Stackbridge

Legal

Privacy policy

What we collect, why, for how long, and who else sees it. Short, because there is not much of it: this site sets no cookies and runs no analytics.

Last updated 5 September 2026

01Two different things, kept separate

This policy covers this website. For the website, Stackbridge is the data controller.

It does not cover the Stackbridge product running inside a customer’s organisation. There, the customer is the controller and decides what goes in; we are a processor acting on their instructions, under the data processing agreement in their contract. In an on-premises or air-gapped deployment, which is how Stackbridge is normally sold, their data never reaches us at all, because there is no network path by which it could. Section 7 says what that means in practice.

02This site sets no cookies

No cookies, no local storage, no analytics, no tracking pixels, no session recording, no advertising tags, and no third-party scripts of any kind. There is no consent banner because there is nothing to consent to.

Web fonts are served from this domain rather than from Google Fonts: they are downloaded once when the site is built and shipped as part of it, so your browser never makes a request to a font host and no IP address is disclosed that way.

03If you request a demo

The form is the only place this site collects anything. You choose what to put in it.

What we collect
Your name, work email address and company. Optionally your team size and whatever context you write in the message box.
Why
To reply to you and to prepare a demo that is relevant. Nothing else. We do not sell it, share it for anyone else’s marketing, or add you to a list you did not ask for.
Legal basis
Steps taken at your request before entering into a contract (GDPR Art. 6(1)(b)), and our legitimate interest in responding to business enquiries (Art. 6(1)(f)).
Who else sees it
The submission is written to our own server logs, so that a request is never lost to a misconfigured integration, and delivered into our internal tooling so the team sees it. That tooling is operated by a business software provider acting as our processor. Beyond that, nobody: no data broker, no advertising network, no enrichment service.
How long we keep it
Until the conversation is over and for up to 24 months afterwards, so that a follow-up in a year’s time is not a cold start. Ask us to delete it sooner and we will.

04Your IP address, briefly

When you submit the form, your IP address is used only to count how many submissions came from the same place, so the form cannot be flooded. It is kept in memory alongside the timestamps of those submissions, which are discarded after ten minutes; the address itself is dropped once its last submission has aged out, and everything is gone when the process restarts. It is never written to a database and never attached to your enquiry.

Separately, the server that hosts this site keeps ordinary technical logs, which is normal for any web server and necessary to operate and secure it (Art. 6(1)(f)). Those logs are kept short-term by our hosting provider, who acts as our processor.

05Where your data is

We are an EU company and we choose EU regions. If any processor we use stores data outside the European Economic Area, that transfer is covered by the European Commission’s Standard Contractual Clauses. Tell us you need the details for a vendor review and we will send the current list of processors and where each one runs. We would rather answer that question once, properly, than have you infer it.

06What you can ask us to do

You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, ask for it in a portable format, and object to processing based on legitimate interest. Email lennert@versaminds.live and we will answer within one month, normally much sooner.

If we get it wrong, you have the right to complain to your data protection supervisory authority. For us that is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données). We would appreciate the chance to fix it first.

07The product, in one paragraph

Stackbridge captures engineering knowledge from tools a customer already uses and makes it searchable. Inside a customer’s deployment it holds the content they connect to it, the questions their people ask it, a record of who changed what, and a record of which entries were opened, so that “what did this departing engineer read” can be answered. That last one is always on rather than switched on per organisation, and it covers opening an entry, in the app or over MCP. It does not cover search results or chat answers, which quote entry content without opening it. Those records carry a retention window the customer configures (30 days unless they raise it), and only their administrators can read them.

Two commitments hold in every deployment. Customer content is never used to train models. And the customer chooses the model: a cloud provider under their own agreement, or a model running on their own hardware, in which case no content leaves their network at any point. Full detail is in the security overview.

08Changes

If this policy changes materially we will update the date at the top and, where the change affects someone whose data we already hold, tell them directly rather than relying on them to re-read the page.

Who we are

Legal name
VersaMinds
Trading as
Stackbridge
Registered office
P.V. Bavegemstraat 17, 9200 Dendermonde, Belgium
Company number
0804.360.325
VAT number
BE 0804.360.325
Security reports
lennert@versaminds.live