Privacy Policy
Belfort Advisory BV and Belfort Law BV
Last updated: September 2026
This policy explains what personal data Belfort Advisory BV and Belfort Law BV (“Belfort”, “we”) process, why, who receives it, and what you can do about it. It applies to this website, to people who contact us, and to people whose data we handle in the course of our work, including people who are not our clients. We process personal data in line with the GDPR and Belgian data protection law.
1. Who is responsible
| Entity | Enterprise number | Controller for |
|---|---|---|
| Belfort Advisory BV | BE 1026.995.022 | This website (hosting, analytics), the Advisory contact form, Advisory engagements, recruitment and business development |
| Belfort Law BV | BE 0426.532.457 | The Law contact form and legal matters, including investigations conducted under Belfort Law's direction |
Both are Belgian companies. For any privacy question or request, write to info@belfort-advisory.com. We have not appointed a data protection officer, as neither company is required to.
2. What we process and why
| Activity | Data | Legal basis | Retention |
|---|---|---|---|
| Answering contact form enquiries | Name, email address, message; phone number and company if you choose to add them | Steps at your request before a contract (Art. 6(1)(b) GDPR) or our legitimate interest in answering you (Art. 6(1)(f)) | 12 months after our last exchange, unless an engagement follows |
| Website analytics | Pages viewed, referring site, browser, operating system, device type and country. Visits are counted using a hash of your IP address and browser that is discarded after 24 hours | Legitimate interest in understanding which content is useful (Art. 6(1)(f)) | Only aggregated statistics are kept |
| Hosting and security | IP address, request details and timestamps in server logs | Legitimate interest in keeping the website available and secure (Art. 6(1)(f)) | Short-term, in line with our hosting provider's log retention |
| Recruitment | CV, contact details, interview notes and anything else you send us | Steps at your request before a contract (Art. 6(1)(b)) | 12 months after the application process closes, longer only with your consent |
| Business development | Business contact details and professional role, obtained from you, from LinkedIn, at events or through referrals | Legitimate interest in building professional relationships (Art. 6(1)(f)) | Until you object, or 24 months without interaction |
| Client engagements, anti-money laundering and know-your-client checks | Identity and contact details of client representatives and beneficial owners, engagement records | Performance of the contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) | Up to 10 years after the end of the engagement, as required by anti-money laundering law and our General Terms |
3. People involved in our investigations
Much of our work concerns people who never contacted us: employees or contractors under investigation, witnesses, and counterparties. If you are one of them, this section applies to you.
- Sources. Data usually comes from our client (typically your employer), from its IT systems, logs and records, from interviews, and from public sources.
- Categories. Identification and employment data, communications and system activity relevant to the matter, and statements. An investigation can involve data about suspected offences (Art. 10 GDPR), which Belfort Law processes where Belgian law allows, for example to establish, exercise or defend legal claims.
- Our role. In many engagements our client is the controller and we act as its processor. In that case the client's privacy notice governs, and we pass on any request you send us. Where Belfort Law determines how the matter is handled, it acts as controller.
- Legal basis. The legitimate interest of our client, or our own, in investigating suspected misconduct and in establishing, exercising or defending legal claims (Art. 6(1)(f)), and legal obligations (Art. 6(1)(c)).
- Limits on information and access. We may delay informing you, or limit access, where doing so earlier would seriously prejudice the investigation (Art. 14(5)(b) GDPR), and where the professional secrecy of Belfort Law's lawyers applies. Those limits last only as long as the reason for them.
- Retention. For the duration of the matter and any resulting proceedings, then for the limitation period that applies to potential claims.
4. Who receives your data
We do not sell personal data or share it for advertising. The following service providers process data on our behalf under a data processing agreement:
| Provider | Purpose | Location and safeguard |
|---|---|---|
| Vercel Inc. | Website hosting and analytics | Server functions run in Frankfurt (EU). Vercel is a US company and serves pages through a global network. EU-US Data Privacy Framework and Standard Contractual Clauses |
| Resend | Delivering contact form submissions to our mailbox | United States. Standard Contractual Clauses |
| Microsoft Ireland Operations Ltd | Email, documents and collaboration (Microsoft 365) | EU Data Boundary. Any remaining transfers under the Data Privacy Framework and Standard Contractual Clauses |
| Sanity | Website content management; images are loaded from Sanity's network, which receives your IP address | EEA and United States. Standard Contractual Clauses |
We also share data with our accountants and auditors, who are bound by confidentiality, and with courts, regulators or authorities where the law requires it.
5. Cookies and local storage
This website sets no cookies. Our analytics work without cookies and do not follow you across other sites, and our fonts are served from our own domain rather than from Google.
If you switch between light and dark mode, your browser's local storage remembers that choice under the key darkMode. It contains no personal data, never leaves your device, and exists only to deliver a feature you asked for, so it does not require consent. You can clear it through your browser settings.
6. Your rights
Right to object
Where we rely on legitimate interest, you can object at any time on grounds relating to your situation (Art. 21 GDPR). You can object to business development contact at any time, without giving a reason, and we will stop.
You can also ask us to:
- give you access to the personal data we hold about you and a copy of it
- correct data that is inaccurate or incomplete
- erase your data, unless we must keep it by law or need it for legal claims
- restrict processing while a question about accuracy or lawfulness is resolved
- send data you gave us, based on contract or consent, to you or another provider (portability)
- withdraw consent where we asked for it, without affecting earlier processing
Send requests to info@belfort-advisory.com. We may ask you to confirm your identity. We answer within one month; for complex or numerous requests we can extend that by two further months, and we will tell you why within the first month.
If you think we handle your data unlawfully, you can lodge a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be). We would appreciate the chance to fix it first.
7. Security
Access to personal data is limited to the people who need it for the matter at hand. The website is served over HTTPS only, with HSTS and restrictive security headers, and contact form submissions are validated and filtered for spam before delivery. We choose providers that encrypt data at rest and in transit. Investigation material is held separately from general business data and is subject to engagement-specific access controls.
8. Changes to this policy
When we change how we process personal data, we update this page and the date at the top. The current version is always at belfort-advisory.com/privacy.