Privacy Policy
Broodbaar attaches great importance to protecting your data and respecting your privacy.
Broodbaar is responsible for processing personal data as shown in this statement. You can contact us using the contact details below:
Broodbaar
Mechelsesteenweg 586C/11
1800 Vilvoorde
info@broodbaar.be
Processed personal data
Broodbaar processes your personal data because you provide it to us for the use of our services. An overview of the personal data we process:
- First and last name
- Company name
- Address data (place of employment)
- Phone number
- Email address
- IP Address
- Bank account number (if applicable)
The processing of personal data is limited to data minimally necessary for the purposes for which they are processed.
Purpose and legal grounds for processing
Broodbaar processes your data for the following purposes:
- Processing your orders (contract execution)
- Informing about changes to our services and products (legitimate interest)
- Sending newsletters (consent of the data subject)
We only use the provided data for the purposes for which we obtained the data.
Retention period
Broodbaar does not retain personal data longer than necessary for the purpose for which it was provided, or as required by law. As a general rule, we retain personal data for a maximum of 3 years after last use.
Sharing personal data with third parties
Broodbaar does not sell your data to third parties and only provides it if this is necessary for the execution of our agreement or to comply with a legal obligation. We conclude a processor agreement with companies that process your data on our behalf to ensure the same level of security and confidentiality. Broodbaar remains responsible for the processing.
Broodbaar uses a third party for:
- Making our website and ordering system available (web hosting within the EU) - all personal data you provided as mentioned above
- Managing and distributing newsletters - Name and email address
- Processing online payments - Name, email address and customer reference
- Creating backups in a form unreadable to the third party (encryption)
Broodbaar also provides anonymous personal data to third parties. More information about this can be found in our cookie policy.
View, modify or delete data
You have the right to view, correct or delete the personal data we have received from you. This is made possible to the maximum extent via your personal pages on the website where your data can be viewed and modified. These pages also provide insight into your order and payment history that Broodbaar has.
You can request the deletion of all personal data we have via your personal pages. This action is irreversible and deletes all personal data we have and anonymizes the order history. This is possible when there are no outstanding amounts on your account and your last order is at least 3 months in the past.
For customers who pay by invoice, we are bound by legal obligations; deletion of documents that may contain personal data is only possible in this case 7 years after the last invoice date.
You have the right to withdraw your consent for processing the data, object to the processing, or to make your data transferable in a computer file. If you wish to exercise this, send a specified request to info@broodbaar.be. It is necessary to authenticate yourself by means of a copy of your identity card. Before sending, make your photo, identity card number and date of birth unreadable.
Complaints
If you have a complaint about the processing of your personal data, you can contact us directly. You also have the right to file a complaint with the Privacy Commission (supervisory authority for data protection).
Data security
Broodbaar takes appropriate technical and organizational measures to protect personal data against unlawful disclosure, including:
- The website's ordering system is encrypted with TLS (recognizable by the lock in the address bar).
- Authentication is always required for access to personal data
- Online payment traffic runs through external payment providers. Broodbaar does not receive or store any data about your payment methods. This communication runs directly with the PCI certified payment providers.
- We encrypt personal data through encryption or hashing when there is reason to do so
- We make backups of our data to restore them in case of physical or technical failures