Privacy Policy
How we handle personal data on appsky.be — explained plainly.
Last updated: 7 July 2026
Who we are
This policy explains how AppSky SRL, trading as AppSky (“AppSky”, “we”), with registered office at Avenue du Roi Albert 63, 1120 Brussels, Belgium, registered with the Crossroads Bank for Enterprises under number 0766.319.202 (VAT BE 0766.319.202), processes personal data when you visit appsky.be. We are the controller for the processing described below.
We are a small studio and are not required to appoint a data protection officer. For anything related to your personal data, email hello@appsky.be — a person will answer.
What this policy covers — and what it doesn’t
This policy covers the appsky.be website only: a marketing site where you can read about our work, browse the guides and case studies, and book an introduction call. This website does not collect or process any patient or health data.
When we build software for clients, the personal data processed in those projects is governed by separate written agreements, including data processing agreements where we act as a processor. Those engagements fall outside the scope of this policy.
What we collect, why, and on what legal basis
Hosting and security (Cloudflare)
The site is served through Cloudflare’s content delivery network, including our media domain media.appsky.be (Cloudflare R2). When your browser requests a page, Cloudflare processes technical data such as your IP address, browser characteristics, and the pages requested, in order to deliver the site and protect it from abuse. Legal basis: our legitimate interest in running a fast, secure website (Article 6(1)(f) GDPR). These technical logs are kept for a short period and are not used to profile you.
Analytics (self-hosted Umami)
We measure how the site is used with Umami, a privacy-focused analytics tool that runs on our own infrastructure (umami.softwhale.be) — no data goes to an analytics vendor. Umami is cookieless: it stores nothing on your device and does not follow you across other websites. It records page views, the referring site, browser and device type, country, and clicks on buttons such as “book a call”. IP addresses are used transiently to derive an approximate location and are not stored. The result is aggregated statistics that cannot reasonably be traced back to you. Legal basis: our legitimate interest in understanding how the site performs (Article 6(1)(f) GDPR).
Marketing attribution (the appsky_vid cookie)
To know which channels bring the visitors who go on to book a call, the site sets one first-party cookie, appsky_vid, containing a randomly generated visitor ID, and stores your first and most recent arrival details in your browser’s local storage: the landing page, the referring site, campaign (UTM) parameters, and advertising click IDs (gclid, fbclid, li_fat_id, msclkid, ttclid) if you arrived through an ad. This data stays in your browser and only reaches us if you book a call (see below). The cookie expires 12 months after your most recent visit; the local storage entries remain until you delete them. Legal basis: your consent (Article 6(1)(a) GDPR), which we ask for through the cookie banner on your first visit — if you decline, nothing is stored and the site works exactly the same. You can withdraw consent at any time by removing the cookie and stored data through your browser settings.
Booking a call (Cal.com scheduling)
The booking widget on the contact page and the “book a call” links run on Cal.com scheduling software that is self-hosted for us by Softwhale at cal.softwhale.be, on infrastructure provided by Railway (EU region — Amsterdam, the Netherlands) — bookings do not pass through Cal.com’s cloud service. When you book, we process the details you enter (name, email address, anything you write in the notes), your time zone and language, and the meeting details. The attribution data described above (visitor ID, source, campaign, click IDs) is attached to the booking so we know how you found us. Legal basis: taking steps at your request before entering into a contract (Article 6(1)(b) GDPR) for the booking itself, and our legitimate interest (Article 6(1)(f) GDPR) for the attached attribution data.
If you email hello@appsky.be, we process your email address, name, and whatever you choose to write, in order to reply and follow up. Legal basis: steps prior to a possible contract (Article 6(1)(b) GDPR) where your message concerns a potential engagement, and otherwise our legitimate interest in answering correspondence (Article 6(1)(f) GDPR).
What we don’t do
- No advertising or social-media tracking pixels, and no third-party marketing cookies.
- No selling or renting of personal data — ever.
- No newsletter, user accounts, or payments on this site.
- No automated decision-making or profiling with legal or similarly significant effects.
Who receives your data
We keep the circle small:
- Cloudflare, Inc. — hosting, content delivery, and media storage (Cloudflare R2). Cloudflare serves content from data centres worldwide, including in the EU.
- Softwhale — the studio behind AppSky, which operates our analytics (Umami) and scheduling (Cal.com) systems on Railway (EU region — Amsterdam, the Netherlands).
- Professional advisers or public authorities, where the law requires it.
These parties process data on our instructions and do not use it for their own purposes.
International transfers
We aim to keep personal data within the European Economic Area. Where Cloudflare processes data outside the EEA (for example on its US infrastructure), the transfer is covered by the European Commission’s adequacy decision for the EU–US Data Privacy Framework, under which Cloudflare is certified, complemented by standard contractual clauses.
How long we keep data
- Booking and email correspondence: for the duration of our exchange and up to 3 years after our last meaningful contact, unless an engagement follows (contractual retention rules then apply) or the law requires longer.
- Attribution data: the appsky_vid cookie expires 12 months after your most recent visit; local storage entries stay until you delete them.
- Analytics: kept as aggregated usage statistics that contain no direct identifiers and cannot reasonably be linked back to you.
- Cloudflare technical logs: kept for a short rolling period for security and delivery purposes.
Your rights
Under the GDPR you can ask us for access to your data, correction, deletion, restriction of processing, and a portable copy, and you can object to any processing based on legitimate interest, and withdraw your consent to the attribution measurement described above at any time. Email hello@appsky.be; we respond within one month. We may ask you to confirm your identity before acting on a request.
If you are unhappy with how we handle your request, you can lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Rue de la Presse 35, 1000 Brussels, +32 (0)2 274 48 00, contact@apd-gba.be, www.dataprotectionauthority.be — or with the supervisory authority of your own EU member state.
Cookies and local storage in detail
The complete list of what this site stores on your device:
- appsky_vid (first-party cookie) — random visitor ID used for marketing attribution; set only if you consent via the cookie banner, and expires 12 months after your most recent visit.
- appsky:first_touch:v1 and appsky:latest_touch:v1 (local storage) — how you first and most recently arrived: landing page, referring site, campaign parameters, and ad click IDs; kept until deleted.
- appsky:visitor_id:v1 (local storage) — a copy of the visitor ID; kept until deleted.
- appsky-lang (local storage) — remembers your answer to the language suggestion banner so we don’t ask again; strictly functional.
Umami analytics sets no cookies. The booking widget on the contact page loads from cal.softwhale.be and may use strictly necessary storage of its own in order to function. You can delete all of the above at any time via your browser’s site-data settings.
Security
appsky.be is a static website served over HTTPS (TLS). We collect the minimum data needed for the purposes above, and access to the booking and analytics systems is restricted to the AppSky team and protected by authentication.
Changes to this policy
We will update this policy when the website or our tooling changes, and adjust the date at the top. Meaningful changes will be visible on this page — we won’t quietly move the goalposts.
AppSky