Privacybeleid

dgtgroup BV and its entities dgtgroup BE BV, TSS BV and NFGD BV

Last updated: 26/08/2026

This Privacy Policy explains how dgtgroup BV, dgtgroup BE BV, TSS BV and NFGD BV (together, “dgtgroup”, “we”, “us” or “our”) process personal data. Please read it carefully. This Policy applies to personal data processed through our websites, business contacts, services, communications and other interactions described below.

1. Who is responsible for your personal data

The relevant controller is the dgtgroup entity that determines why and how your personal data are processed in the context of your relationship or interaction with us. The applicable entity will normally be clear from the contract, communication, website notice or service through which we obtain your personal data.

The entities covered by this Policy are:

  • dgtgroup BV, registered office: Gulkenrodestraat 7/9&10,2160 Wommelgem (Belgium), registered with the Crossroads Bank for Enterprises under number BE 1019.163.459
  • dgtgroup BE BV, registered office: Gulkenrodestraat 7/9&10,2160 Wommelgem (Belgium) registered with the Crossroads Bank for Enterprises under number BE 0884.473.219
  • TSS BV, registered office: Koraalrood 48, Zoetermeer (The Netherlands) registered with the Crossroads Bank for Enterprises under number 27042587;
  • NFGD BV, registered office: Koraalrood 48, Zoetermeer (The Netherlands) registered with the Crossroads Bank for Enterprises under number 29042060

Where two or more dgtgroup entities jointly determine the purposes and means of a processing activity, they may act as joint controllers. You may exercise your data-protection rights by contacting the DPO using the details in section 2.

2. Data Protection Officer and contact details

dgtgroup has appointed Nathalie Claes as Data Protection Officer (DPO). For questions about this Policy, the processing of your personal data or the exercise of your rights, contact the DPO at privacy@dgtgroup.eu.

General contact details: Gulkenrodestraat 7/9&10,2160 Wommelgem (Belgium),

3. Personal data we may process

  • Depending on your relationship with us and the purposes below, we may process the following categories of personal data:
  • Identity and contact data, such as name, title, employer, business or private address, email address and telephone number;
  • Professional and business data, such as job title, organisation, business relationship, correspondence and meeting notes;
  • Contractual, commercial and financial data, such as orders, invoices, payment details, service-related communications and contract information;
  • Website and electronic usage data, such as IP address, device and browser information, log data, cookie data and pages or features used;
  • Communication data, such as messages, requests, complaints and feedback;
  • Compliance, legal and security data where necessary, such as identification data required by law, audit records or information relating to claims or disputes; and

We do not intentionally request special categories of personal data or criminal-conviction data through our websites unless this is necessary, lawful and specifically communicated. If such data are processed, the applicable legal basis and safeguards must be documented and reflected in this Policy.

4. Sources of personal data

We may receive personal data directly from you, from your employer or organisation, from other persons involved in our business relationship, from publicly available professional sources, from service providers, or automatically through your use of our websites and services. 

5. Why we process personal data and our legal bases

We process personal data only when we have a valid legal basis under applicable data-protection law. The purposes and legal bases that may apply are set out below. Delete any purpose that does not apply and complete the blanks before publication.

5.1 Managing business relationships, requests and communications

We may process identity, contact, professional and communication data to respond to enquiries, manage our relationship with customers, prospective customers, suppliers, partners and other business contacts, and administer related communications. The legal basis is the performance of a contract or taking steps at your request before entering into a contract, or our legitimate interest in conducting and managing our business relationship.

5.2 Providing and administering products or services

We may process data necessary to provide, support, administer and improve our products or services, including service communications, account administration and handling requests. The legal basis is the performance of a contract, compliance with a legal obligation, or our legitimate interest in operating and improving our services. 

5.3 Supplier and partner management

We may process business-contact, contractual and financial data to select, engage and manage suppliers, service providers and business partners, including contract and payment administration. The legal basis is the performance of a contract, compliance with legal obligations, or our legitimate interest in managing our business operations.

