Privacy Policy
This policy explains what personal data we process, why we process it, how long we keep it and what rights you have. It applies to this website, to our sales and onboarding process, and to the Digitalnatie Service Suite platform.
Last updated: August 6, 2026
On this page
- 1. Introduction
- 2. Data controller
- 3. Personal data we collect
- 4. Purposes of processing
- 5. Legal basis
- 6. Data stored inside Service Suite
- 7. How long we keep data
- 8. Sharing with others
- 9. International transfers
- 10. Security measures
- 11. Your rights
- 12. Cookies and local storage
- 13. Complaints
- 14. Changes to this policy
- 15. Contact
1. Introduction
Digitalnatie builds and operates Digitalnatie Service Suite, a service operations platform for companies with technicians in the field. We take the protection of personal data seriously, and we would rather be precise about it than reassuring.
This policy applies to three groups: visitors who contact us through this website, the people at our customers who use the platform, and anyone whose data ends up in a customer's environment. The role we play differs per group, which is why the next section separates them.
We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
2. Data controller
For the personal data described in sections 3 to 5, Digitalnatie is the data controller within the meaning of Article 4(7) GDPR.
- Company
- Digitalnatie
- Country
- Belgium
- VAT number
- Coming soon
- Privacy contact
- [email protected]
- General and support
- [email protected]
We have not appointed a Data Protection Officer, because we do not meet the criteria of Article 37 GDPR that would require one. Privacy requests are handled directly by our team at [email protected].
3. Personal data we collect
We collect only what we need for the purposes in section 4. We do not buy personal data from third parties, and we do not build profiles for advertising.
| Category | Examples | Where it comes from |
|---|---|---|
| Contact and company details | Name, business email address, telephone number, company name, sector, approximate team size | Forms on this website, email, meetings and demonstrations |
| Account data | User name, business email address, interface language, role and permissions within the customer's environment | Created by the customer's administrator, or by us during onboarding |
| Usage and support data | Records of actions performed in the platform, support requests and the correspondence about them | Generated when the platform is used or when support is contacted |
| Billing data | Billing contact, billing address, VAT number, subscription details, invoice and payment history | Provided by the customer when the subscription starts |
| Technical data from this website | IP address, browser type and version, and the date and time of a form submission | Recorded automatically when a form on this website is submitted |
The technical data in the last row is recorded for one reason only: to rate-limit our forms and block automated abuse. It is not used to recognise you, to profile you, or to measure your behaviour on the site.
We do not knowingly collect special categories of personal data as defined in Article 9 GDPR, and we ask customers not to enter such data into free-text fields in the platform.
4. Purposes of processing
We process personal data to:
- provide, maintain and support the Service Suite platform;
- create and manage user accounts and their access rights;
- answer contact requests, demonstration requests and quotation requests;
- onboard new customers and configure their environment;
- invoice, follow up payments and keep our accounts;
- send service messages about the platform, such as planned maintenance or a change that affects the customer;
- keep the platform secure and prevent abuse of our forms;
- improve the reliability and usability of the platform;
- comply with our legal obligations.
We do not use personal data for automated decision-making that produces legal effects concerning a person, or that similarly significantly affects them, within the meaning of Article 22 GDPR.
Some optional features help draft service reports automatically from information already recorded on the job. A person always reviews and approves the result before it is used. The feature supports the technician's writing; it takes no decisions about individuals.
5. Legal basis
Every purpose rests on one of the legal grounds in Article 6(1) GDPR:
| Purpose | Legal basis |
|---|---|
| Delivering the platform, managing accounts and providing support | Performance of a contract — Article 6(1)(b) |
| Answering an enquiry and preparing a quotation | Steps taken at your request prior to entering into a contract — Article 6(1)(b) |
| Invoicing, accounting and statutory record keeping | Compliance with a legal obligation — Article 6(1)(c) |
| Securing the platform, preventing abuse and improving our services | Our legitimate interests — Article 6(1)(f) |
| Commercial email to someone who is not yet a customer | Consent — Article 6(1)(a), withdrawable at any time |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms and concluded that the processing is proportionate and expected. You can object to it at any time under section 10.
6. Data stored inside Service Suite
Service Suite is a tool our customers use to run their own operation. The content they put into it — their clients, sites, installations, work orders, technicians, reports and invoices — is their data, not ours.
For that content the customer is the data controller and Digitalnatie acts solely as a data processor under Article 28 GDPR. We do not use customer content for our own purposes, and we never sell it.
