Privacy Policy
Privacy Policy — Becardi B.V. (Belgium)
Effective Date: 05/13/2026
Introduction
Becardi B.V. (“Becardi”, “we”, “us”) values the protection of personal data. This privacy policy describes which personal data we process, why, on what legal basis, for how long, and what rights data subjects have under the GDPR and Belgian regulations (GBA/APD).
Scope
This policy applies to all personal data we process from visitors, customers, suppliers, employees, candidates, and other contact persons in Belgium and the EU, including data obtained through our website(s), services (including payments via Stripe PSP), email, telephone, and contracts.
Processing Activities and Purposes
Examples of processing activities:
Customer management and contract execution: name, address, email, billing details, transaction data (including Mollie transaction IDs) — legal basis: performance of contract.
Payments and fraud prevention: payment details, IP address, transaction history — legal basis: performance of contract and legal obligations.
Marketing and newsletters: email, preferences — legal basis: consent (opt-in) or legitimate interest after a balancing of interests; in case of consent, the possibility of withdrawal.
Recruitment: CV details, references, contact details — legal basis: recruitment consideration/consent.
Website management and analytics: IP address (anonymized where possible), usage data — legal basis: consent for non-essential cookies; necessary for technical operation without consent.
Supplier and compliance management: contact details, contractual information, due diligence data — legal basis: performance of contract/legitimate interest.
Legal Bases
We base processing on one or more of the following legal grounds: performance of a contract, legal obligation, consent, legitimate interest, or vital interests where applicable. For marketing and analytics, we request explicit prior consent where necessary.
Recipients and Transfers
Internal recipients: relevant departments (sales, finance, support, IT, compliance).
External recipients: service providers (payment processors such as Stripe, IT hosting, cloud providers, accounting, lawyers). These parties process data as processors based on data processing agreements.
Transfer outside the EEA: may take place if necessary. We ensure appropriate safeguards (EU standard contractual clauses, adequacy decision, or other legally permitted mechanisms). Details available upon request.
Retention Periods
Personal data is kept no longer than necessary for the purpose for which it was collected or as required by law (e.g., fiscal retention obligation usually 7–10 years). Specific retention periods per processing activity can be provided upon request.
Rights of Data Subjects
Under the GDPR, stakeholders have, among others, the right to:
access,
rectification,
erasure (“right to be forgotten”) if a legal basis is lacking,
restriction of processing,
data portability (for data processed based on consent or contract),
objection to processing based on legitimate interest or direct marketing,
withdrawal of consent (without affecting the lawfulness of processing before withdrawal). Requests can be directed to info@becardi.be; we will respond within one month (extension possible in case of complexity).
Complaints
You may lodge a complaint with Becardi via info@juwelenpiu.be. Additionally, you have the right to lodge a complaint with the Belgian Data Protection Authority (GBA/APD): https://www.gegevensbeschermingsautoriteit.be
Security
We take technical and organizational measures to protect personal data (access restrictions, encryption where appropriate, backups, incident management). Access is restricted to authorized personnel on a need-to-know basis.
Processors and Contractual Safeguards
We enter into data processing agreements with third parties (including Stripe) that process personal data. These contain obligations regarding security, limited use, and cooperation with requests from data subjects.
Profiling and Automated Decisions
If we apply automated decision-making or profiling that has legal consequences or significantly affects you, we will provide specific information and offer human intervention and objection rights where necessary.
Data Breaches
In the event of a personal data breach, we assess the severity and, if necessary, report the breach to the supervisory authority and, when required, to the data subjects within the legally prescribed timeframes.
Processing of Special Categories of Personal Data
In principle, we do not process special categories of personal data (such as health data). If necessary (e.g., employment-related medical data), this only occurs if a specific legal basis or explicit consent is present and with appropriate additional security.
Changes
This policy may be adjusted. We publish changes on our website with the current effective date.
Contact Details
Becardi B.V.
Email DPO/privacy: info@juwelenpiu.be
Compliance: info@juwelenpiu.be
Address/phone:
Bredabaan 307
2930 Brasschaat
+32 3 2971959
For specific details regarding cookies and Stripe-related processing, please refer to our Cookie Policy and Stripe’s privacy statement: https://stripe.com/privacy
