Privacy Statement
1. Purpose and Scope
1.1 Purpose
This policy explains how we process and protect personal data in accordance with the General Data Protection Regulation (GDPR). It describes the principles we follow when handling personal data and clarifies our roles and responsibilities when providing our services or operating our organisation.
The purpose of this document is to provide transparency on how personal data is handled, to ensure that processing activities are carried out in a controlled and lawful manner, and to give customers, partners, and other stakeholders a clear understanding of our approach to data protection.
This policy applies to personal data processed in the context of our business operations and when delivering our services.
1.2 Scope
This policy covers all processing of personal data carried out by us in the course of operating our organisation and providing our services.
Two different roles exist in this context:
1.2.1 Controller Role
For personal data relating to our own organisation, such as employee information, supplier contacts, and business relations, we act as the data controller and determine the purposes and means of processing.
1.2.2 Processor Role
When delivering services to customers, we process personal data on behalf of the customer. In that case, the customer determines the purpose and scope of the processing and remains the data controller.
When acting as a processor, we process personal data strictly according to the documented instructions of the customer and the contractual arrangements in place.
This policy applies to all employees, contractors, and third parties involved in processing personal data on our behalf.
2. Principles for Processing Personal Data
We process personal data in accordance with the principles established by the GDPR. These principles guide how personal data is handled across our organisation and when delivering services to customers.
Personal data is processed in a lawful, fair, and transparent manner. Processing activities are performed for clearly defined purposes and only to the extent necessary for those purposes. We avoid collecting or using personal data beyond what is required for the relevant activity or service.
Personal data is kept accurate and, where necessary, updated. When inaccuracies are identified, appropriate corrections are made without undue delay.
Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected or to comply with legal or contractual obligations. Retention and disposal rules are defined in the relevant internal procedures governing data disposal and destruction.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. Security controls applied to personal data are defined in the applicable security policies and operational procedures.
When we act as a processor for our customers, personal data is processed exclusively according to the documented instructions of the customer and the applicable contractual agreements. We do not use customer data for our own purposes.
3. Processing of Personal Data
3.1 Personal Data Controlled by the Organisation
In the course of operating our organisation, we process personal data for which we act as the data controller. This concerns personal data related to employees, contractors, customers, suppliers, and other business contacts.
This processing is necessary for the normal functioning of the organisation and may include activities such as human resources management, supplier management, customer relationship management, financial administration, and compliance with legal or contractual obligations.
Personal data processed in this context may include identification information, contact details, professional information, and other data necessary to support the relevant business activity.
When acting as the data controller, we determine the purposes and means of processing. Processing is carried out in accordance with the GDPR and applicable legal requirements.
Personal data is only accessible to authorised personnel who require access in order to perform their duties. Access is limited according to the principle of least privilege and is subject to the security measures defined in our internal policies and procedures.
Where external service providers process personal data on our behalf, appropriate contractual and organisational safeguards are established to ensure that personal data is handled in accordance with applicable data protection requirements.
3.2 Personal Data Processed on Behalf of Customers
When delivering our services, we process personal data on behalf of our customers. In this context, the customer acts as the data controller and determines the purpose, scope, and legal basis for the processing. We act as a data processor and process personal data strictly according to the documented instructions of the customer and the contractual agreements in place.
Personal data is received from the customer as part of the operation of the services provided. The nature and categories of personal data processed depend on the specific service and the instructions defined by the customer.
We do not determine the purpose of the processing and do not use customer data for our own purposes. Processing activities are limited to what is necessary to provide the agreed services.
Where personal data needs to be stored as part of the service, this is done in accordance with the contractual arrangements with the customer and the applicable security measures implemented within our infrastructure. If personal data is processed only transiently as part of a processing operation, it is not retained once the processing task has been completed.
Access to personal data processed on behalf of customers is restricted to authorised personnel who require access in order to operate or support the service. Access is governed by internal security policies and operational procedures.
We support our customers in fulfilling their data protection obligations where required, including responding to requests from data subjects or authorities, in accordance with the contractual arrangements governing the service.
4. Data Subject Rights
Individuals whose personal data we process have rights under the GDPR regarding how their personal data is handled.
These rights include the right to request access to personal data, the right to request correction of inaccurate data, the right to request deletion of personal data where applicable, the right to request restriction of processing, and the right to object to certain processing activities. Individuals may also have the right to request the transfer of their personal data to another organisation where applicable.
When we act as the data controller, requests related to these rights can be addressed directly to us. We review such requests and respond in accordance with the applicable legal requirements.
When we process personal data on behalf of a customer, the customer remains the data controller and is responsible for handling requests from data subjects. In such cases, we support the customer where necessary to allow them to fulfil their obligations under the GDPR.
Requests concerning personal data can be submitted through the contact channels described in this policy.
5. Subprocessors and Service Providers
In the course of operating our services and infrastructure, we may rely on external service providers who process personal data on our behalf. When these providers process personal data in support of our services, they act as subprocessors.
Subprocessors are engaged only where necessary for the delivery, operation, or support of our services. Before engaging such providers, we verify that appropriate safeguards are in place to ensure that personal data is handled in accordance with applicable data protection requirements.
Appropriate contractual arrangements are established with subprocessors to ensure that personal data is processed only for the agreed purposes and that adequate security and confidentiality measures are applied.
Subprocessors are required to process personal data exclusively according to our instructions and may not use the data for their own purposes.
A list of subprocessors used in the delivery of our services is maintained and made available to customers where and when relevant.
6. Data Location and International Transfers
Personal data processed within our services is hosted in infrastructure located within the European Economic Area (EEA). We apply data residency rules to ensure that personal data remains within the EEA.
Our infrastructure providers operate data centres in European regions, and services are configured to store and process personal data within those regions.
If personal data needs to be transferred outside the European Economic Area, such transfers are only performed where appropriate safeguards are in place in accordance with the GDPR. These safeguards ensure that personal data continues to receive an adequate level of protection.
Transfers outside the EEA are subject to contractual and organisational controls and are only carried out when required for the delivery of the service or to comply with legal obligations.
7. Protection of Personal Data
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure.
Security measures applied to personal data are defined in our internal information security policies and operational procedures. These measures include controls governing access management, system security, network protection, monitoring, and incident handling.
Access to personal data is restricted to authorised personnel who require access to perform their duties. Access rights are granted and reviewed according to the principle of least privilege.
Personal data processed within our systems is protected using appropriate security mechanisms such as secure communication channels, controlled system access, and protection of stored data. The detailed implementation of these controls is governed by the applicable internal security policies.
Where external service providers are involved in the operation of our services, they are required to apply appropriate security measures consistent with the protection of personal data.
8. Contact and Complaints
If you have questions regarding this privacy policy or the way personal data is processed by us, you may contact us using the contact details provided below.
Requests related to personal data protection or the exercise of data subject rights can also be submitted through these contact channels.
Data Protection Officer
Docbyte NV
Kortrijksesteenweg 1144
BE-9051 Gent
Belgium
Email: gdpr@docbyte.com
Phone: +32 9 242 87 30
If you believe that your personal data has been processed in a manner that does not comply with applicable data protection legislation, you have the right to lodge a complaint with the competent supervisory authority.
In Belgium, the competent authority is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de Protection des Données).
9. Changes to This Privacy Policy
This privacy policy may be updated from time to time to reflect changes in legal requirements, organisational practices, or the services we provide.
Updates to this document are subject to the internal review and approval process governing policy documents within the organisation. Revisions are documented through the document versioning and approval process.
The most recent version of this policy is the version approved and maintained by the organisation.