Privacy Statement

Data Controller

Name
Daniel Van Waeyenberg
Legal form
Sole trader
Company number
BE 0847.486.525
Registered address
Zavelvennestraat 141, 3500 Hasselt, België
Email
contact@ndlink.app

1. Data We Collect

Required for registration: first name and email address. Without these, no account can be created. Required to create a profile: first name, location, date of birth, gender and preferred language.

Optional: last name, profile photo, 'about me', search preferences, interests, optional links to social media profiles, and information about your neurodivergent traits, strengths and challenges. For PRO profiles: self-reported information about practice, expertise, education…

Data about diagnoses and neurodivergent traits are special category data (GDPR Art. 9 — health data). Providing them is entirely voluntary and based solely on your explicit consent.

Profile photos are used solely for profile display. We do not apply automatic facial recognition or biometric analysis.

We also collect technical data for security and quality purposes: IP address, browser type, device type, session duration and the number of pages viewed per session. For logged-in users we also store appearance preferences (color theme, dark mode, font, text size, Experience Pack) so they carry over between devices. This data is processed on the basis of our legitimate interest in securing the platform and improving the user experience (GDPR Art. 6(1)(f)).

ND-Link is exclusively intended for users aged 18 and over.

2. How We Use Your Data

Your data is used to operate the platform, match you with other users, and communicate with you. We do not sell your personal data to third parties.

Profile information you fill in (such as name, photo, interests and traits) may be visible to other users of the platform, depending on your privacy settings.

We do not use your personal data for advertising profiling or personalised advertising.

3. Legal Basis (GDPR)

We process your ordinary personal data on the basis of your consent and the performance of the contract between you and us (GDPR Art. 6(1)(a) and (b)). You may withdraw your consent at any time.

Data about diagnoses, neurodivergent traits and mental health is processed solely on the basis of your explicit consent (GDPR Art. 9(2)(a)). You give this consent by voluntarily filling in this information. You can delete it at any time via your profile.

Technical security data (IP address, session data) is processed on the basis of legitimate interest (GDPR Art. 6(1)(f)).

4. Data Retention

We retain your data for as long as your account is active. When you delete your account, your personal data is actively removed from our operational systems within 30 days. Data may temporarily remain in technical backups but will also be deleted there within a reasonable period.

Technical security logs (IP address, browser, session data) are retained for a maximum of 90 days.

5. Security

We take appropriate technical and organisational measures to protect your personal data, including encrypted connections (HTTPS), access restrictions, secure password storage (bcrypt hashing) and monitoring of suspicious traffic.

6. External Processors

We may engage external processors for hosting, payment processing, email delivery and security. Data processing agreements are concluded with these parties where required by the GDPR. We remain responsible for the protection of your data.

7. International Data Transfers

Some external processors may process data outside the European Economic Area (EEA). In such cases, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.

8. Personal Toolkit Data (Me-menu)

The personal toolkit (signal plan, helpful thoughts, reframes, gratitude diary, emotion history, personality test, sensory profile, planning) is stored locally on your device by default and never sent to our servers. You can optionally choose to sync this data to our servers via Me → My data. This sync is entirely voluntary and can be disabled at any time. When you disable sync, your data is actively deleted from our operational systems.

Because this data may include information about your mental health and wellbeing, it qualifies as special category data under GDPR Art. 9. It is only processed on the basis of your explicit consent, given at the moment you enable sync. If you enable sync, this data is included in your data export.

9. Abuse Prevention After Account Deletion

To prevent circumvention of free plan limits through repeated account deletion and re-registration, we retain a cryptographic fingerprint of your email address after your account is deleted. This fingerprint is a one-way hash (SHA-256) combined with a server-side secret key. It cannot be reversed to identify you and is not linked to any personal data such as your name or email address. Only anonymous numeric counters (number of matches and messages used) are stored alongside the fingerprint. This processing is based on our legitimate interest in preventing platform abuse (GDPR Art. 6(1)(f)). The fingerprint is automatically and permanently deleted 12 months after your account deletion. You may request earlier deletion by contacting us.

10. Your Rights

Under GDPR you have the right to access, rectify, erase, and port your personal data. After logging in you can rectify your data, download a copy, and delete your account directly via your account settings.

11. Cookies

We use only functional cookies required for the platform to operate (session, CSRF). No tracking or advertising cookies are used.

12. Supervisory Authority

You have the right to lodge a complaint with the supervisory authority if you believe your personal data is being processed unlawfully. In Belgium, this is:

Authority
Gegevensbeschermingsautoriteit (GBA)
Address
Drukpersstraat 35, 1000 Brussel
Phone
+32 (0)2 274 48 00
Email
contact@apd-gba.be
Website
gegevensbeschermingsautoriteit.be

13. Contact

For privacy-related questions, please email contact@ndlink.app.