Privacy Policy

PRIVACY POLICY

Updated on November 20, 2019

Welcome to https://www.lexor.be ! Thank you for your interest in our advanced time registration approach, and in our company in general. We guarantee a service at the highest standards. The protection of your personal data is therefore of our utmost concern. We are taking all necessary precautions to protect your personal data in order to ensure you that you can continue to entrust us with your personal data. Hence, we are always handling your personal data in a safe and confidential manner.

All reasonable protection measures have been taken in order to avoid loss, alterations, access by persons who are not authorized to obtain access, accidental dissemination among third parties and/or any other unlawful or illegitimate processing of the collected personal data.

Who are we?

Lexor is an application developed by FLEXSOFT NV, with registered office at 9051 Gent, Twaalfapostelenstraat 20 and registered in the Crossroad Bank of Enterprises under number 0873.414.031 (hereinafter referred to as “Flexsoft”, “we”, “us” or “our”).

You can contact us via the following contact details:

Flexsoft

Twaalfapostelenstraat 20

9051 Sint-Denijs-Westrem

Belgium

+32 478 47 58 47

info@lexor.be

Your personal data shall only be processed in accordance with the existing and applicable legal provisions concerning the protection of personal data, including the Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as ‘GDPR’) and the national implementing legislation.

Clarification of terms used

For the purposes of this privacy statement, the concept of ‘personal data’ refers to: any information relating to an identified or identifiable natural person (the ‘data subject’). A natural person shall be deemed ‘identifiable’ if he or she can be identified on a direct or indirect basis, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Hence, all information on the basis whereof a natural person can be identified must be taken into account. I.e.: amongst others the person’s name, date of birth, address, telephone number, e-mail address and IP-address are taken into account.

The term ‘processing’ has a broad scope and inter alia refers to the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of personal data.

Person responsible for the processing of your personal data (“controller”):

Flexsoft is the legal person responsible for the processing of your personal data as described in this privacy policy, unless specified otherwise. This means that we determine the purposes and means of the processing of your personal data.


For the avoidance of doubt, this privacy policy does not apply to the extent we process personal data in our role of a “data processor” on behalf of our customers (including where we offer to our customers access to or the use of the Lexor (Beta) Platform). As a data processor, we process personal data which is submitted by or for a customer for the purpose of using our Lexor (Beta) Platform. In this case, the customer (and/or its affiliates) is the responsible controller of the personal data concerned. If your data has been submitted to us by or on behalf of a customer or Flexsoft, and you wish to exercise any rights you may have under applicable data protection laws, please inquire with the applicable customer directly.

When do we collect your personal data?

The privacy policy applies to the processing of personal data collected by Flexsoft when you:

  • visit our website;
  • provide us with your contact-details through the contact form on our website, webchat and/or chatbot;
  • become or aim to become a user of the Lexor (Beta) Platform (e.g. as an employee of one of our customers);
  • want to register for our Lexor partner program;
  • receive communication from us (including e-mails);
  • conclude an agreement with us;
  • contact our customer service (e.g. via telephone or e-mail).

Furthermore, our IT-systems process certain personal data on an automatic basis. We make use of cookies when you visit our websites. Cookies are small files which contain certain information and which are save on your tablet or mobile device to, inter alia, enhance the usability of our website in the most optimal manner. At any moment however, you can delete or switch off all cookies installed on your device through the settings of your browser. Please note that by altering you cookie-settings, our website may not function appropriately any longer. If you would like to obtain more information on this topic, please feel free to consult our cookie policy https://lexor.be/cookie-policy . For more information about ‘cookies’ in general, please contact the following website: www.allaboutcookies.org.

In principle, we do not aim to collect personal data regarding persons younger than 16 years old. Persons younger than 16 years old may not provide us with their personal data or with a statement of consent without providing the consent of the persons carrying the parental responsibility of such persons.

What personal data do we process, why and on which legal basis?

The schedule below provides which categories of personal data are processed by us (column 1), why such personal data is being processed (the ‘purposes’ – column 2) and on which legal basis such processing takes place (column 3).

