Privacy Policy
How we handle your personal data — transparent and in compliance with GDPR.
Who we are
BV De Cock ICT, trading as Deskflow, is the data controller for the personal data collected via the website www.deskflow.eu and the Deskflow platform.
BV De Cock ICT
Stationsstraat 20, 2980 Sint-Katelijne-Waver, Belgium
Company number: BE0891.296.376
Email: info@deskflow.eu
Phone: +32 3 290 34 80
BV De Cock ICT has not appointed a Data Protection Officer (DPO), as the nature and scope of our processing activities do not legally require one. For any privacy-related questions, please contact info@deskflow.eu.
What personal data do we process?
Depending on how you interact with us, we process the following categories of personal data:
Identification and contact details
- Name, first name, job title
- Email address, phone number
- Company name and company registration number
- Billing and delivery address
Usage data and technical data
- IP address and device information (device type, operating system, browser)
- Pages visited, click behaviour and session duration on our website
- Login times and usage patterns in the Deskflow platform
Communication and interaction data
- Content of messages via the contact form or email
- Notes and call records from our CRM system
- Preferences for marketing and newsletter communications
Customer and billing data
- Subscription and contract details
- Payment history (no full payment card details)
We do not process special categories of personal data (such as health data, racial or ethnic origin, political opinions or biometric data).
The personal data originates from: you directly (via forms, email or phone contact), automatically through your use of our website or platform, and in some cases from publicly available sources or business networks for prospecting purposes.
Purposes and legal bases
We only process personal data for specified, explicit and legitimate purposes. The table below sets out, for each purpose, the legal basis under Article 6 GDPR.
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Performance of a contract (delivery of the Deskflow platform, invoicing, customer management) | Art. 6(1)(b) — performance of a contract |
| Responding to contact and demo requests | Art. 6(1)(b) — pre-contractual measures at the request of the data subject |
| Sending commercial newsletters and marketing communications | Art. 6(1)(a) — consent |
| Direct marketing to existing customers about similar services | Art. 6(1)(f) — legitimate interest (soft opt-in, Art. XII.13 Belgian Code of Economic Law) |
| Website analytics and optimising user experience | Art. 6(1)(a) — consent (via cookie banner) |
| Identification of website visitors for B2B prospecting (Leadinfo) | Art. 6(1)(f) — legitimate interest |
| Complying with legal obligations (accounting law, tax obligations) | Art. 6(1)(c) — legal obligation |
| Securing our systems and fraud prevention | Art. 6(1)(f) — legitimate interest |
Where we rely on legitimate interest (Art. 6(1)(f) GDPR), we have carried out a balancing test and established that our interest does not disproportionately outweigh the rights and freedoms of data subjects. You have the right to object to this (see Article 8).
Where you have given consent for marketing or cookies, you may withdraw this consent at any time without affecting the lawfulness of processing carried out before withdrawal. You can withdraw your consent via info@deskflow.eu or, for cookies, via the cookie banner on our website.
Retention periods
We do not retain your personal data for longer than necessary for the purposes for which it was collected, taking into account statutory retention obligations.
| Category | Retention period |
|---|---|
| Customer data and contractual documents | 10 years after the end of the contractual relationship (accounting law) |
| Invoices and accounting records | 7 years (Art. 4 VAT Code; Art. 6 Accounting Law) |
| Contact form and email correspondence (non-customers) | 2 years after the last contact |
| Prospects / CRM data | 3 years after the last relevant contact, or upon request for deletion |
| Applicant data | 6 months after completion of the procedure (unless you consent to a longer period) |
| Website logs (IP addresses, server logs) | 13 months |
| Analytics cookies and related data | 13 months after the cookie is placed |
| Marketing email list (consent) | Until consent is withdrawn, or 3 years after the last interaction |
Recipients and processors
We do not share your personal data with third parties unless this is necessary for the performance of our services, legally required, or you have given consent. We have entered into a data processing agreement with all external processors in accordance with Article 28 GDPR.
| Processor / recipient | Purpose | Location |
|---|---|---|
| Google Analytics (Google LLC) | Website analytics and statistics | US (see Art. 6) |
| Leadinfo (Leadinfo B.V.) | Identification of business website visitors | Netherlands / US |
| HubSpot (HubSpot Inc.) | Inbound marketing, forms, lead management | US (see Art. 6) |
| StoryLane | Interactive product demos | US (see Art. 6) |
| Hosting provider (cloud infrastructure) | Storage and availability of the Deskflow platform | EU |
We never sell your personal data to third parties.
