KoraLytics · GDPR
GDPR compliance
Last updated: 7 April 2026
This document sets out in full how KoraLytics complies with the General Data Protection Regulation (EU) 2016/679 and the Belgian law of 30 July 2018. It is addressed to data subjects, partner institutions and any supervisory authority.
Table of contents
1. Data controller
Entity : KoraLytics — a service of KINETIC DEV SRL
Company no. : 1034.345.048 — VAT: BE 1034.345.048 — Peppol: 0208:1034345048
Registered office : Brussels, Belgium
DPO / privacy contact : support@koralytics.be
KoraLytics acts as data controller within the meaning of article 4(7) of the GDPR for all the processing described in this document. It alone determines the purposes and means of processing, except for operations entrusted to processors acting in its name and on its behalf.
2. Record of processing activities
In accordance with article 30 of the GDPR, KoraLytics keeps an internal record of its processing activities. The main processing operations are summarised below:
Diaspora profile collection
Purpose
Statistical and analytical mapping of the skilled African diaspora for collective intelligence purposes
Data processed
Socio-demographic data (age, gender, country of origin and residence, sector, education, income, involvement); optional data (CV, profile photo)
Legal basis
Explicit and informed consent (art. 6.1.a) — double opt-in with timestamped record
Retention period
30 days in identifiable form, then irreversible anonymisation and indefinite retention in aggregated form
Recipients
Internal team; technical processors (Neon DB, Vercel) under a DPA
Transfers outside the EU
Data hosted in the EU (Frankfurt). Vercel access from the USA covered by SCC
Draft management
Purpose
Allowing the form to be resumed while being filled in
Data processed
Partial form data, last name, resume code, optional email address
Legal basis
Legitimate interest (art. 6.1.f) — feature necessary to the user experience
Retention period
30 days, then automatic deletion
Recipients
Internal team; Neon DB
Transfers outside the EU
EU only
Sending transactional emails
Purpose
Sending the form resume code and the profile management link
Data processed
Email address, last name, secure access token
Legal basis
Performance of a pre-contractual measure / consent (art. 6.1.b and 6.1.a)
Retention period
Resend logs kept for 30 days
Recipients
Resend Inc. (email processor, DPA signed)
Transfers outside the EU
Transfer to the USA covered by SCC
Institutional contact form
Purpose
Handling requests from institutions, embassies or research bodies
Data processed
Name, organisation, role, professional email address, message
Legal basis
Consent (art. 6.1.a) — explicit confirmation checkbox
Retention period
12 months from the last interaction
Recipients
KoraLytics sales team; Resend Inc.
Transfers outside the EU
Transfer to the USA covered by SCC
Anonymised audience statistics
Purpose
Measuring traffic and continuously improving the service
Data processed
Truncated IP address, pages visited, session duration, device and browser type
Legal basis
Consent (art. 6.1.a) — collected through the cookie consent banner
Retention period
13 months maximum
Recipients
Internal analytics tool; no third-party sharing
Transfers outside the EU
Data processed in the EU
3. Detailed legal bases
Consent — art. 6.1.a
The main legal basis for profile collection. Consent is obtained granularly (a separate checkbox for each purpose), freely given, specific, informed and unambiguous. It is recorded with a timestamp and the form version. It can be withdrawn at any time without affecting earlier processing.
Legitimate interest — art. 6.1.f
Used for draft management and securing the service. A balancing test was carried out: the interest of KoraLytics in ensuring continuity of navigation is proportionate, the data processed is minimal and the impact on privacy is limited. Individuals retain an effective right to object.
Legal obligation — art. 6.1.c
KoraLytics may be required to disclose personal data to the competent authorities upon judicial or administrative request, strictly within the limits provided by law.
4. How data is collected and data minimisation
KoraLytics applies the principle of data minimisation (art. 5.1.c GDPR):
- Only data strictly necessary for the stated purposes is collected.
- Sensitive fields (CV, photo) are optional and clearly identified as such.
- Uploaded files (CV, photo) are base64-encoded, stored in the database and never publicly exposed.
- The IP address is collected solely for fraud detection and truncated for analytics purposes.
- No biometric, genetic, health or sexual orientation data is collected.
- The form follows the Privacy by Design principle: each step tells the user the nature and use of the data requested.
5. Processors and international transfers
In accordance with article 28 of the GDPR, every processor with access to personal data is bound by a Data Processing Agreement (DPA) meeting GDPR requirements.
| Processor | Role | Location | Safeguards |
|---|---|---|---|
| Vercel Inc. | Web hosting & deployment | USA (with EU edge) | European Commission SCC, DPA available |
| Neon Inc. | Serverless PostgreSQL database | EU — Frankfurt (AWS eu-central-1) | EU hosting, DPA available |
| Resend Inc. | Transactional emails | USA | European Commission SCC, DPA available |
| GitHub Inc. | Source code management (private repository) | USA | European Commission SCC |
No identifiable personal data is shared with client institutions or partners. Analyses and reports produced for third parties are based exclusively on aggregated and anonymised data.
