Legal
Privacy notice
This is a site of essays and two biographies. It sets no cookies, runs no advertising trackers, has no contact form and no mailing list, and loads its typefaces from its own server rather than someone else’s. The list of what is actually processed is short, and this page is it.
Last updated 27 September 2026 · Company details are in the legal notice.
In short
Three things are processed, and none of them identify you to us.
- Server logs
- Page counts
- Your email
Our host records the requests it serves, your IP address among them, for a few days. That is how a page is delivered and kept from being attacked. Nothing is copied out of it.
Cookieless analytics tell us that an essay was read a hundred times and roughly from where. They store no identifier on your device and build no profile of you.
If you write to us, we have what you wrote. It is treated as confidential whether or not it leads to a mandate, and it is never used for marketing.
Who is responsible for your data
The controller is Gennoor BV, an independent advisory practice established in Belgium. Its registered office, enterprise number and VAT number are in the legal notice.
For anything about personal data — a question, a request to exercise a right, or a complaint — write to contact@gennoor.ai. Both principals read that address. The practice is small enough that it is not required to appoint a data protection officer under art. 37 GDPR, and has not appointed one; that address is the contact point.
What happens when you read a page
Serving a page requires our host to handle the request, and its logs record the technical facts of that request:
- your IP address;
- the page requested, and the date and time;
- the HTTP status and the amount of data sent;
- your browser's user-agent string, and the referring page if your browser sent one.
Purpose. Delivering the site, keeping it available, and diagnosing faults and abuse — a denial-of-service attempt is visible in nothing else.
Legal basis. Legitimate interests, art. 6(1)(f) GDPR: operating and defending one's own website. There is no realistic way to serve a page without processing the address it is being sent to, and the logs are not used for anything else.
These logs stay with the host. They are not exported into any other system, not combined with the analytics, and not used to work out who an individual reader is.
The text and images of the page are fetched, at the moment you request it, from the content management system described in the legal notice. That fetch is made by our server, not by your browser: nothing about you reaches it, and it sets nothing on your device.
Analytics, and why there is no cookie banner
We want to know which essays get read. We do not want to know who read them, and we are not willing to hand a reader to an advertising network to find out. So the site uses Fathom Analytics (Conva Ventures Inc., Canada), which is built for that trade-off:
- it sets no cookies and stores nothing on your device;
- it does not track you across other websites, and cannot — there is no shared identifier to track you with;
- it does not fingerprint your browser;
- it does not retain your IP address. The address is used in passing to derive a country, then discarded;
- what remains is aggregate: pages viewed, referring sites, country, device type and browser, as counts.
Why you are not being asked to accept cookies
A consent banner is required, under art. 129 of the Belgian Electronic Communications Act implementing art. 5(3) of the ePrivacy Directive, when a site stores information on your device or reads information already stored there. This site does neither — no cookies, no local storage, nothing. That, and not a judgement about how polite the analytics are, is why there is no banner to dismiss. To the extent any transient processing takes place before the data is aggregated, it rests on legitimate interests, art. 6(1)(f): knowing whether published work is read at all.
The one exception is not a reader's: editing this site sets a single cookie that switches the editor's own view to unpublished drafts. It is set only after a signed-in Studio session asks for it, it holds no personal data, and nobody reading the site ever receives it.
If you would rather not appear even in a count, a tracker-blocking extension or your browser's own blocking will stop the request, and nothing on the site depends on it.
When you write to us
There is deliberately no form on this site. The only way to reach the practice is to write to contact@gennoor.ai or to approach a principal on LinkedIn, which means you decide what we receive. Ordinarily that is your name, your email address, your role and organisation, and whatever you have chosen to tell us about the situation.
Purpose. Reading your note, replying to it, and taking the conversation forward if there is one to have.
Legal basis. Art. 6(1)(b) GDPR where the exchange is a step towards an engagement, and art. 6(1)(f) otherwise — answering someone who has written to us is the plainest legitimate interest there is.
Anything sent to that address is treated as confidential, whether or not it leads to a mandate. It is not added to a mailing list, not used for marketing, and not passed to anyone outside the practice. Where a first note describes a board matter in confidence, it is handled the way the engagement itself would be.
Please do not send special category data — health, political opinions, trade union membership and the rest of art. 9 GDPR — in a first note. It is almost never needed to establish whether there is a mandate, and an unsolicited email is not a secure channel for it.
What this site deliberately does not do
Most of a privacy notice is usually taken up with practices to disclose. It is more useful to say what is absent, because each of these is a deliberate build decision rather than an oversight:
- No cookies of any kind for a reader — not analytics, not preference, not "strictly necessary". None are set.
- No browser storage — no localStorage, no sessionStorage, no IndexedDB.
- No Google Analytics, and no advertising or conversion pixel from anyone.
- No third-party fonts. Newsreader and Inter are served from this site's own domain. Reading a page here sends no request to Google Fonts, which would otherwise disclose your IP address to a third country before you had done anything at all.
- No social media embeds — no LinkedIn badge, no share buttons, no embedded posts. Only plain links.
- No contact form and no newsletter. There is nothing to submit and no list to join.
- No session recording, heatmaps or A/B testing.
- No profiling and no automated decision-making within the meaning of art. 22 GDPR.
- No sale of data, and no sharing for anyone else's purposes. There is no commercial arrangement under which data about readers of this site goes anywhere.
Links to LinkedIn
The site links to the Gennoor company page and to both principals' LinkedIn profiles. These are ordinary links, not embedded widgets, so while you are on this site LinkedIn is not told you are here.
