Legal · GDPR

Privacy Policy

This is the “regulation on the Protection of privacy” (hereinafter the “rules”) of OneTec SRL (hereinafter “OneTec” or the “employer”). We take your privacy seriously and are committed to comply with data protection laws, especially the General Data Protection Regulation (GDPR).

01

Who are we?

Organizing an event is always an important challenge for agencies. They spend all their energy in thousands of details in order to have happy visitors and organizers.

OneTec's goal is to improve organizers' efficiency and to create a unique customer experience by using cutting-edge innovation.

OneTec's story starts as a Software Developers' Company in early 2000. The first major event OneTec worked for was in 2002 on a huge international medical congress and since, OneTec never stopped working in this sector.

The expansion of OneTec occurred by organic growth, but also with some major acquisitions: Cerix (Belgian leading company in short-term IT rental), AIM (Voting Systems), Whos-in (ticketing and access control), Getyoo (interactive services for visitors on public and professional fairs), Bebotics (photobooths and custom event experiences) and Eventattitude (Brand Activation interactive & personalised experiences).

Today, OneTec's services consist of 3 main axes: Event Technology, Brand Activation and IT/AV rental.

We take your privacy seriously and are committed to comply with data protection laws, and especially the General Data Protection Regulation (GDPR).

OneTec is a company existing and operating under Belgian law, with statutory seat located at Leuvensesteenweg 542/C4, 1930 Zaventem and registered at the Crossroads Bank for Enterprises under company number 0478.889.493.

We use our best efforts to bring the data processing activities of OneTec into compliance with applicable data protection legislation, including Regulation (EU) 2016/679 (GDPR) and the Belgian Data Protection Act of 8 December 1992, each as applicable and amended from time to time.

02

Which data?

Considered as confidential information within the meaning of this Regulation: all employer information that has not been made public. Confidential information that has been made public illegally must also be considered as confidential information.

All personal data, as defined by the GDPR, namely:

« Any information relating to an identified or identifiable natural person; an 'identifiable individual' meaning a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, online id, or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity. »

Hereinafter referred to as the “confidential information”.

We most commonly — but not always — process the following categories of confidential information about you:

  • Your personal data (last name, first name, address, city, country)
  • Your professional data (company, job title)
  • Your email address
  • The picture representing you and the other persons on the picture
  • On an aggregated basis, limited socio-demographic data: gender (female/male/undefined), age (or range), language
  • The answers that were asked by our client and that you were invited to fill in

We process your confidential information for the following purposes, only with your consent:

  • Sending your registration confirmation, reminder, thank-you message or post-event survey
  • Sending documents related to the event
  • Sending your picture to your email address
  • Posting your picture on a privately accessible photo gallery
  • Transferring your picture and answers to our client so they can know you better. Our client is not authorised to use your personal data for marketing purposes and will not use your picture for corporate communications unless consent was asked and given by you
  • Transferring your picture and email address to our client so you can receive special offers and promotions
  • Transferring your picture to our client so it may be used for corporate internal or external communications (e.g. social media or website)
  • Transferring your picture and email address to our client and providing socio-demographic insights to help tailor marketing activities
03

Employees' commitment

This regulation contains directives to be respected by all OneTec's employees in the exercise of their functions. Employees come into contact with confidential information in the performance of their duties. Employees must maintain confidential information at any time under the seal of secrecy and won't share it with anyone other than authorised colleagues, after checking, to access the confidential information in question.

The employees commit not to share confidential information voluntarily or involuntarily with unauthorised persons, including third parties.

The employees also commit to never use the confidential information at the expense of the employer, or for any other purpose than those of their mission.

These commitments are the subject of an internal contract agreed by all employees, including members of the Board of Directors, the management, volunteers, interns, sub-processors, clients, etc. (hereinafter the “collaborators”) and, therefore, any person who comes into contact with confidential employer information or information that may be considered as personal data under the GDPR regulation.

04

Your rights

Subject to applicable data protection laws, you have the rights to access, rectify and erase your personal data, the rights to object to or limit the processing of your personal data and the right to data portability, meaning that:

  • You have the right to be informed about how we use your personal data and how to exercise your rights.
  • You have the right to be provided with clear, transparent and easily understandable information about how we use your personal data and your rights — this is mentioned on every screen we use to collect your personal information, and you have the right not to complete it.
  • You have the right to obtain access to your personal data, so you are aware and can check that we are using your personal data in accordance with applicable data protection laws.
  • You have the right to request the deletion of your personal data where there is no compelling reason for us to keep using it. Note that this is not an absolute right to erasure and exceptions apply.
  • You are entitled to have your personal data rectified if it is inaccurate or incomplete.
  • You have the 'right to be forgotten' which enables you to request the deletion or removal of your personal data where there is no compelling reason for us to keep using it.
  • You have the right to 'block' or suppress further use of your personal data. When processing is restricted, we can still store your personal data, but may not use it further.
  • You have the right to obtain and reuse your personal data for your own purposes across different services.
  • You have the right to lodge a complaint about the way we handle or process your personal data with your national data protection authority.
  • If you have given your consent, you have the right to withdraw your consent at any time (though doing so does not mean anything we have done with your personal data with your consent up to that point is unlawful).

