Privacy Notice
This notice sets out how Time Solutions processes personal data: which data, for which purpose, on which legal basis, for how long, who receives it and which rights you can exercise. It is drafted to satisfy Articles 12 to 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data. Terms defined in the GDPR carry that meaning here.
Contents
- Identity of the controller
- Scope, and the two capacities in which we act
- Processing activities
- Source of the data
- Cookies and similar technologies
- Recipients and processors
- Transfers outside the European Economic Area
- Retention periods
- Automated decision making and artificial intelligence
- Security and personal data breaches
- Your rights, and how to exercise them
- Complaints and remedies
- Amendments
Article 1. Identity of the controller
1.1. The controller for the processing described in this notice is:
| Entity | De Cauwer Capital BV, trading under the name Time Solutions |
|---|---|
| Enterprise number | BE 1035.343.554 |
| Registered office | Lange Kievitstraat 132, 2018 Antwerpen, Belgium |
| Website | timesolutions.be |
| Contact | mdc@timesolutions.be |
1.2. No Data Protection Officer has been appointed. None of the three grounds in Article 37(1) GDPR is met: we are not a public authority, our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, and they do not consist of large scale processing of special categories of data. All privacy correspondence reaches the address in Article 1.1 and is handled by the founder personally.
Article 2. Scope, and the two capacities in which we act
2.1. This notice applies to the processing for which Time Solutions determines the purposes and the means, and therefore acts as controller within the meaning of Article 4(7) GDPR: this website, our commercial correspondence, our client and supplier administration, and our recruitment.
2.2. Where we design, build or operate digital infrastructure for a client and that infrastructure processes personal data belonging to that client, such as data concerning its customers, its staff or its suppliers, the client determines the purposes and the means. The client is then the controller and Time Solutions acts as processor within the meaning of Article 4(8) GDPR, exclusively on the client's documented instructions. That processing is governed by the data processing agreement concluded under Article 28(3) GDPR with that client, and not by this notice.
2.3. If you are a data subject of one of our clients and you address a request to us, we are not entitled to act on it ourselves. We forward it to the client without undue delay and inform you that we have done so.
Article 3. Processing activities
3.1. Each processing activity is set out below with its purpose, the categories of data concerned and its legal basis under Article 6(1) GDPR.
3.2. Consultation of this website
| Data | IP address, date and time, resource requested, HTTP status code, user agent, referrer |
|---|---|
| Purpose | Delivering the website, keeping it available, and detecting, investigating and remedying abuse and security incidents |
| Legal basis | Our legitimate interest in operating and defending our own infrastructure (Article 6(1)(f) GDPR) |
| Balancing | The data is not enriched, not linked to an identified person, not profiled and not used commercially. The interference with your interests is minimal and the processing is necessary to run the site at all |
3.3. The contact form on the home page
The form transmits nothing to this website. It composes a message locally in your browser and hands it to your own mail application, where you decide whether to send it. Nothing you type is received, stored or logged by this site, and nothing is sent to a third party form service. If you do not send the message, no processing takes place.
3.4. Correspondence and commercial contact
| Data | Name, email address, any telephone number, company and function details, and the content of your message |
|---|---|
| Purpose | Answering your enquiry, preparing a quotation, and the follow up that a concrete enquiry reasonably invites |
| Legal basis | Steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR), or our legitimate interest in answering enquiries and maintaining business relationships (Article 6(1)(f) GDPR) |
3.5. Client and supplier administration
| Data | Identification and contact details of contact persons, contractual and project correspondence, invoicing and payment data |
|---|---|
| Purpose | Performance of the agreement, project administration, invoicing, recovery of unpaid sums, and the statutory bookkeeping and tax obligations that follow from it |
| Legal basis | Performance of a contract (Article 6(1)(b) GDPR); compliance with a legal obligation for accounting and VAT records (Article 6(1)(c) GDPR); our legitimate interest in establishing, exercising or defending legal claims (Article 6(1)(f) GDPR) |
3.6. Job applications
| Data | Name and contact details, curriculum vitae, motivation, links to work you have published, portfolio or repository content you send us, and our assessment notes |
|---|---|
| Purpose | Assessing your application and conducting the selection procedure |
| Legal basis | Steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR). Retention of your file beyond the procedure takes place only with your consent (Article 6(1)(a) GDPR), which you may withdraw at any time |
Please do not send us special categories of personal data within the meaning of Article 9 GDPR, being data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, data concerning health, or data concerning a person's sex life or sexual orientation. We do not request it, we have no basis on which to process it, and we delete it if we receive it.
Article 4. Source of the data
4.1. In almost every case the data reaches us from you directly.
4.2. In addition, we may consult publicly accessible professional sources about a company we are in contact with, such as its website, the Crossroads Bank for Enterprises, publicly filed annual accounts, or a professional network profile, in order to prepare a conversation. That processing rests on our legitimate interest in preparing a commercial contact properly.
4.3. We do not purchase personal data, we do not scrape it, and we do not enrich it through data brokers.
Article 5. Cookies and similar technologies
5.1. This website sets no cookies and writes nothing to local storage or session storage for tracking purposes. There is no analytics, no advertising pixel, no heat mapping, no session identifier and no device fingerprinting.
