Cookies and Privacy
This privacy policy (the “Privacy Policy”) is addressed to:
- our prospective, current and former members of personnel;
- our suppliers who are natural persons (such as self-employed persons) or the representatives or contact persons of our prospective suppliers who are legal entities; and
- our website’s visitors and any third parties following our company, such as analysts and individuals having signed up for our newsletters.
The policy does not apply to any information processed about legal entities.
You are receiving this Privacy Policy because Phena is processing information about you which constitutes “personal data” and Phena considers the protection of your personal data and privacy a very important matter.
Phena is responsible for the processing of your personal data as it decides why and how it is processed, thereby acting as the “controller”. In this Privacy Policy, “we” or “us” refers to Phena.
As from 25 May 2018, Phena will be subject to and will comply with the revised data protection rules applicable in the European Union under the General Data Protection Regulation (the “GDPR”)[1] and this Privacy Policy will be effective.
In line with our commitment to protect your personal data, we want to inform you and explain in all transparency:
- why and how Phena collects, uses and stores your personal data; and
- what your rights and our obligations are in relation to such processing.
- What type of personal data do we collect?
We collect basic identification information about all individuals with whom we interact, such as your name, title, position, company name, email and/or postal address and fixed and/or mobile phone number.
This information may either be directly provided by you, communicated to us by the legal entity for whom you work (e.g. if you are the contact person designated by your employer to manage the Phena account), supplied to us by one of our service providers (e.g. financial institutions or recruiters) or obtained from publicly available sources (e.g. social media profiles).
- Prospective, current and former members of personnel
For our prospective current and former employees, we may in addition also collect the following information:
- additional identification information (e.g. date and place of birth, nationality, ID card or passport numbers and copy of ID card, contact person in case of emergency);
- your family information (e.g. marital status, number of children, date of birth and household composition, as well as working status of the spouse);
- your education and experience (e.g. employment and education history, other details included in the CVs, professional qualifications and experience);
- other information relating to your recruitment (e.g. information you provided during your interview, handwriting sample for personality assessment based on your handwriting, notes and comments made during the recruitment process);
- your function (e.g. position information such as position title and reference number, supervisor and subordinates, employment dates such as dates of hiring/promotion/position change, work schedule, performance evaluations, language skills);
- your remuneration data (such as salary level and amount, years of experience, bonus, stocks, options, expenses information, insurance and other benefits, pension entitlements and bank account details);
- your social security information (such as tax/social security status, insurance details, disabilities, attendance information including illness or leaves of absence)
- your electronic identification data (e.g. login, passwords, IP address, badge number, logs relating to the usage of IT tools, online identifiers/cookies, Phena professional email address and unique code identifying each employee’s account for expenses, sound or image recording such as CCTV or voice recordings);
- information required to set up insider lists imposed under Belgian law (using the model issued by the FSMA);
- your picture; and
- more generally, information about the activities you are carrying out in your professional capacity at Phena.
- (Representatives of) suppliers
For (the representatives of) our suppliers, we may in addition also collect the following information:
- your electronic identification data where required for the purpose of the delivery of products or services to our company (e.g. login, access right, passwords, badge number, IP address, online identifiers/cookies, logs, access and connexion times, image recording or sound such as badge pictures, CCTV or voice recordings); and
- for natural persons acting as suppliers or service providers, financial information (e.g. bank account details, bills and invoices) and information relating to the contract (e.g. type of agreement, parties and duration).
- Website’s visitors and any third parties following our company such as analysts and individuals having signed up for our newsletters
For website’s visitors and any third parties following our company such as analysts and individuals having signed up for our newsletters, we may in addition also collect the following information:
- electronic identification data (http header fields, IP address, browser identification information, information on hardware and software location data if available);
- information regarding your browser and device (e.g. internet service provider’s domain, browser’s type and version, operating system and platform, screen resolution, device manufacturer and model);
- information provided by you during registration to receive one or more newsletters (e.g. address, type of profile and interest in one or several newsletters);
- data collected through cookies, code on the website and our newsletter delivery provider’s web beacons (e.g. language preferences and analytics of the use of the website, such as the pages visited, in which order these pages were visited and the duration of the visit); and
- for analysts following our company, their estimates and any related opinions, forecasts, or projections.
To the extent authorised or required by law, we may also process sensitive data, such as trade union membership or health data. Phena will only do so as strictly required for the relevant purposes listed in Section 4 below or to comply with a legal obligation and, where required, subject to having obtained your prior consent. In such case, the data will be accessed and processed solely under the responsibility of a representative of Phena who is subject to an obligation of confidentiality.
Whenever personal data is collected (e.g. in forms), we will indicate whether the provision of such data is mandatory (e.g. with an asterisk) and the consequences of a refusal to provide the requested data.
We may also collect your national registry number or social security number but will only process such data if and when legally required.
- When do we collect personal data?
