1) Scope and definitions
This policy applies to visitors, leads, and customers who use our website(s), forms, checkout, and email communications.
- Personal data: any information relating to an identified or identifiable natural person (e.g., name, email, IP).
- Processor: a third party processing personal data on our behalf (e.g., email or payment provider).
2) Who we are & how to reach us
How Siam’ple is the data controller for the processing described in this policy. For questions or to exercise your rights, contact info@howsiample.com. We may ask you to verify your identity to prevent misuse.
3) What data we collect
- Identification & contact: name, email, (optional) phone, country/region, company name and VAT number (for B2B).
- Account/order data: order number, purchased products (digital content), billing address, payment status (via provider), download or access history.
- Communication & preferences: newsletter lists, tags/segments, submitted forms, support requests, reviews.
- Technical/log data: IP address, device/browser, error logs, session/event data, limited cookie IDs (see Cookie Policy).
4) Purposes and legal bases
- Contract performance: processing orders/pre-orders, delivering digital content, customer support. Legal basis: performance of a contract or steps prior to entering into a contract.
- Invoicing & legal obligations: storing invoicing data, VAT administration. Legal basis: legal obligation (tax/accounting).
- Direct marketing & service emails: nurture, product updates, newsletters, promotions; plus transactional emails (order confirmation, access). Legal basis: consent (newsletters) and/or legitimate interest (existing customer communications, subject to e-privacy rules). You can unsubscribe at any time.
- Website optimisation, security & abuse prevention: basic analytics, troubleshooting, performance/security logs. Legal basis: legitimate interest, plus consent where cookies require it.
- Reviews/testimonials (optional): publishing with your consent (e.g., first name/initials). Legal basis: consent, withdrawable.
5) Retention periods
- Contract and invoicing data: up to 7 years (tax retention).
- Marketing/newsletter data: until you unsubscribe or we regularly clean our lists.
- Technical logs/analytics: typically up to 12 months, unless longer is needed for security or legal claims.
Retention can vary depending on legal obligations or ongoing disputes.
6) Cookies
We use necessary cookies and—where you consent—functional/analytics/marketing cookies. Details (types, purposes, durations) are set out in our Cookie Policy. You can manage preferences via the cookie banner.
7) Who we share data with (processors)
We share only what is necessary with carefully selected processors and vendors offering appropriate safeguards:
- Website/hosting & email hosting: Easyhost adn Systeme.io
- Email campaigns & CRM: Brevo (Sendinblue) and/or Systeme.io
- Automations: n8n (self-hosted or cloud), restricted to necessary fields
- Payment providers: Stripe, Mollie (payment-relevant data only)
- Communication tools (optional): Slack for internal order notifications
Where required, we sign a data processing agreement with each processor. We do not sell personal data. Transfers outside the EEA occur only with appropriate safeguards (e.g., EU Standard Contractual Clauses) or an adequacy decision.
8) Security
We implement appropriate technical and organisational measures (access controls, encryption where appropriate, backups, least-privilege access). No system is 100% secure; in case of a data breach, we follow legal procedures (notify the authority/affected individuals where required).
9) Direct marketing & your choices
- We send marketing communications with your consent or as an existing customer within legal exceptions.
- You may unsubscribe at any time via the link in our emails or by emailing info@howsiample.com.
- Withdrawing consent does not affect processing done prior to your withdrawal.
10) Your rights
You have the right to access, rectification, erasure (“right to be forgotten”), restriction of processing, objection (including to direct marketing), and data portability.
Submit your request via info@howsiample.com. We generally respond within 1 month. We may request additional information to verify your identity. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse it (with reasons).
Right to lodge a complaint: you can file a complaint with the Belgian Data Protection Authority (GBA), Drukpersstraat 35, 1000 Brussels — see the authority’s website.
11) International transfers
Where processors outside the EEA are used, we ensure appropriate safeguards (e.g., SCCs), complemented by technical/organisational measures if needed. Information about specific transfers is available on request at info@howsiample.com.
12) Minors
Our services and digital content are aimed at adults. We do not knowingly collect data from children. Parents/guardians who believe data was collected in error can contact us for deletion.
13) Changes to this policy
We may update this policy (e.g., when adding features or to reflect legal changes). The last updated date appears at the top. For material changes, we will provide reasonable notice (e.g., via website/email).
14) Governing law & jurisdiction
This policy is governed by Belgian law. The courts of the judicial district of Brussels have jurisdiction, without prejudice to mandatory consumer rules.