RoomPulse · Data protection information · v1.0

The app your facilitator is using, and everything it does with your data.

RoomPulse is the live participation app built and operated by AIM Learning Solutions. It runs polls, timers, team challenges and shared walls during an event, on the phone already in your pocket. This page holds every privacy, retention and security document that applies to it.

We built RoomPulse because the tools we were using put our clients' data on platforms outside the EU, under terms we could not change and a supply chain we could not see. This one we run ourselves. That is why the list below is short, and why we can put it in writing.

  • Threesub-processors engaged directly, each processing our data in the EU
  • FrankfurtEvery participant record stored in Germany, and application compute pinned there too
  • Zerotrackers, analytics or third-party scripts on a participant's phone
  • Deletedwhen the event ends, by default, with a certificate to prove it

Version 1.0, issued 10 August 2026 and effective for events from 15 September 2026. This statement describes RoomPulse as delivered from that date.

0Document register

Every document governing how RoomPulse handles personal data. Each is versioned and dated, and the reference is stable so it can be cited in a contract or a processing record.

Ref.DocumentSectionVersionUpdated
RP-PS-01Privacy StatementWhat is collected, why, for how long, and your rights. Shown to participants before they join.21.010 Aug 2026
RP-TOM-01Technical and Organisational MeasuresThe security controls protecting personal data, as required by Article 32 GDPR.31.010 Aug 2026
RP-RET-01Retention and Deletion PolicyRetention options, the automated purge, and the deletion certificate issued afterwards.2.41.010 Aug 2026
RP-RES-01Data Residency and Sub-processorsWhere data is stored and processed, and every third party involved.41.010 Aug 2026
RP-CK-01Cookie NoticeThe one cookie RoomPulse sets, and what it is for.51.010 Aug 2026
RP-IC-01Questions We Are Often AskedAnswers to the data protection questions organisations put to us before approving the app for an event.61.010 Aug 2026
RP-ROPA-01Record of Processing ActivitiesOur Article 30(2) processor record, published here in full, not held back for a request.71.010 Aug 2026
RP-DPA-01Data Processing AgreementSend us your template and we will sign it. If you would rather we supplied one, we can. Either way the annexes are already written: the description of processing is section 7, the security measures section 3, the sub-processor list section 4.2.7, 3, 4.2On requestn/a

1About RoomPulse

A facilitator builds a running order before the event. During it, they push one activity at a time to everyone's phone. Participants join by scanning a QR code or typing a short code. There is no account, no app store download and no password.

Key facts

Default retention
ImmediateAll participant data is deleted when the session ends. An organiser may extend to 24 hours, 7 or 30 days. Never longer.
Data held in
FrankfurtGermany. Database, file storage and application servers are all in the EU.
Transfers outside the EEA
EU onlyParticipant data is stored only in Germany. Section 4.3 sets out each provider's contractual position in full.
Trackers and analytics
NoneNo analytics, advertising or third-party scripts. This page makes no external request either.

1.1What the app does

Most live-participation tools cover the first group below. RoomPulse covers all six, because an away day is not a webinar: people move, form teams, go outdoors, make things, and meet colleagues they have never worked with. The app has to follow them.

Ask the room

  • Multiple-choice polls with results that build live
  • Word clouds from words participants choose or type
  • Open-text idea walls
  • Rating scales and ranking
  • Questions and answers with upvoting, threaded replies and moderation
  • Structured multi-field capture, for when one question is not enough

Run the clock

  • One countdown, in sync on several hundred phones at once
  • Rotation timers that tell each trio when to switch speaker
  • Break timers that nudge people back
  • Guided reflection walks, paced by an audio cue
  • Segment markers that buzz the phone in your pocket
  • A private timer only the facilitator sees

Send teams out

  • Automatic allocation into deliberately mixed teams
  • Each team guided to its own meeting point
  • Challenges that open one after another as a team finishes them
  • Different content for every team, so no one can copy their neighbours
  • Hints when a team is stuck, on request or from the facilitator
  • Messages pushed to one team, a few, or everyone, with no shared screen

