Introduction
EVD is strongly committed to protecting your privacy and handling your information in an open and transparent manner.This privacy notice explains how European VAT Desk (EVD) collects and uses personal data, and describes the rights you have with respect to your personal data.
EVD processes personal data for a variety of purposes. We collect this personal data directly from you, for example, if you visit www.vatdesk.eu, if you submit your contact details to receive marketing communications from us, if you submit event-related data to attend EVD events. Alternatively, we process your personal data in the context of providing professional services to your employer or service provider. Finally, we obtain your personal data via publicly available sources, such as LinkedIn. This privacy notice is intended to cover all of the above-mentioned scenarios.
This privacy statement also contains information about when we share your personal data with other third parties (for example, our service providers).
By submitting any personal data to us, you agree with the use by EVD of such data in accordance with this privacy statement.
COLLECTION OF PERSONAL DATA
We receive personal data, such as name, title, company address, email address, and telephone and fax numbers, from website visitors; for example when an individual subscribes to updates from us. Visitors are also able to send an email to us through the website. Their messages will contain the user’s screen name and email address, as well as any additional information the user may wish to include in the message.
Personal data that we collect about you when you visit our website falls into several categories.
Information that you provide voluntarily
We collect personal data that you provide voluntarily through our site, for example, when completing online forms to contact us, subscribing to a newsletter, , subscribing to receive marketing communications from us, registering for events that we are organizing. The information we collect about you include the following:
- Name
- Job title, job level or job function, role
- Company or organization
- Company data
- Contact information, including primary email, email address and telephone numbers
- Demographic information, such as industry, country, postcode, preferences and interests
- Information pertinent to fulfilling our services to you
- Any other personal data that you voluntarily choose to provide to us
We do not intentionally collect sensitive category data, unless you provide us with such data. While there may be free text boxes on the site where you are able to enter any information, we do not intend to process sensitive information. You are not required to provide, and should not disclose, sensitive personal information in the free text boxes. If you choose to provide any sensitive personal information in this manner, you acknowledge you consent to the collection and processing of this sensitive information.
If you register on our site, your personal data will be stored in our CRM system. Data of registrants is deleted after an individual has not actively engaged with EVD for 24 months, or sooner if required by law.
If you have opted out of receiving EVD publications, your basic contact details will remain on our opt-out list.
Information that we collect automatically
When you visit our site, we collect certain personal data automatically from your device. Specifically, the data we collect automatically include information, such as your IP address, pixel ID, device type, unique device identification number, browser type, broad geographic location (e.g., country or city-level location) and other technical information. We also collect information about how your device has interacted with our site, including the pages accessed, time you visited the site and links clicked. Collecting this information enables us to better understand the visitors who come to our site, where they come from and what content on our site is of interest to them. We use this information for our internal analytics purposes, and to improve the quality and relevance of our site to our visitors. Information will be collected using cookies and similar tracking technology, as explained further in the EVD Cookie Policy.
Our site uses Google analytycs (GA) ActiveCampaigns (AC) in order to provide reporting, visualisations and analysis of data. GA/AC process the following types of personal data: your IP address (to populate geosegmentation reports) and user IDs, email addresses, names and passwords to the extent provided directly by visitors of the site. Your personal data will be processed by GA/AC for the following purposes: (i) to capture web metrics about the journey of users within our site (e.g. pages viewed and links clicked); (ii) to analyze and understand overall site traffic information; (iii) to allow us to make informed decisions about our site; and (iv) to authenticate users and permit them to access our site.
Our site also uses various social media plugins.
Purposes for which we process your personal data as a visitor to our site are:
- To administer and manage our site, including to confirm and authenticate your identity, and prevent unauthorized access to restricted areas of our site
- To personalize and enrich your browsing experience by displaying content (including targeted advertising) that is more likely to be relevant and of interest to you
- To analyze the data of visitors to our site and site traffic information
- To capture webmetrics about the journey of users within our site
- To determine the company, organization, institution or agency that you work for or with which you are otherwise associated
- To develop our business and services
- To provide you with marketing communications,
- To conduct benchmarking and data analysis (for example, regarding usage of our site and demographic analyses of visitors of our site)
- To understand how visitors use the features and functions of our site
- To monitor and enforce compliance with applicable terms of use
- To conduct quality and risk management reviews
- To allow for event and webinar sign-up
- To allow for content download and lead capturing
- Any other purpose for which you provided information to EVD
Legal grounds for processing personal data of visitors of our site are:
- Our legitimate interest in the effective delivery of information and services to you, and the effective and lawful operation of our businesses
- Our legitimate interest in developing and improving our site, and your user experience
- Explicit consent of the visitor
When you engage us to provide you with professional services, we collect and use personal data when we have a valid business reason to do so in connection with those services.Where we need to process personal data to provide professional services, we ask our clients to provide the necessary information to the data subjects regarding its use.
