Legal
Privacy Policy
IsoMod ("we", "us", or "our") is committed to protecting the personal data of our customers and their users. This Privacy Policy explains what data we collect when you use the IsoMod platform, how we use it, and the rights you have over it. It applies to all services operated at isomod.be and any associated mobile or desktop applications.
1. Data We Collect
We collect the following categories of data depending on how you use the platform:
- Account data: name, email address, job title, and hashed password when you create a user account.
- Work order and operational data: work orders, checklists, time entries, service requests, parts, maintenance records, and any attachments or notes you create within the platform.
- Equipment and asset data: asset details, serial numbers, calibration records, and compliance documents uploaded by your organisation.
- Location data: GPS coordinates captured by the mobile application when technicians check in or complete field assignments, if location permission is granted on the device.
- Device and usage data: browser type, operating system, IP address, pages visited, and interaction events (clicks, form submissions) collected for analytics and security purposes.
- Communications: messages sent to our support team and any feedback you submit through the platform.
2. How We Use Your Data
- Service delivery: to operate the IsoMod platform, process work orders, generate reports, and send notifications.
- Compliance tracking: to support ISO 9001 and related quality management workflows, including CAPA, internal audits, and document control.
- Analytics: aggregated, anonymised usage statistics to improve the product and identify performance issues.
- Security: to detect and prevent unauthorised access, fraud, and abuse.
- Legal obligations: to comply with applicable laws, regulations, and lawful requests from public authorities.
We do not sell your personal data to third parties. We do not use your data for advertising purposes.
3. Data Storage and Security
All data is stored in the European Union. Your data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. We apply role-based access controls, automated backups, and regular security reviews.
While we implement industry-standard safeguards, no system is completely immune to risk. We will notify affected users and the relevant supervisory authority in the event of a data breach, as required by GDPR Article 33.
4. Data Retention
We retain your data for as long as your account is active or as needed to provide services. After contract termination:
- Operational data (work orders, records) is retained for 30 days following contract end, then securely deleted.
- Audit logs are retained for 7 years to satisfy legal and regulatory requirements.
- Anonymised aggregate statistics may be retained indefinitely.
You may request earlier deletion of personal data by contacting us (see Section 7).
5. Your Rights (GDPR)
If you are located in the European Economic Area, you have the following rights under the GDPR:
- Right of access: obtain a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): request deletion of your personal data, subject to legal retention obligations.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to restriction: request that we limit the processing of your data in certain circumstances.
- Right to object: object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
6. Cookies
We use strictly necessary session cookies to keep you logged in and to protect against cross-site request forgery. We use functional cookies to remember your preferences (language, theme). We use analytics cookies to collect anonymised usage data.
We do not use advertising or tracking cookies. You may disable non-essential cookies in your browser settings at any time; doing so will not prevent you from using the core functionality of the platform.
7. Contact
For privacy-related questions, requests, or complaints, please contact our data privacy team:
IsoModEmail: [email protected]
You also have the right to lodge a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be).
8. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify users via email or a prominent in-app notice at least 14 days before the changes take effect. The current version is always available at /privacy.