article 2262bis of the Civil Code.

Accounting records are kept for 7 years, as required by article III.86 of the Belgian Code of Economic Law.

Website statistics are aggregated and kept for a maximum of 24 months.

Cloudflare security logs are kept for a maximum of 24 hours.

6. Who we share data with

We only share data with service providers needed to do our work, and only to the extent strictly necessary.

Current subprocessors and service providers:

CategoryProviderHosting / location
Email and documentsMicrosoft 365EU data centres (EU Data Boundary)
Website hostingCloudflare PagesGlobal CDN, EU edge prioritised
Calendar schedulingCal.euEU hosting
Payments (where applicable)StripeEU + US (SCCs)
LLM providers (client assignments)OpenAI, Anthropic, Google, Microsoft Azure OpenAIUS / EU (DPF + SCCs); business API, training off
Automation platformsn8n (self-hosted or cloud), Make, Power AutomateClient tenant or EU
AccountingAccounting firm in BelgiumBelgium
Belgian tax authoritiesFPS FinanceBelgium

We do not sell data, use advertising networks or share client data for commercial purposes. For any new subprocessor that gets access to client personal data, we inform the relevant client in advance.

7. Data transfers outside the EU

By default, we keep your data in the EU.

Where a specific part of an assignment requires a tool outside the EU, such as an AI provider with servers in the US, we use the legal frameworks provided by the European Commission. This may include:

  • the EU-US Data Privacy Framework for providers certified under that framework;
  • Standard Contractual Clauses, modules 2 and 3, under Decision (EU) 2021/914, where needed;
  • a transfer impact assessment for processing that is relevant to your case.

8. Your GDPR rights

Under the General Data Protection Regulation, you have the right to:

  • know what data we hold about you, right of access under article 15;
  • correct inaccurate data under article 16;
  • have your data deleted under article 17, the right to be forgotten;
  • restrict processing under article 18;
  • receive your data in a readable format, data portability under article 20;
  • object to processing based on legitimate interest under article 21;
  • withdraw consent at any time under article 7, where consent was the legal basis.

You can send a request to hello@modus-ops.be. We respond within 30 days, in line with article 12 GDPR.

If you disagree with how we handle your request, you can file a complaint with the Belgian Data Protection Authority:

Gegevensbeschermingsautoriteit / Autorité de protection des données
Drukpersstraat 35, 1000 Brussels
www.gegevensbeschermingsautoriteit.be
contact@apd-gba.be

9. Security

We secure your data using common best practices:

  • TLS encryption for all data transport;
  • MFA on all administrator accounts, including Microsoft 365, GitHub, Cloudflare and Cal.eu;
  • principle of least privilege for system access;
  • strong passwords through a password manager;
  • no local storage of client credentials;
  • keys remain with you or in secure secrets stores;
  • periodic review of access rights.

For client assignments, we work within your own tenant and with your own keys wherever possible.

We do not copy your data into our environment unless strictly necessary and unless you have given permission.

10. Data breach procedure

In the very unlikely event of a personal data breach that creates a risk to your rights and freedoms, we notify the Belgian Data Protection Authority within 72 hours after becoming aware of it, as required by article 33 GDPR.

Where the breach creates a high risk, we also notify you directly, as required by article 34 GDPR.

11. Children

Our services are directed exclusively at organisations and business users.

We do not knowingly collect data from persons under 16.

If this happens, we delete the data as soon as we become aware of it.

12. Changes to this policy

We may update this policy if our services or applicable rules change, including EU AI Act implementing measures.

The version and last-updated date at the top show when this last happened.

Substantial changes that affect your rights will be communicated by email to active clients.

13. Contact and complaints

Send your question or complaint to hello@modus-ops.be.

A real human will respond within 30 days.