In the context of providing professional services to clients, EVD also processes personal data of individuals who are not directly our clients (for example, employees, customers or suppliers of our clients).
The majority of the personal data we collect and use to provide our services is supplied voluntarily by (or collected by us from third-party sources at the request of) our clients. Because of this, if you are a client of EVD, then it will generally be obvious to you what personal data we collect and use. This information can include:
- Basic information, such as your name, the company you work for, your position and your relationship to a person
- Contact information, such as your postal address, email address and telephone numbers
- Any other personal data relating to you or other third parties which you provide to us for the purpose of receiving our services
We use this information:
- To provide services to you
- To administer our relationship and maintain contractual relations
- For accounting and tax purposes
- For marketing and business development
- To comply with our legal and regulatory obligations
- To establish, exercise or defend legal rights
- For historical and statistical purposes
EVD processes personal data about contacts (former, existing and potential EVD clients and/or individuals employed with them) using a customer relationship system (CRM) and a marketing automation tool (MA). These CRM/MA systems support the marketing operations of EVD. Contacts in our CRM systems will be sent EVD newsletters, marketing materials, learning opportunities, surveys and invitations to events.
In our CRM systems, we process the following categories of personal data:
- Name, job title, address, email address, phone number
- Name of employer or organization the individual is associated with
- Marketing preferences
We do not intentionally collect sensitive category data, unless you provide us with such data (for example, special dietary requirements which reveal your religious affiliation or any food allergies), if you attend one of our events.
Data of business contacts who have not been actively engaged with EVD in the past 24 months will be deleted from our CRM systems. If you have opted out of receiving future EVD publications, your basic contact details will remain on our opt-out list.
Legal grounds for processing personal data of business contacts are:
- Explicit consent of the business contact
- Our legitimate interest in managing the relationship with our business contacts and providing information about EVD, our services and events we organize
We process personal data about participants in EVD meetings, conferences, events and learning sessions (events).
As part of our event management processes, we process the following personal data (but only to the extent required for a specific event):
- Name, Client personnel information (home, office and business information)
- Customer information (home, office and business information)
- Email address
- Gender
- Names of employers
- Occupation (job title)
- Telephone or fax numbers
We do not intentionally collect sensitive category data, unless you provide us with such data.
Legal grounds for processing personal data of participants are:
- Explicit consent of the participant
- Our legitimate interest in organizing events and managing the registration process for such events.
- Our legitimate interest in protecting our people, assets and information, and to prevent unauthorized people gaining access to off-site EVD events.
- Our legitimate interest in providing information about EVD, our services and events we organize
As part of the professional services EVD provides to clients, EVD processes personal data of individuals with whom we do not have a direct (contractual or other) relationship.
Where we need to process personal data to provide our services, we ask our clients to provide the necessary information to the data subjects concerned regarding its use.
We seek confirmation from our clients that they have the authority to provide personal data to us in connection with the performance of the services and that any personal data they provide to us has been processed in accordance with applicable law.
Given the diversity of services we provide, we process many categories of personal data such as:
- Personal details (such as name, age, data of birth, gender, marital status and country)
- Contact details (such as phone numbers, email address and postal address)
- Financial details (such as salary, payroll, income, investments, benefits and tax status)
- Employment details (such as role, rank, experience, performance data and employment numbers)
Legal grounds for processing personal data of individuals whose personal data we obtain in connection with providing services to our clients are:
- Compliance with a legal or regulatory obligation
- Our legitimate interest in making sure our clients are provided with seamless, consistent and high-quality services worldwide
We process personal data about our suppliers (including subcontractors, and individuals associated with our suppliers and contractors) in order to manage our relationship and contract, and to receive services from our suppliers.
The personal data we process is generally limited to contact information (name, name of employer, phone, email and other contact details) and financial information (payment-related information).
In addition, we also use data about our suppliers to check whether we have a conflict of interest or audit independence restriction to appointing a supplier. Before we take on a new supplier, we also carry out audit independence and other background checks required by law or regulation, for example, adverse media, bribery and corruption, and other financial crime checks.