Personal data will be collected by Phena:
- whenever individuals apply to become an employee of a Phena entity;
- whenever employees interact with Phena, its personnel, its IT equipment and other systems;
- whenever Phena interacts with former employees;
- whenever Phena interacts with (the representatives of) our suppliers;
- whenever individuals visit our website or sign up for our newsletters; and
- upon request from analysts.
- On which legal basis and for which purposes do we process personal data?
- Legal basis for the processing
We are not allowed to process personal data if we do not have a valid legal ground. Therefore, we will only process personal data if:
- we have obtained your prior consent;
- the processing is necessary to perform our contractual obligations towards you or to take pre-contractual steps at your request;
- the processing is necessary to comply with our legal or regulatory obligations;
- the processing is necessary to protect your vital interests or those of another natural person; or
- the processing is necessary for the legitimate interests of Phena and does not unduly affect your interests or fundamental rights and freedoms.
Please note that, when processing your personal data on this last basis, we always seek to maintain a balance between our legitimate interest and your privacy. Examples of such ‘legitimate interests’ are:
- to benefit from cost-effective services (e.g. we may opt to use certain platforms offered by suppliers);
- to prevent fraud or criminal activity as well as to protect the security of our IT systems, architecture and networks; and
- to meet our corporate and social responsibility objectives.
- Purposes of the processing
We always process your personal data for a specific purpose and only process the personal data which is relevant to achieve that purpose. In particular, we process personal data for one of the following purposes.
- Prospective, current and former members of personnel
In relation to prospective, current and former members of the personnel, we process personal data for:
- recruitment activities;
- personnel administration (including organisation of work, tasks, benefits, expenses and absence management, performing employment and background checks, creating and maintaining employee directories, travel arrangements);
- payroll management (such as administering remuneration and other contractual benefits, salaries and pay reviews and other awards such as stock options, stock grants and bonuses, pensions and saving plans, benefits to families, business expenses);
- performance reviews (such as appraisals, promotions, career and succession planning, staffing and talent management);
- monitoring employees’ activities in the workplace, including compliance with policies as well as health and safety rules in place;
- managing any disciplinary action and handle internal complaints relating to violence, moral harassment and undesirable (sexual) conduct;
- replying to an official request from a public or judicial authority with the necessary authorisation; and
- ensuring compliance and reporting (such as complying with our policies and legal requirements, income tax and insurance deductions, managing alleged cases of misconduct fraud; conducting audits, defending litigtion);
- ensuring business continuity;
- managing mergers and acquisitions involving our company; and
- any other purposes imposed by law and authorities.
- (Representatives of) suppliers
- implement tasks in preparation of or under existing contracts;
- monitor activities at our facilities, including compliance with applicable policies as well as health and safety rules in place;
- manage our IT resources, including infrastructure management and business continuity; and
- billing and invoicing.
- Website’s visitors and any third parties following our company such as analysts and individuals having signed up for our newsletters
In relation to Phena’s website’s visitors and any third parties following our company such as analysts and individuals having signed up for our newsletters, we process personal data to:
- manage and improve our website (e.g. diagnose server problems, optimize traffic, integrate and optimize web pages where appropriate);
- measure the usage of our website (e.g. by drawing up statistics about the traffic or by gathering information regarding the users’ behaviour and the pages they visit);
- improve and personalize your experience and better tailor content to you (e.g. by remembering your selections and preferences, using cookies);
- periodically send newsletter and promotional emails about our portfolio, and information which you or your company may find interesting, using the email address which you have provided (if you choose to do so);
- analyse the performance of email campaigns and improve the email delivery services to better communicate with our subscribers;
- monitor and prevent fraud, infringement and other potential misuse of our website; and
- communicate the analysts’ opinions for third-parties on Phena’s website
- General
In addition to the above specific purposes, we process all collected personal data for the following general purposes:
- storing contact details (e.g. business cards);
- manage and administer the relationship between Phena and the data subjects;
- manage our IT resources, including infrastructure management & business continuity;
- preserve the company’s economic interests and ensure compliance and reporting (such as complying with our policies and local legal requirements, tax and deductions, managing alleged cases of misconduct or fraud, conducting audits and defending litigation);
- comply with any legal obligations imposed on Phena in relation to its activities;
- reply to an official request from a public or judicial authority with the necessary authorisation;
- archiving and record-keeping; and
- manage mergers and acquisitions involving our company.
- How do we protect personal data?
We have implemented appropriate technical and organisational measures to provide a level of security and confidentiality to your personal data. These measures take into account:
- the state of the art of the technology;
- the costs of its implementation;
- the nature of the data;
- and the risk of the processing.
The purpose thereof is to protect it against accidental or unlawful destruction or alteration, accidental loss, unauthorized disclosure or access and against other unlawful forms of processing.
Moreover, when handling your personal data, we:
- only collect and process personal data which is adequate, relevant and not excessive, as required to meet the above purposes; and
- ensure that your personal data remains up to date and accurate.
For the latter, we may request you to confirm the personal data we hold about you. You are also invited to spontaneously inform us whenever there is a change in your personal circumstances so we can ensure your personal data is kept up-to-dat
- Who has access to personal data and with whom are they shared?