Make something together

  • Answers as text, numbers or lists, and photographs where an organiser enables them
  • A judging queue so creative answers can be scored quickly
  • A scoreboard that shows collective progress, not a ranking
  • Shared walls that fill as contributions arrive
  • A closing mosaic assembled live on the main screen from every team's photo

Read the room

  • A prediction game: vote privately, then guess what the room did
  • Scored on how well you read the room, never on how you voted
  • Human-or-AI quizzes against the clock
  • Who-knows-whom mapping, and who met whom today
  • A live connection graph on the big screen as the room mixes
  • A private receipt showing each person only their own answers

Close and hand over

  • Big-screen views for the projector, separate from the facilitator console
  • A presenter remote for running the room from your pocket
  • A facilitator console that works on a laptop or a phone
  • A self-contained report of the day, handed to the organiser
  • Automatic deletion of participant data afterwards
  • A deletion certificate confirming it happened

Every one of those is configured per session by the facilitator rather than hard-coded, so the same app runs a twenty-person workshop in one meeting room and an event of several hundred spread across a whole venue, indoors or out.

1.2Who is accountable

For each event, the organisation that commissioned it decides what is collected and why. They are the controller. AIM Learning Solutions runs the app on their instructions, which makes us the processor. Both are named in the privacy notice shown on your phone before you join.

2Privacy statement

DOCRP-PS-01

Written for participants. If you are joining an event on your phone, this is what happens to what you type, tap and photograph.

2.1Who is responsible

The organisation running your event (your employer, your agency, or the body that invited you) decides what the app collects and why. Under data protection law they are the controller. AIM Learning Solutions provides and operates RoomPulse on their written instructions, which makes us the processor. We do not use anything collected during your event for our own purposes, and we never sell or share it.

Where your event is run by an institution, body, office or agency of the European Union, the controller's obligations arise under Regulation (EU) 2018/1725 and their supervisory authority is the European Data Protection Supervisor. Our own obligations as a Belgian processor arise under the GDPR (Regulation (EU) 2016/679). The two are aligned, and the practical protections described below are the same either way.

2.2What is collected

How you are identified is chosen by the organiser before the event, and stated on the notice you see before you join. Anonymous is the default for new sessions.

Identity modeWhat identifies youTypical use
Anonymous (default)Nothing. A random token in your browser tells one device from another so you are not asked the same question twice. It is not linked to you and is discarded with everything else.Feedback, sensitive topics, large plenaries
First nameA first name you type yourself. You may type anything.Smaller workshops where a facilitator addresses people by name
NicknameA display name you choose.Games and scoreboards
RosterYour name and organisational unit, imported in advance by the organiser.Events where who-met-whom is part of the exercise

In addition, depending on which activities the facilitator runs:

CategoryDetail
Your answersChoices in a poll, ratings, rankings, words for a word cloud, free text you write, questions you post and votes you give them.
Photographs (only if enabled)Off unless the organiser switches photo challenges on for the event. Where they are on, only where a challenge asks for one, and only if you have agreed. See section 2.3.
Team and progressWhich team you were put in, which challenges it completed, the score, and the time of each submission.
TechnicalOne functional cookie holding a signed session token. Your IP address and browser type also appear in the runtime logs our hosting provider keeps in order to deliver the page and limit abuse. Those logs are held by that provider for one hour, are not readable by the app, and are never written to our database.
Not collectedNo email address. No account or password. No location. No device fingerprinting. No analytics or advertising identifiers. No contacts, no microphone, no background access to your phone.

2.3Photographs, where an event uses them

The most sensitive thing the app handles

This section applies only if the organiser has enabled photo challenges for your event. Photography is off unless it is deliberately switched on, and many events never use it. If it is off, the app cannot access your camera at all and nothing below applies to you.

Where it is on, some team challenges ask a team to photograph something: an object, a scene, or the team itself. A photograph of a person is personal data, and a group photo is personal data about everyone in it. We treat it accordingly.

