Privacy policy

This policy informs data subjects of the conditions under which Dérard - Valmondier Belgium SRL collects, processes and stores their personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and the Belgian law of 30 July 2018.
1. Data Controller
The data controller is Dérard - Valmondier Belgium SRL, with registered office at Avenue Louise 480/18, 1050 Ixelles, Belgique, registered under number BE 0683.571.965. Any request may be sent to info@drjcloud.com or by post to the registered office, to the attention of the DPO.
2. Data Protection Officer
The Company has appointed a DPO in accordance with articles 37 et seq. of the GDPR. Contact: info@drjcloud.com.
3. Categories of data collected
- Identification data: name, surname, position, professional postal and electronic address, phone, login credentials
- Professional data: employer's business name, services used, subscription history
- Technical data: IP address, browser, operating system, connection logs, activity traces, session duration
- Financial data: bank details, SEPA mandate, payment history
- Behavioural data: pages consulted, preferences and aggregated usage statistics, according to your cookie choices
4. Purposes and legal bases
- Contract performance (Art. 6.1.b): order management, Service provision, support, billing
- Legal obligations (Art. 6.1.c): accounting, anti-money laundering, responses to authority requests
- Legitimate interests (Art. 6.1.f): security, fraud prevention, improvement of the site and Services, prospecting existing customers
- Consent (Art. 6.1.a): prospecting of non-clients, non-strictly-necessary cookies
5. Recipients
Data is accessible, strictly as needed, to authorised staff, to technical subprocessors bound by article 28 of the GDPR, to authorised authorities, to advisors, and to potential acquirers in case of asset transfer.
6. List of subprocessors
- OVH SAS (Roubaix, France and Brussels, Belgium) - Hosting and backups - EU
- Resend (transactional email) (Dublin) - Transactional emails - EU
- OVH SAS (Paris) - Transactional emails - EU
- Cloudflare, Inc. (Dublin) - DNS and content delivery (CDN) - EU
- Cloudflare Inc. (San Francisco) - DDoS protection - EU-US Data Privacy Framework adequacy decision
7. Transfers outside the EU
The Company prioritises keeping data in the EU. Any transfer to a third country takes place under one of the guarantees provided in articles 44 to 50 of the GDPR (adequacy decision, standard contractual clauses, BCR or explicit consent).
8. Retention periods
- Accounting and tax data: 10 years
- Contractual data: contract duration + 5 years
- Non-client prospects: 3 years from the last contact
- Non-essential cookies: 13 months maximum
- Connection logs: 1 year
- Job applicant data: 2 years from the last contact
9. Rights of data subjects
In accordance with articles 15 to 22 of the GDPR:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure / right to be forgotten (Art. 17)
- Right to restriction (Art. 18)
- Right to portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent (Art. 7.3)
- Right to set post-mortem directives
- Right not to be subject to automated decision (Art. 22)
These rights may be exercised by email at info@drjcloud.com or by post. Reasoned response within 1 month, extendable by 2 months in case of complexity.
10. Right to lodge a complaint
- Belgium: APD/GBA, Rue de la Presse 35, 1000 Brussels - autoriteprotectiondonnees.be
- France: CNIL, 3 place de Fontenoy, 75007 Paris - cnil.fr
- Luxembourg: CNPD, 15 boulevard du Jazz, 4370 Belvaux
- Netherlands: Autoriteit Persoonsgegevens, Bezuidenhoutseweg 30, 2594 AV The Hague
- Other EU/EEA States: authority of the place of habitual residence, place of work or place of the infringement
11. Security measures
In accordance with article 32 of the GDPR: TLS 1.3 encryption, AES-256 encryption at rest, pseudonymisation, geo-replicated encrypted backups, role-based access control (RBAC), mandatory MFA for administrators, logging, annual penetration tests, continuous training, confidentiality clauses, continuity plan.
12. Breach notification
In case of a breach likely to result in a risk, notification to the supervisory authority within 72 hours (Art. 33). In case of high risk, notification to data subjects without undue delay (Art. 34).
13. Modifications
This policy may be modified. Any substantial modification is notified by any appropriate means, in particular through the client areas or by email.