Privacy Statement

This privacy statement explains which data we collect via our product Visto, including on the website, the dashboard, and the participant app, how we use and protect this data, and what rights you have regarding your personal data. We process your data in accordance with the General Data Protection Regulation (GDPR).

  1. About us

    Vistolabs is a Dutch company, registered with the Dutch Chamber of Commerce under number 96681675. Our office is located at Texelaar 9c, 9613DH Meerstad (please note: this is not a visitor address). Vistolabs is responsible for processing your personal data through our services. You can find more information about our product at https://vistolabs.nl.

  2. Your data that we collect

    We collect data when you use our website or app. This data is collected in different ways, depending on your usage.

    1. Our website

      When you visit our website, we collect the following data:

      • IP address and browser data: This data is collected and linked to your browser to improve the user experience.
      • Cookies and sessions: We use cookies and session data to enable login and keep you logged in.
      • User data: We collect usage data for analytics and improvements to our website to optimize your experience.
    2. Our app

      When you use our participant app, we collect:

      • Device data: We process device data to communicate with you and link your device to your account for data security purposes.
      • Location data: Location data may be collected after you have explicitly consented to this. You can withdraw this consent at any time via the app or your device.
      • Sensor information: We may collect data from other sensors, once you have explicitly consented to each subject, for the research you are participating in.
      • User data: We process anonymous data for analytics and app improvements for the benefit of the participant.
  3. Purposes of this data processing

    We process your personal data exclusively for the following purposes:

    • Service provision: To provide our services, both for users and participants. This may include enabling certain functionalities or providing support.
    • Establishing a processing agreement: To use the product, we need your personal data to enter into an agreement and process payments.
    • Improving the user experience: We use the data to analyze and improve our services for both users and participants.
    • Supporting participation in research: Participant data is used to provide researchers with the necessary data for their research.
  4. Who do we share personal data with?

    In some cases, we are required to share your personal data with third parties to properly perform our services. This varies per product.

    1. Data of you as a user

      To efficiently provide our service, we engage other parties to process personal data on our behalf, such as accountants or payment providers. Sometimes, we are legally required or ordered by a court to share personal data with third parties, such as the police.

    2. Data of you as a participant

      The data we collect from you as a participant is shared only with the research you are participating in. A separate processing agreement exists between you as a participant and the research. We will inform you about the data we collect for the research, and the researcher will inform you about the use of this data.

  5. How do we protect your data?

    We take strict measures to store your data securely and accurately and to prevent unauthorized access.

    • Encryption of sensitive data: Sensitive data, such as results and passwords, is encrypted according to industry standards.
    • Encryption of data traffic: Our website uses a valid SSL certificate to encrypt communication between your computer and our website, including passwords you enter.
    • Organizational measures: We have strict rules for accessing and processing your data, both as a user and a participant.
  6. Your rights

    As a user, you have the following rights regarding your personal data. Requests regarding these rights can be submitted via [email protected].

    • Right of access, correction, and deletion: You have the right to access, correct, or delete your personal data.
    • Right to restrict processing and object: You can request us to restrict the processing of your data or object to the processing.
    • Right to data portability: You can request your data in a structured format and transfer it to another party.
  7. Retention periods

    The retention periods of personal data depend on the type of information and the user's preferences regarding the retention of participant data. We keep participants informed of the specific retention periods set by the user.

    • Research and project data: Retention periods are aligned with the user's wishes and the nature of the research project.
    • Research results: Retention periods are aligned with the user's wishes and the nature of the research project.
    • Generic data: For general data, such as user statistics, we apply a retention period of up to two years, unless legal obligations require a longer period.
  8. Changes to the privacy statement

    We reserve the right to modify this privacy statement. Changes will be published on our website. We recommend that you regularly consult the privacy statement.

  9. Contact information

    If you have any questions or requests regarding this privacy statement, you can contact us at:

    • Email: [email protected]
    • Address: Vistolabs, Texelaar 9c 9613DH Meerstad (no visitor address), Netherlands

This privacy statement was last updated on April 2, 2025.