  • You are asked separately. Photo consent is a distinct choice when you join, not bundled into joining. If you decline you can still take part in every challenge. A teammate uploads instead, and you need not be in the picture.
  • Location and device data are removed. Phone cameras embed GPS coordinates, timestamps and device identifiers in image files. RoomPulse removes this metadata on your own phone, before the image ever leaves it — the photo is re-encoded in your browser, which discards everything except the picture itself. Our server then independently checks each incoming image and refuses any that still carries metadata. We never hold the place a photo was taken or the phone that took it.
  • Images are stored privately. They go to a private, access-controlled store in the EU. They are never publicly addressable, and each view is authorised individually and expires.
  • Shown only where the challenge says. A photo may appear on the event's big screen or in a shared wall. That is the point of the activity, and it is described before you submit.
  • No face recognition. We do not run facial recognition, biometric matching, automatic tagging or any form of image analysis. Ever.
  • Deleted with everything else, on the retention schedule in section 2.4.

2.4How long it is kept

DOCRP-RET-01

Retention is set per event by the organiser and shown on the notice before you join. The options are deliberately short, and the shortest is the default.

SettingWhat happens
Immediate (default)All participant data, including any photographs, is permanently deleted as soon as the facilitator closes the session, typically within minutes of the event ending.
24 hours / 7 days / 30 daysChosen only where the organiser needs the raw responses to write up the event. Deletion then happens automatically at the end of that period.

Deletion is carried out by an automated task running every five minutes inside the database itself, so it does not depend on anyone remembering. A separate daily watchdog, running on independent infrastructure, checks that no deletion is overdue and raises an alarm if the task ever falls behind. Afterwards the system re-counts every table to confirm nothing is left, and issues a deletion certificate recording what was deleted and when. An administrator can also trigger the full deletion immediately at any point after an event ends, and can export or erase a single participant's data on request during one.

What is kept afterwards is anonymous summary only. For example, "62 of 88 people chose option B", or a team's total score. Where a future activity type summarises words people typed, rare answers will be suppressed before the summary is kept, so an unusual response cannot be traced back to one person. Free text is never kept. The event's written report is generated at the end and handed to the organiser. From that moment they hold it, and it is governed by their retention rules, not ours.

2.5Why it is collected, and on what basis

To run the session you are taking part in: to show the facilitator how the room is responding, to give you your timer and your team's challenges, and to produce a summary for the organiser. The legal basis is set by the controller and named in the notice you see before joining. For EU bodies it is normally the performance of a task carried out in the public interest. Where the controller relies on consent for photographs, this is how we implement it: you are asked separately from joining, and refusing costs you nothing, so the choice is a real one. Participation in any activity is voluntary. You can skip a question or close the page at any time.

2.6Your rights

You may ask for access to your data, correction, erasure, restriction of processing, or object to it. Because retention is usually immediate, the fastest route during an event is to tell the facilitator. They can delete your responses on the spot, and the change takes effect at once. Otherwise contact the organiser as controller, or us at dpo@aim-associes.com and we will pass it on.

You also have the right to complain to a supervisory authority. That is the European Data Protection Supervisor where the controller is an EU body, and your national authority otherwise. In Belgium that is the Autorité de protection des données / Gegevensbeschermingsautoriteit.

If a personal data breach occurs, we notify the controller without undue delay so they can meet their own notification deadlines, and we support their assessment.

3Technical and organisational measures

DOCRP-TOM-01

The controls protecting personal data processed through RoomPulse, appropriate to the risk of a short-lived event application handling responses and photographs. Required by Article 32 GDPR.

3.1Access control

  • Facilitator accounts are created by invitation only. Self-registration is disabled at the identity provider.
  • Minimum 12-character passwords. Credentials are salted and hashed by the identity provider and never visible to us.
  • Three separate roles (administrator, session owner, facilitator), each scoped to the specific events a person is assigned to.
  • Every privileged action is checked independently at three layers: the page, the server action, and the database.
  • Deactivating an account revokes access immediately and terminates existing sessions.