In that role we:
- process personal data only on the documented instructions of the customer;
- bind everyone with access to a duty of confidentiality;
- apply the security measures described in section 9;
- assist the customer, as far as reasonably possible, with requests from data subjects and with its own security and breach-notification obligations;
- engage a sub-processor only under a written agreement imposing equivalent obligations;
- return or delete the data at the end of the contract, as described in section 7.
A data processing agreement covering this relationship is available to every customer on request via [email protected]. If you are an individual whose data sits inside a customer's environment, address your request to that customer; we will forward it if it reaches us instead.
7. How long we keep data
We keep personal data no longer than is necessary for the purpose it was collected for, unless a longer period is required by law.
| Data | Retention period |
|---|---|
| Enquiries that do not lead to a contract | Up to 24 months after the last contact |
| Account data and platform content | For the duration of the subscription |
| Account data and platform content after termination | Available for export for 30 days after the contract ends, then deleted within a further 90 days |
| Invoices and accounting records | 10 years, in line with the applicable Belgian tax and accounting retention obligations |
| Support correspondence | Up to 24 months after the request is closed |
| Technical data from website form submissions | Up to 12 months |
Once a retention period ends the data is deleted. Residual copies may persist for a short additional period before they are permanently erased in the ordinary course of our deletion cycle.
9. International transfers
The primary hosting and storage of the Service Suite platform are located within the European Economic Area (EEA). For certain supporting or optional services, a limited part of the personal data may be processed outside the EEA.
Where that happens, we rely on a transfer mechanism permitted by Chapter V GDPR: an adequacy decision of the European Commission, or the European Commission's Standard Contractual Clauses together with additional safeguards where the circumstances require them.
You can request more detail about the safeguards that apply to a specific transfer via [email protected].
10. Security measures
We take appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, as required by Article 32 GDPR. Without describing them in a level of detail that would itself create a risk, these include:
- encryption of data in transit;
- individual named accounts, with access granted on a need-to-know basis and role-based permissions;
- logical separation of customer data through access rules, roles and permissions;
- logging of administrative access;
- confidentiality obligations for everyone who works on the platform;
- periodic review of access rights and of the measures themselves;
- a documented procedure for handling security incidents.
No online service can be guaranteed to be completely secure. Where Digitalnatie acts as the data controller for the processing concerned, we report a notifiable breach to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where Digitalnatie acts as a processor, we inform the customer as data controller without undue delay after becoming aware of the breach. We provide the customer with reasonable assistance with its own notification and communication obligations.
11. Your rights
Under the GDPR you have the right to:
- obtain access to the personal data we hold about you;
- have inaccurate or incomplete data corrected;
- have your data erased, where one of the grounds in Article 17 GDPR applies;
- ask us to restrict the processing;
- receive the data you provided in a structured, commonly used and machine-readable format, and have it transmitted to another controller;
- object to processing based on our legitimate interests;
- withdraw your consent at any time, where the processing is based on consent — without affecting the lawfulness of what was processed before you withdrew it.
To exercise a right, write to [email protected]. We answer within one month. If your request is complex or if we receive several from you, we may extend that period by two further months and will tell you why within the first month. We may ask for information to confirm your identity before we act.
Exercising these rights is free of charge. We may charge a reasonable fee, or refuse to act, only if a request is manifestly unfounded or excessive, and we will explain why.
13. Complaints
If you believe we have not handled your personal data correctly, please contact us first at [email protected]. We would like the chance to put it right.
You also have the right to lodge a complaint with the Belgian supervisory authority:
- Authority
- Gegevensbeschermingsautoriteit / Autorité de protection des données
- Address
- Drukpersstraat 35, 1000 Brussels, Belgium
- [email protected]
- Website
- www.dataprotectionauthority.be
If you live or work in another EU member state, you may also lodge your complaint with the supervisory authority there.
14. Changes to this policy
We may update this policy, for example when we add a feature or when the law changes. The version in force is always the one on this page, and it carries the revision date shown at the top.
If a change materially affects how we process personal data, we inform our customers by email or through the platform before it takes effect.
15. Contact
Questions about this policy, or about the personal data we hold, are answered within one month.
- Privacy
- [email protected]
- General and support
- [email protected]
- Company
- Digitalnatie, Belgium
- VAT number
- Coming soon
This policy is published in Dutch, French and English. In case of any difference between the versions, the Dutch version prevails.
Back to top