Last updated: 20-DEC-2020

1. WHO ARE WE
We are GDPRWise BV residing at Lange Lozanastraat 2, 2018 Antwerpen, Belgium and company registration number 0759426856.

We care about your privacy and every time we deal with your personal data we do so in accordance with the provisions of the general data protection regulation and the national law relating to the processing of personal data.

We are required under data protection legislation to make the information contained in this privacy policy accessible to you. This privacy policy sets out which measures are taken to protect your privacy when using our services or products, and what rights you have in this respect.

When processing your personal data we are in most cases the “data controller”. This means that we determine the purpose and means of the processing.

By using our services and/or products, you agree to the collection and processing of some of your personal data in accordance with the purpose described in our privacy policy. You are invited to read this privacy policy carefully and familiarise yourself with its content. Future amendments to this policy cannot be excluded. We therefore ask that you read the privacy policy from time to time.

You can reach our Privacy Coordinator at privacy@gdprwise.eu for any questions or to exercise your rights.

2. PROCESSING OF YOUR PERSONAL DATA
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). We try to collect as little personal information as possible in order to achieve our goals.

We comply with data protection laws which require that the personal information we process about you must be:

  • Collected only for valid purpose(s) that we have clearly explained to you.
  • Used lawfully, fairly and in a transparent way which means in a way that is relevant to the purpose(s) we informed you about, limited only to those purpose(s) and in no way incompatible with those purpose(s).
  • Accurate and kept up to date, kept only as long as necessary for the purpose(s) we have told you about and handled securely.

We may request certain information from you in order to enable you to use or purchase our services or products. If have processes in place to obtain your personal information in a different way, we will state this in this privacy policy. If you have any questions do contact our privacy coordinator.

More specifically we will collect any or all of the following data elements :

  • Bank account
  • Company address
  • Company registration number
  • Cookie – essential
  • Correspondence content
  • Customer name
  • Date & time
  • Electronic identification data
  • Involved party name
  • Payment card details
  • Payment balance data
  • Signature
  • VAT number
  • Work email address

We rely on you to provide us with correct data. If the data changes, we invite you to let us know, so we can keep the data up to date.

We process the data to allow us to deliver the services/products, and to continually improve the services/products available to you and adapt them to your needs. More specifically we perform the below processing:

    • Customer invoicing & accounting

Description: Calculating the fee owed, sending out invoices and ensuring payment
Purpose: To ensure proper payment
Legal basis: Contract
Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action
Data is processed in the EU

    • Corporate website

Description: Corporate website for consultation by client or prospective client
Purpose: To inform client or prospective client
Legal basis: Legitimate interests
Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action
Data is processed in the EU

    • Customer card / App payments

Description: Processing payments through debit card, credit card or payment App
Purpose: To ensure proper payment
Legal basis: Contract
Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action
Data is processed in the EU

    • Newsletter / promotion

Description: Keeping your clients up to date about what your company has to offer
Purpose: To promote similar services to exisiting customers
Legal basis: Legitimate interests
Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action
Data is processed in the EU

    • Customer correspondence

Description: communication with customers in electronic or paper form
Purpose: To provide proper service to the client
Legal basis: Contract
Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action
Data is processed in the EU

    • Customer prospecting

Description: Gathering of prospective customer information
Purpose: To communicate goods and services to prospective customers
Legal basis: Legitimate interests
Retention period: All prospects that have not converted to customers will be deleted after 2 years
Data is processed in the EU

    • GDPRWise Web Application – My Company Section

Description: GDPRWise web tool to support customers getting their GDPR in order.
Purpose: Offering core customer service
Legal basis: Contract
Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action
Data is processed in the EU

In the above processing we are the data controller.

    • GDPRWise Web Application – Third Party Dossier

Description: GDPRWise web tool to support customers getting their GDPR in order.
Purpose: Offering core customer service
Legal basis: Contract
Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action
Data is processed in the EU
Data controller: User Account owner
Data processor: GDPRWise BV

Where you provided consent, you have the right to revoke it. You have the right to withdraw your consent at any time.

