# Privacy policy

We are very pleased that you have shown interest in our company. Data protection is a particularly high priority for Protector BVBA.

### Website

It is possible to use our websites without providing personal data. However, for specific reasons and for certain services via our website, it may be necessary to process personal data. Every visit to and use of the website is subject to this privacy policy.

### Projects

For specific projects, it may be necessary for us to process personal data on an individual basis. This information, as well as its nature, scope and purpose, will always be communicated to the data subject, and explicit consent must be given prior to any type of processing. The data subject may exercise the right to withdraw his or her consent at any time by contacting Protector BVBA/NV via the email address: [info@protector.be](mailto:%20info@protector.be.). The processing of a data subject’s personal data will always be carried out in accordance with the General Data Protection Regulation and in accordance with the country-specific data protection rules applied by Protector BVBA to each individual situation. Personal data will be treated in strict confidence. Such personal data will not be transferred to third parties, unless stated otherwise. All our projects are subject to this privacy policy.

---

## Definitions

### General Data Protection Regulation:

The General Data Protection Regulation is a set of rules designed to protect the personal data of European citizens. This Regulation concerns the protection of personal data in the broadest sense of the term, regardless of their form or nature: private, professional or public. The GDPR was approved in April 2016 and has been fully applicable in all EU countries since 25 May 2018.

### Anonymisation:

The anonymisation of personal data consists of modifying the content or structure of such data in order to make it very difficult or impossible to ‘re-identify’ natural persons.

### Restriction of processing:

The restriction of processing is the marking of stored personal data with the aim of limiting their processing in the future.

### Data subject:

The data subject is an identified or identifiable natural person whose personal data are processed by the controller.

### Third party:

A third party is a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

### Aggregated data:

Aggregated data are composed of microdata files and are the result of a combination of various measures. They are obtained by adding up or averaging individual values. They provide information about groups with common characteristics.

### Recipient:

The recipient is a natural or legal person, public authority, agency or another body to which personal data are disclosed, whether or not it is a third party. However, public authorities which may receive personal data in the context of a particular investigation in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall comply with the applicable data protection rules according to the purposes of the processing.

### Personal data:

‘Personal data’ means any information relating to an identified or identifiable natural person (“data subject”). In the above definition, “any information” means all information, such as names, genders, professions and other types of data available in various forms, including alphabetical, numerical and graphical, and stored on paper or in computers or otherwise.

### Profiling:

Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

### Pseudonymisation:

Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

### Consent:

The consent of the data subject is any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

### Encryption:

Encryption is the process by which data segments are mathematically scrambled using a password.

### Processor:

Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

### Processing:

Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

### Controller or data controller:

The controller or data controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

---

## Name and address of the controller

Protector Belgium BVBA, with its registered office in Belgium at 1070 Brussels, Biestebroekstraat 2A, VAT BE 0421.283.965, RPR Brussels, and reachable by telephone at

 +32 2 526 07 70, and by email at [info@protector.be.](mailto:info@protector.be.)

---

## Legal bases and nature of the personal data we collect, use and process

Through this privacy policy, we aim to inform the general public about the nature and legal bases of the personal data that we may collect, use and/or process.

### Legal bases

We may be required to collect, use and/or process personal data based on the following:

- Consent: the individual has clearly given us permission to process his/her personal data for a specific purpose.
- Contract: the processing is necessary for a contract we have with the individual, or because the individual has asked us to take specific steps before entering into a contract.
- Legal obligation: the processing is necessary to comply with the law (excluding contractual obligations).
- Public task: the processing is necessary to perform a task carried out in the public interest.
- Legitimate interests: the processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a valid reason to protect the individual’s personal data which overrides those legitimate interests.

### Nature

Examples of personal data that we may need to collect, use and process include, but are not limited to: first name, last name, maiden name, email address, home address (street, postcode, city), telephone number, photograph, date of birth, national registration number (social security), employee number, IP address, cookie ID, location data, social media profile IDs/links, employment history, job title, education history (...). Special categories of personal data may include: sex/gender, race/ethnicity, place of birth/place of origin, spouse’s surname (...).

---

## Technical and organisational measures

Protector has taken numerous technical and organisational measures to ensure the most optimal protection of personal data. The following measures have been taken, among others (non-exhaustive list):

- Only authorised personnel have access to personal data relating to specific projects
- Only persons who process personal data have access to them
- Use of passwords
- Encryption
- Anonymisation
- Data aggregation
- Firewalls

---

## Rights of the data subject

In accordance with the [GDPR](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679), all data subjects have the following rights:

- Right to transparency
- Right to confirmation
- Right of access
- Right to rectification
- Right to erasure (the “right to be forgotten”)
- Right to restriction of processing
- Right to data portability
- Right to object
- Automated individual decision-making, including profiling
- Right to withdraw consent for data protection.

For more information about these rights, you may consult the [GDPR](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679).

If you would like more information about this privacy policy, have any questions, or wish to exercise any of the above rights, please do not hesitate to contact us at the following address: [info@protector.be](mailto:info@protector.be.)

This privacy policy may be amended without prior notice. We therefore recommend that you consult it regularly.

---

 |  | ## What Our Customers Say  "We are more than satisfied with the work you completed. And we have nothing but praise for your employees."  Patrick |

|---|---|
