Personal data and cookies policy
Personal data processing policy (version dated 16/12/2024)
This Nordnet Personal Data Processing Policy applies to all Nordnet customers who use the Orange Satellite with Nordnet Offer in Belgium.
It may change from time to time. The version in force is the one published on the website https://www.nordnet.com/be/en/personal-data-cookies-policy.
The persons concerned by the processing carried out within the framework of this Policy are the:
- Customers with a residential and/or professional offer, users of the Orange Satellite with Nordnet Offer ;
- Prospects ;
- Rights holders, representatives and agents of customers ;
What is personal data?
Personal data is any information relating to an identified natural person or a natural person who can be identified, directly or indirectly, in accordance with Article 4, 11) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, and Article 2 of French Law No. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties in its current version.
What are the essential principles of data protection?
Nordnet processes this data in compliance with the essential principles of personal data protection as defined by the regulations and in particular Article 5 of the GDPR, namely:
- The principles of lawfulness, fairness and transparency,
- The principle of purpose limitation
- The principle of data minimisation
- The principle of accuracy
- The principle of keeping data for no longer than is necessary for the purposes for which it is processed
- The principle of integrity and confidentiality
Where does the personal data processed by Nordnet come from?
In the course of its activities, Nordnet collects and processes personal data in various ways in its capacity as data controller.
Certain data are made available by the customer or collected directly from the customer by Nordnet and others are collected through the services provided by Nordnet.
Nordnet does not process any sensitive personal information relating to the customer's state of health, sexual orientation, political sensitivities, ethnic origin, religious or political convictions.
Nordnet may also be the recipient of data collected from you by a third party acting on your behalf or with your authorisation (e.g. when you use digital assistance).
Certain data may be collected indirectly via cookies, which are the subject of a Cookies Policy accessible on the https://www.nordnet.com/be/en/personal-data-cookies-policy?anchor=cookies website.
Nordnet may also receive data from:
- The satellite operator for the provision of the satellite internet access service
- The authorities
- The telecommunications mediation service
- Organisations aiming to combat fraud or to deal with unpaid bills.
What type of data does Nordnet process?
Nordnet may process the following types of data:
- Identification data: surname, first name, e-mail address, postal address, telephone number, administrative identifier, proof of identity or residence, etc;
- Personal data: household composition, interests, etc;
- Professional life: job held, work organisation, etc;
- Personal characteristics: marital status, legal protection measures, social measures from which the customer benefits insofar as this is necessary to take out an offer;
- Financial data: means of payment, invoices, payment history, etc;
- Products and services owned or used, offers and options;
- Consumption statements;
- Information relating to equipment, services, after-sales service and assistance;
- Technical data: browsing data, connection logs, data linked to the installation of software subscribed to by Nordnet, etc;
- Complaints and possible disputes;
When personal data is collected, the customer is informed whether it is compulsory or optional, and when it is compulsory, failure to provide personal data presented as compulsory may make it impossible to process your request.
How is your personal data used?
Nordnet collects and processes your personal data for specific, explicit and legitimate purposes. They are processed in accordance with the purposes previously defined by Nordnet.
Nordnet processes your data as part of your browsing on our website nordnet.com/be, your requests for information or eligibility as well as your possible participation in giveaways.
Nordnet processes personal data for the purposes of contractual or pre-contractual management of customers and prospective customers under the Orange Satellite with Nordnet Offer.
To this end, several processing operations are carried out on the personal data collected, in particular in order to:
- Respond to requests relating to the exercise of personal rights;
- Respond to requests for information (including when you request that Nordnet call you back or use the contact form);
- Carrying out or enabling your eligibility as part of your Internet access;
- Providing services (in particular delivering products or services ordered, activating the offer);
- Identify and authenticate the customer and/or user, contacts (...);
- Enter the order and your action requests;
- Managing equipment, preparing it, configuring it, dispatching it, collecting it, repackaging it, destroying it;
- Managing incoming mail;
- Invoice and collect payments/ if necessary, carry out debt collection;
- Providing after-sales service and, where applicable, legal guarantees, as well as assistance and responding to requests for information;
- Handling contract terminations (such as cancellations and withdrawals), or portability requests, such as changing supplier;
- Responding to any complaints and disputes, and handling requests from the Electronic Communications Ombudsman.
Nordnet processes personal data based on its legitimate interests, in particular in order to:
- Manage requests for information or eligibility;
- Carry out surveys of customers or prospective customers;
- Carry out processing for statistical purposes;
- Ensuring the security of platforms, services and networks;
- Deploy and operate services;
- Combating fraud;
- Analysing the use of services in order to make proposals to customers;
- Improve offers, customer relations and support;
- Dealing with security incidents and improving security.
