GDPR Lingerie Fanny Deprez Luc valid from 25/5/2018

1. Responsible data management::

Deprez L.

Genemeerstraat 53

3581 Beringen

tel: 011/34.68.30

VAT: BE 0698,372,878

email: info@lingeriefanny.be

2. data collected and their retention time, retention method, security and managers::

(a) Bancontact service::

information: Last 4 digits of your card number, the amount, date and hour of the transaction

retention time: all transactions 10 calendar days protected via code, last transaction via menu structure requien

-storage method: digital with the possibility of making a hardcopy on thermal paper

Security: terminal hidden in locked vehicle. digital security provided by Worldline

connection via 3G/4G network, full online

- responsibilities: hardcopy: is given with the customer if requested

physical terminal access: Deprez L.

digital access : Worldline

b) Sumup

information: Last 4 digits of your card number, the amount, date and hour of the transaction, transaction code,

card type, location where the payment was made.

retention time: all transactions from 26/5/2017 protected by code, no removal possible

storage method: digital, limited monthly summary via paper.

Security: terminal hidden in locked vehicle. digital security provided by Norton and Sumup. terminal protected by code, connection via 3G/4G network only during hours of use

- responsibilities: terminal access: Deprez L.

digital access : -Deprez L. for physical access to the terminal,

-Deprez L, Norton and Sumup for digital access

(c) payconiq

-data via payconiq: the amount, date and hour of the transaction, first name, possible message,

-data via KBC: iban and bic code, account holder name, street, house number, postal number, municipality, amount, possible message, date

-retention time: digital data via terminal; all transactions from 07/08/2017 protected by password, no deletion possible

digital data via KBC : maximum 9 calendar years after receipt of payment

hardcopy KBC : minimum 5 and maximum 9 calendar years

-storage method: via payconiq; Digital

via KBC; digital and hardcopy

Security: terminal hidden in locked vehicle. digital security provided by Norton and Payconiq. terminal protected by code, connection via 3G/4G network only during hours of use.

- responsibilities: physical terminal access: Deprez L.

digital access payconiq : -Deprez L for physical access,

-Norton and Payconiq for digital data

digital access KBC: Norton and KBC

hardcopy KBC: -Deprez L to the tax return,

-Accounting firm Theys C.V. from the tax return

-in the case of checks carried out by the Ministry, the Ministry concerned

(d) cash register:

- information: the amount, date, hour of the transaction,

- retention time: minimum 5 years, maximum 9 years

- storage method: internal memory cash register, thermal cash register rollers

- security: internal memory accessible via code, thermal cash register rolls via closed archiving,

no remote access possible (island company).

- responsibilities: internal memory and cash register rolls Deprez L.

in case of ministry control: the ministry concerned.

(e) loyalty card:

- details: amount, date, size, model of the 5 last purchases, total amount, discount amount, name, first name, street, house number, bus number, postal number, municipality, signature.

- retention time: minimum 5 years, maximum 9 years.

- storage method: only by paper carrier.

- security: closed archiving.

- responsibilities: until the end of the quarter: Deprez L.

from the beginning of the next quarter: Accounting firm Theys C.V.

in case of ministry control: the ministry concerned.

(f) website: www.lingeriefanny.be and www.huisfanny.be

- information: the IP address, date and hour, the pages visited, protocol used, page status, web service used.

- retention time: maximum 30 calendar days

- storage method: digital

- security: access only via username and password, tracking email to external email account indicating the ip address of the computer that has accessed itself.

- responsible: Deprez L.

(g) order via ourwebshop.

- information relating to your person: name, first name, street, house number, postal number, municipality, country, telephone, email address, email traffic,

- details relating to your payment provided via KBC: Your IBAN and BIC code, Name of the Bank Account Holder, street, number, postal number, municipality, order code.

- details relating to your order: Order code, purchased item, number, price, total price, account creation date and hour, valid orders placed, total issued since registration, date receipt payment, date delivery package, barcode package, content package.

- Retention time: Order and Personal Data: 30 days after delivery, a hardcopy is created and the digital data is deleted.

responsible digital data Deprez L.

Responsible hardcopy until the end of the quarter Deprez L., from the beginning of the next quarter Accounting office Theys C.V., under audit by the ministry, the ministry concerned.

- retention time: Payment details: both digital and hardcopy; minimum 5 and a maximum of 8 calendar years after receipt of your payment.

responsible digital: KBC;

responsible hardcopy: until the end of the quarter Deprez L., from the beginning of the next quarter Accounting office Theys C.V., under audit by the Ministry, the ministry concerned.

- security: all digital data is encrypted via 128-bit encryption by an https connection, storage of the data is protected by username and password, with a confirmation email to a separate email address indicating the ip address, when accessing or attempting access to the data.

- responsible order and personal data:

digital data: Deprez L.

hardcopy: until the end of the quarter Deprez L.,

from the beginning of the next quarter Accounting office Theys C.V.,

control by the Ministry, the ministry concerned.

- responsible payment information:

digital data: KBC;

hardcopy: up to the Tax Return Deprez L.,

from the tax return Accounting Office Theys C.V.,

by the ministry, the ministry concerned

3) why is this data retained.

All data from all previous data sources shall be retained only for statutory accounting obligations.

We assure you that we are doing everything we can to protect your privacy.

Your data will never be disclosed to third parties.

You can always contact the privacy commission for further information and questions about your rights.