Privacy Policy
This policy explains what personal data we collect when you visit aster-medical.be or contact us, why we collect it, who we share it with, and what rights you have.
1. Who is responsible for your data
The data controller for this website is:
Apogalenos Ltd
71-75 Shelton Street
Covent Garden
London, WC2H 9JQ
United Kingdom
Company number: 16125281 (registered in England and Wales)
Website: www.aster-medical.be
Contact: contact form
If you have any question about this policy or about how we handle your data, contact us using the details above.
2. What we collect and why
2.1 When you visit the website
Our server records standard technical information each time a page is requested, including your IP address, the date and time of the request, the page requested, and your browser's user-agent string. We use this to deliver the website, keep it secure, and diagnose faults. Our legal basis is our legitimate interest in operating a secure website (Article 6(1)(f) GDPR).
2.2 Analytics and visitor identification (only with your consent)
If you accept the relevant cookies in our consent banner, we use:
- Google Analytics 4 to understand how visitors use the site — which pages are viewed, how long visitors stay, and how they arrived. We have enabled IP anonymisation.
- Snitcher Radar to identify the company that a visit originates from, based on the visiting network's IP address. This helps us understand which organisations are interested in Aster.
Neither of these is loaded until you give consent. Our legal basis is your consent (Article 6(1)(a) GDPR), and for the storage of information on your device, your consent under Article 129 of the Belgian Code of Economic Law (which implements the ePrivacy Directive). You can withdraw your consent at any time — see section 6.
2.3 When you submit the contact form
If you fill in the contact form, we collect the name, email address, telephone number, and role you provide, together with your message. We use this solely to respond to your enquiry and to follow up on it. Our legal basis is your consent and, where your enquiry relates to a potential contract, the steps necessary to enter into that contract (Article 6(1)(a) and (b) GDPR).
Please do not include sensitive information (for example, health data or patient information) in the contact form.
3. Cookies and similar technologies
We use the following cookies and local storage. Nothing beyond the strictly necessary category is set until you consent.
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
aster_consent_v1 |
This website | Stores your cookie choices so we do not ask again on every page. | Local storage | Until you clear it |
_ga, _ga_MWPBBL0XM9 |
Distinguishes visitors and sessions. | Analytics | Up to 13 months | |
snitcher_device_id, snitcher_session |
Snitcher | Identifies a device and session so a visit can be attributed to a company. | Visitor identification | Up to 12 months |
You can change or withdraw your choices at any time using the Cookie settings button shown at the bottom-left of every page.
3.1 What Snitcher Radar processes
When you consent to visitor identification, Snitcher Radar processes your IP address in order to determine which company the visit originates from, and discloses that company information to us. We do not receive your name or your individual identity from this service.
Snitcher acts as our processor for this activity, under a data processing agreement. Separately, Snitcher also acts as an independent controller for a limited set of technical data used to operate, secure and improve its own service. That processing is carried out on an aggregated or pseudonymised basis, is not linked back to us or to our website, and does not involve retaining identifiable personal data such as full email addresses or form contents.
4. Who we share your data with
We do not sell your personal data. We share it only with the service providers below, each of which acts as our processor under a data processing agreement, and only to the extent needed to provide their service.
| Provider | Purpose | Location |
|---|---|---|
| Google Ireland Limited (Google Analytics), with Google LLC as sub-processor | Website analytics | Ireland (EU), with transfers to the United States |
| Snitcher (Radar) | Company-level visitor identification | Netherlands (EU) |
| Splitforms | Delivery of contact form submissions | United States (no EU data residency) |
| IONOS France (IONOS SARL) | Hosting and serving the website | France (EU) |
5. Transfers outside the EEA
We are established in the United Kingdom. Where we receive personal data from visitors in the EU/EEA, that transfer is covered by the European Commission's adequacy decision for the United Kingdom of 28 June 2021.
Some of our providers are established outside the European Economic Area. Where personal data is transferred to the United States, we rely on the following safeguards.
Google. Google LLC is certified under the EU-US Data Privacy Framework. Google's data processing terms also incorporate the European Commission's Standard Contractual Clauses (Modules 2 and 3) as a supplementary safeguard. Google Ireland Limited is our contracting processor, with Google LLC acting as its sub-processor.
Splitforms. Splitforms is not certified under the EU-US Data Privacy Framework. Transfers to Splitforms are covered by the European Commission's Standard Contractual Clauses (Module 2, controller to processor), incorporated into our agreement with them, together with a transfer impact assessment. Splitforms processes data on servers in the United States and does not currently offer EU data residency.
Snitcher B.V. is established in the Netherlands and processes personal data within the EU. Its approved sub-processors are listed in its data processing agreement; most are located in the EU, with error logging in the United States and content delivery provided globally. Where a sub-processor is outside the EEA, the transfer is covered by the Standard Contractual Clauses incorporated into that agreement.
You can request a copy of the safeguards we rely on by contacting us using the details in section 1.
6. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectify data that is inaccurate or incomplete.
- Erase your data where we no longer have a lawful reason to keep it.
- Restrict how we use your data in certain circumstances.
- Object to processing based on our legitimate interests.
- Data portability — receive data you gave us in a structured, machine-readable format.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before you withdrew it.
To exercise any of these rights, use the contact form on our home page and state clearly which right you wish to exercise. We will respond within one month. We may ask you to confirm your identity before acting on a request.
If you believe we have handled your data unlawfully, you have the right to lodge a complaint with a supervisory authority. As our company is established in the United Kingdom, our lead supervisory authority is the UK Information Commissioner's Office. If you are in Belgium or another EU member state, you also have the right to complain to your local supervisory authority — for Belgium, the Belgian Data Protection Authority.
United Kingdom — Information Commissioner's Office (ICO)
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
ico.org.uk
Tel: +44 303 123 1113
If you are in Belgium, you may instead contact the Belgian Data Protection Authority:
Gegevensbeschermingsautoriteit / Autorité de protection des données
Drukpersstraat 35, 1000 Brussels, Belgium
www.gegevensbeschermingsautoriteit.be
contact@apd-gba.be
7. How long we keep your data
- Server logs: up to 12 months.
- Analytics data: up to 14 months, then deleted or aggregated.
- Visitor identification data: up to 12 months.
- Contact form enquiries: up to 24 months after our last contact with you, unless a contract or legal obligation requires longer.
- Your consent record: kept for as long as needed to demonstrate that consent was validly given.
8. Whether you must provide your data
You are not obliged to provide us with any personal data. However, if you do not provide the information requested in the contact form, we will not be able to respond to your enquiry. Providing your data is never a statutory or contractual requirement, and there is no consequence for refusing beyond our inability to reply.
9. Automated decision-making
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. Snitcher Radar identifies the company associated with a visit, but this does not result in any automated decision about you as an individual.
10. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit, access controls, and keeping our software up to date. No method of transmission or storage is completely secure, but we work to protect your data against unauthorised access, alteration, or loss.
11. Children
This website is intended for healthcare professionals and is not directed at children. We do not knowingly collect personal data from anyone under 16.
12. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date at the top of this page. If the change is significant, we will make that clear on the website.
13. Contact
Questions about this policy or about your data can be sent through the contact form on our home page.