Last updated: 9 September 2026
Admitura is operated by Admitura – Pieter Beirnaert, [postal address], Belgium, enterprise number BE 0XXX.XXX.XXX. Privacy questions: privacy@admitura.com or the form at the bottom of this page.
Two roles. For the accounts, billing, and usage data we need to run Admitura itself, we are the controller and this policy applies. For everything inside a workspace — the forms an organization builds, the requests people submit to it, reviews and scores — that organization is the controller and we only process the data on its behalf as a processor, under our Data Processing Agreement.
Admitura stores the data you and your organization put into it: workspace and account details (name, work email, a hashed password), the intake forms your organization builds, the requests people submit through them (including the submitter's name and email), and the reviews, scores, comments, and workflow history your team creates while processing those requests.
We also keep operational records needed to run the service securely and to bill for it: sign-in verification codes, audit log entries, email delivery state, server logs with IP addresses (kept briefly for security and abuse prevention), and billing details held by our payment provider — we never see full card numbers. We do not sell data, and we do not use your data to train AI models.
Application data is stored in a managed PostgreSQL database in the EU/EEA and the application runs on managed cloud infrastructure in the EU. Access to production data is limited to the operator of the service. We share data only with the providers we need to run Admitura, each bound by a data-processing contract:
Where a provider is outside the EEA, transfers are covered by the EU Standard Contractual Clauses or the EU–US Data Privacy Framework. We may also disclose data where the law requires it or to protect the rights, safety, or property of Admitura, its customers, or others.
Admitura uses only the cookies required to sign you in and keep your session secure. There are no advertising or cross-site tracking cookies, so no cookie banner is needed.
We measure page views using our hosting provider's built-in analytics. It sets no cookies, stores nothing on your device, and does not follow you across other websites. To count visits it processes your IP address and browser user agent, which it discards after deriving an anonymous, non-reversible visit identifier. We rely on our legitimate interest in understanding how the service is used.
If you submitted a request to an organization using Admitura, that organization decides how your submission is processed and for how long it is kept. Requester accounts can view and update their own submissions through the portal. For questions about a specific submission, contact the organization you submitted to — they administer the workspace that holds your data. If you contact us instead, we will point you to them and help them respond.
Workspace data is kept for as long as the workspace exists. When a workspace is deleted it is scheduled for permanent erasure after a short grace period (currently 7 days) and then removed from production along with any files uploaded to it; backup copies rotate out within 30 days.
When someone in a workspace deletes an individual request it goes to that workspace's trash, where it can be restored for 30 days. After that it is permanently deleted, together with its attachments. Messages sent through our feedback and privacy request forms are kept for 24 months so we can show how a request was handled, then deleted.
Server logs are kept for at most 30 days. Invoicing records are kept for the period Belgian tax law requires (currently 7 years). Unverified sign-ups that never complete are removed periodically.
Under the GDPR you can ask to access, correct, delete, or export the personal data we hold about you, to restrict or object to certain processing, and to withdraw consent where processing is based on it. Use the form below or email privacy@admitura.com. We answer within 30 days. If you are unhappy with our answer you can complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit, www.dataprotectionauthority.be) or your local supervisory authority.
You can ask for your personal data or your organization's entire workspace to be deleted at any time — no account required. Self-service deletion is on our roadmap; until it ships, use the request form below and we'll handle it manually and promptly:
Every request is confirmed by email and completed within 30 days.
We will update this page when our practices change and note the date at the top. For significant changes we notify workspace administrators by email or in-app.
Use this form for any privacy question, data request, or deletion request. It goes straight to the operator of the service, and you'll get a confirmation by email.