Personal data protection policy
This policy sets out how we handle the information we collect about you when you visit our site (mariethiebaut.be).
Who is the data controller and who is the data protection officer?
Bruno MICHAUX & Marie THIEBAUT, Notaires associés processes personal data in the course of its activities.
Bruno MICHAUX & Marie THIEBAUT, Notaires associés located at Boulevard Saint-Michel 78,1040 Etterbeek with company number 0738.390.031, is responsible for the processing of personal data carried out within the firm (hereinafter "the firm"). The data controller is the natural or legal person who determines the purposes and means of processing personal data.
The Study is committed to the protection of privacy. It is committed to protecting and processing your personal data with particular care and transparency, in strict compliance with privacy protection legislation, in particular the General Data Protection Regulationes (EU) 2016/679 (hereinafter "RGPD") and the Code of Conduct of the Chambre nationale des notaires of January 28, 2021 specifying certain modalitys d'application du Règlement général sur la protection des données (UE) 2016/679 (RGPD) pour les notaires (ci-après "Code de conduite")
In accordance with the RGPD and the Code of Conduct, the firm has appointed a data protection delegate, namely Privanot ASBL. The data protection delegate can be contacted at the following e-mail address: info@privanot.be, or by letter at the following address: Privanot asbl, Rue de la Montagne 30, 1000 Brussels.
By means of this data protection policy, we would like to give you more information on how we handle the personal data we hold. In this policy, you will find answers to the following questions:
- Who is the data controller and who is the data protection officer?
- Why are your personal data processed?
- What is the legal basis for processing your personal data?
- What personal data does the study process?
- What are the sources of information?
- To whom may your personal data be communicated?
- Who are the study's subcontractors?
- Will your personal data be transferred outside the European Economic Area (EEA)?
- How long will your personal data be stored?
- How is the security and confidentiality of your personal data ensured?
- What rights do you have?
Please note that information on the processing of personal data of internal employees carried out within the framework of human resources can be found in the company's employment regulations.
Why are your personal data processed?
Purposes - The firm collects and processes personal data primarily to ensure the legal security of transactions whose authenticity is guaranteed by the notary, and to manage the files entrusted to the notary.
In addition, processing operations are necessary to achieve other important tasks and objectives, namely :
- management of the office's files, including processing carried out before and after the execution of an authentic act, such as the necessary searches and verifications, as well as any other processing required to fulfill the notary's duties as a public officer and the missions entrusted to him by citizens;
- administrative management and follow-up of citizens' files, including invoicing and accounting;
- carry out the necessary checks and controls within the framework of anti-money-laundering legislation;
- ensure the security of buildings, property, staff and visitors through camera surveillance;
- optimize website navigation through the use of cookies;
- improve user-friendliness and services by using citizen feedback and statistical analysis of the study's operations and services with the help of software ;
What is the legal basis for processing your personal data?
Lawfulness - The processing of personal data by a notary is considered to be lawful if, in most cases, it is necessary for the fulfilment of a legal obligation.necessary to comply with a legal obligation to which the notary is subject, or necessary for the performance of a mission of public interest entrusted to the notary in charge of the file within the firm.
The processing of personal data is carried out by the firm on the basis of, but not limited to, the following legislation:
- The law of 25 Ventôse An XI containing the organization of the notarial profession;
- The law of September 18, 2017 relating to the prevention of money laundering and terrorist financing and limiting the use of cash.
In addition, the lawfulness of processing may also be based on the legitimate interest of the data controller, as in the case of improving customer satisfaction or securing the study by means of a surveillance camera.
Finally, the lawfulness of processing may be based on the consent of the data subject, for example when non-functional cookies are used on the survey website.
What personal data does the company process?
