Privacy Policy

Effective date: 2026-02-09

This Privacy Policy applies to the MakelaarCC website, the MakelaarCC web application, and MakelaarCC services (collectively, the Service), operated by Mathias Van Hecke, solo entrepreneur, trading as Forgr, VAT number BE1034814905. This Privacy Policy explains how we collect, use, share, retain, and protect personal data when you use the Service.

MakelaarCC is a business-to-business software product for real estate offices and their team members. Parts of the Service, such as public booking pages, are also used by visitors scheduling property viewings. This Privacy Policy applies to both categories of users where relevant.

For information about cookies and similar technologies, see our Cookie Policy. For the contractual terms governing use of the Service, see our Terms of Service.

Definitions

Personal data means any information relating to an identified or identifiable natural person. This can include names, email addresses, phone numbers, company information, booking details, payment-related information, device data, and information about how the Service is used.

The marketing site means the public-facing informational pages on the MakelaarCC website, including the homepage, product information, pricing, and other public content.

The web application means the authenticated parts of the Service used by offices, administrators, and realtors, including dashboards, office settings, listings, bookings, invitations, and subscription management.

Public booking pages means the pages used by prospective buyers, tenants, or other visitors to schedule viewings without creating a full office account.

What data we collect

We collect information you actively provide to us, information generated through your use of the Service, and certain technical information automatically sent by your browser or device.

We do not sell your personal data or the data entered into the Service.

Information you provide directly

  • Contact details such as name, email address, and phone number.
  • Account details such as login credentials and user profile information.
  • Business details such as office name, company information, and subscription-related data.
  • Booking-related data such as visitor names, email addresses, phone numbers, comments, and scheduled times.
  • Support communications and any information you send to us by email or through the Service.

Information collected automatically

  • IP address, browser type, device information, operating system, and timestamps.
  • Usage data such as pages visited, feature usage, and interaction patterns.
  • Error and diagnostic data needed to maintain security, reliability, and performance.
  • Security-related information such as CSRF protection cookies and authentication session metadata.

Data from public sources

We may supplement the information you provide with publicly available business information, for example to verify business identity or company details.

Third-party services and sub-processors

We use third-party service providers to operate the Service. These providers may process personal data on our behalf to the extent necessary to provide their services.

Required for the marketing site

CompanyPurposeInformation collected
CloudflareNetwork, DNS, security, and hosting infrastructureIP address and request metadata
HetznerServer infrastructureIP address and service data processed on hosted systems

Required for the web application

CompanyPurposeInformation collected
SentryError logging and diagnosticsIP address, technical diagnostics, and error context
StripePayment processing and subscription billingPayment method details, billing data, IP address, and transaction metadata
ResendTransactional email deliveryEmail address and message delivery metadata

Optional services

The following service is optional and is activated only after you opt in through our consent mechanism.

CompanyPurposeInformation collected
Microsoft ClarityAnalytics and product improvementIP address, browser data, clicks, usage patterns, and page interactions

How we use personal data

  • To create and manage accounts and office workspaces.
  • To provide booking, listing, scheduling, and subscription functionality.
  • To send transactional emails such as invitations, booking confirmations, and account notifications.
  • To process payments and manage subscriptions.
  • To secure the Service, prevent abuse, and investigate incidents.
  • To maintain, troubleshoot, and improve the Service.
  • To comply with legal, tax, accounting, and regulatory obligations.

Legal bases for processing

Under the GDPR, we rely on the following legal bases for processing personal data.

Processing activityLegal basisDetail
Account creation and managementPerformance of a contract, Article 6(1)(b) GDPRNecessary to provide the Service
Bookings and appointmentsPerformance of a contract, Article 6(1)(b) GDPRCore service functionality
Stripe subscription and payment processingPerformance of a contract, Article 6(1)(b) GDPRNecessary to bill paid plans and manage subscriptions
Transactional emailsPerformance of a contract, Article 6(1)(b) GDPRRequired for service communications
Infrastructure security and error loggingLegitimate interests, Article 6(1)(f) GDPRNeeded to secure, monitor, and maintain the Service
Optional analytics via Microsoft ClarityConsent, Article 6(1)(a) GDPREnabled only after opt-in
Billing and accounting recordsLegal obligation, Article 6(1)(c) GDPRRequired under Belgian tax and accounting law

International data transfers

Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards under Chapter V of the GDPR, including the EU-US Data Privacy Framework where applicable and Standard Contractual Clauses where necessary.

Sub-processorCountryTransfer mechanism
StripeUnited StatesEU-US Data Privacy Framework
SentryUnited StatesEU-US Data Privacy Framework
ResendUnited StatesStandard Contractual Clauses
Microsoft ClarityUnited StatesEU-US Data Privacy Framework

Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These measures include access controls, secure hosting, transport-layer security, logging, and operational safeguards. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Your rights

Subject to applicable law, you may have the right to access, correct, update, delete, restrict, or object to the processing of your personal data, as well as the right to data portability and the right to withdraw consent where processing is based on consent.

  • Access the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request deletion of your data, subject to legal retention obligations.
  • Restrict or object to certain types of processing.
  • Receive your data in a structured, commonly used, machine-readable format where applicable.
  • Lodge a complaint with a competent data protection authority.

To exercise these rights, contact us at [email protected]. We will respond within the period required by applicable law.

Data retention

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy and to comply with our legal obligations.

Data typeRetention periodReason
Account and office dataDuration of active account plus up to 30 daysService delivery and post-cancellation processing
Booking and appointment dataDuration of active account plus up to 30 daysService delivery and orderly account closure
Billing and invoice records7 years after the transactionBelgian tax and accounting obligations
Error logs and diagnosticsUp to 90 daysDebugging, security, and service stability
Server access logsUp to 90 daysSecurity monitoring and incident response
Backup copiesDeleted within 90 days of account deletionDisaster recovery
CRM recordUntil deletion is requested, unless legal retention appliesBusiness administration

Children

The Service is not directed to children under the age of 18, and we do not knowingly collect personal data directly from children.

External links

The Service may link to external websites or services that are not operated by us. We are not responsible for the content, security, or privacy practices of third-party sites.

Governing language

This Privacy Policy is drafted in English. If a translated version is provided, it is for convenience only. In the event of any inconsistency, the English version prevails.

Changes to this policy

We may update this Privacy Policy from time to time to reflect operational, legal, or regulatory changes. When required by law, we will provide notice of material changes before they take effect.

Contact

If you have questions or concerns about this Privacy Policy or our data practices, contact us at [email protected].