Privacy Policy
Processing of personal data of the client and the user of the website
In this document, you will find our full privacy policy regarding the processing of personal data of the client and the user of the website, as well as the terms of use. ESOMUS (hereinafter "we") is aware of the importance of respecting privacy and protecting the personal data of the clients and visitors of its website.
1. Scope of application
This website is operated by ESOMUS, srl, whose registered office is located at rue de l'arbre à la Croix, 293, 4460 Horion-Hozémont, and whose company registration number (BCE) is BE0723595056. We act as data controller when we process the personal data of our clients and the users of our website.
It is important to us to create and maintain an environment in which our clients can be assured that their information will not be misused. We comply with applicable data protection regulations, in particular the General Data Protection Regulation 2016/679 (GDPR), as well as the related national legislation.
When you visit our website, this privacy policy and the terms of use apply. Use of this website, the platform, and their content is only permitted subject to compliance with this policy.
2. What personal data do we collect ?
Most of our website can be accessed without you having to provide any personal data. We may collect and process the following categories of data:
- Name, title, address;
- Contact details (email address, telephone number);
- Company;
- Login data (username and password) for the section of the site reserved for clients;
- Location data (IP addresses, GPS signals from a mobile device);
- Information from cookies, web beacons, or the Internet;
- Pages viewed, browser type, browsing time, and operating system;
- Telephone conversations, which may be recorded for quality assurance or training purposes.
We may also collect publicly available information in order to verify the data we have previously collected and to manage and expand our activities.
3. Why do we collect this information and on what legal basis ?
We collect the aforementioned information in order to better understand your needs and provide you with a better service, in particular to:
- Answer your questions about our products or services;
- Provide you with the products and services you have ordered;
- Give you access to the online client platform;
- Verify your identity and financial data for payment purposes;
- Improve our products and services;
- Comply with legal and regulatory obligations;
- Prevent fraud, terrorism, and security incidents;
- Send you periodic promotional emails (with your consent).
We process personal data on the basis of Article 6(1)(a), (b), (c), and (f) of the GDPR.
| Purpose | Data | Legal basis | Retention period |
|---|---|---|---|
| Direct marketing (clients) | Name and contact details (email) | Legitimate interest | 10 years after the end of the business relationship |
| Direct marketing (prospects) | Name and contact details (email) | Consent | 10 years |
| Client management | Name, contact details, position, business address | Performance of the contract — Legitimate interest | 10 years after the end of the business relationship |
| Use of Audityx software | Name, contact details, position, business address | Performance of the contract — Legitimate interest | 10 years after the end of the business relationship |
4. How do we use and share your data ?
We may share your personal data with:
- Companies belonging to the same group and/or subsidiaries;
- Any third party with whom you have asked us to share your data;
- Companies, institutions and/or partners that assist us in providing our services (hosting, data analysis, marketing support).
These companies only have access to your data when strictly necessary for the performance of their activities. Your personal data will never be sold or rented to third parties.
In the event of a sale to, or merger of, ESOMUS's activities with another company, your data will be disclosed to the potential acquirer's advisor and will be transferred to the new owners. Its use will remain subject to this policy.
5. Transfer outside the European Economic Area
We do not transfer your personal data to third countries located outside the EEA, except to countries wishing to follow the ISQM international standard. Such a transfer is lawful if the recipient is located in a country ensuring an adequate level of protection confirmed by an adequacy decision of the European Commission or via standard contractual clauses.
In certain specific cases, we ask for your prior consent to transfer your data outside the EEA.
6. Rights of the data subject
Data protection legislation grants you the following rights:
- Right of access: consult the information held about you and obtain a copy;
- Right to rectification: correct, complete, or delete any outdated or incorrect information;
- Right to restriction: restrict the processing of your data;
- Right to object: object to the processing of your data;
- Right to data portability: receive your data in a structured format and transmit it to another controller.
7. Procedure for exercising your rights
We may ask you to provide proof of your identity to ensure that your request is legitimate. In certain circumstances provided for by law, we may refuse access to your information.
You have the right to lodge a complaint with the competent supervisory authority. In Belgium, this is the Data Protection Authority, rue de la Presse 35, 1000 Brussels (contact@apd-gba.be).
8. Security
We have implemented reasonable technical and organisational measures to protect your data against destruction, loss, accidental or unlawful alteration, unauthorised disclosure, or unauthorised access. However, you should keep in mind that the Internet is an open system and that we cannot guarantee that no unauthorised third party will ever be able to circumvent these measures.
Our websites may contain links to third-party websites. We are not responsible for their privacy policies.
9. Terms of use and liability
A. Rights to the website and content — permitted use
Our website and its content are protected by copyright and intellectual property rights. Visitors are granted a personal, non-exclusive, and non-transferable right of use, allowing them to consult the site for their own use. Any other use is prohibited without our express, prior, and written consent.
B. Prohibited use
You undertake not to use the site unlawfully, not to damage it, not to send viruses or offensive content, and not to infringe the rights of third parties.
C. Liability
We take reasonable steps to ensure that our information is complete and up to date, but we cannot guarantee the complete absence of errors. This information does not constitute professional or legal advice. The user is solely responsible for their use of our websites.
10. Applicable law and competent courts
Belgian law applies to our website, to this policy, and to any disputes relating thereto. In the event of a dispute, only the courts of Liège have jurisdiction.
11. Forms and audience measurement on audityx.com
Contact, demo and quote forms, and the form on the page for French statutory auditors (commissaires aux comptes). The data you enter (name, contact details, company, position, message and details of your request) is sent by e-mail to our team so that we can answer your request. A confirmation is sent to the e-mail address you provided. Legal basis: pre-contractual measures taken at your request and our legitimate interest in answering you (Article 6.1 (b) and (f) GDPR). This data is then processed and kept as described in section 3.
To protect the forms against abuse, the IP address of the device sending a form, as well as the e-mail address entered, are kept in a hashed form, which cannot be traced back, for 24 hours at most. The forms are also protected by Cloudflare Turnstile (Cloudflare, Inc.), which checks that a submission comes from a person using technical signals from the browser and the IP address, without advertising cookies; this data may be processed outside the European Union, Cloudflare, Inc. being certified under the EU–US Data Privacy Framework. If the e-mail to our team cannot be sent, a copy of the request is kept on the website server, hosted in the European Union (OVHcloud), until it is handled, and then deleted.
Audience measurement. If you accept it in the cookie banner, we use Google Analytics (Google Ireland Limited) to understand how the site is used: pages viewed, visit duration, type of device, country and source of visits, as well as form submissions (without their content). Legal basis: your consent (Article 6.1 (a) GDPR), which you can withdraw at any time with the "Cookie settings" link at the bottom of the page. This data may be processed by Google in the United States; Google LLC is certified under the EU–US Data Privacy Framework. It is kept for 14 months at most.
12. Changes to this policy
ESOMUS may amend and update this policy at any time. The updated version will be published on this page and will take effect upon publication. Please check this page regularly.
Contact details
ESOMUS srl — BCE 0723595056
18, Place reine Astrid — Rocourt / Liège, Belgium
Tel.: 04 / 265 61 92 | Mobile: 0471 / 49 34 11
Email: info@esomus.com