5.4 Legal, accounting and compliance obligations

We may process relevant data to comply with legal, tax, accounting, corporate-governance, reporting, record-keeping and other statutory obligations. The legal basis is compliance with a legal obligation.

5.5 Security, fraud prevention and protection of rights

We may process relevant data to protect our websites, systems, premises, information, personnel and business interests; prevent, investigate and address fraud, misuse, security incidents or unlawful activity; and establish, exercise or defend legal claims. The legal basis is our legitimate interest in ensuring security, continuity and legal protection, or compliance with a legal obligation where applicable.

5.6 Marketing

Where permitted by law, we may use contact and professional data to send information about our products, services, events or developments. We will use consent where this is required. In other cases, we may rely on our legitimate interest in promoting our business to existing or relevant professional contacts, subject to your right to object at any time. You can withdraw consent or object to direct marketing by contacting privacy@dgtgroup.eu or using the unsubscribe option in the relevant communication.

5.7 Website operation and improvement

We may process technical and usage data to operate, secure, maintain and improve our websites and to understand their use. Where cookies or similar technologies are used, the Cookie Policy and your consent preferences apply. The legal basis may be our legitimate interest in operating secure and effective websites, or your consent where required.

6. When we share personal data

We may share personal data, where necessary and lawful, with the following categories of recipients:

  • other dgtgroup entities, where this is necessary for shared services, group administration, security, governance or the relevant business relationship;
  • service providers acting on our behalf, such as IT, hosting, communications, professional advisers, accounting, payment, security and support providers;
  • public authorities, regulators, courts, law-enforcement bodies or other third parties where required by law or necessary to protect our rights; and

Where a recipient acts as a processor on our behalf, we put appropriate contractual safeguards in place as required by applicable law. We do not sell personal data.

7. International transfers

Your personal data may be processed in the European Economic Area (EEA). If we transfer personal data outside the EEA, we will do so only where permitted by applicable law and will implement appropriate safeguards, such as an adequacy decision or standard contractual clauses, together with supplementary measures where required. 

8. How long we keep personal data

We keep personal data only for as long as necessary for the purpose for which it was collected, including to meet legal, accounting or reporting requirements and to establish, exercise or defend legal claims. The appropriate retention period depends on the nature of the data and the context of the processing.

After the applicable period, we will delete or anonymise the data, unless a longer retention period is required or permitted by law.

9. Your rights

Subject to the conditions and limits set by applicable data-protection law, you may have the right to:

  • request access to your personal data and receive a copy;
  • request correction of inaccurate or incomplete personal data;
  • request erasure of your personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests, including direct marketing;
  • receive personal data you provided to us in a structured, commonly used and machine-readable format and request its transfer to another controller, where applicable;
  • withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal; and lodge a complaint with the competent data-protection supervisory authority.

To exercise your rights, email privacy@dgtgroup.eu. Please identify the relevant dgtgroup entity and describe your request. We may ask for information necessary to verify your identity. You also have the right to lodge a complaint with the Belgian Data Protection Authority or, where applicable, the supervisory authority in your habitual residence, place of work or place of the alleged infringement. 

For Belgium: 

Gegevensbeschermingsautoriteit, Drukpersstraat 35, 1000 Brussel.

Phone: +32 (0)2 274 48 00 

Email: contact@apd-gba.be

For The Netherlands:

Autoriteit Persoonsgegevens

Visiting address: Hoge Nieuwstraat 8, 2514 EL Den Haag

Postal address: Postbus 93374, 2509 AJ Den Haag

Phone: 088-1805 250

10. Security

We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and other unlawful processing. No security measure can guarantee absolute security.

11. Third-party websites and social media

Our websites may contain links to third-party websites, platforms or social-media services. Those third parties are responsible for their own processing of personal data. We recommend that you read their privacy notices.

12. Changes to this Policy

We may update this Privacy Policy from time to time. The current version will be published here and will show the date of the latest update. Where required, we will provide additional notice of material changes.

13. Applicable law

This Policy is governed by Belgian law, without prejudice to mandatory data-protection rules that may apply.