KARIMT.COM BV
Rozenstraat 5 bus 4, 3630 Maasmechelen
BTW BE 1039.249.684
hello@karimt.com · +32 485 54 27 03
KARIMT.COM BV

Privacy and Data Protection Policy

This policy explains in plain language how KARIMT.COM BV handles personal data. Part A is the privacy statement for clients, prospects and website visitors. Part B describes the measures we take internally to protect data. In doing so, we follow the General Data Protection Regulation (GDPR) and Belgian privacy legislation.

Part A

Privacy statement

For clients, prospects and website visitors.
1

Who is responsible

KARIMT.COM BV, with registered office at Rozenstraat 5 bus 4, 3630 Maasmechelen and company number BE 1039.249.684, is responsible for the processing of your personal data. Questions about this policy or about your data can be sent to hello@karimt.com.

2

What data we process

Depending on your relationship with KARIMT.COM BV, this may involve:

  • identity and contact details: name, company, role, email address, telephone number, address;
  • billing and administrative details: VAT number, invoicing address, payment details;
  • data from our collaboration: briefing, correspondence, project material;
  • website visitor data: data you enter yourself via a form, and limited technical data via the website.
3

What we use it for

We process your data to prepare quotations, carry out assignments, invoice, communicate with you and meet our legal obligations. To a limited extent, we use contact details to inform you about our own services. We only do this if you can reasonably expect it or if you have given your consent.

4

On what basis

We process data because it is necessary to perform our agreement, because the law requires us to, because we have a legitimate interest in doing so (such as smooth operation and informing existing clients), or because you have given us your consent. You can withdraw your consent at any time.

5

Who we share it with

We never sell your data. We only share it with service providers who help us carry out the assignment, and only what is necessary for that purpose. Think of accounting and invoicing software, cloud and email services, hosting, and advertising platforms when we manage campaigns for you. With those processors we make the necessary arrangements on confidentiality and security. Some of them may process data outside the European Economic Area, in which case we ensure appropriate safeguards are in place.

6

How long we keep it

We do not keep your data longer than necessary for the purposes above. We retain administrative and accounting records for as long as the law requires, as a rule seven years. We keep contact details of prospects for as long as there is a reasonable prospect of collaboration.

7

Your rights

You have the right to access your data, to have it corrected or to have it deleted. You can also request that processing be restricted, object to certain processing, and request that your data be transferred. You can send a request to hello@karimt.com. If you are not satisfied, you can lodge a complaint with the Data Protection Authority, Drukpersstraat 35, 1000 Brussels, via contact@apd-gba.be.

8

Cookies

Our website only uses the cookies needed to function properly, and possibly cookies to measure usage. For non-essential cookies we ask for your consent. You can always manage cookies via your browser settings.

9

When we process on behalf of a client

For marketing and communication assignments, we sometimes process personal data on behalf of our client, for example data of their contacts or leads. In that case, our client is the controller and KARIMT.COM BV acts as processor. We set out this division of roles in a separate data processing agreement.

Part B

Data protection policy

The measures we take internally.
10

Our principles

We handle data according to fixed principles: we only process what is lawful and fair, for clear purposes, limited to what is necessary, accurate and up to date, no longer than necessary, and always in a secure manner.

11

Technical and organisational measures

We secure data with concrete measures:

  • access only for those who need it, with strong passwords and two-step verification where possible;
  • encrypted devices and secure, reliable tools and cloud services;
  • regular backups and updates;
  • tidy file management, so that data is not left lying around unnecessarily.
12

Processors and subcontractors

We choose service providers that themselves offer a solid level of data protection. With anyone who processes data on our behalf, we conclude a data processing agreement, and we require them to impose the same care on their own subcontractors.

13

Our dual role

For our own client and business data, we are the controller. When we process data on behalf of a client, we are the processor and follow that client’s instructions within the agreed limits.

14

Data breaches

If we identify a data breach, we act quickly to contain it and limit the consequences. If the breach poses a risk to the individuals concerned, we report it to the Data Protection Authority within seventy-two hours, and where necessary we inform the individuals concerned and our client.

15

Retention and destruction

When data has served its purpose and there is no longer a legal retention obligation, we delete or anonymise it in a secure manner.

16

Review

We update this policy when our operations or regulations require it. The applicable version is always available at karimt.com.