KoraLytics · GDPR

GDPR compliance

Last updated: 7 April 2026

This document sets out in full how KoraLytics complies with the General Data Protection Regulation (EU) 2016/679 and the Belgian law of 30 July 2018. It is addressed to data subjects, partner institutions and any supervisory authority.

1. Data controller

Entity : KoraLytics — a service of KINETIC DEV SRL

Company no. : 1034.345.048 — VAT: BE 1034.345.048 — Peppol: 0208:1034345048

Registered office : Brussels, Belgium

DPO / privacy contact : support@koralytics.be

KoraLytics acts as data controller within the meaning of article 4(7) of the GDPR for all the processing described in this document. It alone determines the purposes and means of processing, except for operations entrusted to processors acting in its name and on its behalf.

2. Record of processing activities

In accordance with article 30 of the GDPR, KoraLytics keeps an internal record of its processing activities. The main processing operations are summarised below:

Diaspora profile collection

Purpose

Statistical and analytical mapping of the skilled African diaspora for collective intelligence purposes

Data processed

Socio-demographic data (age, gender, country of origin and residence, sector, education, income, involvement); optional data (CV, profile photo)

Legal basis

Explicit and informed consent (art. 6.1.a) — double opt-in with timestamped record

Retention period

30 days in identifiable form, then irreversible anonymisation and indefinite retention in aggregated form

Recipients

Internal team; technical processors (Neon DB, Vercel) under a DPA

Transfers outside the EU

Data hosted in the EU (Frankfurt). Vercel access from the USA covered by SCC

Draft management

Purpose

Allowing the form to be resumed while being filled in

Data processed

Partial form data, last name, resume code, optional email address

Legal basis

Legitimate interest (art. 6.1.f) — feature necessary to the user experience

Retention period

30 days, then automatic deletion

Recipients

Internal team; Neon DB

Transfers outside the EU

EU only

Sending transactional emails

Purpose

Sending the form resume code and the profile management link

Data processed

Email address, last name, secure access token

Legal basis

Performance of a pre-contractual measure / consent (art. 6.1.b and 6.1.a)

Retention period

Resend logs kept for 30 days

Recipients

Resend Inc. (email processor, DPA signed)

Transfers outside the EU

Transfer to the USA covered by SCC

Institutional contact form

Purpose

Handling requests from institutions, embassies or research bodies

Data processed

Name, organisation, role, professional email address, message

Legal basis

Consent (art. 6.1.a) — explicit confirmation checkbox

Retention period

12 months from the last interaction

Recipients

KoraLytics sales team; Resend Inc.

Transfers outside the EU

Transfer to the USA covered by SCC

Anonymised audience statistics

Purpose

Measuring traffic and continuously improving the service

Data processed

Truncated IP address, pages visited, session duration, device and browser type

Legal basis

Consent (art. 6.1.a) — collected through the cookie consent banner

Retention period

13 months maximum

Recipients

Internal analytics tool; no third-party sharing

Transfers outside the EU

Data processed in the EU

3. Detailed legal bases

Consent — art. 6.1.a

The main legal basis for profile collection. Consent is obtained granularly (a separate checkbox for each purpose), freely given, specific, informed and unambiguous. It is recorded with a timestamp and the form version. It can be withdrawn at any time without affecting earlier processing.

Legitimate interest — art. 6.1.f

Used for draft management and securing the service. A balancing test was carried out: the interest of KoraLytics in ensuring continuity of navigation is proportionate, the data processed is minimal and the impact on privacy is limited. Individuals retain an effective right to object.

Legal obligation — art. 6.1.c

KoraLytics may be required to disclose personal data to the competent authorities upon judicial or administrative request, strictly within the limits provided by law.

4. How data is collected and data minimisation

KoraLytics applies the principle of data minimisation (art. 5.1.c GDPR):

  • Only data strictly necessary for the stated purposes is collected.
  • Sensitive fields (CV, photo) are optional and clearly identified as such.
  • Uploaded files (CV, photo) are base64-encoded, stored in the database and never publicly exposed.
  • The IP address is collected solely for fraud detection and truncated for analytics purposes.
  • No biometric, genetic, health or sexual orientation data is collected.
  • The form follows the Privacy by Design principle: each step tells the user the nature and use of the data requested.

5. Processors and international transfers

In accordance with article 28 of the GDPR, every processor with access to personal data is bound by a Data Processing Agreement (DPA) meeting GDPR requirements.

ProcessorRoleLocationSafeguards
Vercel Inc.Web hosting & deploymentUSA (with EU edge)European Commission SCC, DPA available
Neon Inc.Serverless PostgreSQL databaseEU — Frankfurt (AWS eu-central-1)EU hosting, DPA available
Resend Inc.Transactional emailsUSAEuropean Commission SCC, DPA available
GitHub Inc.Source code management (private repository)USAEuropean Commission SCC

No identifiable personal data is shared with client institutions or partners. Analyses and reports produced for third parties are based exclusively on aggregated and anonymised data.