3.2Database protection

  • Row-level security is enabled on every table and denies by default. Access is granted only by explicit policy.
  • The public application key carries no database privileges whatsoever, so it is useless for reading data even though it is present in every browser.
  • Participants never connect to the database. All access is mediated by the server, which validates every request.
  • Participant identity is carried in a signed, HTTP-only cookie. No identifier ever appears in a web address, which removes a common class of data-exposure flaw.
  • Administrative keys are held server-side only and are never sent to a browser.

3.3Encryption and storage

  • All traffic is encrypted in transit with TLS 1.2 or above. HTTPS is enforced.
  • Data at rest is encrypted by the hosting provider using AES-256.
  • Uploaded images are held in a private store with no public addresses. Access is by short-lived authorised links generated per view.
  • Image metadata, including GPS coordinates and device identifiers, is stripped on the server before storage.
  • Backups are encrypted at rest and taken daily by our database provider. A restored backup could briefly contain data already deleted from the live system, so we confirm the backup window per project with the controller instead of claiming deletion is instantaneous everywhere. This is the one place where "deleted" means "deleted from the live service, and from backups as they age out".

3.4Data minimisation

  • Anonymous participation is the default for every new event. A name is collected only where an organiser deliberately turns it on.
  • Each activity type declares what categories of data it collects, and the participant notice is generated from the event's actual running order, so it cannot drift from reality.
  • No analytics, advertising, tag managers, session recording or heat-mapping of any kind.
  • No externally hosted fonts, scripts or images. The app makes no third-party requests from a participant's browser.

3.5Deletion and accountability

  • Automated deletion runs inside the database every five minutes, independent of any external scheduler.
  • A monitoring task checks daily for any event whose deletion is overdue and alerts administrators.
  • Deletion is verified in the same database transaction by re-counting every table that can hold personal data; if anything remains, the deletion is rolled back and retried rather than reported as done. A certificate records the result, carries a cryptographic fingerprint (SHA-256) of its own contents, and is published at an unguessable web address the organiser can open — and re-check — without an account.
  • In an anonymous session there is nothing to look up. Nobody at AIM can connect a response to a person, because the link does not exist. A participant who wants their contribution removed during an event points it out to the facilitator and it goes immediately. Where an organiser has chosen to collect names, we can also act on a request for access or erasure.

3.6Organisational measures

  • Access is limited to the AIM staff delivering the event, on a need-to-know basis.
  • Staff are bound by confidentiality obligations.
  • We enter into a written processing agreement with the controller for every engagement.
  • We use only sub-processors that publish data processing terms incorporating the European Commission's Standard Contractual Clauses.
  • Changes to the schema or to security policy are made through reviewed, version-controlled migrations, and tested against an automated access-control suite before release.
  • Load and resilience testing is carried out before large events.

4Data residency and sub-processors

DOCRP-RES-01

All personal data processed through RoomPulse is stored and processed in the European Union. There is no transfer to a third country in normal operation.

4.1Where data is processed

Database · Frankfurt File storage · Frankfurt Application servers · Frankfurt

Every component is pinned to an EU region. Participants receive no email. The application makes no requests to third-party services from a participant's browser, so no data leaves the EEA by that route either.

Where this is contractual, and where it is configuration

Storage is contractual. Our database provider's terms commit that where a customer directs processing in a specific geographical region, the data is stored and primarily processed in that region. We have directed Frankfurt. Every participant record, every uploaded photograph and every account lives there, so for the data itself, EU residency is a contractual obligation, not a preference.

Compute is configuration, and we would rather tell you than have you read it in their terms. Our hosting provider's agreement states that its primary processing facilities are in the United States and permits processing elsewhere in the world, relying on the Standard Contractual Clauses. We pin every function to that provider's Frankfurt region, so requests execute in Germany. That is our configuration, not their guarantee.

What limits the exposure is that this provider stores nothing. It holds no database and no files. Personal data passes through it only in transit, for the moment it takes to serve a request, and is written only to the database in Frankfurt.