Depending on the services you request, the research department may process the following personal data:
- identification data (surname, first name, marital status, national registration number, place and date of birth, etc.) ;
- contact data (postal address, e-mail address, telephone number, etc.);
- economic and financial data (bank account number, etc.);
- data relating to legal capacity;
- data relating to professional activity;
- data relating to acts carried out within the firm;
- data relating to family, social, tax or other circumstances that the notary must collect from official sources and administrations concerning you;
- video surveillance images;
- data relating to the quality/satisfaction of services provided.
What are the sources of information?
As a public official, the notary is required to collect and use personal data about you in the course of his or her work.
Your personal data may come from
- yourself or your legal representative ;
- authentic data sources strictly regulated by specific legislation, such as the National Register, the Crossroads Bank of Social Security, the Central Inheritance Register
- the Central Register of Cohabitation and Marriage Contracts, etc. ;
- official bodies authorized to supply data to notaries as part of their public functions;
- images filmed by one or more video surveillance cameras.
To whom may your personal data be communicated?
Personal data processed by the firm may be communicated to third parties ("recipients"), depending on the context of the processing, and in particular :
- to legally authorized partners, such as public services and notarial institutions, for the storage of deed transcripts and their metadata in the context of electronic registration and for the registration of your data in the central registers of the notarial profession (e.g. the Central Register of Notarial Contracts). (e.g. the Central Register of Marriage Contracts, the Central Register of Power of Attorney Contracts, the Central Register of Declarations relating to the appointment of a trustee or a person of trust, etc.).
- the Fédération Royale du Notariat belge asbl, for data relating to real estate assets to be recorded in a notarial databasethe purpose of which is to generate statistics and enable notaries to estimate the value of real estate in the exercise of their functions;
- the provincial chamber of notaries involved in your case and/or the national chamber of notaries (e.g., as part of their accounting control functions or in the context of preventing and combating money laundering);
- other notaries involved in your file (e.g., in connection with a real estate deed);
- the State Archives for the preservation of files, minutes and wills;
- banks involved in your case;
- thechartered accountant/tax specialist who manages the firm's accounts;
- subcontractors for the management and continuity of the office, such as software suppliers for the preparation of deeds.
Who are the firm's subcontractors?
A subcontractor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the study.
The study uses the following categories of subcontractors in particular:
- hardware suppliers ;
- software suppliers, e.g. for file management and accounting;
- server/back-up supplier;
- video surveillance camera suppliers;
Will your personal data be transferred outside the European Economic Area (EEA)?
In principle, your personal data will not be transferred outside the European Economic Area (hereinafter "EEA").
However, should your personal data nevertheless be transferred to countries outside the EEAoutside the EEA and the European Commission has considered that the country to which the data is transferred does not offer a level of protection that is compatible with the EEA.does not offer an adequate level of protection, the study will endeavor to protect your personal data by providing additional guarantees (for example, by entering into standard contractual clauses approved by the European Commission, by adopting binding corporate rules, etc.).).
How long will your personal data be kept?
In accordance with the principle of limiting the storage of personal data, the above-mentioned data may only be stored for as long as is necessary to achieve the purpose for which it was collected.The above-mentioned data may only be kept for as long as is necessary to achieve the intended purpose, in accordance with the laws specifically applicable and the statute of limitations for commercial and personal claims. The retention periods below correspond to the retention periods indicated in the study's register of processing activities.
Retention periods vary according to the nature of the documents concerned, i.e. :
- citizens' client files will be kept for as long as the citizen has not chosen to change notary, and will be kept for a maximum of the citizen's entire lifetime to enable the provision of advisory services (in accordance with article 9 of the Ventôse An XI law containing the organization of the notarial profession);
- files are kept for 30 years following their closure for evidentiary purposes (in accordance with article 3.27 of the new Civil Code);
- minutes are kept for 75 years after signature of the deed, after which they are transferred to the State archives (in accordance with article 62 of the Ventôse An XI law on the organization of the notarial profession);
- books (accounts) are kept for 30 years after the close of the financial year;
- account statements are kept for 30 years after the close of the financial year concerned;
- personal data covered by the law on money laundering are deleted after a 10-year retention period (in compliance witharticles 60 and 62(1) of the Act of September 18, 2017 on the prevention of money laundering and terrorist financing and on the restriction of the use of cash);
- camera images will be kept for a maximum of one month (in accordance with article 6 of the law of March 21, 2007 regulating the installation and use of surveillance cameras);
- personal data processed for website management purposes will be kept for as long as necessary to achieve the intended purpose;
How are the security and confidentiality of your personal data guaranteed?
