Privacy policy
Last updated: 28 September 2026
This privacy policy explains how IntelVisions ("we", "us") handles personal data in the access portal at apps.intelvisions.nl (the "portal") and in the gate that protects the apps published through it. We process personal data in line with the General Data Protection Regulation (GDPR).
1. Who is responsible
The controller for the processing described here is:
[Owner's full name], trading as IntelVisions (eenmanszaak) Galileistraat [number] 1704 SE Heerhugowaard, the Netherlands Chamber of Commerce (KvK) number: 60511761 E-mail: info@intelvisions.eu Phone: +31 6 16693291
The portal groups people and apps into spaces. Some spaces are run for other organisations, for example a client of ours. For the members and apps of such a space, that organisation decides who is invited and what its apps do. For those spaces we process personal data on the organisation's behalf, as its processor [under a data processing agreement]. Questions about such a space or its apps can also go to that organisation.
2. What the portal does
- You sign in with your Google account. We don't receive or store your Google password.
- The portal shows the apps you have access to.
- Every request to a protected app first passes the gate, which checks whether you may open it.
- Apps are published by members of a space; they run on their own computers and are connected to the portal through a secure tunnel.
3. Personal data we process
| What | Details | Why | Legal basis | How long we keep it |
|---|---|---|---|---|
| Account | Google account identifier, e-mail address, name, link to your Google profile picture, account status, time of your first and last sign-in | To recognise you and let you in | Performance of the service you use (art. 6(1)(b) GDPR); where there is no agreement with you, our legitimate interest and that of the organisation that invited you in controlling access (art. 6(1)(f)) | Until your account is deleted |
| Google Workspace domain | The company domain of your Google account, if any | Only at sign-in, to check whether your organisation lets its members join a space automatically | Legitimate interest (art. 6(1)(f)) | Not stored |
| Memberships and access | The spaces you belong to, your role and status there, the apps shared with you, who invited you | To decide what you may see and open | Performance of the service / legitimate interest (art. 6(1)(b) and (f)) | Until the membership is ended or your account is deleted |
| Invitations | The invited e-mail address, the role, who invited and when | To let the invited person in when they first sign in | Legitimate interest of the inviting organisation (art. 6(1)(f)) | Until accepted, revoked or expired, then deleted after 12 months |
| Portal sessions | A random session identifier (stored only in scrambled, "hashed" form), your IP address and browser identification (user agent), timestamps | To keep you signed in, and for security | Performance of the service / legitimate interest (art. 6(1)(b) and (f)) | A session ends after 8 hours without activity and after 7 days at most; it is deleted within minutes after that |
| Sign-ins on apps | Which app, on which address, when last used | To let you use an app without signing in again for every page | Performance of the service (art. 6(1)(b)) | Ends with your portal session; deleted after at most 7 days of inactivity |
| Audit log | Who did what and when (for example signing in, changes to spaces, apps, members and access, creating tokens), including the IP address. For refused sign-ins without an account, only the domain of the e-mail address is recorded | Security, accountability and resolving problems | Legitimate interest (art. 6(1)(f)) | 12 months |
| API and agent tokens | Name, permissions, when created and last used. The token itself is stored only in hashed form | To let scripts and app connections act on your behalf | Performance of the service (art. 6(1)(b)) | Until revoked or your account is deleted |
| Request logs | IP address, time, requested address, browser identification and response of requests to the portal and apps | Operating the service securely, detecting and blocking abuse | Legitimate interest (art. 6(1)(f)) | Rotated automatically; kept for [at most a few weeks] |
| Abuse protection | IP addresses of requests, checked against lists of known malicious addresses; short-lived counters of sign-in attempts per IP address | Protecting the service against attacks | Legitimate interest (art. 6(1)(f)) | Attempt counters: 1 day. [Addresses that show attack patterns may be shared with the CrowdSec community blocklist, see section 5] |
We also count the amount of data transferred per app per day. These figures are not about individual people.
We do not use your data for advertising, we do not sell it, and the portal contains no analytics or tracking tools.
4. What apps receive about you
When you open a protected app, the gate tells the app who you are:
- an identifier that is specific to that space (not your Google identifier),
- your e-mail address and name,
- your level of access (for example owner or viewer),
in the form of HTTP headers and a digitally signed statement.
Apps are run by us or by members of the space they belong to. What an app does with this information is the responsibility of whoever runs it, under their own privacy information. If an app is set to "public", anyone can open it without signing in, and the gate passes nothing about you to it.
5. Who else receives data
- Google (Google Ireland Limited / Google LLC): you sign in on Google's pages, under Google's privacy policy. Google tells us your account identifier, e-mail address, name and profile picture link, and Google learns that you signed in to our portal.
- Hosting: our server is a virtual private server provided by OVH SAS (Roubaix, France) in a data centre in the European Union. OVH acts as our processor.
- Let's Encrypt (Internet Security Research Group) issues the security certificates for the portal's web addresses. Only web addresses are involved, no personal data about you.
- CrowdSec: our web server checks incoming IP addresses against CrowdSec's lists of malicious addresses. [If an address shows attack patterns, it may be reported to CrowdSec's community blocklist.]
- App operators: see section 4.
- Authorities: only where we are legally obliged to.
6. Transfers outside the European Economic Area
Our server is located in the European Union. Google LLC is based in the United States. Where personal data is transferred to the United States as part of signing in with Google, this is covered by the EU-U.S. Data Privacy Framework, or by the European Commission's Standard Contractual Clauses.
7. Cookies
The portal only uses cookies that are strictly necessary for signing in and for security. Under the Dutch Telecommunications Act (article 11.7a), these don't require your consent.
| Cookie | Purpose | Lifetime |
|---|---|---|
__Host-g8te_session |
Keeps you signed in to the portal | Until you sign out, and at most 7 days |
__Host-g8te_app |
Keeps you signed in to one app's address | Ends with your portal session; the browser keeps it for at most 30 days |
__Host-g8te_state |
A one-time check during signing in to an app | 10 minutes |
Google sets its own cookies on its sign-in pages. Apps you open may set their own cookies; see the information of whoever runs the app.
8. Security
We protect personal data with measures that include encrypted connections (HTTPS) for all traffic, access checks on every request to an app, storing tokens and session identifiers only in hashed form, encrypting the portal's own keys, giving the software and administrators no more access than they need, and keeping an audit log. Only a small number of administrators can manage the portal.
9. Your rights
You have the right to:
- access the personal data we hold about you;
- rectification: your name and e-mail address come from your Google account; change them there, and they are updated the next time you sign in;
- erasure: we delete your account and the data linked to it. Entries in the audit log are kept for their retention period, but without a link to you, and your e-mail address is removed from them;
- restriction of processing;
- object to processing based on our legitimate interest;
- data portability.
To use these rights, e-mail info@intelvisions.eu. We respond within one month and may ask you to confirm your identity first. If you are a member of a space run for another organisation, you can also contact that organisation.
You also have the right to lodge a complaint with a supervisory authority, in the Netherlands the Autoriteit Persoonsgegevens.
10. Automated decisions
We don't take decisions about you that are based solely on automated processing and that have legal or similarly significant effects. Who can open which app follows from rules set by the administrators of a space: invitations, and optionally letting everyone from a particular organisation's Google Workspace domain join.
11. Changes to this policy
We may update this policy, for example when the portal changes. The date at the top shows the latest version. We will announce significant changes in the portal or by e-mail.