The exception worth naming is logs. Serving a request produces a runtime log entry containing the IP address and browser type, held by that provider and not by us. Retention is one hour, we do not enable the extended observability tier, and we send logs to no third party. If the distinction matters to your assessment, raise it early: the application is portable and we can host it elsewhere.

One limitation we would rather state than have you discover. Our hosting provider's published data processing addendum applies to its paid plans; we are on its free tier, so that addendum does not currently cover us. We therefore have no separate processor agreement with the host — unlike the database and email providers below, whose terms do apply. This is a contractual gap, not a technical one: the residency configuration, the Frankfurt pin and the one-hour log retention described above are all in force regardless. If your assessment requires a processor agreement covering compute, tell us and we will move to a plan or a provider that gives you one.

4.2Sub-processors

We engage three sub-processors directly. Their published terms are linked below so you can read them without asking us for a copy; the database and email providers' terms incorporate the European Commission's Standard Contractual Clauses and apply to us, while the hosting provider's addendum does not cover its free tier — see the note in section 4.1. Links open on the provider's own site and pass no referrer.

Sub-processorPurposeLocation of processingTheir terms
SupabaseDatabase, authentication, file storageFrankfurt, Germany (eu-central-1)Data Processing Addendum
VercelApplication hosting and deliveryFrankfurt, Germany (fra1)Data Processing Agreement
BrevoInvitation and notification email to AIM staff only, never to participantsEuropean UnionTerms of Use, Appendix 3

Their sub-processors, and why the chain matters

Three is the number we engage. Each of them engages others in turn, which is normal and lawful under Article 28(4), and the chain is worth showing you in full.

Supabase publishes a list of around two dozen, most of which support their own helpdesk, billing and monitoring, not customer databases. The ones that host infrastructure are Amazon Web Services, Google, Cloudflare, Fly.io and Upstash. Their list also names OpenAI, for natural language features in their own product. RoomPulse uses no Supabase AI feature, and no participant data is sent to any model. Vercel's list covers Amazon Web Services, Google, Microsoft, Datadog and Honeycomb, plus several providers used only for AI features we do not enable.

Both publish their current list and let you subscribe to changes: Supabase sub-processors and Vercel Trust Center. We review both when they change, and a client can be notified of anything material before their event.

4.3Position on US-parent providers

Stated plainly, so you do not have to go looking for it

Supabase Inc. and Vercel Inc. are incorporated in the United States, and the infrastructure we use from them is in Germany. Both build the European Commission's Standard Contractual Clauses into their terms automatically, with no separate signature: Supabase applies Modules Two and Three, Vercel applies Modules One, Two and Three together with the UK addendum.

The two are not equivalent on residency, and the difference is worth stating. Supabase commits contractually to the region a customer directs. Vercel's agreement records that its primary processing facilities are in the United States and reserves the right to process elsewhere. Our compute runs in Frankfurt because we configured it to, and because Vercel stores no participant data at any point, but we are not going to describe that as a contractual guarantee when it is not.

Our email provider, Brevo, reaches AIM staff only and never participants. Their terms note that they may rely on the EU-US Data Privacy Framework for transfers to the United States. No participant data is ever sent to them.

We consider the residual risk low and appropriately mitigated. We do not claim it is nil.

Where a client requires infrastructure with no non-EU corporate parent, RoomPulse is built to be portable. It uses standard PostgreSQL and no proprietary lock-in beyond authentication and live messaging. A migration path to EU-sovereign hosting is documented and can be executed on request.

5Cookies

DOCRP-CK-01

RoomPulse sets one cookie. It is strictly necessary to deliver the service you asked for, so no consent banner is required. There is nothing to consent to in any case, because there is nothing else.