6. Technical and organisational security measures
In accordance with article 32 of the GDPR, KoraLytics has put the following measures in place:
Encryption
- ▸TLS 1.3 for all transfers in transit
- ▸Encryption at rest of the database (AES-256)
- ▸Access tokens generated with cryptographically secure UUID v4
Access control
- ▸Database access restricted by IP and credentials
- ▸Administration interface protected by Basic Auth (staging only)
- ▸Strict separation between staging and production
Data integrity
- ▸Automatic daily backups (Neon point-in-time recovery)
- ▸Logging of sensitive operations (admin access, deletions)
- ▸Soft delete for profiles — no immediate physical deletion
Organisation
- ▸Data access limited to what is strictly necessary (least privilege principle)
- ▸Team training on GDPR good practice
- ▸Documented incident response procedure
7. Rights of data subjects — how to exercise them
In accordance with articles 15 to 22 of the GDPR, you have the following rights. Any request should be sent to support@koralytics.be — we will reply within a maximum of 30 days (extendable to 3 months for complex requests, with notification within 30 days).
Access (art. 15)
Obtain confirmation that data concerning you is being processed and, if so, obtain a copy in a readable format along with information about the processing.
Rectification (art. 16)
Correct inaccurate or incomplete data concerning you. You can edit your profile directly through your personal management link.
Erasure (art. 17)
Request the deletion of your data when it is no longer necessary, when you withdraw your consent, or when you object to the processing. For profiles, deletion is carried out within 72 hours of the request (soft delete then permanent purge within 30 days).
Restriction (art. 18)
Request that your data be kept but no longer actively processed, in particular while the accuracy of the data is verified or an objection is examined.
Portability (art. 20)
Receive your data in a structured, commonly used, machine-readable format (JSON) and transmit it to another controller. This right applies to data processed on the basis of consent or a contract.
Objection (art. 21)
Object at any time to processing based on legitimate interest or for profiling purposes. KoraLytics will stop the processing unless there are compelling legitimate grounds.
Withdrawal of consent
Withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal. Withdrawal can be exercised directly from your profile or by email.
Automated decision-making (art. 22)
KoraLytics carries out no automated decision-making and no profiling producing legal effects or significantly affecting data subjects.
8. Handling of personal data breaches
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, KoraLytics undertakes to:
- Detect and contain the incident as quickly as possible using access logs and security alerts.
- Notify the Belgian Data Protection Authority (APD) within 72 hours of becoming aware of the breach, in accordance with article 33 of the GDPR.
- Inform the data subjects without undue delay if the breach is likely to result in a high risk to their rights and freedoms (art. 34 GDPR), with a clear description of the nature of the breach, the data involved and the remediation measures taken.
- Document the incident in the internal breach register, regardless of the notification obligation.
9. Protection of minors
The KoraLytics service is intended exclusively for people aged 16 or over. By submitting a profile, you declare that you have reached this age. KoraLytics does not knowingly collect personal data relating to minors under 16. If you become aware of such collection, please contact us immediately at support@koralytics.be so that we can delete the data concerned.
10. Data protection impact assessment (DPIA)
In accordance with article 35 of the GDPR, KoraLytics has carried out a Data Protection Impact Assessment (DPIA) for the collection of diaspora profiles, on the grounds that this processing involves large-scale socio-demographic data liable to indirectly reveal the ethnic or national origin of participants.
Systematic description
Voluntary collection of around 70 socio-professional fields through a secure form, storage in an encrypted database, anonymisation before analysis.
Assessment of necessity and proportionality
The data collected is strictly necessary for the mapping purpose. The granularity of the fields is justified by the analytical richness required to produce diaspora intelligence institutions can act on.
Risks identified
Potential re-identification from rare combinations of data, unauthorised access to the database, data leakage during transfers.
Mitigation measures
Irreversible anonymisation after 30 days, end-to-end encryption, restricted access, no publication of individual data, k-anonymity applied in analyses.
Conclusion
Processing may continue; the residual risks are acceptable given the technical and organisational measures in place. The DPIA will be updated annually or whenever the processing changes substantially.
11. Competent supervisory authority
As an entity established in Belgium, KoraLytics is subject to the supervision of the Belgian Data Protection Authority (APD), lead authority within the meaning of the GDPR one-stop-shop mechanism.
Data Protection Authority
Rue de la Presse 35, 1000 Brussels, Belgium
Tel.: +32 (0)2 274 48 00
You may also lodge a complaint with the data protection authority of your member state of habitual residence or work.
Contact — Data protection officer
For any question about the GDPR compliance of KoraLytics, to exercise your rights, or to report an incident:
support@koralytics.be
Reply guaranteed within 30 calendar days.