This is the website of Haystack
Our postal address is:
Romeinse straat 4
Our number for value added tax is BE 0474 816 879.
Our company is located at the following address:
Romeinse straat 4
Your personal data, our responsibility
On our website we will collect personal data. These data will be managed by our company.
When you visit our site we will keep the following data:
- your domain name (ip address)
- your e-mail address in case you put messages/questions on our website
- your e-mail address in case you communicate this to us
- your e-mail address in case you participate in one of our discussions forums
- all information related to the pages of other sites that you have consulted in order to reach our site – all information related to the pages that you have consulted on our website
- all information that you have supplied to us voluntarily (such as research information and/or site-registration)
This information will be used:
- for improving the content of our website
- for being able to contact you for direct marketing purposes
In case we receive or transfer data on our website, we will always use the technologies for codification recognised as being the normal standard within the IT sector. We have made use of the necessary security measures to avoid loss, unjustified use or change of information that we may have received on our site/ In case we would receive or transfer sensitive information, such as for example financial information, we will make use of a secured server.
Haystack and GDPR
Haystack’s Support Director leads the GDPR internal team which consists of cross functional business process owners. Each of them is responsible for his/her assigned business process and the identification, collection, use and disclosure of personal data in it. In close collaboration with the whole team, we are committed to create and communicate clear processes and policies which allow all employees at Haystack to respect the privacy standards set by this internal team and as such comply to GDPR.
Privacy is not new to Haystack: it has always been top of mind at Haystack being a market research company processing personal data. We take great care to protect privacy of our employees, clients and not in the least our panelists and respondents. The principals we adoperate are the following four:
- Anonymizing or pseudonymizing data where possible
- Minimizing the amount of data (only those data relevant to the research)
- Securing personal data to only those parties concerned and always subject to written and mutually agreed conditions (employing tec, org, phys. security measures to protect the data in our care)
- Respecting the rights of the individuals
In concreto, we are, as we write this, fully engaged in updating all privacy notices (data processor agreements) to both clients and field suppliers, panelists and recruiters in accordance to GDPR. For those parties processing personal data on our behalf, we foresee the necessary contracts (addenda) to specify roles and responsibilities when processing personal data or when and how to notify us in case of security events. Moreover, we are implementing unambiguous written consents for individuals participating in our research projects and we aim to communicate transparently about the processing of his/her personal data further on.
Individuals have the right to request erasure of their personal data, access them or transfer those data. Haystack is preparing processes which strive to meet these requests in a reasonable way. An incident response policy is currently elaborated in order to notify data protection authorities in case of data breaches.
Last but not least, we have been since 2016 organizing awareness sessions for all our employees. We continue with more specific training sessions preceding May 25th 2018. After this date, we will continuously monitor that all processes and policies are respected by the concerned parties.
– via e-mail: Elke De Brabandere, Support Manager: firstname.lastname@example.org
– via phone: + 32 (0) 16 62 11 58
– by post: Romeinse straat 4 – 3001 Heverlee – Belgium
• In case you send us your postal address via the web It is possible that you will receive periodical mailings from us with information on products and services and upcoming events. In case you do not want (anymore) to receive such information, please contact us on the above-mentioned address. It is possible that you will receive information on companies/organisations with whom we are connected. These companies/organisations may be part of the following sectors:
– commercial partners In case you do not want to receive mailings from these companies/organisations (anymore), please contact us on the above-mentioned address. PS: In case of the latter you should not forget to give us your exact name and address (correctly spelled). We commit ourselves to delete your data from the list that we use collectively with other companies/organisations.
• In case you have communicated your telephone number to us via the web It is possible that you will be contacted by phone by our company with reference to information about our products and our services for upcoming events. In case you do not want (anymore) to receive such calls, please contact us on the above-mentioned address. It is possible that you will be contacted by other companies/organisations with whom we have contractual obligations. These companies/organisations may be part of the following sectors: – commercial partners In case you would not like to receive (anymore) such calls, please contact us at the above-mentioned address. PS: In case of the latter you should not forget to give us your exact name and address (correctly spelled). We commit ourselves to delete your data from the list that we use collectively with other companies/organisations.
