Skip to content

Privacy statement

What we record about you, why, for how long, and who may see it. As short as possible, and without sentences that only a lawyer understands.

This page is a translation of the Dutch text. If the two versions differ, the Dutch version prevails. Lees de Nederlandse versie.

This is a provisional version. The final version will be published at the end of September 2026.

Who is responsible

BRIX is not an independent organisation but a collaboration. The eight consortium partners are joint controllers of the data in this portal:

  • BUas
  • Enversed
  • Fontys
  • H20 Arena
  • MindLabs
  • Tilburg University
  • TU/e

The partners have agreed among themselves who does what. That is what Article 26 of the GDPR requires, and this is a summary of it:

  • One point of contact. BRIX is your point of contact for the overarching services, and you can always come back here. Ask your question via contact.
  • Access, correction and erasure go through that same point. We give the partner concerned ten working days to cooperate, so that we can answer you within the statutory month.
  • Until assignment, it is joint. Once your request is with a lab and a track starts, that lab is itself responsible for the data in that track, and the terms of that organisation apply. What a lab delivers also goes to BRIX: the result, the case and the communication about it.
  • Service agreements with the labs. We set these up with each lab, so that it is clear who is responsible for which service.
  • You can approach any of the eight. With joint responsibility, it is not up to you as the data subject to work out who signed for what.
  • A complaint can always go to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

What we record, and why

When you request an intake

What
Your name and email address, and your phone number and organisation if you provide them. Also what you write yourself about your question, and the sector and region you work in.
Why
To contact you and to decide which lab fits your question.
Legal basis
Your consent, which you give with the tick box below the form.

I agree to the privacy statement. BRIX shares my details with the lab that fits my question, and with no one else.

When you view the site

What
Which page you view, in which language, the name of the website you came from, your country and the type of device. Your IP address and browser details are not kept: we turn them into a code using a key that is replaced every day. No cookie.
Why
To know whether people find the site and which pages work. BRIX is built with public funds, and accountability comes with that.
Legal basis
Legitimate interest. With Global Privacy Control or Do Not Track switched on, we do not count you.

When you have an account in the portal

What
Your name, your email address, and which role you have at which lab. You log in with a password you choose yourself, or with a one-time link sent to your inbox. We never see the password itself: Supabase keeps an encrypted fingerprint of it.
Why
To give you access to the data of your lab and not that of another.
Legal basis
The performance of the collaboration you take part in.

With images

What
For every photo we record who took it and who holds the rights. That is sometimes personal data — the name of a photographer.
Why
We do not publish an image without accounting for its rights. The portal is built with public funds, and we are accountable for that.

Who sees what

This is the core of the agreement between the labs, and it is arranged more strictly than you might expect.

The BRIX team
Sees all requests in full. Without an overview there is no node, and then we cannot bring you to the right lab.
The lab you are assigned to
Sees your request in full, because that lab is going to work with you.
The other consortium partners
See no name and no contact details, and not what you wrote either. They do see: the date, the sector, the region, the phase, the status, which lab got it and why. Enough to check that the distribution is fair, too little to approach someone else’s client.

How long we keep it

We keep a request for 24 months after the last contact. Not from the date of the request: a track that was dormant for a year and then picks up again should not be erased halfway.

After that, your name, email address, phone number and the description of your question are removed. What remains is anonymised — sector, region, phase, status and lead time — because we are publicly funded and account for how many questions came in and where they ended up. No one is identifiable in those figures.

We keep visit figures for 25 months. They contain no IP address, and after one day it can no longer be seen which views belonged to the same visitor.

Changed your mind? Email us and we will delete your request straight away.

Where your data is stored

On servers within the European Union. We use Supabase for the database, login and file storage — in Frankfurt — and Vercel for hosting, in the same region. Our email goes through Brevo, a French company processing within the EU: that is the party which sees your name and email address as soon as we email you. They may only use your data to make this site work.

What we do not do

  • We do not sell your data or pass it on for commercial purposes.
  • We do not track you across other websites.
  • We do not set tracking cookies — at the moment not a single cookie. See the cookie page.
  • We do not make decisions about you based on automated profiling.

Your rights

You may ask what we hold about you, have it corrected, have it deleted, or object to the processing. You may also simply withdraw your consent. Send a message via contact; we respond within a month.

If we cannot resolve it together, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Version 2026-09-2. With every request we record which version you read. If this statement changes in substance, it gets a new number, and your request keeps referring to the text as it was then.