Legal

Privacy Policy

Belfort Advisory BV and Belfort Law BV

Last updated: September 2026

This policy explains what personal data Belfort Advisory BV and Belfort Law BV (“Belfort”, “we”) process, why, who receives it, and what you can do about it. It applies to this website, to people who contact us, and to people whose data we handle in the course of our work, including people who are not our clients. We process personal data in line with the GDPR and Belgian data protection law.

1. Who is responsible

EntityEnterprise numberController for
Belfort Advisory BVBE 1026.995.022This website (hosting, analytics), the Advisory contact form, Advisory engagements, recruitment and business development
Belfort Law BVBE 0426.532.457The Law contact form and legal matters, including investigations conducted under Belfort Law's direction

Both are Belgian companies. For any privacy question or request, write to info@belfort-advisory.com. We have not appointed a data protection officer, as neither company is required to.

2. What we process and why

ActivityDataLegal basisRetention
Answering contact form enquiriesName, email address, message; phone number and company if you choose to add themSteps at your request before a contract (Art. 6(1)(b) GDPR) or our legitimate interest in answering you (Art. 6(1)(f))12 months after our last exchange, unless an engagement follows
Website analyticsPages viewed, referring site, browser, operating system, device type and country. Visits are counted using a hash of your IP address and browser that is discarded after 24 hoursLegitimate interest in understanding which content is useful (Art. 6(1)(f))Only aggregated statistics are kept
Hosting and securityIP address, request details and timestamps in server logsLegitimate interest in keeping the website available and secure (Art. 6(1)(f))Short-term, in line with our hosting provider's log retention
RecruitmentCV, contact details, interview notes and anything else you send usSteps at your request before a contract (Art. 6(1)(b))12 months after the application process closes, longer only with your consent
Business developmentBusiness contact details and professional role, obtained from you, from LinkedIn, at events or through referralsLegitimate interest in building professional relationships (Art. 6(1)(f))Until you object, or 24 months without interaction
Client engagements, anti-money laundering and know-your-client checksIdentity and contact details of client representatives and beneficial owners, engagement recordsPerformance of the contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))Up to 10 years after the end of the engagement, as required by anti-money laundering law and our General Terms

3. People involved in our investigations

Much of our work concerns people who never contacted us: employees or contractors under investigation, witnesses, and counterparties. If you are one of them, this section applies to you.

  • Sources. Data usually comes from our client (typically your employer), from its IT systems, logs and records, from interviews, and from public sources.
  • Categories. Identification and employment data, communications and system activity relevant to the matter, and statements. An investigation can involve data about suspected offences (Art. 10 GDPR), which Belfort Law processes where Belgian law allows, for example to establish, exercise or defend legal claims.
  • Our role. In many engagements our client is the controller and we act as its processor. In that case the client's privacy notice governs, and we pass on any request you send us. Where Belfort Law determines how the matter is handled, it acts as controller.
  • Legal basis. The legitimate interest of our client, or our own, in investigating suspected misconduct and in establishing, exercising or defending legal claims (Art. 6(1)(f)), and legal obligations (Art. 6(1)(c)).
  • Limits on information and access. We may delay informing you, or limit access, where doing so earlier would seriously prejudice the investigation (Art. 14(5)(b) GDPR), and where the professional secrecy of Belfort Law's lawyers applies. Those limits last only as long as the reason for them.
  • Retention. For the duration of the matter and any resulting proceedings, then for the limitation period that applies to potential claims.

4. Who receives your data

We do not sell personal data or share it for advertising. The following service providers process data on our behalf under a data processing agreement:

ProviderPurposeLocation and safeguard
Vercel Inc.Website hosting and analyticsServer functions run in Frankfurt (EU). Vercel is a US company and serves pages through a global network. EU-US Data Privacy Framework and Standard Contractual Clauses
ResendDelivering contact form submissions to our mailboxUnited States. Standard Contractual Clauses
Microsoft Ireland Operations LtdEmail, documents and collaboration (Microsoft 365)EU Data Boundary. Any remaining transfers under the Data Privacy Framework and Standard Contractual Clauses
SanityWebsite content management; images are loaded from Sanity's network, which receives your IP addressEEA and United States. Standard Contractual Clauses

We also share data with our accountants and auditors, who are bound by confidentiality, and with courts, regulators or authorities where the law requires it.

5. Cookies and local storage

This website sets no cookies. Our analytics work without cookies and do not follow you across other sites, and our fonts are served from our own domain rather than from Google.

If you switch between light and dark mode, your browser's local storage remembers that choice under the key darkMode. It contains no personal data, never leaves your device, and exists only to deliver a feature you asked for, so it does not require consent. You can clear it through your browser settings.

6. Your rights

Right to object

Where we rely on legitimate interest, you can object at any time on grounds relating to your situation (Art. 21 GDPR). You can object to business development contact at any time, without giving a reason, and we will stop.

You can also ask us to:

  • give you access to the personal data we hold about you and a copy of it
  • correct data that is inaccurate or incomplete
  • erase your data, unless we must keep it by law or need it for legal claims
  • restrict processing while a question about accuracy or lawfulness is resolved
  • send data you gave us, based on contract or consent, to you or another provider (portability)
  • withdraw consent where we asked for it, without affecting earlier processing

Send requests to info@belfort-advisory.com. We may ask you to confirm your identity. We answer within one month; for complex or numerous requests we can extend that by two further months, and we will tell you why within the first month.

If you think we handle your data unlawfully, you can lodge a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be). We would appreciate the chance to fix it first.

7. Security

Access to personal data is limited to the people who need it for the matter at hand. The website is served over HTTPS only, with HSTS and restrictive security headers, and contact form submissions are validated and filtered for spam before delivery. We choose providers that encrypt data at rest and in transit. Investigation material is held separately from general business data and is subject to engagement-specific access controls.

8. Changes to this policy

When we change how we process personal data, we update this page and the date at the top. The current version is always at belfort-advisory.com/privacy.