- Transfers to third parties
We may transfer or give access to personal data to third parties outside Phena to complete the purposes listed in Section 4.2 above, to the extent they need it to carry out the instructions we have given to them. Such third parties may include:
- third parties who process personal data, such as our payroll provider, our (IT) systems providers, website designers and hosting provider, payment services providers, banks, insurances companies and pensions funds, social security bodies secratary and social secratary, event organisers (e.g. for shareholders’ meetings), email delivery service providers, database and cloud providers and consultants;
- any third party to whom we assign or novate any of our rights or obligations under a relevant agreement;
- our advisors and external lawyers in the context of the sale or transfer of any part of our business or its assets; and
- any national and/or international regulatory, enforcement or exchange body or court where we are required to do so by applicable law or regulation or at their request.
The above third parties are contractually obliged to protect the confidentiality and security of your personal data, in compliance with applicable law.
Transfers outside the European Economic Area
The personal data transferred by Phena may also be processed in a country outside the European Economic Area (“EEA”), which covers the EU Member States, Iceland, Liechtenstein and Norway. Non-EEA countries may not offer the same level of personal data protection as EEA countries.
If your personal data is transferred outside the EEA, we will therefore put in place suitable safeguards to ensure such transfer is carried out in compliance with the applicable data protection rules. You may request additional information in this respect and obtain a copy of the relevant safeguard by exercising your rights as set out below.
- How do we use cookies and other similar technology on our websites?
A cookie is a text file which may be placed on your device when visiting our website. It contains information that is collected from your device and sent back to the website on each subsequent visit so as to remember your actions and preferences over time.
Phena uses cookies to remember your language preferences and to simplify your use of the website. It also uses Google Analytics for the purposes of managing the website (including measuring the usage of the website and drawing up statistics) as well as for the modification and improvement of the website.
Please note that you can modify your browser so that it notifies you when cookies are sent to it. If you do not want to receive cookies, you can also refuse cookies altogether by activating the relevant settings on your browser. Please note that if you choose to refuse all the cookies, some sections of the website may not be accessible by you or not work properly. Finally, you can also delete cookies that have already been set.
For more information about how to manage cookies on your device, please consult the Help function of your browser or visit https://www.aboutcookies.org, which contains comprehensive information on how to do so on a wide variety of browsers (link is external).
- How long do we store your data?
We will only retain personal data for as long as necessary to fulfil the purpose for which it was collected or to comply with legal, regulatory or internal policy requirements.
We only keep data related to candidates for recruitment purposes for a maximum period of two years. For current employees, the retention period is the time of your employment, unless overriding legal or regulatory schedules require a longer or shorter retention period.
For contracts, the retention period is the term of your (or your company’s) contract with us, plus the period of time until the legal claims under this contract become time-barred, unless overriding legal or regulatory schedules require a longer or shorter retention period.
Personal data collected and processed in the context of a dispute are deleted (i) as soon as an amicable settlement has been reached, (ii) once a decision in last resort has been rendered or (iii) when the claim becomes time barred.
When the above retention periods expire, your personal data is removed from our systems.
However, if individuals wish to have their personal data removed from our databases, they can make a request as described in Section 8, which we will review as set out below.
- What are your rights and how can you exercise them?
- Your rights
You have a right of access to your personal data as processed by Phena under this policy. If you believe that any information we hold about you is incorrect or incomplete, you may also request the correction thereof. Phena will promptly correct any such information.
You also have the right to:
- request the erasure of your personal data;
- request the restriction of the processing of your personal data;
- withdraw your consent where Phena obtained your consent to process personal data (without this withdrawal affecting the lawfulness of processing prior to the withdrawal);
- object to the processing of your personal data for direct marketing purposes; or
- object to the processing of your personal data for other purposes in certain cases where Phena processes your personal data on another legal basis than your consent,
Phena will review such requests, withdrawal or objection and honour them as required under the applicable data protection rules.
In addition, you also have the right to data portability. This is the right to obtain the personal data you have provided to Phena in a structured, commonly used and machine-readable format and to request the transmission of such personal data to a third party, without hindrance from Phena and subject to your own confidentiality obligations.
Exercising your rights
If you have a question or want to exercise the above rights, you may send an email to info@phena.be or a letter at Phena, , Weidestraat 1, 8670 Wulpe , with a scan of your identity card for identification purpose, it being understood that we shall only use such data to verify your identity and shall not retain the scan after completion of the verification. When sending us such a scan, please make sure to redact your picture and national registry number or equivalent on the scan.
If you are not satisfied with how we process your personal data, please address your request to Phena by mail info@phena.be or by letter at Phena, Weidestraat 1, 8670 Wulpe and we will investigate your concern.
In any case, you also have the right to file a complaint with the competent data protection authorities, in addition to your rights above.
- Updates to this policy
This policy may be subject to amendments. Any future changes or additions to the processing of personal data as described in this policy affecting you will communicated to you through an appropriate channel, depending on how we normally communicate with you.
(1) Regulation 2016/679 of the EU Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation or “GDPR”).