The processing of personal data shall only take place for one or more specific purposes:

  • you have given your consent for the processing of personal data for one or more specific purposes;
  • the processing of the personal data is necessary for the performance of a contract to which you are a contracting party;
  • the processing is necessary for the compliance with a legal obligation to which the controller is subject;
  • the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data

Furthermore, there is always a demonstrable legal basis for every processing of personal data. The definitions used in the column ‘legal basis’ has the following meaning:

  • you have given your consent for the processing of personal data for one or more specific purposes;
  • the processing of the personal data is necessary for the performance of a contract to which you are a contracting party;
  • the processing is necessary for the compliance with a legal obligation to which the controller is subject;
  • the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data

Categories of personal data

Purposes

Legal basis

Identification – and contact details: username, e-mail address, telephone number, choice of language, payment details, IP-address, device information, browser identification, usage of our website or the Lexor (Beta) Platform and IMEI-code

Administration and execution of your order

Agreement

Identification – and contact details: username, e-mail address, telephone number, choice of language, payment details, IP-address and IMEI-code

Execution of the contract (including invoicing)

Agreement

Identification – and contact details: username, e-mail address, choice of language, payment details, IP-address and IMEI-code

Client service before, during and after sale and complaint handling

Agreement

Identification – and contact details: e-mail address, mail subjects, Microsoft Office documents, telephone number, IP-address, device information, usage of our website or the Lexor (Beta) Platform and IMEI-code

Collection of product-feedback aiming at enhancing our products and services

Legitimate interests

Identification - and contact details (e-mail address), IP-address and IMEI-code

To inform you, as a customer, about technical information concerning the Lexor (Beta) Platform, e.g. by means of a newsletter

Legitimate interests

Identification - and contact details (e-mail address), IP-address and IMEI-code

To respond to your question issued with the contact form on our website

Legitimate interests

Identification – and contact details (surname, name, address), payment details and invoices

To provide you with commercial information regarding our products and services

Consent

Identification – and contact details (surname, name, address), payment details and invoices

To comply with legal, regulatory and administrative obligations

Legal obligation

Identification – and contact details (surname, name, address), payment details and invoices

To protect and safeguard our rights

Legitimate interests

We also collect information about you from other sources (e.g. your Office 365 account for which Microsoft’s privacy policy applies), and combine this with personal data provided by you. This helps us to update, expand and analyze our records and create more tailored advertising to provide services that may be of interest to you. We will always ask your consent for such processing activity. Flexsoft is not responsible for, and has no control over the privacy and data security practices of such third parties. For more information related to the processing of your personal data by such third parties, please reach out to the respective third party directly.

Your privacy-rights

In order to give you more control regarding the processing of personal data, you have various rights at your disposal. These rights are inter alia discussed and provided in articles 15-22 GDPR.

You have the following rights:

Right of access to the processed personal data (art. 15 GDPR):

You have the right to obtain our confirmation as to whether or not your personal data is being processed, and, where that is the case, to obtain access to the personal data and the following information:

  • The purposes of the processing;
  • The categories of personal data concerned;
  • The recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
  • Where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  • The existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
  • the right to lodge a complaint with a supervisory authority;
  • where the personal data are not collected from the data subject, any available information as to their source;
  • the existence of automated decision-making.

In the event that we cannot provide you access to the personal data (for example in the event of a legal obligation to restrict the data subject from access to such information), we shall inform you of the reasons of such an inability.

Furthermore, you can also request a copy of the personal data undergoing processing free of charge. Please note however, that we are entitled to charge reasonable fee based on administrative costs for each additional copy you request.

The right to be forgotten or to request erasure of personal data (art. 17 GDPR)

In certain instances, you may request us to erase your personal data. Be aware however that under such circumstance, we will not be able to provide you with our services any longer. Furthermore, we ask you to bear in mind that the ‘right to be forgotten’ is not an absolute right. We shall have the right to continue to store your personal data, inter alia, in the following cases: (i) where such storage is necessary for the performance of a contract to which you are a contracting party, (ii) where such storage is necessary for compliance with a legal obligation, or (iii) where such storage is necessary for the establishment, exercise or defence of legal claims. We shall inform you of the reasons for the storage of your personal data in our response to your request of erasure.

The right to rectification (art. 16 GDPR):

In the event that your personal data are inaccurate, dated or incomplete, you can request us to rectify or complete your personal data.

The right to data portability (art. 20 GDPR):

Under certain conditions, you shall also have the right to request us to transmit the personal data you provided us with and for which you have given us your consent, to another controller. We shall transmit such personal data directly to the new controller in so far as such transmission is technically feasible.

Right to restriction of processing (art. 18 GDPR):

You shall have the right to obtain the restriction of processing where one of the following applies:

  • You contest the accuracy of the personal data (in such an event the use of the personal data shall be limited for a period enabling us to verify the accuracy of the personal data);
  • The processing of the personal data is unlawful;
  • We no longer need the personal data for the purposes of the processing, but you require them for the establishment, exercise or defence of legal claims;
  • Pending the verification whether the legitimate grounds for the processing of the personal data override those of the data subject, you may request us to limit the usage of the personal data.

The right to object (art. 21 GDPR):

You have the right to object, on grounds relating to your particular situation, the processing of your personal data in case that such processing is done for the performance of a task carried out in the public interest or for the purposes of the legitimate interests pursued by us. In such an event, we shall no longer process the personal data unless (i) there are compelling legitimate grounds for the processing which override your interests, rights and freedoms, or (ii) the processing of the personal data is done for the establishment, exercise or defence of legal claims.

