GDPR · Regulation (EU) 2016/679

Privacy Policy

Last updated: 21 July 2026. The protection of your personal data is a priority.

This is an automatic translation of the French privacy policy. The French version is binding.

View the French version

This site applies the principles of the GDPR: lawfulness, minimisation, purpose limitation, security and transparency (privacy by design & by default).

1. Data controller

Floriane Bonnier, Gemeenteraadslid MR+ — Stad Brussel.

Data controller & data protection contact:

  • Email : floriane.bonnier@brucity.be
  • GSM : +32 499 14 18 62

2. Data collected, purposes and legal bases

No special categories of personal data are requested. Please do not share health data or opinions via the chat.

ProcessingDataPurposeLegal basisRetention
AI chatQuestion, answer, timestamp, anonymised session ID (SHA-256 hash), category, urgency flag. No IP address stored.Answer, improve quality and securityLegitimate interest (6.1.f)12 months max
Contact formName, email, messageHandle your requestConsent (6.1.a)Processing + 12 months
Report AI answerReason, optional contact, log IDHuman editorial control, qualityLegitimate interest + AI Act24 months
Chat session cookieAnonymous ID (localStorage)Conversation continuityePrivacy exemptionUntil deletion

3. Recipients

  • Floriane Bonnier and her team (strictly limited access).
  • GDPR-compliant technical subcontractors (hosting, AI) bound by contract (art. 28 GDPR).
  • No resale, no advertising transfer, no commercial profiling.

4. Transfers outside the EU

Data is hosted in the European Economic Area. Any transfer relies on an adequacy decision or standard contractual clauses (art. 44-49 GDPR).

5. Your rights (art. 15-22 GDPR)

  • Access, rectification, erasure (‘right to be forgotten’).
  • Restriction, objection, portability.
  • Withdraw consent at any time.
  • No automated individual decision-making — the AI does not take legal decisions.
  • Lodge a complaint with the Belgian Data Protection Authority (APD).

6. Security

TLS encryption in transit, access segregation, RLS policies at database level, minimal logging. Breach notification within 72 hours to the DPA (art. 33 GDPR).

7. AI transparency (AI Act EU 2024/1689)

In accordance with Article 50 of the European AI Regulation, you are clearly informed that your messages are processed by an AI system. The AI does not make automated decisions producing legal effects.

8. Minors

This site is not targeted at minors under 13. Young users are encouraged to consult their parents.

9. Changes

This policy may evolve to reflect changes in EU law (AI Act, Data Act, NIS2). Major changes will be announced on the site.