Skip to content
Prezentix
  • NL
  • EN
  • DE
  • FR
Back to the website

Privacy policy

Last updated on 6 September 2026

Prezentix is a visitor registration platform by ICT Basis. This policy explains which personal data we process, why we do so, how long we keep it and what rights you have. It covers this website (https://www.prezentix.com) and the Prezentix application at https://app.prezentix.com.

We deliberately write this in plain language. If anything is unclear, or if you want to know exactly what we hold about you, email [email protected] — a person will answer.

On this page

  1. 1. Who is responsible
  2. 2. Two roles, and why the difference matters
  3. 3. Your visit to this website
  4. 4. The contact form and demo requests
  5. 5. Customers, subscriptions and the customer portal
  6. 6. Visitor data in the Prezentix application
  7. 7. Are you a visitor at a reception desk?
  8. 8. Who gets to see the data
  9. 9. Where the data is held
  10. 10. How long we keep data
  11. 11. How we secure the data
  12. 12. Your rights
  13. 13. Changes to this policy

1. Who is responsible

Prezentix is a product of ICT Basis. For the processing described in this policy as ours, we are the data controller:

  • Company: ICT Basis
  • Address: Ooievaarlaan 7, BE-9800 Deinze
  • Company and VAT number: BE 0830.568.042
  • Email for privacy matters: [email protected]
  • Website: https://www.prezentix.com

We have not appointed a data protection officer. Our processing does not fall within the cases where the law requires one: we carry out no large-scale systematic monitoring and we process no special categories of data. Privacy questions reach the address above directly.

2. Two roles, and why the difference matters

Prezentix encounters personal data in two very different roles. Which rights you have, and who you should address them to, depends on which role applies.

RoleWhenWho decides
ControllerYou visit this website, request a demo, or you are a contact person or administrator at one of our customers.ICT Basis — we determine ourselves why and for how long we process that data.
ProcessorYou sign in on a Prezentix kiosk at an organisation’s reception, or your details are held in a customer’s application.The organisation using the kiosk. We process that data solely on their instructions.

Did you sign in at a reception desk? Then the organisation you visited is responsible for your data, not Prezentix. Read on at Are you a visitor at a reception desk? — we will still point you in the right direction.

In our role as processor we never use visitor data for our own purposes. We do not sell it, we do not use it for advertising, and we do not train models on it.

What we do keep are counts per customer environment — how many registrations, pre-registrations and call minutes — in order to invoice, to follow capacity and to see that the service works. There is no visitor data in them. Where we add such counts up across customers, for instance for a figure on this website, no individual customer and no individual person can be distinguished in the result.

3. Your visit to this website

This website sets no cookies and stores nothing in your browser. That is why there is no cookie banner: there is nothing to ask consent for. We do count how often each page is viewed, using a measurement that works without cookies and without fingerprinting — it does not recognise you and does not follow you.

What does happen

  • Our hosting provider keeps ordinary server logs: your IP address, the time, the page requested and your browser type. This is needed to keep the site running, to investigate faults and to prevent abuse. Legal basis: our legitimate interest in a secure, working website (Article 6(1)(f) GDPR).
  • Traffic to this site passes through Cloudflare, which speeds up the site and blocks attacks. Cloudflare therefore also sees your IP address.

One thing does come from outside: the measurement script described below. Everything else — the typeface, the styles, the images and our own script — sits on our own server.

We do not link those log entries to individuals and do not use them to build profiles.

How we count visits

We use Cloudflare Web Analytics. It sets no cookies, stores nothing in your browser and does not fingerprint your device or your IP address. No profile is built, and you are not followed from one website to the next.

What we get to see are totals: which pages are viewed, which search engine or website people arrive from, from which country, and with what kind of device and browser. Never who. Legal basis: our legitimate interest in knowing whether our website works and is being found (Article 6(1)(f) GDPR). If you would rather not be counted, any tracker or ad blocker stops the script; the site works just as well without it.

4. The contact form and demo requests

If you fill in the form on our website, we process the following:

WhatWhy
Name, company, email address and optionally a phone numberTo answer your question and to arrange a demo, a trial or a proposal.
Number of sites and screens, the selected topic and your messageTo make a proposal that fits your situation.
Your IP address and the time of submissionTo stop automated spam.

