Privacy Notice
Last updated: 16 August 2026 - This Privacy Notice explains how Secudea BV processes personal data when you use our website, contact us, use our customer portal, use Secudea-operated services, or otherwise interact with us.
1. Data Controller
The controller responsible for the processing described in this Privacy Notice is: Secudea BV
Karel de Brouckerestraat 6
B-8800 Roeselare
Belgium
Enterprise / VAT number: BE 0506.816.783
Email: info@secudea.be
For security vulnerabilities, please use security@secudea.be and follow our Vulnerability Disclosure Policy.
2. Scope of this Privacy Notice
This Privacy Notice applies to personal data processed through:
- secudea.be;
- portal.secudea.be;
- cyrias.secudea.be;
- Secudea contact forms;
- customer and support communications;
- Secudea-operated applications and services where this Privacy Notice is referenced; * vulnerability reports submitted to Secudea; and
- technical and security logging associated with these services.
Specific services may be subject to additional privacy or contractual information where required.
3. Personal Data We Process
The personal data we process depends on how you interact with Secudea.
3.1 Contact and enquiry data
When you contact us through a website form, email, telephone, or another communication channel, we may process:
- your name;
- email address;
- telephone number;
- organisation or employer;
- job title, where provided;
- enquiry category;
- message contents; and
- related correspondence.
3.2 Customer and contractual data
When you or your organisation engage Secudea for services, consultancy, training, assessments, software, or support, we may process:
- business contact details;
- organisation and role information;
- contractual correspondence;
- project-related communications;
- invoicing and administrative information; and
- support communications.
3.3 Portal and service account data
Where you use a Secudea customer portal or hosted service, we may process:
- your name;
- business email address;
- organisation;
- user or account identifier;
- account status;
- assigned roles and permissions;
- authentication-related information;
- login events; and
- security and audit events associated with your account.
Passwords are not intended to be stored in readable form.
3.4 Technical and security information
When you access our websites or services, Secudea may process technical information necessary to operate, troubleshoot, monitor, and secure its systems, including:
- IP address;
- date and time of access;
- requested URL or resource;
- HTTP response information;
- browser or user-agent information;
- authentication events;
- failed login attempts;
- system and application events;
- security events; and
- information necessary to investigate suspected abuse or security incidents.
3.5 Vulnerability reports
If you report a suspected security vulnerability, we may process:
- your name or alias;
- contact details;
- organisation, where provided;
- vulnerability description;
- affected systems or products;
- reproduction information;
- supporting technical evidence; and
- correspondence concerning investigation and remediation.
Please do not submit personal data, customer data, or confidential third-party information unless it is strictly necessary to demonstrate the vulnerability.
4. Why We Process Personal Data
4.1 Contact requests
We process information submitted through our contact channels in order to:
- respond to enquiries;
- communicate with you;
- prepare requested information or quotations;
- discuss potential services; and
- maintain appropriate business correspondence.
Legal basis: Article 6(1)(b) GDPR where processing is necessary to take steps at your request before entering into a contract, or Article 6(1)(f) GDPR where we rely on our legitimate interest in responding to professional and business enquiries.
4.2 Customer administration and service delivery
We process customer and business-contact information in order to:
- perform agreements;
- deliver consultancy, training, assessments, software, or other services;
- administer projects;
- provide customer support;
- manage customer accounts; and
- communicate regarding service delivery.
Legal basis: Article 6(1)(b) GDPR where the data subject is party to the agreement. Where the agreement is with an organisation rather than the individual directly, processing of business-contact information may be based on Article 6(1)(f) GDPR and our legitimate interest in administering the commercial relationship.
4.3 Customer portals and hosted services
We process portal and account information in order to:
- create and maintain user accounts;
- authenticate users;
- administer access permissions;
- provide the requested service;
- support users; and
- maintain the confidentiality, integrity, and availability of the service.
Legal basis: Article 6(1)(b) GDPR where processing is necessary for delivery of the relevant service, and Article 6(1)(f) GDPR for security, access-control, audit, and service-protection activities.
4.4 Security and operation of our systems
We process technical, security, and logging information in order to:
- operate our systems and services;
- maintain service availability;
- prevent and detect unauthorised access;
- investigate suspicious activity;
- protect Secudea, its customers, and users;
- troubleshoot technical problems;
- investigate security incidents; and
- maintain security audit trails.
Legal basis: Article 6(1)(f) GDPR, based on Secudea’s legitimate interest in protecting its systems, software, information, customers, and services. Where specific security processing is required by applicable law, Article 6(1)(c) GDPR may also apply.
4.5 Legal, accounting, and regulatory obligations
Certain information is processed or retained in order to comply with applicable legal requirements, including accounting, taxation, regulatory, and legal-record obligations.
Legal basis: Article 6(1)(c) GDPR.
4.6 Vulnerability reporting and security research
Information submitted through our vulnerability-reporting process is processed in order to:
- validate reported vulnerabilities;
- communicate with the reporter;
- investigate affected systems or products;
- remediate security vulnerabilities;
- coordinate disclosure where appropriate; and
- maintain evidence relating to security risks and remediation.
Legal basis: Article 6(1)(f) GDPR, based on Secudea’s legitimate interest in maintaining the security of its products and services. Processing may additionally be required to meet applicable cybersecurity obligations.
5. Recipients and Service Providers
Secudea does not sell personal data.
Personal data may be shared with service providers where this is necessary to operate our business and services. Depending on the relevant processing, these providers may include:
- hosting and infrastructure providers;
- email and communication providers;
- backup providers;
- security and monitoring providers;
- software and technical service providers;
- professional advisers;
- accounting providers; and
- other suppliers necessary for the delivery of Secudea services.