Nordnet processes personal data based on the collection of your consent, in particular for the purposes of canvassing and contractual follow-up. These include in particular:
- To carry out processing for the purposes of organising direct marketing operations, sales promotions, givaways, etc;
- To make fully automated decisions based on profiling;
- To share data relating to the conclusion and performance of the contract, its possible withdrawal or termination with Orange Belgium.
Depending on the applicable regulations, your status as a consumer or professional, the means of communication used and the operation concerned, Nordnet may need to obtain your prior consent. For all practical purposes, you are reminded that the fact of not expressly consenting to the receipt of commercial canvassing on a new collection form shall not constitute opposition to the receipt of commercial offers and information from Nordnet, without any further action on your part, in the event that you have previously consented to the receipt thereof.
Nordnet processes your data in order to meet its legal or regulatory obligations, in particular in order to:
- Keeping the required data, including location and connection data;
- Respond to requests for data from authorised authorities or bodies;
- Respond to judicial requisitions and interception requests;
- Respond to requests for emergency communications, warning messages or information of general interest, sent by the authorities;
To sum up:
Process | Activities |
---|---|
Issuing a contract offer | Execution of pre-contractual measures |
Contract management | Contract performance |
Customer administration | Contract performance |
Security | A legal obligation The legitimate interests pursued by Nordnet or by a third party involved in the execution of the Offer |
Combating fraud | A legal obligation The legitimate interests pursued by Nordnet |
Litigation management | A legal obligation The legitimate interests pursued by Nordnet |
Marketing (direct) | Consent The legitimate interests pursued by Nordnet |
Network management | A legal obligation The legitimate interests pursued by Nordnet or by a third party involved in the execution of the Offer |
Cooperation with the justice and security services | A legal obligation |
Manage identity, user accounts and authentication. | Contract performance |
Service provision | Contract performance |
Service Improvement | Contract performance The legitimate interests pursued by Nordnet |
Statistics | Processing of anonymised data. |
How long is your personal data kept?
our data will be kept for the duration:
- Necessary for the fulfilment of the aforementioned purposes;
- Defined in accordance with legal retention obligations;
- Legal statute of limitations.
The retention periods for personal data are applied by Nordnet, in particular on the basis of the following criteria:
Purpose of processing | Retention period |
---|---|
Prospect file management | 3 years from the date of collection or last contact from the prospect. |
Customer file management | Duration of the commercial relationship + 3 years for a residential offer to a consumer and + 5 years for a professional. Periods required to establish proof of a right or contract: prescription in civil and commercial matters 5 years. Obligation to keep books and documents created in the course of commercial activities: 10 years from the end of the financial year. Retention of contracts concluded by electronic means: 10 years from delivery or service. |
Exercising the right of access or rectification | 1 year retention period for identity documents. |
Exercising the right to object | 3 years retention period for identity documents. |
Data relating to your interactions and preferences for TV offers, with a view to making recommendations. | As long as the offer is active and for usage data 18 months. |
Management of orders, deliveries and invoicing | 10 years. |
Audience measurement statistics | 13 months. |
Connection data | 13 months. |
Newsletter management | Until the person concerned unsubscribes. |
Banking data | 5 years. |
Storing bank card numbers | Data relating to bank cards must be deleted once the transaction has been completed (actual payment), plus the withdrawal period if applicable. They may be kept in an intermediate archive for the purpose of proof in the event of the transaction being contested for a period of 13 months. This period may be extended to 15 months to take account of the possibility of using deferred debit payment cards. Longer retention period if consent is given to facilitate regular payments or subsequent purchases, for example. |
Bank card visual cryptogram (CVV2) | Time required to complete each transaction. |
Management of an opt-out list for canvassing | At least 3 years from the date of inclusion in the list. Statutory limitation period 5 years. |
Management of recruitment files | Data is kept for 24 months after the last contact with the candidate. |
Data enabling us to respond to requests for information from the authorities and to court orders | 3 years from the date of the response. |
Data relating to requests to exercise the rights of data subjects | 5 years after the request has been processed or, failing that, as soon as a decision by the competent supervisory authority is time-barred or litigation is time-barred. |
Data needed to ensure that stolen mobiles are blocked when they are used | 18 months after the registration date. |
Who is your personal data intended for?
Your data is intended for use by Nordnet's departments as well as its subcontractors (within the meaning of the RGPD) involved in the provision of services, and more generally in order to commercially propose Nordnet's Offer, collect/enter the Order, execute or provide all or part of the Offer, carry out the delivery and/or installation, where applicable, of the Equipment, and/or the operations for which it may have been entrusted by Nordnet (in particular in respect of maintenance, assistance, customer service, collection, canvassing, auditing, etc.).
Some of these operations may be carried out outside the European Union, with regard to the commercial proposal of the Offer, Order entry, assistance and customer service, under the responsibility and control of Nordnet.
