GDPR Compliance
Last updated: 19 August 2026
This statement describes how DIJIWEB complies with the General Data Protection Regulation (GDPR) and Belgian privacy legislation.
1. Legal framework
Dijiweb BV (BE 1002.204.295) processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the Belgian framework Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data. The competent supervisory authority is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit, GBA).
2. How we comply with the GDPR
- Data minimisation: we only collect the data needed for our services — no tracking, no marketing profiles.
- Record of processing activities: we document which data we process, why and for how long.
- Data processing agreements: we conclude an agreement in accordance with Article 28 GDPR with every service provider that processes personal data on our behalf.
- Privacy by design: new functionality is designed with data protection as the starting point, with role-based access restrictions.
- European focus: wherever possible we choose European service providers and storage within the EEA; transfers outside the EEA only take place with appropriate safeguards.
- Security: encrypted connections (TLS), encrypted password storage and systematic updates of our systems.
3. Controller and processor
For the data of our own customers, website visitors and contact requests we act as data controller. How we process that data is described in our privacy policy.
When we manage systems or develop software on behalf of customers in which personal data is processed, we act as a processor. In that case we conclude a data processing agreement with you; request one via [email protected].
The processors we rely on ourselves (identity management, customer administration, data validation, remote support and hosting infrastructure) are listed in our privacy policy.
4. Data breaches
We have an internal procedure for detecting, investigating and documenting personal data breaches. When a breach poses a risk to your rights and freedoms, we report it to the Data Protection Authority within 72 hours. If the breach poses a high risk, we also inform the affected individuals directly.
5. Data protection officer
Given the nature and scale of our processing activities, we are not legally required to appoint a data protection officer (DPO). For all data protection questions, [email protected] is your central point of contact; we respond within one month.
6. Exercising your rights
You have the right of access, rectification, erasure, restriction, portability and objection. How to exercise these rights and how to lodge a complaint with the Data Protection Authority is described in our privacy policy.