Once you follow one, you are on LinkedIn and LinkedIn Ireland Unlimited Company becomes the controller for what happens next, under its own privacy policy. If you contact a principal there rather than by email, that message sits in LinkedIn's messaging system as well as being read by us.
Who else sees the data
Three suppliers process personal data on the practice's instructions, under a written processor agreement, and for no purpose of their own:
- Vercel Inc.
- Hosting and delivery of the pagesUnited States, served from European edge locationsData processing addendum incorporating the European Commission’s Standard Contractual Clauses
- Conva Ventures Inc. (Fathom Analytics)
- Aggregate visitor statisticsCanadaEuropean Commission adequacy decision for Canadian commercial organisations
- [TO CONFIRM — the mailbox provider behind contact@gennoor.ai, e.g. Microsoft 365, Google Workspace, Fastmail, Proton]
The content management system behind the site (Sanity AS, Norway) is not in that list, because it holds the practice's own text and images and receives nothing about you: it is read by our server, never by your browser. See how the site is delivered.
Beyond those three, personal data is disclosed only where the law requires it — a binding request from a Belgian authority or a court. There are no advertising partners, no data brokers and no analytics resellers, because there is nothing here for them to receive.
Transfers outside the EEA
Two of the three suppliers sit outside the European Economic Area.
United States — hosting
Pages are served from European edge locations, but Vercel Inc. is a United States company and its personnel can access the infrastructure handling them. The transfer rests on the Standard Contractual Clauses adopted by the European Commission, incorporated into Vercel's data processing addendum, together with the technical measures it applies.
Canada — analytics
Fathom Analytics is operated from Canada, which the European Commission has recognised as providing an adequate level of protection for personal data processed by commercial organisations. No further transfer instrument is required. In practice there is very little to transfer: what reaches Canada has already been stripped of your IP address.
A copy of the relevant transfer documentation can be requested at contact@gennoor.ai.
How long anything is kept
- Server logs — kept by the host on its own short operational schedule, measured in days rather than months, and then deleted. No copy is retained by the practice.
- Analytics — retained as aggregate counts, which do not identify anyone and are kept to allow year-on-year comparison of which essays are read.
- Correspondence that does not lead to a mandate — kept for up to 24 months, so that a conversation resumed a year later does not have to start again, and then deleted.
- Correspondence that becomes a client record — kept for the duration of the engagement and afterwards for as long as the practice may need to account for its advice, and where accounting records are involved for the seven years Belgian law requires.
You can ask for correspondence to be deleted sooner: see your rights below.
Your rights, and how to use them
Under the GDPR you have the following rights over personal data concerning you:
- Access
- A copy of the personal data held about you, and confirmation of what is done with it.
- Rectification
- Correction of anything inaccurate, and completion of anything incomplete.
- Erasure
- Deletion, where there is no longer a reason to keep it. Correspondence that has become a client record is the usual exception.
- Restriction
- A pause on processing while an accuracy or objection question is resolved.
- Objection
- An objection to anything done on the basis of legitimate interests — which, on this site, is the server logs and the statistics.
- Portability
- A machine-readable copy of data you provided, where it is processed by automated means on the basis of consent or a contract.
- Human decisions
- Nothing here is decided automatically, and no profiles are built — so there is no automated decision to contest.
How to exercise them
Write to contact@gennoor.ai. No particular form of words is needed and there is no charge. You will have an answer within one month; if a request is genuinely complex we may extend that by a further two months, and will tell you within the first month if so.
We may need to establish that you are who you say you are before acting — disclosing a mailbox to the wrong person would be the breach, not the safeguard. Note also the honest limit of clauses 02 and 03: in the logs and the statistics there is nothing tying a record to you as a person, so an access request there cannot be answered with your data specifically. It can be, and will be, answered fully for correspondence.
Complaining to a supervisory authority
If you think personal data has been handled wrongly, we would rather hear it first and put it right. You are entitled to go straight to a regulator, and nothing here is a precondition for doing so.
The competent authority for Gennoor BV is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35 / Rue de la Presse 35, 1000 Brussels, +32 2 274 48 00, contact@apd-gba.be, dataprotectionauthority.be.
You may also complain to the supervisory authority of the EU or EEA country where you live or work, and you have the right to a judicial remedy.
Security
The site is served only over HTTPS. Because there is no reader account, no form and no database of readers behind it, there is no store of visitor data to be breached — the strongest security measure available is not collecting the data in the first place, and that is the one relied on here.
Editing the site is a separate surface: it requires a sign-in held only by the two directors, and what it reaches is the practice's own published text, not a store of information about readers.
Correspondence is a different matter again: it sits in a mailbox, protected by the provider's controls and by multi-factor authentication on the accounts that reach it. Email in transit is not a secure channel by nature; if something genuinely sensitive needs to reach us, say so in a first note and a better channel will be arranged.
Children
The site is written for boards, executives and investors. It is not directed at children, nothing on it is designed to appeal to them, and no personal data is knowingly collected from anyone under 16. If you believe a child has sent us personal data, write to contact@gennoor.ai and it will be deleted.
Changes to this notice
This notice is dated. It will change if the site does — if a form is ever added, if the analytics are replaced, if a supplier changes — and the date at the top is the date the wording last changed, not the date of the last deployment.
Where a change materially affects how personal data is handled, it will be described here rather than made silently. The version in force when you dealt with the practice can be requested at contact@gennoor.ai.
Also
Company details and terms of use
The legal notice carries the statutory identification of Gennoor BV — registered office, enterprise and VAT numbers — along with copyright, quotation terms and applicable law.