Service providers processing personal data on Secudea’s behalf are required to handle that information in accordance with applicable data-protection requirements and appropriate contractual obligations. Personal data may also be disclosed where required by law, court order, competent authority, or where necessary for the establishment, exercise, or defence of legal claims.
6. International Transfers
Secudea seeks to use service providers located within the European Economic Area where reasonably appropriate. Where personal data is transferred to a country outside the European Economic Area, Secudea will ensure that an appropriate transfer mechanism is available as required by the GDPR.
Depending on the recipient and destination, this may include:
- a European Commission adequacy decision;
- European Commission Standard Contractual Clauses; or
- another legally recognised safeguard.
Additional information about relevant international-transfer safeguards can be requested from Secudea.
7. Data Retention
Secudea retains personal data only for as long as required for the relevant purpose, applicable legal obligations, security requirements, and the establishment or defence of legal claims. Unless a different retention requirement applies, Secudea uses the following general retention periods.
Contact enquiries
Contact-form submissions and ordinary business enquiries are normally retained for up to 24 months after the last meaningful communication. Where an enquiry develops into a contractual relationship, relevant correspondence may become part of the customer or contractual record.
Unsuccessful quotations and proposals
Quotations and proposal-related correspondence that do not result in a customer engagement are normally retained for up to 24 months after the quotation or last related communication.
Customer and contractual records
Customer contracts, significant contractual correspondence, and related business records are normally retained for 7 years after termination or completion of the relevant contractual relationship, unless a longer period is required by applicable law or necessary in relation to legal claims.
Accounting and financial records
Accounting, invoicing, and other records subject to statutory retention requirements are retained for the period required by applicable Belgian law. Website logs Ordinary web-server logs are normally retained for up to 90 days, unless a longer retention period is necessary for security investigation, abuse prevention, troubleshooting, or legal purposes.
Authentication and security logs
Authentication records, access-control events, and security-relevant audit logs are normally retained for up to 12 months. Relevant records may be retained longer where associated with a security incident, suspected abuse, legal obligation, or active investigation.
Portal accounts
Account information is retained while the account remains active. Following account closure, account records that are no longer required for service delivery are normally deleted or anonymised within 12 months, unless retention is necessary for contractual, legal, security, or audit purposes.
Support records
Customer support records are normally retained for up to 5 years after closure of the relevant support matter, where required to maintain service history, resolve recurring issues, or protect Secudea’s legitimate interests.
Vulnerability reports and security investigations
Confirmed vulnerability reports and significant associated investigation records may be retained for up to 7 years after closure, where necessary to maintain product-security history, demonstrate remediation, manage recurring risks, or meet legal and regulatory obligations. Reports determined to be irrelevant, duplicate, or clearly invalid may be deleted earlier.
Backups
Personal data may remain in protected backup copies for a limited period after deletion from active systems. Backup copies are retained and overwritten according to Secudea’s Backup and Recovery Policy and are not used for ordinary processing. Where information must be restored from backup, applicable deletion and retention controls will be reapplied where technically feasible.
8. Security
Secudea applies technical and organisational measures intended to protect personal data against:
- unauthorised access;
- accidental or unlawful destruction;
- loss;
- alteration;
- unauthorised disclosure; and
- other unlawful processing.
Security measures are selected according to the nature of the information, associated risks, applicable contractual obligations, and Secudea’s cybersecurity governance framework. No information system can be guaranteed to be completely secure. Suspected vulnerabilities affecting Secudea systems should be reported in accordance with our Vulnerability Disclosure Policy.
9. Your Rights
Subject to the conditions and limitations of the GDPR, you may have the right to:
- obtain confirmation as to whether Secudea processes your personal data;
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive certain personal data in a portable format where the right to data portability applies; and
- withdraw consent where processing is based on consent.
Where processing is based on Secudea’s legitimate interests, you may object to that processing based on circumstances relating to your particular situation. These rights are not absolute and may be subject to legal conditions or exceptions.
10. Exercising Your Rights
Requests relating to personal data may be submitted to: info@secudea.be
To protect personal data, Secudea may request reasonable information necessary to confirm the identity of the person making the request. Secudea will respond within the time limits required by applicable data-protection law.
11. Complaints
If you believe that Secudea has processed your personal data unlawfully, you may contact us so that we can investigate your concern.
You also have the right to lodge a complaint with the Belgian Data Protection Authority:
Gegevensbeschermingsautoriteit / Autorité de protection des données
Drukpersstraat 35 / Rue de la Presse 35
1000 Brussels
Belgium
Website: www.dataprotectionauthority.be
You may also have the right to lodge a complaint with another competent supervisory authority where applicable.
12. Cookies and Similar Technologies
Information about cookies and similar technologies used by secudea.be is provided in our Cookie Notice. Where non-essential technologies require consent, they will not be activated before the required consent has been obtained.
13. Security Vulnerabilities
Please do not use a privacy-rights request to report security vulnerabilities. Suspected security vulnerabilities affecting Secudea systems, services, or software should be reported to: security@secudea.be
Please review our Vulnerability Disclosure Policy before submitting a report.
14. Changes to This Privacy Notice
Secudea may update this Privacy Notice where necessary to reflect:
- changes to our services;
- changes to our processing activities;
- changes to our service providers;
- legal or regulatory developments; or
- improvements to our privacy and security practices.
The date at the top of this page indicates when the Privacy Notice was last updated. Material changes will be communicated where required by applicable law.