The company takes appropriate technical and organizational measures to ensure a level of security appropriate to the risk. In addition, the firm ensures that it adopts the security measures for the processing of personal data set out in the Code of Conduct of the National Chamber of Notaries of January 28, 2021.
Security measures are taken to prevent the loss, destruction, alteration or unauthorized disclosure of personal data that has been transmitted, stored or otherwise processed, or unauthorized access to such data.
In particular, the notary's office ensures that :
- access to premises containing data media is restricted to authorized persons ;
- the server environment is properly secured;
- personal data is stored and destroyed securely;
- employees and subcontractors are provided with secure access to the data required to achieve the intended purpose;
- a personal data breach notification procedure applicable to all members of the study is in place;
- a procedure for managing the rights of data subjects applicable to all members of the study is in place;
- an information security policy accessible to all study members is in place;
- awareness of the RGPD is raised among study members;
- technical security measures, such as firewalls, antivirus software and regular security updates, are applied.
These measures are regularly monitored and revised by the aforementioned DPO following an audit.
The firm has, in accordance with Article 28 of the RGPD and Article 2 of the Code of Ethics of the National Chamber of Notaries of January 28, 2021, signed a subcontracting agreement with the various subcontractors it uses.
What are your rights?
Under the RGPD, you have several rights as a person concerned by the processing of your personal data by the firm.
Thus, you have, depending on the circumstances and, subject to compliance with its legal obligations and the fulfilment of its public interest missions by the data controller, the following rights:
- Right to information: you have the right to know, among other things, the personal data that the study processes about you, the purposes of this processing, how long this data is kept, etc. ;
- Right of access: you have the right to consult and obtain communication of your personal data held and processed by the company;
- Right of rectification: you have the right to obtain rectification of inaccurate or incomplete personal data concerning you;
- Right to erasure: you have the right to request the destruction of your personal data processed by the firm;
- Right to restrict processing : you have the right to restrict the processing of your personal data, for example if you dispute the accuracy of the data;
- Right to data portability: you have the right to receive your personal data in a structured, commonly used and machine-readable format, and to transmit it to a third party;
- Right to object: you have the right to object to the processing of your personal data by the notary's office.
You can exercise your rights directly with the notary's office by e-mail info@mtnotaires.be or by letter Boulevard Saint-Michel 78, 1040 Etterbeek or with the Data Protection Officer by e-mailinfo@privanot.be.
Finally, if you feel that your rights are not being respected in accordance with the RGPD, you are entitled to lodge a complaint with the Data Protection Authority (rue de la Presse 35, 1000 Brussels or via their website https://www.autoriteprotectiondonnees.be/citoyen ).
Technical and organizational measures
The creation, security and maintenance of our site is entrusted to a specialized partner: Ricochet Consult 2.0 SRL.
We use the highest standards in terms of encryption, antivirus, firewalling and anti-ddos.
Hosting is provided by a totally dedicated infrastructure, with no sharing of resources or data.
The publicly accessible version of our site is entirely static, making it virtually invulnerable to external attack.
We anonymize all data collected through our site.
Our staff and those of our subcontractors who have access to personal data are contractually bound by an obligation of confidentiality.
Cookies
We use cookies. A cookie is an identifier stored temporarily on your machine when you visit a website. Thanks to this identifier, a website is able to personalize your surfing experience, from one page to another, from one day to another, from one month to another, etc... Cookies can also be used to keep track of you, even when you leave one site for another! We do not use cookies of this kind. For us, cookies are mainly used for traffic statistics and to track chat dialogues.