Legal document · Last updated : 12 July 2026

Privacy Policy

This policy explains how Aydera collects, uses and protects your personal data when you use our services (website, family app, professional app, institution app). It complies with the General Data Protection Regulation (GDPR, EU 2016/679) and the Belgian law of 30 July 2018.

1. Data controller

Aydera, established at Belgium, is the controller of your personal data. For any question about this policy or to exercise your rights, contact our Data Protection Officer (DPO): dpo@aydera.be.

2. Data we collect

Depending on your profile and use of the service, we process the following categories:

Account data : email, password (hashed), phone number, preferred language, role (family / professional / institution), account creation date, last logins, social provider IDs (Google, Apple) if you use those sign-in methods.
Profile data (families) : name, first name, postal address (geolocated for matching), profile photo (optional).
Data about beneficiaries (the person being cared for) : first name, date of birth, mobility level, communication notes, dietary requirements, support categories required, address if different from the family home. This information falls under the special category of health data (Art. 9 GDPR) and benefits from enhanced protection — see §3 and §8.
Profile data (professionals) : name, first name, date of birth, profession (INAMI number where applicable), VAT / company registration number, professional address (geolocated), bio, photo, hourly rate, service area, languages spoken, uploaded documents (ID, diploma, criminal record extract model 2, professional liability insurance certificate, and — for mobile assistance — driving licence).
Profile data (institutions) : legal name, VAT number, company registration number, PEPPOL identifier, institution type, address (geolocated), billing email, AViQ/PHARE accreditation where applicable.
Operational data : assignments created (on-site or mobile assistance — in the latter case, pick-up and drop-off addresses), matching proposals, scheduled and completed interventions, intervention reports (observations, any incidents — also health data within the meaning of Art. 9 GDPR), availability, mission-related internal conversations.
Billing and payment data : invoices issued and received, SEPA mandates and card tokens (managed by our provider Mollie; we never store the full card number or CVC), direct debit history.
Technical data : IP address, browser type, session identifiers, audit logs (sensitive actions).

3. Purposes and legal bases

  • Providing the service (matching family/institution ↔ professional, scheduling interventions, messaging). Legal basis: performance of a contract (Art. 6.1.b GDPR).
  • Care follow-up and beneficiaries' health data (mobility, communication notes, intervention reports). Legal basis: Art. 9.2.h GDPR (medico-social care), processed under a duty of confidentiality with access restricted to the family/institution's advisor and the assigned professional.
  • Identity and qualification verification of professionals, including checking for convictions incompatible with the role (criminal record extract model 2). Legal basis: legal obligation and legitimate interest (Art. 6.1.c and 6.1.f); processing of data relating to criminal convictions (Art. 10 GDPR) is strictly limited to this verification, required to practice a profession involving vulnerable people.
  • Invoicing and accounting obligations. Legal basis: legal obligation (Art. 6.1.c GDPR; Belgian VAT Code, 7-year retention).
  • Security and fraud prevention (audit logs, abuse detection). Legal basis: legitimate interest.
  • Transactional communications (registration confirmation, email verification link, password recovery, payment confirmation, intervention reminders). Legal basis: performance of a contract.
  • Marketing communications (newsletters, tips). Legal basis: consent (Art. 6.1.a), revocable at any time via the unsubscribe link in every email.

4. Recipients and processors

Your data is never sold. It may be shared with the following recipients, each accessing only the data necessary for their task:

  • Railway (application and database hosting, European Union) and Cloudflare R2 (storage of uploaded files — photos, supporting documents, European Union): technical infrastructure.
  • Netlify (hosting of the web applications — showcase site and family/pro/institution/admin apps), European infrastructure.
  • Mollie (payments, Netherlands): creation and execution of SEPA mandates and card payments.
  • Resend (transactional email delivery, Ireland): verification emails, invoices, confirmations.
  • Spryng (SMS delivery, Netherlands): phone number verification codes and reminders.
  • Geoapify (geocoding, Germany): resolving postal addresses into coordinates for geographic matching.
  • Third-party transport partners (e.g. Family Cabs), for mobile assistance assignments entrusted to an external partner rather than an Aydera professional: only the information necessary for the trip (pick-up and drop-off addresses, time slot, information useful for the beneficiary's care) is shared with them. This partner may apply its own terms for the portion of the trip it carries out.
  • Google Workspace: our team's internal professional email (@aydera.be domain) — your exchanges with your advisor or our support may go through this tool.
  • Cloudflare (DNS only): domain name resolution. No personal user data is hosted at Cloudflare in this capacity.
  • Google / Apple (where applicable): authentication if you use these sign-in methods.

Your data may also be disclosed to Belgian or European authorities where we are legally required to do so (tax authorities, courts, AViQ/PHARE for accreditation agreements).

5. Transfers outside the EU

Our hosting policy is European Union only: the application, the database, uploaded files and email delivery are all hosted in Europe.

Only Google and Apple, if you choose to sign in with these providers, may process your data in the United States as part of authentication. This transfer is governed by the European Commission's standard contractual clauses and/or the EU–US Data Privacy Framework.

6. Retention periods

  • Active account: for as long as the account exists.
  • Deleted account: immediate erasure of personally identifying data (anonymisation), within a maximum of 30 days following the request.
  • Invoices and accounting documents: 7 years after issuance (Belgian legal obligation).
  • Intervention reports: legal retention period applicable to the type of care (generally 10 to 30 years), in a form dissociated from your identity after account deletion.
  • Technical audit logs: 12 months.
  • Active sessions: 30 days of inactivity before automatic expiry.

7. Your rights

In accordance with the GDPR, you have the following rights:

  • Right of access (Art. 15): obtain a copy of your data.
  • Right to rectification (Art. 16): correct inaccurate data.
  • Right to erasure (Art. 17): request deletion of your account.
  • Right to restriction (Art. 18): temporarily restrict processing.
  • Right to data portability (Art. 20): retrieve your data in a structured format (JSON).
  • Right to object (Art. 21): object to certain processing (in particular marketing).
  • Right to withdraw your consent at any time, where processing is based on consent.

To exercise these rights, write to our DPO: dpo@aydera.be. You can also request deletion of your account directly from your personal space (Profile → Preferences → Privacy).

If you believe your rights are not being respected, you may lodge a complaint with the Belgian Data Protection Authority (APD/GBA): www.autoriteprotectiondonnees.be.

8. Security and enhanced protection of health data

We implement technical and organisational measures to protect your data: encryption of communications (TLS), password hashing (bcrypt), environment isolation, audit logs, regular encrypted backups.

Beneficiaries' health data (mobility, communication notes, intervention reports) is subject to enhanced access control: only the family/institution's advisor and the professional assigned to the relevant mission may view it. Access by Aydera staff is logged and restricted according to their authorisation level.

9. Cookies and trackers

We only use cookies strictly necessary for the operation of the service (authentication session, language preferences). No advertising or third-party audience-measurement cookie is set without your explicit consent. You can configure your browser to refuse all cookies, but some features (in particular sign-in) will no longer work.

10. Minors

The Aydera service is not intended for people under 16 as account holders. Minor beneficiaries are represented by their parents or legal guardians, who create and manage the account and data on their behalf.

11. Changes

This policy may be updated to reflect legal or technical developments. The date of the last update is shown at the top of the document. Substantial changes will be notified to you by email before they take effect.

12. Contact

Data Protection Officer: dpo@aydera.be
General support: support@aydera.be

© 2026 Aydera · Legal document.