Skip to content
Hookt
Home How it works Subscription
My Hookt

Privacy Policy

Version: 5 October 2026.

Terms overviewBusiness TermsMobile / Verification TermsData Processing AgreementPrivacy Policy

This Policy explains how personal data is used when businesses protect communications with Hookt and when anyone, including a private individual, verifies them. Hookt subscriptions are B2B only; ordinary mobile verification does not require a subscription or a Hookt account.

  1. Who operates Hookt
  2. Our role and the subscribing business’s role
  3. Visiting this website
  4. Business accounts and administration
  5. Protecting and sending communications
  6. Verifying a protected message
  7. Using the mobile app
  8. Local history on your device
  9. Security, events and feedback
  10. Contact correspondence
  11. Lawful bases
  12. Recipients and service providers
  13. Processing locations and transfers
  14. How long information is retained
  15. Your data-protection rights
  16. Changes to this Policy

1. Who operates Hookt

Jero.Eu BV
Rodenbachlaan 82
3550 Heusden-Zolder
Belgium
Enterprise/VAT: BE 0843.889.409

Jero.Eu BV operates Hookt. Its data-protection role depends on the purpose of the processing, as explained below. You may write to this address about privacy or use the Contact page when online sending becomes available.

2. Our role and the subscribing business’s role

Jero.Eu BV acts as controller for its own customer and company relationships, account and organization administration, subscriptions, billing, accounting, invoicing, correspondence, service administration, legal compliance, platform security, fraud and abuse prevention, audit and operational logging. This includes verification-event or feedback information where we determine a separate security or service-integrity purpose.

Jero.Eu BV acts as processor when it processes protected-communication personal data on behalf of a subscribing business: protecting and sending its messages, preparing recipient-specific QR credentials, and maintaining associated verification and evidence records under its documented instructions. The DPA governs those activities, not our independent controller processing.

A later verification uses the communication and evidence record originally processed for the subscribing business. That customer-controlled purpose can coexist with our separate purposes of securing the platform, preventing abuse, auditing and operating Hookt safely. Verification is not assigned a single role for every purpose.

3. Visiting this website

The website uses locally hosted pages, images, icons and fonts. It does not use application analytics, advertising trackers, cookies or browser storage. Hosting and networking services handle connection information and may keep operational and security logs. Subscription and customer-area links currently lead to availability notices.

The LinkedIn and X links lead to platform homepages; they are not Hookt profiles. If you visit them, the relevant platform receives your request and applies its own privacy practices. No social tracking software is embedded here.

4. Business accounts and administration

We process business names and identifiers, contact and authorized-user details, email addresses, access roles, account and subscription information, administrative actions and billing records. Information comes from the business, its users, authorized Microsoft identity services and, when billing is enabled, payment and invoicing providers. No consumer account or profile is required for ordinary mobile verification.

5. Protecting and sending communications

Hookt processes the sender, recipients, subject, sending information and supported email content needed to protect and send a message through the business’s authorized email service. The business chooses the contents and is responsible for their lawful use.

Hookt processes email body and attachment contents only as necessary to protect and send the communication. They are not retained as part of the permanent verification record. Limited encrypted temporary material can exist during the sending and recovery lifecycle where necessary. These contents are separate from the long-term verification and evidence record. Their technical use expires, and cleanup removes the encrypted material after completion or expiry; cleanup depends on the sending service running. The default technical lifetime is 24 hours, which is not a guarantee that every copy is deleted at that exact time.

6. Verifying a protected message

A unique QR code or verification link lets Hookt check its associated protected-communication information. Results can show the sending organization, sender information, subject, masked recipient, sending and verification times and a reference, where available. For newly protected messages, we retain the validated send-time sender address alongside organization and sender identifiers, protected recipient-related information, subject, sending evidence and credential-related data. Older records may lack this historical sender information; unavailable details are not reconstructed from a later directory address.

The person holding a usable QR or link can request its result; ordinary verification does not prove that person is the intended recipient. Keep verification links and QR codes appropriately protected. The check does not establish that every word, link, attachment or instruction in the surrounding email is safe or truthful.

7. Using the mobile app

Anyone may use Hookt Mobile, including private individuals with no commercial relationship with us. Camera frames are handled locally and transiently to scan a QR code. The decoded verification input is sent to the Hookt backend, which checks the associated record and returns a result. A network connection is required; the scanning flow does not upload or retain camera images.

Selected verification results are saved locally on your device. They can include sender and organization information, subject, masked recipient, reference, result, timestamps and feedback outcome. Optional feedback can report whether information matches or appears suspicious. It is a user report, separate from the technical verification result.

8. Local history on your device

Scan history is intentionally retained as a verification and evidence reference. Hookt applies no automatic expiry and provides no history-clearing function. It remains until the app or its data is removed or the operating system otherwise removes the local data. Hookt does not synchronize this history between devices.

Removing the app or app data removes the local history, subject to operating-system and device backup or restore behavior. App offloading may retain data. Device access controls and backup settings affect who can access it and whether it can return after a restore. Local deletion does not delete separate server-side verification and evidence records. See account deletion information.

9. Security, events and feedback

We record verification events, feedback and relevant administrative, audit and security information to operate Hookt, support the subscribing business and investigate abuse. Verification events link a protected message and organization to an event time and technical result. New verification scan records do not retain IP addresses or browser/device User-Agent strings; connection information may still be used transiently for network and security controls. Feedback can be associated with a protected message or an unrecognized QR report.

We apply measures appropriate to the risks, including access controls, encryption for selected sensitive data, protected credential handling, rate controls and security monitoring. These measures reduce risks but cannot prevent every incident. We do not use verification or feedback for advertising profiling or automated decisions with legal or similarly significant effects.

