Data charter

This charter summarises the commitments of Dérard - Valmondier Belgium SRL regarding personal data protection, in accordance with the GDPR (EU 2016/679), the Belgian law of 30 July 2018, and any equivalent European or national legislation. It complements the Privacy Policy.
1. Company commitment
The Company undertakes to respect the principles of article 5 GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability.
2. Data protection by design and by default
In accordance with article 25 GDPR, data protection is built in from the design stage and guaranteed by default. Each major change to a service or system undergoes a prior review.
3. Records of processing activities
The Company maintains records in accordance with article 30 GDPR, listing all processing operations carried out under its responsibility and as processor.
4. Roles
4.1. Controller for data collected directly (prospects, clients, suppliers, candidates, website visitors, employees).
4.2. Processor within the meaning of article 28 GDPR for Client data hosted, backed up or administered under the Services.
5. Technical measures
- TLS 1.3 encryption and EV certificates
- Data encrypted at rest (AES-256)
- Pseudonymisation for testing, development and analysis
- Encrypted backups every 6 hours, 90-day retention, geographic replication within the EU
- Strict separation of client tenants
- Strong authentication, mandatory administrator MFA, credential rotation
- Role-based access control (least privilege)
- Logging of access to personal data, logs kept for 1 year
- Annual external penetration tests
- CVE monitoring and prompt security patching
6. Organisational measures
- Mandatory annual staff awareness training
- Confidentiality agreement signed by each employee
- IT equipment usage policy
- Formal onboarding and offboarding procedures
- Continuity and disaster recovery plans tested annually
- Formal security incident management procedure
7. DPO
The Company has appointed a DPO in accordance with articles 37 to 39 GDPR. Contact: info@drjcloud.com.
8. Breach notification
- To the supervisory authority within 72 hours (Art. 33)
- To data subjects where the risk is high, without undue delay (Art. 34)
- To Clients when the Company acts as processor, without undue delay (Art. 33.2)
The Company documents every breach and the measures taken.
9. DPIA
In accordance with article 35 GDPR, the Company conducts a prior impact assessment for any processing likely to result in a high risk. It is reviewed at each substantial change, and at least every 3 years.
10. International transfers
- Adequacy decision (Art. 45 GDPR)
- Standard contractual clauses (Commission decision 2021/914)
- Binding corporate rules (Art. 47 GDPR)
- Codes of conduct or certifications (Art. 40 and 42 GDPR)
- Article 49 derogations, applied strictly
12. Cooperation with regulators
The Company cooperates actively with supervisory authorities and responds to their requests within the time limits they set.
13. Periodic review
The charter is reviewed annually by Management, under the supervision of the DPO. Any substantial change is communicated by appropriate means.