5.2. This is why no consent banner is shown. Under Article 129 of the Belgian Act of 13 June 2005 on electronic communications, which transposes Article 5(3) of Directive 2002/58/EC, consent is required for storing information on, or gaining access to information already stored on, your device, unless that storage or access is strictly necessary. Here there is neither.
Article 6. Recipients and processors
6.1. Personal data is not sold, rented or exchanged, and it is not shared for the marketing purposes of a third party.
6.2. Data is disclosed only to the following categories of recipient:
- our hosting provider, which stores the website and its access logs on our behalf;
- our email and office provider, which carries and stores our correspondence;
- our accountant and, where necessary, our lawyer, each bound by professional secrecy;
- public authorities, where a legal obligation or a valid legal request compels disclosure.
6.3. Each processor acts under a written agreement meeting the requirements of Article 28(3) GDPR, processes the data only on our documented instructions, is bound by confidentiality, and may not use the data for its own purposes. A processor may not engage a sub-processor without our prior authorisation.
Article 7. Transfers outside the European Economic Area
7.1. Processing is kept within the European Economic Area wherever possible. The fonts, scripts and images on this website are served from this domain, so consulting a page does not disclose your IP address to a recipient in a third country.
7.2. Where a provider processes data outside the European Economic Area, the transfer takes place on the basis of an adequacy decision of the European Commission under Article 45 GDPR or, failing that, on the basis of the Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 under Article 46(2)(c) GDPR, together with the supplementary measures indicated by a transfer impact assessment.
7.3. You may request a copy of the safeguards in place at the address in Article 1.1.
Article 8. Retention periods
8.1. Personal data is not kept longer than is necessary for the purpose for which it was collected, subject to the statutory minimum periods below.
| Server logs | A short technical period, after which they are overwritten |
|---|---|
| Enquiries | Where no contract follows: up to twelve months after the last contact |
| Client files | For the duration of the relationship, and thereafter for the limitation period applicable to claims arising from it |
| Accounts | Seven years, as required by Belgian accounting and VAT legislation |
| Applications | Until the position is filled, then erased. With your consent, two years from the last contact for future openings |
8.2. At the end of the applicable period the data is erased or irreversibly anonymised.
Article 9. Automated decision making and artificial intelligence
9.1. We take no decision concerning you that produces legal effects or similarly significantly affects you and that is based solely on automated processing within the meaning of Article 22 GDPR. Applications are assessed by a person. Commercial decisions are taken by a person.
9.2. We build systems that use artificial intelligence for our clients. In those projects the client is the controller and decides how such systems are used. We design them so that a person can review, correct and override what the system proposes, and we assist our clients in meeting their own obligations under Regulation (EU) 2024/1689 (the AI Act).
9.3. Personal data obtained through this website, through correspondence with us or through a client engagement is not used to train general purpose artificial intelligence models, and is not made available to third parties for that purpose.
Article 10. Security and personal data breaches
10.1. We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR: transport encryption on this website, access restricted to those who need it, multi factor authentication on the accounts that matter, data minimisation by default, and third party dependencies that are pinned and reviewed rather than loaded from external origins.
10.2. No measure offers absolute protection. Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, we notify the Data Protection Authority without undue delay and where feasible within 72 hours, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk, we inform the data subjects concerned in accordance with Article 34 GDPR.
Article 11. Your rights, and how to exercise them
11.1. Under Articles 15 to 22 GDPR you have the right to:
- access: obtain confirmation as to whether we process your data and, if so, a copy of it together with the information listed in Article 15;
- rectification: have inaccurate data corrected and incomplete data completed;
- erasure: have your data deleted where one of the grounds in Article 17 applies;
- restriction: have the processing limited while a dispute about accuracy or lawfulness is resolved;
- portability: receive the data you provided in a structured, commonly used and machine readable format, and have it transmitted to another controller where technically feasible;
- object: object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest, and object at any time and without reason to processing for direct marketing;
- withdraw consent: where processing rests on consent, withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
11.2. Requests are addressed to mdc@timesolutions.be. We reply within one month of receipt. Where the request is complex or where several requests have been made, that period may be extended by two further months, in which case we inform you of the extension and the reasons for it within the first month.
11.3. Exercising these rights is free of charge. Only where a request is manifestly unfounded or excessive, in particular because of its repetitive character, may we charge a reasonable fee or refuse to act, in which case we state our reasons.
11.4. Where we have reasonable doubts as to the identity of the person making the request, we may request the additional information necessary to confirm it, and no more than that verification requires.
Article 12. Complaints and remedies
12.1. If you consider that we process your data unlawfully, we would prefer to hear it first, at the address in Article 1.1.
12.2. You are entitled in any event to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit, Autorité de protection des données), gegevensbeschermingsautoriteit.be, or with the supervisory authority of the Member State of your habitual residence or place of work.
12.3. You also have the right to an effective judicial remedy against a controller or processor under Article 79 GDPR, and the right to compensation for material or non-material damage under Article 82 GDPR.
Article 13. Amendments
13.1. This notice may be amended to reflect a change in our processing or in the applicable law. The version number and the date at the head of this page change with it.
13.2. Where an amendment is material, we take reasonable steps to bring it to the attention of the persons affected. The version published on this page is the version that applies.
Back to the home page