Privacy Policy
Last updated: 26 September 2026
DIJIWEB takes the protection of your personal data seriously. This privacy policy explains what data we collect, why we collect it, how long we keep it and which rights you have.
1. Who is responsible for your data?
The data controller is Dijiweb BV, with registered office at Portweg 8, 8600 Diksmuide, Belgium, registered with the Crossroads Bank for Enterprises under number BE 1002.204.295 (VAT BE 1002.204.295, RLE Ghent, Veurne division). You can reach us at [email protected].
We process your personal data in accordance with the General Data Protection Regulation (GDPR) and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
2. What data do we process, and why?
| When | Data | Purpose and legal basis |
|---|---|---|
| Contact form | Name, email address, phone number, subject and your message | Answering your question and following up on your request (pre-contractual measures and legitimate interest) |
| Creating an account | First and last name, email address, password (encrypted), phone number, address (street, postcode, city, country), language preference and — optionally — company name and VAT number | Creating and securing your customer account (performance of the contract) |
| Customer panel | Contact details, invoices, support tickets, active services | Customer administration and service delivery (performance of the contract; statutory accounting obligations) |
| Remote support | Session data of the support session (via ISL Online) | Remote technical assistance at your request (performance of the contract) |
| Visiting the website | Technical log data such as IP address, browser type, timestamp. Our anti-spam check (ALTCHA) runs on our own server: no third party is involved and no cookies are set. | Security, abuse prevention and proper functioning of the website (legitimate interest) |
| Website statistics | Pages visited, referring website, device and browser type, country and load times — measured with Rybbit on our own server, without cookies. The customer panel is not measured. | Understanding how the website is used in order to improve it (legitimate interest) |
| Session recording (only with your consent) | How you use the website (scrolling, clicks, mouse movements), on our own server. What you type into forms is never recorded, and neither is the customer panel. | Making the website easier to use (consent — withdraw at any time via “Privacy settings”) |
When you register or update your details, we may validate your email address, phone number, address and VAT number to safeguard the quality of our customer records (legitimate interest). You can read more about cookies in our cookie policy.
We do not collect personal data for marketing purposes, do not send newsletters without your consent and never sell your data to third parties.
3. Who receives your data?
We only share your data with service providers (processors) that we need in order to deliver our services, and only to the extent necessary:
- Network and security (Cloudflare, Inc.): all traffic to this website passes through Cloudflare (DNS, encrypted connection and protection against attacks). This involves processing technical data such as your IP address, including outside the EEA (see section 4).
- Data validation (EuroValid): verification of email addresses, phone numbers, addresses and VAT numbers.
- Remote support (ISL Online): remote support sessions, only when you request them.
- Data centres within the EU that host our own servers. Our identity management (Zitadel) and customer administration (Odoo) run under our own control on those servers — your login details, invoices, support tickets and contact details are therefore not entrusted to an external software vendor.
We conclude data processing agreements with our processors in accordance with Article 28 GDPR. For hosting services (web hosting, VPS, domains) we refer you to our partner platform Servitus; when you purchase services there, Servitus acts as the data controller for that customer relationship.
We only disclose data to authorities when required to do so by law or by court order.
4. Transfers outside the EEA
Wherever possible we choose European service providers and storage within the European Economic Area. One exception: Cloudflare, Inc. (United States) processes technical connection data for the network traffic to our website. This transfer is based on the European Commission adequacy decision for the EU-US Data Privacy Framework, to which Cloudflare has self-certified, supplemented by standard contractual clauses.
5. How long do we keep your data?
- Contact form: as long as needed to fully answer and follow up on your question.
- Account data: as long as your account is active; after account deletion we erase your data, except for what we are legally required to keep.
- Invoices and accounting records: for the statutory retention periods that apply to accounting and tax obligations.
- Technical logs: limited in time, only as long as needed for security and troubleshooting.
- Website statistics and session recordings: at most 12 months, then deleted automatically.
6. How do we protect your data?
We take appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access: encrypted connections (TLS), encrypted password storage, role-based access restrictions and systematic updates of our systems.
Did you discover a vulnerability in our systems? Please report it through our responsible disclosure policy.
7. Your rights
Under the GDPR you have the following rights:
- Right of access to the personal data we process about you.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"), insofar as no statutory retention obligation applies.
- Right to restriction of processing.
- Right to data portability.
- Right to object to processing based on our legitimate interest.
- Right to withdraw previously given consent at any time.
You can exercise these rights via [email protected]. We respond within one month. Customers can also view and update their contact details directly in the customer panel.
8. Complaints
Do you have a complaint about the processing of your personal data? Please contact us first at [email protected] — we are happy to look for a solution together. You also have the right to lodge a complaint with the Belgian supervisory authority: the Data Protection Authority (Gegevensbeschermingsautoriteit, GBA), Drukpersstraat 35, 1000 Brussels, www.dataprotectionauthority.be.
9. Changes
We may update this privacy policy, for example when our services or the applicable legislation change. The most recent version can always be found on this page, with the date of the latest change at the top.