Legal grounds for processing personal data of our suppliers are:
- Performance of a contract
- Compliance with a legal or regulatory obligation
- Our legitimate interest in managing payments, fees and charges, and to collect and recover money owed to EVD
- Our legitimate interest in understanding any conflict of interest or challenge with regard to independence legislation
- Our legitimate interest in safeguarding against EVD inadvertently dealing with the proceeds of criminal activities or assist in any other unlawful or fraudulent activities (for example, terrorism)
Security
We take the security of all the data we hold very seriously. We have a framework of policies, procedures and training in place covering professional secrecy, data protection, confidentiality and security and regularly review the appropriateness of the measures we have in place to keep the data we hold secure.
Although we use appropriate security measures once we have received your personal data, the transmission of data over the internet (including by e-mail) is never completely secure. We endeavor to protect personal data, but we cannot guarantee the security of data transmitted to us or by us.
When and how we share personal data and locations of processing
We will only share personal data with others when we are legally permitted to do so. When we share data with others, we put contractual arrangements and security mechanisms in place to protect the data and to comply with our data protection, confidentiality and security standards.
- Third party organisations that provide applications/functionality, data processing or IT services to us
We use third parties to support us in providing our services and to help provide, run and manage our internal IT systems. For example, providers of information technology, cloud based software as a service providers, identity management, website hosting and management, data analysis, data back-up, security and storage services. The servers powering and facilitating that cloud infrastructure are located in secure data centres around the world, and personal data may be stored in any one of them.The CRM is provided by Salesforce and is hosted in Salesforce’s European data centers.
- Third party organisations that otherwise assiste us in providing services or information.
- Auditors and other professional advisers
- Law enforcement or other government and regulatory agencies or to other third parties as required by, and in accordance with, applicable law or regulation
Occasionally, we may receive requests from third parties with authority to obtain disclosure of personal data, such as to check that we are complying with applicable law and regulation, to investigate an alleged crime, to establish, exercise or defend legal rights. We will only fulfil requests for personal data where we are permitted to do so in accordance with applicable law or regulation.
Changes to this privacy statement
We recognise that transparency is an ongoing responsibility so we will keep this privacy statement under regular review.
This privacy statement was last updated on 16 August 2019.
Data controller and contact information
The data controller is EvD (Place Constantin Meunier 20/6, 1190 Brussels in Belgium).
If you have any questions about this privacy statement or how and why we process personal data, please contact us at:
Data Protection Officer
European VAT Desk
Place Constantin Meunier 20/6
1190 Brussels
Belgium
Email: [email protected]
Phone: +32 (0)2 351.26.00
Individuals’ rights and how to exercise them
Individuals have certain rights over their personal data and data controllers are responsible for fulfilling these rights. Where we decide how and why personal data is processed, we are a data controller and include further information about the rights that individuals have and how to exercise them below.
Access to personal data
You have a right of access to personal data held by us as a data controller. This right may be exercised by emailing us at [email protected]. We may charge for a request for access in accordance with applicable law. We will aim to respond to any requests for information promptly, and in any event within the legally required time limits (currently 30 days).
Amendment of personal data
To update personal data submitted to us, you may email us at [email protected] or, where appropriate, contact us via the relevant website registration page or by amending the personal details held on relevant applications with which you registered.
When practically possible, once we are informed that any personal data processed by us is no longer accurate, we will make corrections (where appropriate) based on your updated information.
Withdrawal of consent
Where we process personal data based on consent, individuals have a right to withdraw consent at any time. We do not generally process personal data based on consent (as we can usually rely on another legal basis). To withdraw consent to our processing of your personal data please email us at [email protected] or, to stop receiving an email from a EvD marketing list, please click on the unsubscribe link in the relevant email received from us.
Other data subject rights
This privacy statement is intended to provide information about what personal data we collect about you and how it is used. As well as rights of access and amendment referred to above, individuals may have other rights in relation to the personal data we hold, such as a right to erasure/deletion, to restrict or object to our processing of personal data and the right to data portability. Some of these rights will only be available from 25 May 2018.
If you wish to exercise any of these rights, please send an email to [email protected].
Complaints
We hope that you won’t ever need to, but if you do want to complain about our use of personal data, please send an email with the details of your complaint to [email protected]. We will look into and respond to any complaints we receive.
You also have the right to lodge a complaint with the Belgian Privacy Commission* (CBPL/CPVP), the Belgian data protection regulator.
For further information on your rights and how to complain to the CBPL/CPVP, please refer to the Belgian privacy commission website.