CookiePurposeExpires
Session tokenSigned and HTTP-only. Identifies your device to the event you joined so your answers are yours and you are not asked a question twice. Contains no name and is not readable by scripts.When the event's data is deleted, and in any case within 24 hours
Everything elseNo advertising, analytics, tracking or profiling cookies are set, by us or by anyone else. There are no third-party scripts on the page that could set one.n/a

Facilitators, who do have accounts, also have an authentication cookie for as long as they stay signed in.

6Questions we are often asked

DOCRP-IC-01

These are the questions public and private organisations put to us most often before approving RoomPulse for an event. If yours is not here, write to us at dpo@aim-associes.com and we will answer it properly. Send us your own data processing agreement and we will sign it. If you would rather we supplied one, we can do that too, and it can sit as an annexe to an existing framework contract.

6.1What is the app called, and where is its privacy statement?

RoomPulse, developed and operated by AIM & Associés SRL, also referred to as AIM Learning Solutions, in Brussels. It is our own application, not a resold third-party product, so we can configure it around your requirements instead of asking you to accept it as given.

The privacy statement is section 2 of this document, reference RP-PS-01. Our Article 30 record of processing is section 7, published in full. A notice specific to your event is also shown to every participant before they submit anything. It names you as controller and states that event's identity mode and retention period.

6.2What personal data does the app collect?

That is up to you, and it is minimised by default. New events are set to fully anonymous: no name, no email, no account, no location. Participants are distinguished only by a random device token that is discarded on deletion.

Where an event uses them, the additional categories are a first name or nickname the participant types, or name and organisational unit if you supply a roster. Beyond identity, the app records the participant's own answers (choices, ratings, rankings, free text, posted questions), team membership and progress, and submission timestamps.

Photographs are collected only if you ask for them. They are off by default, and an event can run its full programme without ever enabling them. Where you do want a challenge that needs one, they are the most sensitive category we handle and they are treated separately: consent is asked for on its own, refusal carries no disadvantage, camera metadata including GPS coordinates is stripped before storage, images are held privately with expiring access links, and no facial recognition or image analysis is performed at any point.

6.3How long is the data kept?

As short as you want, and by default no time at all. For an event like yours we would set retention to Immediate: all participant data is permanently deleted when the facilitator closes the session, normally within minutes of the event ending. That covers responses, free text, team records, and any photographs if your event used them. Longer options exist (24 hours, 7 or 30 days) for clients who need the raw material to write up the day. They are never required, and never longer than 30 days.

Deletion is automated, running inside the database every five minutes, so it does not depend on a person remembering or on an external scheduler being available. It is verified by re-counting every table containing personal data and confirming the result is zero — inside the same transaction, so a deletion that leaves anything behind cannot be reported as complete. We then issue you a deletion certificate recording what was deleted, when, by which process, and the verification result, protected by a SHA-256 fingerprint of its contents and published at a private link you can open without an account, at any later date.

What remains afterwards is anonymous aggregate only: counts, distributions and team totals. Where a summary would be built from typed words, rare responses are suppressed before it is kept, so no answer can be traced to an individual. Free text is never retained. Your event report is generated at the end of the day and handed to you. From that point it is under your control and your retention rules.

6.4Is any data transferred outside the EU or EEA?

No participant data is stored outside the EEA, and none is transferred there in normal operation. Every record, response and photograph is held in Frankfurt, Germany. Application compute is pinned to Frankfurt as well. Participants receive no email at all, and the app makes no requests to third-party services from a participant's browser, so no analytics, tag manager or externally hosted font carries anything to a third country by the back door.

Two points of completeness, since you would find both if you looked. First, our providers Supabase and Vercel are US-incorporated companies operating EU regions, with the Standard Contractual Clauses built into their terms. Second, and more precisely: only our database provider commits contractually to the region we direct. Our hosting provider's agreement records US primary facilities and permits processing elsewhere, so we pin compute to Frankfurt by configuration, and that provider stores no participant data at any point. Section 4.3 sets this out in full.

If your organisation requires infrastructure with no non-EU corporate parent, or a contractual rather than configured residency commitment for compute, tell us during preparation. The application is portable and we can move it.

6.5What security measures are in place?