• In case you communicate us your mobile phone number via the web It is possible that you will be contacted via text messages (SMS/MMS/ed) to supply you with information with reference to our products and our services for upcoming events (for direct marketing purposes) on the condition that you have given us your explicit approval or in case you are already customer with us and you have given us your number. In case you do not want (anymore) to receive such messages, please contact us on the above-mentioned address. It is possible that you will receive text messages for direct marketing purposes from other companies/organisations with whom we have contractual obligations on the condition that you have given us your explicit approval. These companies/organisations may be part of the following sectors: – commercial partners In case you do not want us to communicate your mobile phone number anymore to other companies/organisations for receiving of such text messages, please contact us on the above mentioned address. PS: In case of the latter you should not forget to give us your exact name and address (correctly spelled). We commit ourselves to delete your data from the list that we use collectively with other companies/organisations.
• In case you communicate us your e-mail address via the web It is possible that you will be contacted by our company via e-mail to supply you with information with reference to our products and our services for upcoming events (for direct marketing purposes) on the condition that you have given us your explicit approval or in case you are already customer with us and you have given us your e-mail address. In case you do not want (anymore) to receive such e-mails, please contact us on the above-mentioned address. It is possible that you will receive e-mails for direct marketing purposes from other companies/organisations with whom we have contractual obligations on the condition that you have given us your explicit approval. These companies/organisations may be part of the following sectors: – commercial partners In case you do not want us to communicate e-mail address anymore to other companies/organisations for receiving of such text messages, please contact us on the above-mentioned address. PS: In case of the latter you should not forget to give us your exact name and address (correctly spelled). We commit ourselves to delete your data from the list that we use collectively with other companies/organisations.
• In case you do not want to receive any mails or phone calls, please contact the Robinson-list of the Belgian Association for Direct Marketing (online: www.robinsonlist.be, free phone number: 0800-91 886 or by post: BDMV, Robinson list, Buro&Design Center, Heizel Esplanade B46, 1020 Brussels, Belgium)
• On request we will allow visitors to our site to access all information on them that we keep on record. In case you would like such access, please contact us on the above mentioned address.
• On request we allow visitors to correct information that we have kept on record from them. In case you do want to correct such personal information, please contact us on the above mentioned address.
This website uses Google Analytics, a web analytics service provided by Google, Inc. (“Google”).
Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google on servers in the United States . Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage.
By using this website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.
Haystack Mobile Application
What is the purpose of the Haystack application?
The Haystack application is a mobile app designed for your mobile phone, or for another mobile device, which can be used to take part in online questionnaires or online communities such as diaries. When using the app, it is possible to upload pictures, photos, movies etc. if desired. The Haystack app can also use accelerometer data, gyroscope data and real-time location (based on information provided by your device OS). The application sends data, through the internet connection of your mobile device, to the online web environment of the Haystack app.
Account & Data Deletion
At any time, you can delete your account and uninstall the application.
Going Off The Grid
To temporarily stop any collection of information, just uninstall the Haystack application.
Sensor Data Used
Haystack can use accelerometer data, gyroscope data and real-time location (based on information provided by your device OS). These sensor data will not be collected for every survey.
Last updated: Friday, 3 March 2017
Please be aware that you may not use the Application if you are under sixteen (16) years of age.
A. Information collected through the application
Personal information is information which identifies you as an individual, whether directly or indirectly through the combination with other information held by Haystack.
In order for you to download and use the Application, Haystack requires you to provide personal information such as your e-mail address and your confirmation on the age restriction. After verification of your e-mail address, Haystack will store a Haystack ID number which it will use for automated profiling as explained in section B below. In addition, Haystack will collect and process your real-time location based on information provided by your device operating system (‘OS’).
Haystack also collects non-personal information that does not directly or in combination with other information identifies you as an individual.