Please forward any request regarding your rights as a data subject to us by email at info@onetec.eu. We will comply with your request as soon as reasonably practicable and always within the timeframes set forth by applicable data protection law. Please note that we may need to retain certain of your personal data for certain purposes as required or authorised by law. We may also ask you for proof of identity if we have a doubt.

05

Protection of confidential information / Security measures

Legally, if we received your personal data with your consent and with a legitimate interest to collect and disclose it to our client, we are within our rights.

We will ask for your free, prior and informed consent if our clients want to use your personal data for direct marketing purposes or want to publish your picture online (on their social media or websites) or use it for internal or external corporate communications. By giving your consent to our client, you irrevocably waive any claim for (economic) compensation for the use by our client of your picture or personal data.

The provision of your personal data is necessary for the legitimate interests pursued by OneTec provided that these interests prevail over your fundamental rights and freedoms.

We do not subject you to decisions based exclusively on automated processing that produce legal effects concerning you or similarly significantly affect you. The provision of your picture and personal data (i.e. email address) is a necessary condition for the provision of our service. If we cannot process your picture or your email address, you may not use our service.

We do not collect personal data about you from third parties.

We have analysed the risks and reassess them specifically for each data collected (implementation of measures adapted to the risk). Treatment in the legitimate interests of the customer is governed by a contract which regulates the use of the data and the protection. Data collection is done according to the rules of the GDPR: always with application for free, revealed, specific consent by an active event.

In addition, you can read all security measures taken by us, mentioned in this Privacy Policy.

06

Transport of confidential information

In case of transport of confidential information (e.g. on a USB key or a laptop outside of the business premises), employees take into account the following guidelines:

  • Employees limit the transport of confidential information within and exclusively to what is strictly necessary for the performance of their work.
  • Employees need to be permanently aware of the risk of data loss in this type of situation.
  • Employees must do everything in their power to prevent the theft or loss of data (e.g. forgetting their laptop/smartphone on the train, theft of their laptop left in the car…).
  • Employees must never leave their laptop unattended outside of the workplace. Employee victims of a theft of their laptop, smartphone or tablet inform their hierarchical superior without delay and at the latest within six (6) hours of discovery. Employees who find that their laptop, smartphone or tablet has been hacked must inform their superior within six (6) hours of the finding.
  • Employees who use another wireless network than that of the employer must verify if this is a secure network. It is also forbidden for employees to use an open and unsecured WIFI network.

These commitments are the subject of a contract agreed by all employees, including members of the Board of Directors, management, volunteers, interns, sub-processors, clients, etc. (the “collaborators”) and, therefore, any person who comes into contact with confidential employer information or information that may be considered personal data under the GDPR.

07

Where is my confidential information stored?

All data are stored in a SQL database, secured by an encrypted login and password. The data center is located in Europe and duplicated in Belgium for security reasons.

The data will be provided to our client, if allowed by GDPR, through an encrypted file.

The data at rest will be deleted by OneTec at the end of the mission.

Outside OneTec: the servers are physically located at Net7 — our GDPR-compliant subcontractor located in Belgium — and OVH. Inside OneTec: the data only carry through the officers in charge of the project. Each computer is protected by a personal password. The OneTec building is protected by an alarm system.

08

How long do we retain your personal data?

We retain your personal data as long as necessary to achieve the purposes for which we process your personal data. OneTec and our clients and sub-processors do not keep data longer than what is necessary to carry out the mission for which it was collected and won't pass it on to any third party without explicit authorisation by the participating customers.

We use the following criteria to determine the retention periods of personal data:

  • The time elapsed since the event
  • The sensitivity of the personal data
  • Security reasons (for example, the security of our information security systems)
  • Any current or potential dispute or litigation
  • Any legal or regulatory obligation to retain or delete personal data

When you are invited to give your consent, you are always informed about the retention period so you can agree to the use of your data knowingly.

09

How can I stop receiving marketing e-mails?

If you would like to stop receiving e-mails from our clients, you can opt out at any time by unsubscribing from the mailing list of our client or by sending them an email explaining you do not want to receive their newsletter anymore.

Our clients must provide you with the possibility to object to receiving any type of e-mails — e.g. through a link to unsubscribe from their mailing list or by allowing you to send an email to them.

You have the right to object at any time to the processing of your personal data for direct marketing purposes.

You always have the right to lodge a complaint at the competent data protection authority.

Belgian Data Protection Authority / Autorité de protection des données / Gegevensbeschermingsautoriteit

Rue de la Presse, 35, 1000 Bruxelles / Drukpersstraat 35, 1000 Brussel

commission@privacycommission.be

+32 (0)2 274 48 00

10

I have a question or a problem. Who can I contact?

If you have any question or complaint about the processing of your personal data, please contact us by email at info@onetec.eu or by post at Leuvensesteenweg 542/C4, 1930 Zaventem (Belgium).

Get in touch

Questions about your data?

Email us at info@onetec.eu or write to:

OneTec SRL
Leuvensesteenweg 542/C4
1930 Zaventem, Belgium