Section 3 sets them out in full, reference RP-TOM-01. The short version: TLS 1.2+ in transit and AES-256 at rest; deny-by-default row-level security on every table, with the public application key holding no database privileges at all; participants never connect to the database and never appear as an identifier in a web address; invitation-only staff accounts with 12-character minimum passwords and role-based access scoped to individual events; privileged actions checked independently at three layers; private image storage with expiring access links and metadata stripped before upload and verified on arrival; automated, verified deletion with a fingerprinted certificate; and no analytics, trackers or third-party scripts anywhere in the participant experience.

We also run load and resilience testing before large events.

7Record of processing activities

DOCRP-ROPA-01

The record we are required to keep as a processor under Article 30(2) GDPR. Most providers hand this over only when asked. It is a statement of fact, not a negotiation, so we publish it.

Article 30(2) requirementOur entry
ProcessorAIM & Associés SRL (also referred to as AIM Learning Solutions). Enterprise number 0864.046.009. Avenue de Tervueren 36A, 1040 Brussels, Belgium. dpo@aim-associes.com
ControllersThe organisation commissioning each event. Named individually in that event's processing agreement and on the participant notice.
Data protection contactdpo@aim-associes.com, a monitored function mailbox held by the AIM management team and routed to whoever can answer: the Digital Manager, the Security Officer, or the IT team.
Categories of processingCollection, display, aggregation, temporary storage and erasure of participant contributions during a live event, carried out solely on the controller's documented instructions.
Categories of data subjectsParticipants at an event run by the controller, and the controller's own staff who operate the app as facilitators.
Categories of personal dataParticipants: a random device token, and where the controller enables it a first name, nickname, or name and organisational unit from a roster. Contributions: poll choices, ratings, rankings, free text, posted questions and votes, team membership, progress and scores, submission timestamps, and, only where the organiser has enabled photo challenges, photographs taken by participants who have consented. Facilitators: name, work email, role. No special categories are collected by design.
RecipientsThe controller. The sub-processors listed in section 4.2. No one else. Nothing is sold, shared or used for our own purposes.
Third-country transfersNone. All processing takes place in the European Union. See section 4.3 for our position on the corporate nationality of our providers.
RetentionSet per event by the controller: immediate on session close (the default), or 24 hours, 7 days or 30 days. Enforced by an automated task and evidenced by a deletion certificate. See section 2.4.
Security measuresAs set out in full in section 3.

This record is maintained alongside the application. It is reviewed whenever a new activity type, sub-processor or retention option is introduced, and it carries the same version number as this page.

How data protection decisions actually get made here

Data protection questions go to one monitored address, and from there to the person who can answer: the Digital Manager for how the app is built, the Security Officer for controls, the IT team for infrastructure. Nothing waits for whoever happens to pick up the message.

The reason we can answer quickly is that the data protection decisions in this app are architectural, not procedural. Anonymous by default, deletion running inside the database, no participant identifier in a web address, camera metadata stripped on upload. None of those could have been added afterwards by someone reviewing a finished product. They exist because the people accountable for data protection were in the design, alongside the facilitation and engineering choices.

If your assessment needs our position on Data Protection Officer designation, ask and we will confirm it in writing.

8Contact and complaints

If you took part in an event and want to know what was held about you, or want it deleted, the fastest route is to ask the facilitator during the event. It is done immediately. Otherwise write to us and we will act on the controller's instruction.

Data protection contact

dpo@aim-associes.com
AIM & Associés SRL, enterprise number 0864.046.009
Avenue de Tervueren 36A, 1040 Brussels, Belgium

A monitored mailbox held by the AIM management team, routed to whoever can answer: the Digital Manager, the Security Officer, or the IT team. If you are a controller's data protection officer and would prefer to speak, say so and we will arrange a call.

Our record of processing activities is section 7 of this document, so there is nothing to request. For a data processing agreement, send us your template and we will sign it, or ask and we will supply one. We can also complete a security questionnaire in your own format or contribute to a data protection impact assessment.