Automate individual decision-making, including profiling (art. 22 GDPR):

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or which may significantly affect you in a similar manner.

Such right can however not be invoked in the following circumstances:

  • If the decision is authorised by law (for example: in order to prevent tax fraud);
  • If the decision is based on the data subject’s explicit consent; or
  • If the decision is necessary for entering into, or performance of, a contract between the data subject and the data controller (note that in such instances, we shall always make a case by case assessment of whether less privacy intrusive methods can be applied to facilitate the entry into, or performance of the contract).

The right to withdraw your consent (art. 7 AVG):

Where the processing of personal data is based on consent, you shall have the right to withdraw such consent at any time through a simple request.

The exercise of your rights

To exercise the rights listed above, you can contact us via e-mail on the following e-mail address info@lexor.be. In order to verify your identity, we ask you attach a copy of the front side of you ID-card to your e-mail or use another document which allows us to verify your identity.

All rights can be exercised free of charge, unless your request is manifestly unfounded or disproportionate (for example: due to the repetitive character of your request). In such cases, we have the right to charge you with a proportional fee or to refuse to adhere to your request.

Transfer of personal data to third parties

Your personal data shall only be transferred to third parties in conformity with the legal provisions in that regard, when you have provided us with your consent to do so, or when such transfer is necessary to ensure the provision of our services (on the basis of our legitimate interests). No personal data shall be transferred to third parties under any other circumstances, unless we are obligated to do so on the basis of compulsory legal or regulatory provisions (e.g.: the transfer of personal data to external bodies or authorities, such as law enforcement authorities).

Categories of recipients

We see to it that the personal data shall only be accessible within our company to those persons who require access to the personal data in order to comply with the contractual and legal obligations.

In some circumstances, our employees and staff are assisted by external service providers in the execution of their tasks. In order to protect your personal data, we have concluded an agreement with all such external service providers in order to guarantee the safe, respectful and cautious management and administration of your personal data.

Transfer of personal data to third countries

Your personal data shall only be transferred or disclosed to processors or controllers in third countries in so far as we are legally authorised to do so.

In so far as such disclosure or transfer is necessary, we shall take appropriate measures to ensure that your personal data shall be significantly protected and that all disclosures or transfers of personal data outside of the EEA take place in a lawful and legitimate manner. In the event that a disclosure or transfer takes place to a country outside of the EEA, for which the European Commission has not determined that this country does not maintain an equivalent level of protection of the personal data, such disclosure or transfer shall always be subject to contractual or other legally binding instruments which under the terms and conditions for the transfer of personal data to third countries, such as the approved standard terms and provisions for the transfer of personal data to third countries as established by the European Commission.

Protection of your personal data

We have taken all reasonable and suitable technical and organizational measures in order to protect your personal data as well as possible against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. As such, we store your personal data on one central and secured place on our server in order to ensure that third parties shall not have access to your personal data.

Storage of personal data

We store your personal data for the period of time necessary for achieving the purpose for which such personal data is processed. In each case, we determine the appropriate retention period for personal data on the basis of the amount, nature and sensitivity of your personal data processed, the potential risk of harm from unauthorized use or disclosure of your personal data and whether we can achieve the purpose of the processing through other means.

Please note that we must take into account a number of (legal) storage periods (time limits) which oblige us to continue to store your personal data. In the event that no obligation or duty to store the personal data exists, the personal data shall be erased and destroyed on a routine basis once the purpose for which the personal data is collected has been achieved.

Furthermore, we may store your personal data if you have given us your consent to do so or where such storage is necessary for the establishment, exercise or defence of legal claims. In this last instance, certain personal data shall be used for evidence purposes.

Complaints?

The protection of your personal data is our primary concern. As such, we aim to take all necessary measures in order to guarantee the protection of your personal data. Should you have a complaint regarding the manner in which your personal data is processed, please feel free to contact us. We shall try to live up to your expectations and meet your concerns as soon as practically possible.

You may also file your complaint to the supervisory authority for personal data protection. The authority assigned to supervise our organization is the Data Protection Authority:

Website:

https://www.dataprotectionauthority.be

Contact details:

Data Protection Authority
Rue de la Presse 35, 1000 Brussels

 +32 (0)2 274 48 00

 +32 (0)2 274 48 35

contact@apd-gba.be

Do you have any further questions?

Please feel free to contact us via telephone, e-mail or letter. We are happy to be of any further assistance.

Amendments

In order to take action on the basis of your feedback or to clarify changes made in our processing activities, this privacy policy may be amended from time to time. Therefore, we invite you to consult the latest version of this policy on our website.

We use cookies to make your surfing experience enjoyable.

Adjust