Services Privacy Policy

EXATOM through its digital platform optimizes the performance of (data collection) forms on websites of its customers. This services privacy policy describes the data EXATOM collects through the EXATOM platform when providing such services to its customers and how such data is handled by EXATOM.
1. Data collection by EXATOM

EXATOM’s customers add two small pieces of code (tags) to the source code of the pages of their website. These tags transmit certain data which allow EXATOM to detect if forms are on the pages, to detect your activity in relation to these forms, to show you certain widgets when you interact with the forms and to track submissions of the forms or other successful actions on the website. EXATOM will never use the tags to access any content you fill in on the form.

To distinguish between your activities and those of others on the customer website, EXATOM needs a temporary identifier that is unique to you and to which EXATOM can attach anonymous data provided through the EXATOM tag. EXATOM creates such an identifier as follows: EXATOM joins the EXATOM customer-code, your user agent (specification of your internet browser), your IP address and the date of your visit into one long string of text which is than transformed (hashed) through the irreversible cryptographic SHA-256 algorithm into a fixed-size code (hash).

By using the date in the hash, EXATOM is unable to link your activities on the customer website across multiple days. EXATOM can also not link your activity on websites of different customers as the customer-code is used to create the hash.

The IP address is a number that is assigned to your device by your Internet Service Provider and is automatically provided to EXATOM whenever an EXATOM tag on the customer website establishes a connection with the EXATOM servers. In the current state of the internet, IP addresses allow devices and servers to recognize and communicate with one another.
Other than the IP address and the EXATOM hash which may qualify as personal data in certain jurisdictions (‘personal data’), EXATOM does not collect any personal data on you when providing services to its customers.

Anonymous data provided to EXATOM through the EXATOM tags on the customer website will be used to provide the services to the customer and will be deleted after 90 days.

EXATOM does not use any cookies or other persistent storage technologies to uniquely identify you on the customer website or to otherwise collect your personal data. You can learn more about our ‘privacy by design’ approach in our data journey.

2. EXATOM’s use of your personal data

EXATOM uses your personal data for the following specific purposes:
(a) your IP address is used to create the EXATOM hash and to determine your country and geographical region (not your precise location).
(b) the EXATOM hash is used to detect your activity in relation to the forms on the customer website, to show you certain widgets when you interact with the forms and to track your submission of a form or other successful actions on the customer website.
(c) if the availability or security of the EXATOM digital platform is endangered (eg. by DOS attacks), we may also use your IP address for the limited purpose of protecting our platform against such threats or to investigate such threats.

Personal data is processed by EXATOM on the basis of the legitimate interests of EXATOM and its customer. Such use will not affect your interests or fundamental rights and freedoms which would require protection of personal data.

EXATOM only collects data that is strictly needed, adequate and relevant in relation to the purposes listed above. Learn more about how EXATOM applies data minimization in our data journey.

3. EXATOM’s transfer of your data to third party recipients and third countries

EXATOM may disclose your personal data to the following recipients:
(a) EXATOM’s third party service providers who provide services such as hosting and other IT services
(b) while EXATOM does not routinely share your personal data with the EXATOM customer whose website you are visiting, such customer may request access to such data to verify EXATOM’s compliance with applicable privacy laws
(c) a third party in the event of any merger, sale or transfer or other disposition of all or substantially all of EXATOM’s business
(d) a third party as permitted by applicable law, to comply with legal procedures, to respond to requests from public authorities, to enforce EXATOM’s Terms of Use and Privacy Policy and to protect EXATOM’s rights

These recipients may be located in the European Economic Area or in third countries. Any transfer of your data to a recipient in a third country will be made in full compliance with the applicable privacy laws.

The transfers to any recipient will only relate to personal data which is adequate, relevant and limited to what is necessary in relation to the purpose for which it is transferred to such third party.

Other than as outlined above, EXATOM will not transfer your personal data to any third party without your explicit consent.

4. Security, reliability and retention

EXATOM has implemented appropriate technical and organizational measures and integrated the necessary safeguards to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to your personal data and against all other unlawful forms of processing.

EXATOM takes reasonable steps to ensure that your personal data in its possession is accurate, complete, current and reliable for its intended use.

EXATOM will erase your personal data no later than 24 hours after receipt. If you visit an EXATOM customer website on different days, your personal data will be deleted within 24 hours after the end of each such visit. As an exception to the foregoing, EXATOM may store your IP address for up to 7 days for the specific purpose described under section 2 (c) above.

5. Your rights

You may
a) ask EXATOM whether it processes personal data about you, for which purposes, the categories of personal data concerned, to which recipients those data have been disclosed, and the period for which those data will be stored
b) inquire with EXATOM about the appropriate safeguards relating to its transfers to third countries
c) ask EXATOM a copy of the personal data undergoing processing (including for data portability purposes) and have it rectified
d) withdraw your consent or object against the further processing on the basis of legitimate interests and request erasure of your personal data
e) request that the processing of your personal data is restricted by EXATOM
f) request not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you

Except for the purpose described under section 2 (c) above (where EXATOM qualifies as a data controller), EXATOM processes your personal data as a ‘processor’ for the customer whose website you are visiting (and who qualifies as the controller) and EXATOM will forward your request to the customer and assist the customer in responding to your requests.

In order to exercise your rights, you could send EXATOM an e-mail to privacy@exatom.io or a letter on the address below with sufficient proof of your identity. Where EXATOM qualifies at the controller, it will undertake the necessary action without undue delay and typically provide requested information within 30 days from receipt of the request. Where EXATOM qualifies at the processor, it will promptly forward your request to the relevant customer (as the controller).

EXATOM BV
Interleuvenlaan 62 bus 49
3001 Leuven
Belgium

You may also lodge a complaint with a supervisory authority in case of breach of the applicable privacy laws by EXATOM.

6. EXATOM’s coordinates

EXATOM BV
Interleuvenlaan 62 bus 49
3001 Leuven
Belgium
privacy@exatom.io

7. Amendments

EXATOM reserves the right, in its sole discretion, to amend this Services Privacy Policy at any time by posting amendments on this website.

8. Date

28/02/2022