Privacy Policy

Version 1.0 | Last updated: 08.07.2026

Welcome to by Watson. We attach great importance to the protection of your personal data. In this policy we explain clearly which data we collect when you visit our website or contact us, why we do so, how long we keep it and which rights you have.

We write this policy in clear English. If you still have questions after reading it, we are happy to answer them. Our contact details are at the bottom.

1. Who is responsible for your data?

The data controller is:

[OFFICIAL COMPANY NAME] (trading as by Watson)

Registered office: [STREET AND NUMBER, POSTAL CODE AND TOWN]

Company number: [BE 0xxx.xxx.xxx]

Email for privacy questions: [PRIVACY MAILBOX]

Telephone: [GENERAL TELEPHONE NUMBER]

Our offices are located in Kortrijk, Nazareth, Tielt and Waregem. You’ll find the address per office on our contact page.

[IF APPLICABLE: We have appointed a Data Protection Officer. You can reach them via [DPO CONTACT].]

2. Which data we process and for what purpose

For each situation we list which data we ask for, what we use it for, on what legal basis, with whom we may share it and how long we keep it.

2.1 Visiting our website

  • Which data: technical data (IP address, browser type, device, language, pages visited, time), cookie preferences.
  • Purpose: to make the website work, identify errors, gain anonymous or pseudonymised insight into visitor behaviour so we can improve our content.
  • Legal basis: for strictly necessary cookies, our legitimate interest in keeping the website secure and functional (Art. 6.1.f GDPR). For analytical and marketing cookies, your consent (Art. 6.1.a GDPR; Art. 129 Belgian Code of Economic Law (WEC)).
  • Recipients: [HOSTING PROVIDER], [ANALYTICS PROVIDER, e.g. Google Analytics 4], [ANY MARKETING TOOLS]. Full overview in the cookie statement.
  • Retention period: see cookie statement per category. Server logs max. [12] months.

2.2 Contact form and direct email

  • Which data: name, email, phone number (optional), company name (optional) and the content of your message.
  • Purpose: to answer your question or schedule an appointment.
  • Legal basis: your request to engage in a possible collaboration (pre-contractual stage, Art. 6.1.b GDPR) and, for follow-up without a file, your consent.
  • Recipients: the relevant team within by Watson, our CRM provider [NAME CRM].
  • Retention period: up to [24] months after the last contact, unless a client relationship is established. In that case, the periods under 2.5 apply.

2.3 Newsletter subscription

  • Which data: name, email and (optional) job title or sector.
  • Purpose: to send you substantive updates on tax, accountancy, legal and HR advice.
  • Legal basis: your consent (Art. 6.1.a GDPR). You can withdraw that consent at any time via the unsubscribe link at the bottom of each mailing or by sending us an email.
  • Recipients: our email marketing provider [NAME TOOL, e.g. Mailchimp].
  • Retention period: as long as you remain subscribed, plus [12] months after unsubscription for archive and proof purposes. After that, we delete or anonymise your data.

2.4 Applications via the website or spontaneous

  • Which data: contact details, CV, cover letter, education, prior work experience and any additional information you share.
  • Purpose: assessing your application, scheduling an interview, and preparing your personnel file if hired.
  • Legal basis: pre-contractual stage at your request (Art. 6.1.b GDPR) and, for retaining your profile after a rejected application, your consent (Art. 6.1.a GDPR).
  • Recipients: HR and the relevant partner or manager. If we engage an external recruitment agency, we will tell you explicitly.
  • Retention period: if hired, for the duration of your employment and thereafter in line with statutory retention periods for personnel files. If not hired, max. two years with your consent. Otherwise, we delete your data within one month of the selection process.

2.5 Client files

Once you actually become a client of by Watson, additional processing activities apply under a separate agreement (general terms and engagement letter). Specific tax, professional and statutory retention periods apply. Those activities fall outside this privacy policy for website visitors but will be communicated to you explicitly at the start of the collaboration.

3. Legal bases, an overview

We only process personal data when there is a legal basis to do so. In concrete terms, each use in this policy relies on one or more of the following grounds under the GDPR:

  • Consent (Art. 6.1.a): e.g. analytical cookies, newsletter, retention of an application file.
  • Performance of a (pre-)contractual agreement (Art. 6.1.b): e.g. contact form, application, client file.
  • Legal obligation (Art. 6.1.c): e.g. statutory retention obligations for accounting records and tax documents.
  • Legitimate interest (Art. 6.1.f): e.g. the security of our website and fraud prevention. Before relying on this, we always check that your interests do not outweigh ours.

4. With whom do we share your data?

We do not sell your data. We only share it with parties that help us deliver our services, or with whom we are legally required to exchange it. Those are mainly:

  • Our IT and hosting providers.
  • Our CRM and email marketing provider.
  • Our HR and payroll provider (only in the case of an application or hire).
  • Competent authorities, where this is legally required.

With each of these parties we conclude a data processing agreement that sets out how they handle your data.

5. Transfers outside the European Economic Area

Some of our tools (e.g. analytics or cloud providers) may process data in countries outside the European Economic Area. We only do this where there are appropriate safeguards, such as the European Commission’s standard contractual clauses or an adequacy decision. You’ll find the tools concerned in our cookie statement.

6. How long do we keep your data?

We never keep personal data longer than necessary. For each processing activity listed above, we have stated the retention period. Specific statutory periods (e.g. accounting records, tax obligations, ITAA obligations) apply on top of these periods where relevant.

7. How do we secure your data?

We take appropriate technical and organisational measures to protect your data against loss, theft or unauthorised access. Our staff are bound by professional secrecy and trained in information security. We work with encrypted connections (HTTPS), strong passwords, access controls and regular back-ups. Should an incident occur with possible impact on your data, we will notify the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit, GBA) and, if necessary, you.

8. Your rights

The GDPR grants you a number of rights regarding your data. You can exercise them at any time:

  • Right of access: to know which data we hold on you.
  • Right to rectification: to have inaccurate or incomplete data corrected.
  • Right to erasure: to have data deleted, insofar as no statutory retention obligation stands in the way.
  • Right to restriction: to temporarily halt the use of your data.
  • Right to data portability: to receive your data in a common format or have it transferred to another party.
  • Right to object: to processing based on legitimate interest.
  • Right to withdraw consent: for processing for which we asked for consent, you can withdraw at any time without affecting processing prior to the withdrawal.
  • Right not to be subject to an automated decision: we don’t take decisions about you solely on the basis of automated processing with legal effects.

You can exercise these rights by emailing us at [PRIVACY MAILBOX]. We respond within one month. If we ask you to confirm your identity first, that is only to prevent a third party from abusing your rights.

Not satisfied with how we handle your data? You can always file a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), Drukpersstraat 35, 1000 Brussels, contact@apd-gba.be, www.gegevensbeschermingsautoriteit.be.

9. Changes to this policy

We may update this privacy policy as our services or legislation evolve. The most recent version is always available on this page, with the date of the last change. For significant changes we will actively notify you, for example via a banner on the website or an email.

10. Questions or feedback?

We welcome your questions, comments or suggestions. Email us at [PRIVACY MAILBOX] or call [GENERAL TELEPHONE NUMBER].