AdmituraAdmitura

Privacy Policy

Last updated: 17 August 2026

Who is responsible

Admisio is operated by Admitura – Pieter Beirnaert, [postal address], Belgium, enterprise number BE 0XXX.XXX.XXX. Privacy questions: privacy@admisio.app or the form at the bottom of this page.

Two roles. For the accounts, billing, and usage data we need to run Admisio itself, we are the controller and this policy applies. For everything inside a workspace — the forms an organization builds, the requests people submit to it, reviews and scores — that organization is the controller and we only process the data on its behalf as a processor, under our Data Processing Agreement.

What we store

Admisio stores the data you and your organization put into it: workspace and account details (name, work email, a hashed password), the intake forms your organization builds, the requests people submit through them (including the submitter's name and email), and the reviews, scores, comments, and workflow history your team creates while processing those requests.

We also keep operational records needed to run the service securely and to bill for it: sign-in verification codes, audit log entries, email delivery state, server logs with IP addresses (kept briefly for security and abuse prevention), and billing details held by our payment provider — we never see full card numbers. We do not sell data, and we do not use your data to train AI models.

Why we process it (legal basis)

  • To provide the service you signed up for (contract): accounts, workspaces, notifications, support.
  • To bill and keep records (contract and legal obligation): invoices and payment state.
  • To keep the service secure and prevent abuse (legitimate interest): rate limiting, sign-in verification, audit logs, server logs.
  • To tell you about important changes to the service or these terms (contract / legitimate interest). We do not send marketing email without your consent.

Where it lives and who we share it with

Application data is stored in a managed PostgreSQL database in the EU/EEA and the application runs on managed cloud infrastructure in the EU. Access to production data is limited to the operator of the service. We share data only with the providers we need to run Admisio, each bound by a data-processing contract:

  • Vercel Inc.Application hosting, edge network, file (blob) storage, and cookieless usage analytics (EU (Frankfurt) compute; US-headquartered).
  • Railway Corp.Managed PostgreSQL database hosting (EU (europe-west4) region; US-headquartered).
  • Resend Inc.Transactional email delivery (verification codes, notifications) (US-headquartered; EU sending region where available).
  • Stripe Payments Europe Ltd.Subscription billing and payment processing (billing contact and payment data only) (Ireland / US).
  • OpenRouter Inc. and its underlying model providersOptional AI features (draft assessments, form-building assistance). Only used when an organization turns AI features on; only the content of the request being processed is sent (US; model providers vary — no data is used for model training).

Where a provider is outside the EEA, transfers are covered by the EU Standard Contractual Clauses or the EU–US Data Privacy Framework. We may also disclose data where the law requires it or to protect the rights, safety, or property of Admisio, its customers, or others.

Cookies and analytics

Admisio uses only the cookies required to sign you in and keep your session secure. There are no advertising or cross-site tracking cookies, so no cookie banner is needed.

We measure page views using our hosting provider's built-in analytics. It sets no cookies, stores nothing on your device, and does not follow you across other websites. To count visits it processes your IP address and browser user agent, which it discards after deriving an anonymous, non-reversible visit identifier. We rely on our legitimate interest in understanding how the service is used.

Your organization controls its workspace

If you submitted a request to an organization using Admisio, that organization decides how your submission is processed and for how long it is kept. Requester accounts can view and update their own submissions through the portal. For questions about a specific submission, contact the organization you submitted to — they administer the workspace that holds your data. If you contact us instead, we will point you to them and help them respond.

How long we keep it

Workspace data is kept for as long as the workspace exists. When a workspace is deleted it is scheduled for permanent erasure after a short grace period (currently 7 days) and then removed from production along with any files uploaded to it; backup copies rotate out within 30 days.

When someone in a workspace deletes an individual request it goes to that workspace's trash, where it can be restored for 30 days. After that it is permanently deleted, together with its attachments. Messages sent through our feedback and privacy request forms are kept for 24 months so we can show how a request was handled, then deleted.

Server logs are kept for at most 30 days. Invoicing records are kept for the period Belgian tax law requires (currently 7 years). Unverified sign-ups that never complete are removed periodically.

Your rights

Under the GDPR you can ask to access, correct, delete, or export the personal data we hold about you, to restrict or object to certain processing, and to withdraw consent where processing is based on it. Use the form below or email privacy@admisio.app. We answer within 30 days. If you are unhappy with our answer you can complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit, www.dataprotectionauthority.be) or your local supervisory authority.

Data deletion

You can ask for your personal data or your organization's entire workspace to be deleted at any time — no account required. Self-service deletion is on our roadmap; until it ships, use the request form below and we'll handle it manually and promptly:

  • Workspace owners: submit the request from your admin email address to have your workspace and all its data permanently deleted.
  • Individual accounts and submitters: ask to have your account or a submission's personal data removed. Where a submission belongs to an organization's records, we will coordinate with that organization.

Every request is confirmed by email and completed within 30 days.

Changes to this policy

We will update this page when our practices change and note the date at the top. For significant changes we notify workspace administrators by email or in-app.

Submit a privacy request

Use this form for any privacy question, data request, or deletion request. It goes straight to the operator of the service, and you'll get a confirmation by email.

© 2026 Admitura · Home · Terms · Privacy · DPA