We use a hidden field, a minimum completion time, a per-IP limit, and Cloudflare Turnstile — a bot check that in most cases asks nothing of you and, unlike a classic captcha, keeps no advertising profile. Cloudflare may process data from your device and browser for this; see their own privacy policy for details.

Legal basis: taking steps at your request prior to entering into a contract (Article 6(1)(b) GDPR), and our legitimate interest in handling enquiries and keeping spam out (Article 6(1)(f) GDPR).

Your enquiry reaches us as an email at [email protected]; it is not stored in a database or CRM system. We keep that email for up to 24 months after our last contact, unless a customer relationship follows from it — in which case the periods in §10 apply.

You will not receive a newsletter you did not ask for, and your details are never resold or shared with other suppliers.

5. Customers, subscriptions and the customer portal

If you become a customer, we process as controller the data needed to deliver and invoice the service:

  • Organisation details: name, address, company and VAT number, and the contact person with their email address and phone number.
  • Administrator accounts for the customer portal: name, email address, the role within the portal and — where the customer connects Microsoft — the user id from Microsoft Entra ID. If someone signs in with an email code, we additionally process the time of the request, a hashed fingerprint of the browser and a shortened IP address, in order to detect abuse of those codes.
  • Subscription data: the number of sites and screens, the chosen term, discounts and the invoices that follow from them.
  • Technical application logs, which we need to investigate errors and keep the service running.

Payments

Payments run through a hosted Stripe payment page. Your card details therefore go straight to Stripe and not to our servers: we only keep the Stripe customer number, the card brand and the last four digits, so you can see which card your subscription runs on. We never see the full card number.

Signing in

The customer portal works with a Microsoft account (Microsoft Entra ID) or with a one-time six-digit code by email. In neither case do we store a password — the code is held only as an irreversible hash and expires once used. If you choose the Microsoft route, multi-factor authentication, password policy and revoking access remain entirely with your own IT administration.

Legal basis: performance of the contract with your organisation (Article 6(1)(b) GDPR) and our statutory accounting and VAT obligations (Article 6(1)(c) GDPR).

6. Visitor data in the Prezentix application

This is the processor role. Our customers decide which fields appear on the screen, what text a visitor reads, on which legal basis they process that data and how long everything is kept. We carry that out — no more and no less. Depending on what the customer configures, this involves:

CategoryData
Visitor registrationFirst and last name, company, email address, phone number, the person or department being visited, the reason for the visit, a badge number, the sign-in and sign-out time, and whether the visitor accepted the house rules or safety instructions — including the time of that acceptance.
Pre-registrationThe same data, entered in advance by the host, together with a unique invitation code and a QR token with an expiry date, so the visitor only has to scan at the kiosk.
The customer’s employeesName, email address, job title, department, office location and profile photo, synchronised from the customer’s Microsoft Entra environment, or entered or imported by the customer where there is no connection. This is needed so a visitor can select and notify the right person. For a manually entered contact an email address is mandatory, because the arrival notice then goes by email.
Calls and notificationsWho was called, through which channel (phone, video or Teams), the time, the duration and how the call ended. Calls are not recorded and no call content is stored.
Screen usageTechnical events per kiosk: the screen identifier, the time, the browser type and the device’s IP address. Intended for investigating faults, not for tracking visitors.
AI reception assistant (optional)If the customer enables this feature, the visitor’s spoken question is sent to Azure OpenAI to be transcribed and interpreted. We do not keep the audio recording. The conversation itself is held with the customer for a while so the question can be dealt with. If the assistant does not know the answer, the question is passed to a member of the customer’s staff so the visitor can still be helped; that question is deleted after ninety days. Of the usage we only record how much was processed and what it costs.
Connecting to the customer’s own systems (optional)Where the customer switches on our API, they use a key they create themselves to retrieve their own visitor data, or to announce visitors from their own planning tool. Per key we record which administrator created it, when it was last used and from which shortened IP address. Visitors’ e-mail addresses and phone numbers are only included if the customer expressly grants the key that right.
First aidIf the customer uses the first aid log: the name of the person who received first aid, the time, the site and the location within it, a short description of the circumstances, and who helped, witnessed or recorded it. What is not in there matters just as much: no nature of the injury, no treatment given, no outcome and no photos. Prezentix is not an environment for health data. This data has its own retention period set by the customer; after it, only the count, the date and the location remain.

