— Policy
Our privacy policy
Introduction
Peinser BV (“Peinser”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we process, why we process it, how long we keep it, who we may share it with, and the rights you have under applicable data protection law, including the General Data Protection Regulation (“GDPR”).
Peinser BV is a private limited company organised and existing under the laws of Belgium, with registered office at Jagers te-Voetlaan 17, Zemst, Belgium, and registered with the Crossroads Bank for Enterprises under number 0799.620.488.
When Peinser determines the purposes and means of processing personal data, Peinser acts as the data controller. You can contact us regarding privacy or data protection matters at hello@peinser.com.
In some client engagements, Peinser may process personal data on behalf of a client and under that client’s instructions. In those circumstances, the client acts as the data controller and Peinser acts as a data processor. Such processing is governed by the relevant client agreement and, where required, a data processing agreement.
Personal data we process
We only process personal data that is relevant to our activities and the services we provide. Depending on how you interact with Peinser, this may include the following categories of personal data.
Website and business enquiries
When you contact Peinser regarding a potential project, collaboration or other business enquiry, we may process information such as:
- Your name;
- Your professional e-mail address and other contact details you provide;
- Your company, organisation, role or professional function;
- The content of your message and subsequent correspondence;
- Information about a proposed project, engagement or collaboration that you choose to provide to us.
We process this information to respond to your enquiry, discuss your requirements, prepare proposals and quotations, and take steps at your request before potentially entering into a contract.
The legal basis for this processing is the performance of a contract or the taking of pre-contractual steps at your request, in accordance with Article 6(1)(b) GDPR.
Client projects and technical access
In the course of providing consultancy, engineering or IT services, we may process professional contact information relating to our clients and their representatives, including:
- Names and professional contact details;
- Company, team, role and function information;
- Project-related correspondence and documentation;
- Account identifiers, usernames, access records or other technical information necessary to provide the agreed services;
- Other personal data that is necessary for the performance of the relevant engagement.
Where Peinser processes such information for its own contractual administration and delivery of services, the legal basis is the performance of the relevant contract in accordance with Article 6(1)(b) GDPR.
Where Peinser obtains access to personal data controlled by a client solely for the purpose of performing services on that client’s behalf, Peinser generally acts as a data processor. We process such data only in accordance with the client’s documented instructions and the applicable contractual arrangements.
Job applicants and freelance collaborators
If you apply for a position with Peinser or contact us regarding a freelance collaboration, we may process information such as:
- Your name and contact details;
- Your CV or professional profile;
- Your employment and educational history;
- Your skills and professional experience;
- Your portfolio, GitHub profile, LinkedIn profile or similar information you provide;
- Your location and availability;
- Your correspondence with Peinser;
- Other information you voluntarily provide in connection with your application or proposed collaboration.
We process this information to assess your application or proposed collaboration, communicate with you, conduct the selection process and, where appropriate, take steps towards entering into an employment, consultancy or freelance agreement.
The legal basis for this processing is the taking of pre-contractual steps at your request in accordance with Article 6(1)(b) GDPR.
We do not intentionally request special categories of personal data, such as health information, political opinions or religious beliefs, as part of an initial application unless such information is specifically necessary and there is a lawful basis for processing it.
Technical and security information
When our website or IT infrastructure is accessed, limited technical information may be processed by Peinser or its infrastructure providers for operational and security purposes. This may include IP addresses, timestamps, requested resources, browser or user-agent information and security-related logs.
We process such information where necessary to operate, protect and secure our website and systems, diagnose technical issues, prevent abuse and investigate security incidents. The legal basis for this processing is our legitimate interest in maintaining the security, integrity and availability of our IT systems and services in accordance with Article 6(1)(f) GDPR.
We do not use this information for advertising, behavioural profiling or marketing purposes.
When providing information is necessary
Certain personal data may be necessary for us to respond to an enquiry, take steps towards entering into a contract, assess an application or perform an agreed service. You are not generally required by law to provide such information, but if necessary information is not provided, we may be unable to respond to your request, assess your application or enter into or perform the relevant agreement.