The non-personal information collected by Haystack may be your type of device, type of OS, type of mobile browser, information on your use of the Application, accelerometer data and gyroscope data. Further, depending on your device make and type and your permissions, Haystack may also collect the following non-personal data supplied by the device’s OS: activity information, step detection and step count, Bluetooth information and battery information.
In order to improve its profiling algorithms, Haystack may request and collect your feedback on assumptions made by Haystack based on the collected information.
B. Purpose of collection and use of information
Haystack collects and uses personal information for the following specific purposes:
- to build profiles that may allow Haystack to detect places you visit and frequent, when and by what means you are travelling and to make an estimated guess of your age, gender and routine behavior;
- to send you adequate information regarding the application
- to respond to your comments and problems
- for Haystack’s data analysis
- to investigate potentially unlawful use of the application
Haystack may also use your pseudonymised profile to build an interactive map and may share such map with third parties for sales presentation purposes.
Haystack only collects personal information that is adequate, relevant and limited to what is necessary for the above purposes (data minimization).
Non-personal information is used to refine the algorithms that detect transportation modes, to find battery-efficient triggers for the start and stop of transport detection logging and to conduct analytics in order to improve the profiling algorithms and Application.
C. Third party recipients of information
Haystack may disclose your personal and non-personal information to third party recipients such as:
- Haystack’s service providers, such as hosting providers and providers of data analysis, IT services, and other similar services requested by Haystack;
- Other recipients based on legitimate interests as permitted under applicable law;
- A third party as required by applicable law, to comply with legal procedures, to respond to requests from public authorities, to enforce this policy and to protect Haystack’s rights;
- A third party in the event of any merger, sale or transfer or other disposition of all or any portion of Haystack’s business, assets or stock in which said third party is involved.
Transfers only relate to personal information which is adequate, relevant and limited to what is necessary in relation to the purpose for which it is transferred. Other than as set forth above, Haystack will not transfer any of your personal information to third parties without your explicit consent.
D. Security, reliability and retention of information
Haystack has implemented appropriate technical and organizational measures (such as explicit opt-in and pseudonymisation), which are designed to implement data-protection principles (such as data minimization) in an effective manner and integrated the necessary safeguards into the processing in order to protect information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to personal information, and against all other unlawful forms of processing.
For the avoidance of doubt, Haystack defines pseudonymous data as personal data processed in such a manner that they can no longer be attributed to you without the use of additional information, which Haystack keeps separately and subject to technical and organizational measures to this effect.
Haystack takes reasonable steps to ensure that any personal information in its possession is accurate, current and reliable for the purposes set out above.
All personal data collected in the European Economic Area (EEA) will be stored and processed within the EEA. Haystack will only retain your personal data for the minimum period necessary to serve the purposes as set out above, unless a longer retention period is required by law. Non-personal information may be retained without limitation in time.
E. Your rights
In respect of the collection and use of your personal information, you may:
- ask Haystack whether it processes personal data about you, for which purposes, the categories of personal data concerned, to which recipients the information has been disclosed, where possible, the envisaged period for which the personal data will be stored (or, if not possible, the criteria used to determine that period);
- inquire with Haystack about the appropriate safeguards relating to the transfer to a third;
- ask Haystack a copy of the personal data undergoing processing (including for data portability purposes) and have it rectified;
- object against the further processing and request erasure of your personal information on legitimate grounds;
- request that the processing of your personal information is restricted by Haystack;
- request not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you;
In order to do so, you should send Haystack a letter on the address provided below or an e-mail to email@example.com with a copy of your identity card or other proof of your identity. Haystack will undertake the necessary action without undue delay and provide information on action taken (or the absence of any such action) within 30 days.
Romeinse straat 4
You may also lodge a complaint with a supervisory authority in case of breach of the applicable privacy laws by Haystack.
You may at any time immediately stop any collection and processing of personal data by Haystack by uninstalling or deleting the Application. Uninstalling the Application will also delete the Haystack ID number from your mobile device.
If you want to keep the Application but stop the collection of your real-time location data, you may opt-out through the OS settings of your device.
F. Data controller coordinates
Romeinse straat 4