Legal document · Last updated : 12 July 2026
Privacy Policy
This policy explains how Aydera collects, uses and protects your personal data when you use our services (website, family app, professional app, institution app). It complies with the General Data Protection Regulation (GDPR, EU 2016/679) and the Belgian law of 30 July 2018.
1. Data controller
Aydera, established at Belgium, is the controller of your personal data. For any question about this policy or to exercise your rights, contact our Data Protection Officer (DPO): dpo@aydera.be.
2. Data we collect
Depending on your profile and use of the service, we process the following categories:
3. Purposes and legal bases
- Providing the service (matching family/institution ↔ professional, scheduling interventions, messaging). Legal basis: performance of a contract (Art. 6.1.b GDPR).
- Care follow-up and beneficiaries' health data (mobility, communication notes, intervention reports). Legal basis: Art. 9.2.h GDPR (medico-social care), processed under a duty of confidentiality with access restricted to the family/institution's advisor and the assigned professional.
- Identity and qualification verification of professionals, including checking for convictions incompatible with the role (criminal record extract model 2). Legal basis: legal obligation and legitimate interest (Art. 6.1.c and 6.1.f); processing of data relating to criminal convictions (Art. 10 GDPR) is strictly limited to this verification, required to practice a profession involving vulnerable people.
- Invoicing and accounting obligations. Legal basis: legal obligation (Art. 6.1.c GDPR; Belgian VAT Code, 7-year retention).
- Security and fraud prevention (audit logs, abuse detection). Legal basis: legitimate interest.
- Transactional communications (registration confirmation, email verification link, password recovery, payment confirmation, intervention reminders). Legal basis: performance of a contract.
- Marketing communications (newsletters, tips). Legal basis: consent (Art. 6.1.a), revocable at any time via the unsubscribe link in every email.
4. Recipients and processors
Your data is never sold. It may be shared with the following recipients, each accessing only the data necessary for their task:
- Railway (application and database hosting, European Union) and Cloudflare R2 (storage of uploaded files — photos, supporting documents, European Union): technical infrastructure.
- Netlify (hosting of the web applications — showcase site and family/pro/institution/admin apps), European infrastructure.
- Mollie (payments, Netherlands): creation and execution of SEPA mandates and card payments.
- Resend (transactional email delivery, Ireland): verification emails, invoices, confirmations.
- Spryng (SMS delivery, Netherlands): phone number verification codes and reminders.
- Geoapify (geocoding, Germany): resolving postal addresses into coordinates for geographic matching.
- Third-party transport partners (e.g. Family Cabs), for mobile assistance assignments entrusted to an external partner rather than an Aydera professional: only the information necessary for the trip (pick-up and drop-off addresses, time slot, information useful for the beneficiary's care) is shared with them. This partner may apply its own terms for the portion of the trip it carries out.
- Google Workspace: our team's internal professional email (@aydera.be domain) — your exchanges with your advisor or our support may go through this tool.
- Cloudflare (DNS only): domain name resolution. No personal user data is hosted at Cloudflare in this capacity.
- Google / Apple (where applicable): authentication if you use these sign-in methods.
Your data may also be disclosed to Belgian or European authorities where we are legally required to do so (tax authorities, courts, AViQ/PHARE for accreditation agreements).
5. Transfers outside the EU
Our hosting policy is European Union only: the application, the database, uploaded files and email delivery are all hosted in Europe.
Only Google and Apple, if you choose to sign in with these providers, may process your data in the United States as part of authentication. This transfer is governed by the European Commission's standard contractual clauses and/or the EU–US Data Privacy Framework.
6. Retention periods
- Active account: for as long as the account exists.
- Deleted account: immediate erasure of personally identifying data (anonymisation), within a maximum of 30 days following the request.
- Invoices and accounting documents: 7 years after issuance (Belgian legal obligation).
- Intervention reports: legal retention period applicable to the type of care (generally 10 to 30 years), in a form dissociated from your identity after account deletion.
- Technical audit logs: 12 months.
- Active sessions: 30 days of inactivity before automatic expiry.
7. Your rights
In accordance with the GDPR, you have the following rights:
- Right of access (Art. 15): obtain a copy of your data.
- Right to rectification (Art. 16): correct inaccurate data.
- Right to erasure (Art. 17): request deletion of your account.
- Right to restriction (Art. 18): temporarily restrict processing.
- Right to data portability (Art. 20): retrieve your data in a structured format (JSON).
- Right to object (Art. 21): object to certain processing (in particular marketing).
- Right to withdraw your consent at any time, where processing is based on consent.
To exercise these rights, write to our DPO: dpo@aydera.be. You can also request deletion of your account directly from your personal space (Profile → Preferences → Privacy).
If you believe your rights are not being respected, you may lodge a complaint with the Belgian Data Protection Authority (APD/GBA): www.autoriteprotectiondonnees.be.
8. Security and enhanced protection of health data
We implement technical and organisational measures to protect your data: encryption of communications (TLS), password hashing (bcrypt), environment isolation, audit logs, regular encrypted backups.
Beneficiaries' health data (mobility, communication notes, intervention reports) is subject to enhanced access control: only the family/institution's advisor and the professional assigned to the relevant mission may view it. Access by Aydera staff is logged and restricted according to their authorisation level.
9. Cookies and trackers
We only use cookies strictly necessary for the operation of the service (authentication session, language preferences). No advertising or third-party audience-measurement cookie is set without your explicit consent. You can configure your browser to refuse all cookies, but some features (in particular sign-in) will no longer work.
10. Minors
The Aydera service is not intended for people under 16 as account holders. Minor beneficiaries are represented by their parents or legal guardians, who create and manage the account and data on their behalf.
11. Changes
This policy may be updated to reflect legal or technical developments. The date of the last update is shown at the top of the document. Substantial changes will be notified to you by email before they take effect.
12. Contact
Data Protection Officer: dpo@aydera.be
General support: support@aydera.be