Privacy policy

Summary
This policy informs data subjects of the conditions under which Clarify Consult Partner Europe collects, processes and stores their personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and the Belgian law of 30 July 2018.
1. Data Controller
The data controller is Clarify Consult Partner Europe, with registered office at Place Sainte-Gudule 14, 1000 Bruxelles, Belgique, registered under number BE 2269.762.485. Any request may be sent to [email protected] or by post to the registered office, to the attention of the DPO.
2. Data Protection Officer
The Company has appointed a DPO in accordance with articles 37 et seq. GDPR. Contact: [email protected].
3. Categories of data collected
- Identification data: name, surname, position, professional postal and electronic address, phone, login credentials
- Professional data: employer's business name, services used, subscription history
- Technical data: IP address, browser, OS, logs, activity traces, session duration
- Financial data: bank details, SEPA mandate, payment history
- Behavioural data: preferences, consulted modules, aggregated usage statistics
4. Purposes and legal bases
- Contract performance (Art. 6.1.b): order management, Service provision, support, billing
- Legal obligations (Art. 6.1.c): accounting, anti-money laundering, authority requests
- Legitimate interests (Art. 6.1.f): security, fraud prevention, Service improvement, prospecting existing customers
- Consent (Art. 6.1.a): prospect prospecting, non-strictly-necessary cookies
5. Recipients
Data is accessible, strictly as needed, to authorised staff, technical subprocessors bound by article 28 GDPR, authorised authorities, advisors, and potential acquirers in case of asset transfer.
6. List of subprocessors
- OVH SAS (Roubaix, France and Brussels, Belgium) - Hosting, backups - EU
- Resend (transactional email) (Dublin) - Online payments - EU
- OVH SAS (Paris) - Transactional emails - EU
- Cloudflare, Inc. (Dublin) - CRM - EU
- Cloudflare Inc. (San Francisco) - DDoS protection - EU-US Data Privacy Framework adequacy decision
7. Transfers outside the EU
The Company prioritises keeping data in the EU. Any transfer to a third country occurs under one of the guarantees provided in articles 44-50 GDPR (adequacy decision, standard contractual clauses, BCR or explicit consent).
8. Retention periods
- Accounting and tax data: 10 years
- Contractual data: contract duration + 5 years
- Non-client prospects: 3 years from last contact
- Non-essential cookies: 13 months maximum
- Connection logs: 1 year
- Job applicant data: 2 years from last contact
9. Rights of data subjects
In accordance with articles 15 to 22 GDPR:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure / right to be forgotten (Art. 17)
- Right to restriction (Art. 18)
- Right to portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent (Art. 7.3)
- Right to set post-mortem directives
- Right not to be subject to automated decision (Art. 22)
Exercise at [email protected] or by post. Reasoned response within 1 month, extendable by 2 months in case of complexity.
10. Right to lodge a complaint
- Belgium: APD/GBA, Rue de la Presse 35, 1000 Brussels - autoriteprotectiondonnees.be
- France: CNIL, 3 place de Fontenoy, 75007 Paris - cnil.fr
- Luxembourg: CNPD, 15 boulevard du Jazz, 4370 Belvaux
- Netherlands: Autoriteit Persoonsgegevens, Bezuidenhoutseweg 30, 2594 AV The Hague
- Other EU/EEA: authority of habitual residence, workplace or infringement location
11. Security measures
In accordance with article 32 GDPR: TLS 1.3 encryption, AES-256 at rest, pseudonymisation, geo-replicated encrypted backups, RBAC access control, mandatory MFA for admins, logging, annual penetration tests, continuous training, confidentiality clauses, continuity plan.
12. Notification of breaches
In case of breach likely to result in risk, notification to authority within 72 hours (Art. 33). If high risk, notification to data subjects without undue delay (Art. 34).
13. Modifications
This policy may be modified. Any substantial modification is notified by any appropriate means, in particular within the Services or by email.