6. Technical and organisational security measures

In accordance with article 32 of the GDPR, KoraLytics has put the following measures in place:

Encryption

  • TLS 1.3 for all transfers in transit
  • Encryption at rest of the database (AES-256)
  • Access tokens generated with cryptographically secure UUID v4

Access control

  • Database access restricted by IP and credentials
  • Administration interface protected by Basic Auth (staging only)
  • Strict separation between staging and production

Data integrity

  • Automatic daily backups (Neon point-in-time recovery)
  • Logging of sensitive operations (admin access, deletions)
  • Soft delete for profiles — no immediate physical deletion

Organisation

  • Data access limited to what is strictly necessary (least privilege principle)
  • Team training on GDPR good practice
  • Documented incident response procedure

7. Rights of data subjects — how to exercise them

In accordance with articles 15 to 22 of the GDPR, you have the following rights. Any request should be sent to support@koralytics.be — we will reply within a maximum of 30 days (extendable to 3 months for complex requests, with notification within 30 days).

Access (art. 15)

Obtain confirmation that data concerning you is being processed and, if so, obtain a copy in a readable format along with information about the processing.

Rectification (art. 16)

Correct inaccurate or incomplete data concerning you. You can edit your profile directly through your personal management link.

Erasure (art. 17)

Request the deletion of your data when it is no longer necessary, when you withdraw your consent, or when you object to the processing. For profiles, deletion is carried out within 72 hours of the request (soft delete then permanent purge within 30 days).

Restriction (art. 18)

Request that your data be kept but no longer actively processed, in particular while the accuracy of the data is verified or an objection is examined.

Portability (art. 20)

Receive your data in a structured, commonly used, machine-readable format (JSON) and transmit it to another controller. This right applies to data processed on the basis of consent or a contract.

Objection (art. 21)

Object at any time to processing based on legitimate interest or for profiling purposes. KoraLytics will stop the processing unless there are compelling legitimate grounds.

Withdrawal of consent

Withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal. Withdrawal can be exercised directly from your profile or by email.

Automated decision-making (art. 22)

KoraLytics carries out no automated decision-making and no profiling producing legal effects or significantly affecting data subjects.

8. Handling of personal data breaches

In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, KoraLytics undertakes to:

  1. Detect and contain the incident as quickly as possible using access logs and security alerts.
  2. Notify the Belgian Data Protection Authority (APD) within 72 hours of becoming aware of the breach, in accordance with article 33 of the GDPR.
  3. Inform the data subjects without undue delay if the breach is likely to result in a high risk to their rights and freedoms (art. 34 GDPR), with a clear description of the nature of the breach, the data involved and the remediation measures taken.
  4. Document the incident in the internal breach register, regardless of the notification obligation.

9. Protection of minors

The KoraLytics service is intended exclusively for people aged 16 or over. By submitting a profile, you declare that you have reached this age. KoraLytics does not knowingly collect personal data relating to minors under 16. If you become aware of such collection, please contact us immediately at support@koralytics.be so that we can delete the data concerned.

10. Data protection impact assessment (DPIA)

In accordance with article 35 of the GDPR, KoraLytics has carried out a Data Protection Impact Assessment (DPIA) for the collection of diaspora profiles, on the grounds that this processing involves large-scale socio-demographic data liable to indirectly reveal the ethnic or national origin of participants.

Systematic description

Voluntary collection of around 70 socio-professional fields through a secure form, storage in an encrypted database, anonymisation before analysis.

Assessment of necessity and proportionality

The data collected is strictly necessary for the mapping purpose. The granularity of the fields is justified by the analytical richness required to produce diaspora intelligence institutions can act on.

Risks identified

Potential re-identification from rare combinations of data, unauthorised access to the database, data leakage during transfers.

Mitigation measures

Irreversible anonymisation after 30 days, end-to-end encryption, restricted access, no publication of individual data, k-anonymity applied in analyses.

Conclusion

Processing may continue; the residual risks are acceptable given the technical and organisational measures in place. The DPIA will be updated annually or whenever the processing changes substantially.

11. Competent supervisory authority

As an entity established in Belgium, KoraLytics is subject to the supervision of the Belgian Data Protection Authority (APD), lead authority within the meaning of the GDPR one-stop-shop mechanism.

Data Protection Authority

Rue de la Presse 35, 1000 Brussels, Belgium

Tel.: +32 (0)2 274 48 00

www.autoriteprotectiondonnees.be

You may also lodge a complaint with the data protection authority of your member state of habitual residence or work.

Contact — Data protection officer

For any question about the GDPR compliance of KoraLytics, to exercise your rights, or to report an incident:
support@koralytics.be
Reply guaranteed within 30 calendar days.