Privacy and contact
Last updated: 26 September 2026.
Who operates this website?
BudgetWebsite, company and VAT number BE 1032.969.925. Contact: hallo@budgetwebsite.be. Once signed in, you can also contact us through your secure workspace.
What data do we use?
When you submit a request, we use your email address, business information and request to prepare the requested proposal and follow up with you. If this becomes an assignment, we use the file contents to build the website, process feedback, record approvals and provide management.
Your workspace may contain messages, files, website contact details, version-specific approvals, the status of your file and — after acceptance — the selected domain and destination for professional-email forwarding. Only your account and authorised staff can access your file.
Sign-in, cookies and browser storage
We use only storage needed for the service you request. A secure session cookie keeps you signed in for up to seven days. Google sign-in temporarily uses a secure OAuth cookie to protect the sign-in process. These cookies are necessary for sign-in and account security; we do not use marketing or advertising cookies.
An email access link works once and expires after 15 minutes. With Google sign-in, we receive your Google account identity and verified email address. We do not receive access to Gmail or Google Drive.
Your unsent request draft is temporarily stored in your browser session storage so it can survive a sign-in or reload. It is removed when you submit the request or choose “Start over”, and disappears no later than the end of the browser session.
Service providers and security
Cloudflare provides hosting, database services, private file storage, security, Turnstile abuse protection and — when you use the included professional address — Email Routing for incoming-mail forwarding. Resend is used for access emails and file notifications. Google is involved only when you choose Google sign-in. Your chosen existing mailbox provider receives the forwarded messages; BudgetWebsite does not keep a separate mailbox containing those messages. These providers process data only for the relevant technical service and under their applicable data-protection terms.
Where a provider processes data outside the European Economic Area, that transfer relies on an applicable legal mechanism such as an adequacy decision or standard contractual clauses.
IP addresses and similar technical data may be processed for delivery, security and rate limiting. Full briefings and files are not written to application logs.
Why are we allowed to use this data?
For your request, account, file and the preparation or performance of an assignment, we rely on Article 6(1)(b) GDPR: processing is necessary to provide the service you request or to take steps before entering into a contract. For security, abuse prevention and reliable operation, we rely on our legitimate interest under Article 6(1)(f). Where the law requires us to retain certain data, Article 6(1)(c) applies.
The checkbox used when submitting a request confirms that you ask us to process the request and that you have read this information; it is not used as consent for advertising.
How long do we keep data?
An email link expires after 15 minutes and a sign-in session after seven days. We keep a request and file for as long as necessary to handle your request and any resulting assignment. Requests that do not become assignments are removed by our maintenance process no later than 24 months without an assignment, together with their file uploads, messages and events. After that, we retain only what is still needed for legal accounting, tax or evidentiary obligations or for establishing, exercising or defending legal claims. Files and file data no longer needed for those purposes are deleted.
Your rights and questions
You may request access, correction, deletion, restriction or portability of your personal data and may object to processing based on legitimate interest. Email hallo@budgetwebsite.be. Not every request can be fully carried out immediately where a legal retention duty or ongoing legal interest prevents this.
You may also lodge a complaint with the Belgian Data Protection Authority.
What you should not send
Do not send passwords, secret keys or complete customer databases through a request or message. For source code or other sensitive files, we will agree on an appropriate channel when needed.