Disclosure of personal data
We do not sell personal data and we do not use personal data for advertising or direct marketing.
Where necessary for the purposes described in this Privacy Policy, personal data may be disclosed to the following categories of recipients:
- Authorised personnel and contractors working with Peinser;
- IT, hosting, communications, e-mail, cloud and other infrastructure or service providers used to operate our business;
- Professional advisers, such as accountants, legal advisers or other professional service providers, where relevant;
- Public authorities, courts, regulators or law-enforcement authorities where disclosure is required by applicable law;
- Other parties where disclosure is necessary to establish, exercise or defend legal claims.
Service providers that process personal data on our behalf are required to process that data only for the agreed purposes and subject to appropriate contractual and security obligations.
How long do we keep your personal data?
We retain personal data only for as long as necessary for the purpose for which it was collected, taking into account contractual, operational, legal and security requirements.
- Business enquiries: information relating to enquiries that do not result in an engagement is retained only for as long as reasonably necessary to handle and follow up the enquiry and is subsequently deleted when it is no longer required.
- Client engagements: personal data necessary for an active engagement is retained for the duration of that engagement and, where necessary, afterwards to comply with legal obligations or to establish, exercise or defend legal claims.
- Applications and freelance enquiries: application data is retained for the duration of the relevant selection or contracting process and is deleted when it is no longer necessary for that process, except where further retention is necessary to comply with a legal obligation or to establish, exercise or defend legal claims.
- Technical and security logs: logs are retained only for the period reasonably necessary for security, operational troubleshooting and incident investigation.
Where applicable law requires information to be retained for a longer period, we retain that information for the legally required period.
International transfers
We aim to use service providers and infrastructure that process personal data within the European Economic Area (“EEA”).
If personal data is transferred to a country outside the EEA, we ensure that an appropriate transfer mechanism under applicable data protection law is in place. Depending on the destination and provider, this may include an adequacy decision adopted by the European Commission or appropriate safeguards such as Standard Contractual Clauses.
You may contact us at hello@peinser.com if you would like more information about safeguards applicable to an international transfer of your personal data.
Keeping your personal data secure
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
The measures we apply are selected taking into account the nature of the data, the relevant processing activities and the risks associated with the processing. We periodically review our technical and organisational security measures and update them where appropriate.
Cookies and similar technologies
Peinser does not use cookies, advertising trackers or fingerprinting technologies on peinser.com for analytics, advertising, behavioural profiling or traffic aggregation.
Our hosting or infrastructure may process limited technical information that is necessary to deliver and secure the website, as described in the section on technical and security information above.
If we introduce non-essential cookies or tracking technologies in the future, we will update this Privacy Policy and, where required, request appropriate consent before using them.
Your rights
Subject to the conditions and limitations provided by the GDPR, you may have the right to:
- Request access to the personal data we process about you;
- Request correction of inaccurate or incomplete personal data;
- Request deletion of your personal data;
- Request restriction of the processing of your personal data;
- Receive personal data you provided to us in a structured, commonly used and machine-readable format and, where applicable, have it transmitted to another controller;
- Object to processing based on our legitimate interests, subject to the conditions provided by applicable law.
These rights are not absolute and may be subject to exceptions provided by applicable law.
To exercise your rights, please contact hello@peinser.com. We may request additional information where reasonably necessary to verify your identity before processing your request.
Right to lodge a complaint
If you believe that Peinser has processed your personal data in breach of applicable data protection law, you have the right to lodge a complaint with a competent data protection supervisory authority.
In Belgium, the supervisory authority is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données). More information is available at www.gegevensbeschermingsautoriteit.be .
We encourage you to contact us first at hello@peinser.com so that we have an opportunity to address your concern.
Automated decision-making
Peinser does not use personal data to make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect individuals.
Changes to this privacy policy
We may update this Privacy Policy from time to time to reflect changes in our activities, services, technologies or legal obligations. When we make material changes, we will update the revision date shown at the top of this page.
We encourage you to review this Privacy Policy periodically for the latest information about how we process and protect personal data.