International data transfers
Some of our processors are established outside the European Economic Area (EEA), in particular in the United States. Transfers of personal data to a third country are only permitted where an adequate level of protection is guaranteed in accordance with Chapter V GDPR.
For transfers to the US, we rely on the following safeguards:
- EU–US Data Privacy Framework (DPF): Processors certified under the DPF (European Commission adequacy decision of 10 July 2023) offer an adequate level of protection. This applies, among others, to Google LLC and HubSpot Inc. (to the extent certified).
- Standard Contractual Clauses (SCCs): Where a processor does not fall under the DPF, we use the Standard Contractual Clauses approved by the European Commission (Decision 2021/914/EU) as an appropriate safeguard.
You may request a copy of the applicable safeguards via info@deskflow.eu.
Automated decision-making and profiling
Deskflow does not use automated decision-making as referred to in Article 22 GDPR, i.e. decisions based solely on automated processing that produce legal effects concerning you or significantly affect you in a similar way.
We do use simple segmentation (e.g. segmenting email lists by sector or behaviour) for marketing purposes. This is not considered profiling within the meaning of Article 22 GDPR, but you always have the right to object (see Article 8).
Your rights as a data subject
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR): You may request a copy of the personal data we process about you.
- Right to rectification (Art. 16 GDPR): You may have inaccurate or incomplete data corrected.
- Right to erasure (Art. 17 GDPR): You may request deletion of your data, unless we are legally required to retain it.
- Right to restriction of processing (Art. 18 GDPR): In certain cases, you may ask us to temporarily restrict processing.
- Right to data portability (Art. 20 GDPR): You may receive your data in a structured, commonly used and machine-readable format.
- Right to object (Art. 21 GDPR): You may object to processing based on legitimate interest or for direct marketing purposes. If you object to direct marketing, we will stop processing immediately.
- Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not have retroactive effect.
- Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with the Belgian supervisory authority (see Article 13).
Send your request by email to info@deskflow.eu. We will handle your request within one month of receipt. For complex or multiple requests, we may extend this period by two months, and we will inform you in good time. We may ask for proof of identity to prevent misuse.
Security of your data
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, alteration or disclosure. These measures include:
- Encryption of data in transit via TLS/HTTPS
- Access control based on the 'need-to-know' principle
- Regular backups and disaster recovery procedures
- Confidentiality obligations for employees with access to personal data
In the event of a personal data breach that poses a risk to your rights and freedoms, we will report this to the Data Protection Authority within 72 hours in accordance with Article 33 GDPR. Where the breach poses a high risk, we will also notify you personally (Art. 34 GDPR).
Cookies and similar technologies
Our website uses cookies and similar technologies. We distinguish the following categories:
| Category | Purpose | Legal basis |
|---|---|---|
| Strictly necessary cookies | Technical operation of the website (session, preference settings) | Legitimate interest (no consent required) |
| Analytics cookies (Google Analytics) | Measuring website visits and user behaviour | Consent |
| Marketing and tracking cookies | Targeted advertising and retargeting | Consent |
| Functional cookies (e.g. embedded demo integrations) | Enhanced functionality such as embedded demos | Consent |
You can adjust your cookie preferences at any time via the cookie banner on our website or by changing your browser settings. Please note that refusing certain cookies may limit the functionality of our website.
For more information about the specific cookies we place, please contact us via info@deskflow.eu.
Data of minors
Deskflow's services are intended exclusively for professional use by businesses and self-employed individuals. Our website and platform are not directed at minors under the age of 18.
We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a minor, we will delete it as soon as possible. Parents or guardians who believe their child has provided data to us can contact us via info@deskflow.eu.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities or in applicable law. The most current version is always available at www.deskflow.eu/privacyverklaring.
In the event of material changes, we will notify you by email or via a prominent notice on our website. The date of the last update is shown at the top of this page.
Contact and complaints procedure
Do you have questions about this Privacy Policy or about how we process your personal data? Please feel free to contact us:
BV De Cock ICT — Deskflow
Stationsstraat 20, 2980 Sint-Katelijne-Waver
Email: info@deskflow.eu
Phone: +32 3 290 34 80
If you are not satisfied with our response, or if you believe that we are not processing your personal data in accordance with the GDPR, you have the right to lodge a complaint with the competent supervisory authority:
Belgian Data Protection Authority (DPA)
Drukpersstraat 35, 1000 Brussels
Email: contact@apd-gba.be
Phone: +32 (0)2 274 48 00