01Legal
Privacy policy.
How Mirink collects, uses and protects your personal data, in accordance with the General Data Protection Regulation (GDPR) and Belgian law.
Last updated: 28 September 2026
Data controller
Raspberry Design SRL
Quai Henri-Borguet 1, 4032 Liège, Belgium
Company number (BCE) 0835.493.365
Contact for any data-related question: hellomirink.app
Raspberry Design SRL (hereinafter “Mirink”) is the controller of the personal data collected via the Mirink websites (mirink.app, mirink.nl, mirink.be, mirink.fr, mirink.lu, mirink.de) and the Mirink service.
Data collected
1. Mirink websites (visitors)
- Contact form: name, business email, company, e-commerce platform, profile, message.
- Newsletter: email address.
- Visit statistics: pages viewed, visit duration, traffic source, browser type, anonymised IP address. Collected via Matomo, self-hosted on our infrastructure.
2. Mirink service (customers)
- User account: name, email, password (encrypted), company information.
- Billing data: billing address, VAT number, payment history. Payment processing is delegated to Stripe.
- Technical data: activity logs, API requests, connector metadata.
- Supplier API keys (BYOK model): the API keys you entrust to us are encrypted at rest and used solely to execute the requests you ask us to send to your suppliers.
Purposes and legal bases
- Responding to your requests (contact form). Legal basis: legitimate interest or pre-contractual measures.
- Sending you our newsletter. Legal basis: consent (which may be withdrawn at any time).
- Providing the Mirink service (account, access, execution of requests). Legal basis: performance of the contract.
- Invoicing and collecting payments. Legal basis: performance of the contract and legal obligations (accounting, VAT).
- Improving the service and the website (statistics). Legal basis: legitimate interest.
- Complying with our legal obligations (retention of accounting records, fraud prevention). Legal basis: legal obligation.
Recipients and processors
Your data is never sold. It is accessible only to those members of the Raspberry Design SRL team who strictly need it to operate the service, and is shared with the following processors:
- P4X SA (Belgium): hosting of the website, the application and customer data.
- Stripe Payments Europe Ltd (Ireland): payment processing. Stripe is the controller for the data it collects directly.
- Intuition Machines, Inc. — hCaptcha (United States): anti-bot protection of the contact and newsletter forms. The service is only loaded once you start filling in a form; it processes your IP address and technical data from your browser, and may set a technical cookie required for this check.
All operational data is hosted in Belgium. Any transfers outside the European Union (notably via Stripe and hCaptcha) are governed by the mechanisms provided for by the GDPR (standard contractual clauses).
Cookies and trackers
The Mirink websites use Matomo Analytics, self-hosted on our infrastructure and configured to meet the Belgian Data Protection Authority's criteria for exemption from prior consent: anonymised IP addresses, no sharing with third parties, no advertising profiling, no cross-site tracking. No advertising or social media cookies are set.
The only cookies used are those strictly necessary for the website to function (session, technical preferences) or for purely statistical audience measurement.
Retention periods
- Contact requests: 3 years from the last exchange.
- Newsletter: until you unsubscribe.
- Customer accounts: for the entire duration of the contract, then 1 year after termination (subject to legal obligations).
- Billing data: 7 years (Belgian accounting obligation).
- Visit statistics: 13 months maximum.
- Technical logs: 12 months maximum.
Your rights
In accordance with the GDPR, you have the following rights regarding your data:
- Right of access and to obtain a copy
- Right to rectification
- Right to erasure (“right to be forgotten”)
- Right to restriction of processing
- Right to portability of your data
- Right to object to processing
- Right to withdraw your consent at any time, where processing is based on consent
- Right to set post-mortem instructions regarding your data
To exercise these rights, write to us at hellomirink.app. We respond within 30 days at most.
Security
We implement reasonable technical and organisational measures to protect your data: encryption in transit (TLS) and at rest for sensitive data (API keys in particular), access control, regular backups, logging. In the event of a data breach likely to result in a risk to your rights and freedoms, we will notify the Autorité de Protection des Données (Data Protection Authority) within 72 hours and, where applicable, the individuals concerned.
Data protection officer
Given the size of Raspberry Design SRL and the nature of the processing, no data protection officer (DPO) has been appointed to date. Any request concerning your data may be sent directly to hellomirink.app.
Complaints
If you believe your rights are not being respected, you may lodge a complaint with the Belgian Data Protection Authority:
Autorité de Protection des Données (Data Protection Authority)
Rue de la Presse 35, 1000 Bruxelles
www.autoriteprotectiondonnees.be
Changes
This policy may be updated to reflect changes to the service or to the legal framework. The date of the last update appears at the top of this page. If you are a customer of the service, substantial changes will be notified to you by email.