10. Contact correspondence

The contact form is currently unavailable. When enabled, your email address, subject and message will be sent through Microsoft business email services to the monitored Hookt mailbox. Contact-form messages are not intended to be stored in the Hookt application database. Your email address is used for replying, rather than as the sender identity of an automated message.

Correspondence is retained only for as long as reasonably necessary to handle the enquiry, customer relationship, contractual or legal obligations and disputes. No fixed mailbox retention period is imposed by this Policy.

11. Lawful bases

For our controller activities, legitimate interests support appropriate business-contact administration, operating and securing Hookt, fraud and abuse prevention, service integrity, audit and business administration, subject to the rights and interests of the people concerned.

We rely on contract or pre-contractual steps where processing is genuinely necessary for a contract with the individual concerned. A contract with a company does not automatically make this the basis for its employees’ or administrators’ data; legitimate interests are generally the relevant basis for those business contacts. Accounting, tax and required record keeping rely on legal obligations. If a separate optional purpose requires consent, we will explain it and allow withdrawal without affecting earlier lawful processing.

For data processed on behalf of a business, that customer/controller is responsible for its lawful basis, notices and instructions. We process that data under those instructions and the DPA.

12. Recipients and service providers

Authorized staff and providers receive data only as needed for their role. Important service categories include Microsoft Azure for cloud hosting, applications, databases and infrastructure, and Microsoft 365 for business and contact email. The customer’s authorized Microsoft email and identity services also participate in protected sending and business access.

Stripe is planned for payment processing and Billit for invoicing and Peppol-related services; subscription purchasing is not enabled on this website. These services will receive the information necessary for their functions when activated. Payment or invoicing records do not form part of the verification evidence for every communication.

A provider may be a subprocessor for customer-controlled processing, a provider to us for our own controller purposes, or an independent controller for its own regulatory or compliance activities. The DPA addresses providers used as subprocessors. We may also disclose information where required by law or reasonably necessary to establish or defend legal claims.

13. Processing locations and transfers

Cloud, email and other providers may process data in different countries, including through support access. We do not promise that all processing takes place in Belgium or the EEA. Where a transfer outside the EEA requires safeguards, we must use a lawful mechanism, such as an applicable adequacy decision or appropriate contractual safeguards with any necessary supplementary measures. You may request information about applicable locations and safeguards at the address above.

14. How long information is retained

Different purposes have different retention periods. Our retention policy is:

  • Core protected-communication verification and evidence: seven years from sending, to preserve meaningful verification over a normal business-document lifecycle. This covers recorded sender identifiers and validated send-time addresses where available, protected recipient-related information, subject, sending timestamp, credential-related information and associated sending evidence, not a seven-year archive of email bodies or attachment contents.
  • Email bodies and attachment contents: Hookt processes email body and attachment contents only as necessary to protect and send the communication. They are not retained as part of the permanent verification record. Temporary sending and recovery material follows the limited lifecycle described in section 5.
  • Verification events: 24 months from the event.
  • Administrative, audit and security records: normally 24 months. Longer retention applies only where reasonably necessary for an active security investigation, dispute, legal claim or legal obligation.
  • Feedback records: normally 24 months, with the same justified exceptions for an active security investigation, dispute, legal claim or legal obligation.
  • Operational and application logs: normally 90 days. Specific evidence may be preserved longer where reasonably necessary for an active security investigation, dispute, legal claim or legal obligation.
  • Backups: after deletion from active systems, residual copies may remain for a maximum of 90 days. Normal rotation may remove them sooner.
  • Accounting, invoicing and tax records: ten years where required for Belgian accounting or tax obligations. This includes applicable invoices, credit notes, payment and accounting evidence, revenue and tax support records, invoice copies held through Billit and necessary transaction records. This period does not apply to all customer or product data.
  • Organization and subscription configuration: normally 24 months after the subscription ends, then deleted or anonymized unless particular information has a separate accounting, legal, security, dispute or legal-claim retention purpose. This does not shorten the seven-year evidence period or change the separate event and accounting periods.
  • Contact correspondence: only as long as reasonably necessary for correspondence, the customer relationship, contractual and legal obligations and disputes.
  • Device-local history: no automatic Hookt expiry; it follows the device and app-data behavior described in section 8.

Cancellation, suspension or termination does not automatically invalidate earlier protected communications or erase records before their applicable retention period. Retention for a separate legal obligation or claim is limited to the information and duration necessary for that purpose.

15. Your data-protection rights

Where Jero.Eu BV is controller, you may request access, rectification, erasure, restriction, objection and portability where applicable. Rights depend on the legal basis and circumstances. A retention obligation or overriding lawful reason can limit erasure or objection. You can withdraw consent for processing that actually relies on it.

Write to Jero.Eu BV at the address in section 1, describing your request and enough context to help identify the relevant information, such as the organization, communication date or reference if available. An exact QR hash is not required. We may request proportionate information to verify identity and protect other people’s data. We will respond within the applicable GDPR time limits.

For communication data controlled by a subscribing business, requests may need to be handled through or with that business. We will assist it under the DPA and help direct your request appropriately.

You may complain to the Belgian Data Protection Authority or another competent supervisory authority, including in the place of your habitual residence, work or alleged infringement.

16. Changes to this Policy

We will update this Policy when processing or applicable requirements change, identify the version and provide appropriate notice of material changes. New purposes must have an appropriate lawful basis and, where required, additional information or consent.

Privacy PolicyTerms overviewContactAccount deletion information

Hookt

© 2026 Hookt

Back to top ↑
PrivacyTermsContactAccount deletion

Platform homepages — Hookt profiles coming soon.