AI reception assistant and the AI Act

Where a customer switches on the AI reception assistant, that is an AI system within the meaning of Regulation (EU) 2024/1689, the AI Act. We develop that assistant and offer it under our own name: we are therefore the provider, and the customer who switches it on is the deployer. The underlying language model comes from Microsoft (Azure OpenAI). We train no models ourselves, and visitors’ data is not used to train one.

It is a limited-risk system. The assistant turns speech into text, works out what the visitor has come for and helps them find the right contact. There is no facial recognition, no biometric identification or categorisation, no emotion recognition and no automated decision about a person. The assistant therefore falls neither under the prohibited practices of Article 5 nor under the high-risk uses of Annex III.

What does apply is the transparency duty of Article 50: the screen states that the visitor is talking to an AI assistant and not to a member of staff. If handsfree mode is on, where the device waits for a wake word, the screen says so as well.

The assistant may only answer from what the customer has given it: its instructions, its own knowledge items and the employee directory. Where the answer is not in there, it says it does not know and passes the question to a member of staff, instead of making something up. It decides nothing about individuals and does not determine who may enter the building.

Separation between customers

Every customer gets their own, isolated part of the database. Data from different organisations is never mixed and is never reachable from another customer’s environment.

Retention

The customer sets their own retention policy. The default is 90 days. After that, visitor data is deleted automatically, or anonymised where the customer wants to keep the visit statistics without the people behind them. That clean-up runs as a scheduled task, so it does not depend on anyone remembering it.

Data processing agreement

For the data we process on a customer’s instructions we enter into a data processing agreement containing the arrangements required by Article 28 GDPR: acting only on instructions, confidentiality, security, assistance with data subject requests, incident notification, and return or deletion at the end. It is published in full at https://www.prezentix.com/dpa/; for a signed copy, write to [email protected].

7. Are you a visitor at a reception desk?

If you signed in on a Prezentix kiosk, the organisation you visited is the controller. They decide which data is requested and how long it is kept; we may not change any of that without their instruction.

  • If you want to know what data is held about you, or want it corrected or deleted, address your request to that organisation — usually through their reception, their privacy officer or the address in their own privacy policy.
  • If you do not know who to turn to, email us at [email protected]. We will pass your request on to the right organisation immediately and help them act on it.

That organisation may also pull your registration into its own systems, for its visitor reporting for instance. Even then it remains the controller, and your request still belongs with them.

So we do not answer such requests ourselves, but we do not let them sit either.

8. Who gets to see the data

We use a limited number of service providers to make Prezentix work. They process data solely on our instructions and are contractually bound to confidentiality and security.

PartyWhat forWhere
Microsoft (Entra ID, Microsoft Graph, Microsoft 365)Signing in and synchronising employee data (only where Microsoft is connected), and sending our email, including the arrival notice to the contact and the Teams notification.European Union
Microsoft Azure Communication ServicesVoice and video calls from the kiosk to an employee.European Union
Microsoft Azure OpenAISpeech recognition and interpretation for the optional AI reception assistant.European Union
Stripe Payments EuropePayment of subscriptions and invoices.Ireland (EU)
CloudflareSecure access to the application and acceleration of this website.Global network, with EU data centres for European traffic
one.comHosting of this website.European Union

Cloudflare also provides the visitor statistics for this website. What is counted is set out in §3.

Where a customer switches on our API, their visitor data goes to a system they choose themselves — their reporting, their planning. That system is not our service provider but theirs: they decide where it is and what happens to the data afterwards.

We also disclose data where a law or an order from a competent authority obliges us to. We do not sell data and do not share it with advertisers or data brokers.

9. Where the data is held

The application and the database of visitor data run on ICT Basis’s own equipment in Belgium. That equipment is not directly reachable from the internet: traffic runs through an outbound, encrypted Cloudflare tunnel, so no ports need to be opened.

The services in §8 that we use alongside it are chosen so that processing takes place within the European Union. Where a party may nevertheless process data outside the European Economic Area — in practice only Cloudflare, for routing traffic — this takes place on the basis of the European Commission’s standard contractual clauses, supplemented by the EU-US Data Privacy Framework for parties certified under it.