The data processed may, depending on the offers, be intended for Nordnet's subcontractors. In this case, Nordnet only communicates your data to subcontractors with whom Nordnet has concluded a contract by which they guarantee their commitment and their capacity to meet security and confidentiality requirements, and to respect all legal and regulatory obligations in terms of the protection of personal data.
Finally, the data processed may be transmitted to the authorities, administrations, competent bodies, at their request, within the framework of legal or regulatory procedures, requisitions or judicial decisions and requests for communication, as well as to persons subject to an obligation of secrecy who may be recipients of such data in order to assist Nordnet with its legal or regulatory obligations.
Nordnet does not sell your data to third parties for commercial purposes.
Where is your personal data processed?
The data collected is processed by Nordnet and its subcontractors, mainly within the European Union. Customer identification data and electronic communications metadata are kept within the European Union. Certain data may nevertheless be processed outside the European Union, in particular for reasons of storage, assistance or performance of the contract, by subcontractors.
Where applicable, an adequate level of protection of your personal data is required for any transfer of data outside the European Union if the country does not benefit from an adequacy decision issued by the European Commission. In this case, Nordnet takes the necessary measures to ensure that such a transfer presents the appropriate guarantees, in particular contractually, by means of standard contractual clauses of the European Commission or any other approved mechanism, in compliance with the applicable regulations.
What are your rights with regard to personal data?
In particular, you have a right of access, rectification, limitation, deletion and opposition, for legitimate reasons and under the applicable legal conditions, to the processing of your personal data, and the right to object to the transmission to third parties of personal information concerning you or to the receipt of commercial information in accordance with the applicable legal and regulatory provisions.
In accordance with articles L.224-42-1 to L.224-42-4 of the Consumer Code, you also have the right to portability and recovery of your data.
You have the right to lodge a complaint with a supervisory authority (the ADP).
Nordnet does not carry out any processing involving a fully automated decision based on profiling. You are informed that if this were the case, you would be informed and you also have the right to object to a fully automated decision based on profiling being made by Nordnet.
The Customer, as well as any person whose Data may be processed by Nordnet, can exercise all of these rights by submitting a request:
- By e-mail to: coordonnees@nordnet.com (only requests concerning personal data sent to this address will be processed), or
- By post to Nordnet, Département Gestion Clients, 245 Boulevard de Tournai (5ème étage) - CS 20458 - 59664 VILLENEUVE D'ASCQ CEDEX, France,
The request must be accompanied, where applicable, by any useful supporting documents and must specify the identity of the applicant, his contact details (e-mail address, telephone number, postal address, etc.), the Customer number, the subject of his request, and provide proof, where necessary, at Nordnet's request, of his identity in the case of a request for access, portability or deletion.
In the event of an incomplete request, Nordnet may ask the Customer to provide any additional information, and/or proof of identity and/or of his right to act and, in the cases provided for or authorised by the applicable regulations, possibly to explain the legitimate reasons relating to the request.
Within the framework of the exercise of the right of access by which a person requests the transmission of an additional copy of the DCP processed by Nordnet, it may subordinate the delivery of this copy to the payment of a sum corresponding to the administrative costs linked to the additional copy requested.
In the event that the processing of the request is not satisfactory, the person benefits from the right to lodge a complaint with the national control authority competent with regard to the Customer, namely the DPA (whose website can be accessed at the following address: https://www.autoriteprotectiondonnees.be/citoyen) or with the national control authority competent with regard to Nordnet, namely the CNIL (whose website can be accessed at the following address: https://www.cnil.fr).
Finally, any person having the status of Consumer may register free of charge on an opposition list called ‘Do Not Call Me’ (or ‘Do not call me again’) in order to no longer be canvassed by telephone. Customers who are Consumers can do this by registering on the https://www.dncm.be/fr/acceuil website or by calling +32.2.882.19.75 from the telephone number they wish to be added to the list.
How is your personal data secured?
Nordnet attaches particular importance to the security of your personal data and ensures that your personal data is processed in compliance with the applicable regulatory and legal requirements, including when certain operations are carried out by subcontractors.
To this end, Nordnet has put in place appropriate security measures to ensure that access to your data is limited solely to employees, subcontractors or other third parties who need access in order to carry out their duties and who are subject to an obligation of confidentiality.
Appropriate technical and organisational measures to prevent the loss, misuse, alteration and capture of your personal data are implemented by Nordnet and its possible subcontractors, including data encryption. These measures are adapted and revised according to the level of sensitivity of the data processed and according to the level of risk presented by the processing and its implementation.
Access to Nordnet’s information system is restricted to persons who need it for work purposes as part of the duties entrusted to them by Nordnet.
Nordnet trains its employees to protect the personal data they use in the course of their work and asks them to comply with the company's rules and ethical standards.
Nordnet carries out checks and audits to verify that these rules are respected.
Nordnet requires its suppliers to adhere to Nordnet's security principles.
If you wish to contact Nordnet's Data Protection Officer, please send an e-mail to: dpo@nordnet.com