Skip to content
PTProofTempo
OfferLegalTerms

Data protection

Privacy notice

This notice explains the limited personal data ProofTempo uses to operate the website, answer enquiries, develop relevant B2B business, deliver work, invoice, and receive payment.

Version 1.0 · Effective 19 July 2026

On this pageControllerData and purposesBusiness outreachProvidersRetentionYour rights

Controller

Laurens De Leeuw, operating under the ProofTempo trading name, is the controller. The establishment address is Donklaan 79 bus 16, 9290 Berlare, Belgium. Enterprise number: 0695.421.308. Use the protected control below for direct contact.

What we process and why

Website security

Ordinary server logs may contain an IP address, request time, requested URL, browser or user-agent data, and response status. They are used only for availability, abuse prevention, and incident investigation on the basis of our legitimate interest in running a secure website. We do not set cookies or similar trackers and do not use the site for behavioural analytics.

Enquiries and proposals

We process the sender's name, work contact details, company, message, and related correspondence to answer a request, prepare requested pre-contractual steps, or conduct relevant business communication. The basis is the requested pre-contractual step, contract, or our legitimate interest in responding to professional enquiries.

Client delivery

We process project contacts, approvals, communications, and the minimum customer-supplied material needed for an agreed Security Review Sprint. The basis is contract performance. Customers must minimise supplied material and must not send credentials, unnecessary personal data, special-category data, or unrelated production secrets. If ProofTempo processes personal data on a customer's documented instructions, the parties must enter into an appropriate data-processing agreement before that processing starts.

Billing and payment

We process legal identity, invoice, structured e-invoicing, bank, and transaction data to invoice, receive payment, keep accounts, and meet legal obligations. Depending on the agreed route, this may involve Billit and Peppol, Stripe, banking providers, and professional advisers.

Relevant B2B business development

We may record a company name, legal form, public company source, relevance trigger, an impersonal company address, communication history, and objection status. Sources are public company websites, official registers, and other professional sources. The GDPR basis is our legitimate interest in finding organisations for which the service is demonstrably relevant, subject to a documented necessity and balancing check.

Electronic outreach is used only where a separate compliant communication condition exists. Without prior consent or an existing-customer condition, Belgian cold email is limited to an impersonal address belonging to a legal person. A named professional address or an address belonging to a sole trader is not treated as covered by that exception.

Unconditional right to object. You may object to business-development processing at any time, without giving a reason, by replying to the message or using the protected control below. Marketing use stops. We retain only the minimal suppression record required to prevent renewed contact.

Providers, recipients, and transfers

Access is limited to the operator and providers needed for the relevant purpose. Current provider categories include Combell for hosting and email; Billit and Peppol for invoicing; Stripe and banking providers when a payment route is used; and customer-approved workspaces for delivery. Professional advisers or authorities receive data only where necessary or legally required.

We do not sell personal data. If a provider processes data outside the European Economic Area, it must use an applicable adequacy decision or contractual and supplementary safeguards. Information about the safeguard for a specific provider is available by email.

Retention

  • Unanswered or inactive prospect records: no more than six months after the last meaningful activity, with earlier deletion when relevance disappears.
  • Enquiry and proposal correspondence: up to 24 months after the last substantive exchange unless needed for a contract or legal claim.
  • Working security-review material: deleted or returned within 60 days after accepted handoff unless the written order requires a different period.
  • Invoices and accounting records: ten years where the Belgian statutory retention period applies.
  • Suppression record: only the address, objection status, date, and minimal audit data, kept while needed to honour the objection.
  • Server logs: retained on Combell's operational schedule; any exported copy is removed within 90 days unless needed for an active security incident.

Your rights

Depending on the processing, you may request access, correction, deletion, restriction, portability, or withdrawal of consent, and may object to processing based on legitimate interests. Direct-marketing objection is absolute. Use the protected email control below; identity may be verified proportionately before a request is completed.

You may lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données). Providing contact and project data is not legally mandatory, but without the information needed for an enquiry, contract, invoice, or delivery, ProofTempo may be unable to proceed.

No automated decision with legal or similarly significant effect is made about individuals. No personal data is used to train a public AI model. This notice is updated before a materially new data use starts.

ProofTempo · operated by Laurens De Leeuw · KBO 0695.421.308

LegalTerms