Where a customer retrieves data through our API, or has us notify an address of their own with a webhook, it ends up in their own system. They decide where that is; if it sits outside the European Economic Area, that transfer is theirs and not ours. That system is not a party we engage — it is theirs.

10. How long we keep data

DataPeriod
Visitor registrations in the applicationBy default 90 days, configurable by the customer. Automatically deleted or anonymised after that.
Pre-registrationsUntil the invitation expires; the same rules as above apply after that.
Synchronised employee dataFor as long as the employee is active in the customer’s Microsoft environment. Once they are removed there, they disappear from our side at the next synchronisation.
Call and notification logsFor as long as the customer needs them to follow up on usage. They contain no call content.
Enquiries through the contact formUp to 24 months after our last contact.
Customer, subscription and invoicing data7 years after the end of the financial year, because of the statutory retention obligation for accounting and VAT.
Administrator accounts in the customer portalFor as long as the customer keeps them active. When the subscription ends, the entire customer environment is deleted.
Server logs of this websiteAccording to our hosting provider’s period, usually a few weeks.

If a dispute or legal proceedings are ongoing, we may keep the data concerned for longer, but no longer than necessary for that purpose.

11. How we secure the data

  • All traffic to the website and the application is encrypted over HTTPS/TLS.
  • Signing in is possible through Microsoft Entra ID or with a one-time six-digit code by email. We store no passwords; codes are held only as an irreversible hash, are valid for ten minutes, allow five attempts and expire once used. On the Microsoft route the multi-factor authentication policy stays with your own IT administration.
  • Access tokens to Microsoft are stored encrypted (AES-256-GCM).
  • Every customer has their own, isolated part of the database.
  • The servers are not directly reachable from the internet; no ports are open.
  • Within the customer environment, the customer decides who gets which role. Our own access stays limited to what is needed for support, maintenance and resolving faults. Where that requires us to look inside a customer environment, we ask beforehand: an administrator of that customer approves, the access expires by itself after an agreed period, everything that happens is recorded, and the customer receives the overview of it afterwards.
  • Data that is no longer needed is cleaned up automatically instead of being left in place.

If something goes wrong despite all this, we inform the customer concerned without undue delay with everything we know at that moment, so they can meet their own notification duty. Where it concerns data for which we are ourselves responsible, we report the incident to the Belgian Data Protection Authority within 72 hours where the law requires it.

Spotted a security problem in our website or application? Report it at [email protected]. We take such reports seriously and will not take legal action against anyone who reports a problem in good faith and does not abuse it.

12. Your rights

The GDPR gives you the following rights. For data we are responsible for, you exercise them directly with us; for visitor data, turn to the organisation you visited (see §7).

  • Access: find out whether we process data about you and obtain a copy of it.
  • Rectification: have inaccurate or incomplete data corrected.
  • Erasure: have your data deleted where we no longer need it or process it without a proper basis.
  • Restriction: have the processing paused, for instance while a dispute is being resolved.
  • Objection: object to processing we base on our legitimate interest.
  • Portability: receive the data you provided yourself in a common format, or have it transferred.
  • Withdraw consent: where you gave consent, you may withdraw it at any time. What happened before that remains valid.

Send your request to [email protected]. You will have an answer within one month; if your request is exceptionally complex, we will tell you within that month that we need more time. If there is reasonable doubt about who you are, we may ask for additional details, to avoid handing your data to someone else. Exercising your rights is free of charge.

Filing a complaint

If you are not satisfied with how we handle your data, you can always lodge a complaint with the supervisory authority:

  • Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels, Belgium
  • Email: [email protected] — phone: +32 2 274 48 00
  • Website: www.dataprotectionauthority.be

If you live in another European Union country, you may also turn to the supervisory authority of your own country. We would appreciate the chance to put things right ourselves first.

13. Changes to this policy

If something changes in the service, in the parties we work with or in the way we process data, we update this policy and put a new date at the top. The current version is always at https://www.prezentix.com/privacy/.

Where a change matters to our customers, we notify them by email as well, before it takes effect.

ICT Basis · 2026

Ooievaarlaan 7, BE-9800 Deinze · BE 0830.568.042