In case you object to the processing of your data, please contact us so we can evaluate together if a contractual relation is possible and a continuation of the use of our services is possible.

3. PROCESSING OF PERSONAL DATA ON YOUR BEHALF
The specific nature of our relationship makes it unlikely that we will process other people’s personal data on yout behalf. In the exceptional case that this nevertheless occurs, we are the processor and you are the controller. We will then carry out your instructions for the processing, possible subcontracting, the fate of the data at the end of the agreement and the possible transfer of data. We will therefore take the necessary security measures and assist you in fulfilling your obligations under the GDPR.

4. TRANSFER OF PERSONAL DATA
In order to provide certain services or products we might work with third parties such as IT partners, insurance partners, accounting partners, legal advisors… More specifically we reserve the right to transfer your personal data to our partners.

    • VDV Consultants because they act as a data processor for:

Bookkeeping (VAT number, Customer name, Company address, Payment balance data, Involved party name, )

    • Darwin Law because they act as a data processor for:

Legal support (Customer name, Claim specific information, Involved party name, )

    • Zoosh Ltd because they act as a data processor for:

IT Support (VAT number, Customer name, Company address, Involved party name, Date & time, )

    • Linkedin Ireland because they act as a data processor for:

Social media – Linkedin (Electronic localization data, Pictures / images, Involved party name, Date & time, )

In case you object to the transfer of your data, please contact us so we can evaluate together if a contractual relation is possible and a continuation of the use of our services is possible.

Please do note that we may be required by law to process certain data and, as the case may be, to transmit them to the relevant authorities. As this is a legal obligation you can not object this transfer.

5. SECURITY & CONFIDENTIALITY
We undertake to keep your personal data secure & confidential and have established security procedures to avoid any loss, abuse or alteration to this personal data in line with industry best practices.

6. WEBSITE & COOKIES
Our public website does not use any cookies. Our server does log your IP address and/or your domain name in line with security best practices. Those log files are deleted on a weekly basis. Our GDPRWise application for which you require an account does use a single session-cookie to establish the connection with our backend server, which is essential to the working of the application and we can not do without.

We may publish links to websites owned and operated by third parties. If you click on such a link you will navigate to another website. Please make sure you read and understand the privacy policy of that website, as it may differ from our policy and is outside of our control. If you feel unsure or cannot agree with the policy, we suggest you leave that website.

7. SOCIAL MEDIA
If you use the social media functions such as eg “like” or “share” button that may be on our website, or if you visit our social media page, please know that your personal data will be processed by the social media platform. In this processing, the European regulator considers us and the social media platform both to be joint data controllers, which means that we jointly determine why and how your personal data is processed. You can find out how we process your personal data in this privacy statement. You can find information about the processing by the relevant social media platform in their privacy statement. We ask you to read the privacy statement of the social media platform carefully before visiting the social media items on our page or our page on the social media platform.

8. EXERCISING YOUR RIGHTS
In accordance with the general data protection regulation you have the right to:

  • Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you.
  • Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
  • Request erasure of your personal information. This enables you to ask us to remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to remove your personal information where you have exercised your right to object to processing (see below).
  • Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
  • Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
  • Withdraw your prior consent to processing at any time.
  • The right to object to a decision based solely on automated processing, including profiling.
  • The right to receive your personal data in a structured, commonly used and machine-readable format and have transmit those data to another controller.

We sometimes need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.

You can exercises your rights by contacting our Privacy Coordinator via privacy@gdprwise.eu or at the below company address:

    • GDPRWise BV

 

    • c/o Privacy Coordinator

 

    • Lange Lozanastraat 2, 2018 Antwerpen

 

    Belgium

9. DATA PROTECTION AUTHORITY

You can direct any complaints and comments to the competent data protection authority at the below address:

    • Gegevensbeschermingsautoriteit

 

    • Drukpersstraat 35, 1000 Brussel

 

    • https://www.dataprotectionauthority.be

 

    contact@apd-gba.be