Privacy Policy
Last updated: August 2026 · Version 2026.08.2
Overview
DeskCare respects your privacy. This policy explains what personal data we collect, why we collect it, on what basis, and what rights you have.
Data Controller
DeskCare / Len Buckens
Hovenierstraat 3
9940 Evergem, Belgium
Company number: 0525.740.295
VAT: BE 0525.740.295
Telephone: +32 456 91 23 89
Email: hello@deskcare.be
DeskCare does not sell personal data.
Service and business data
Depending on the contact channel and service, we may process:
- name, email address, telephone number, address and municipality
- company name, VAT number, billing data and payment status
- request type, preferred support mode, project scope and deadline
- device, operating-system, network, error and technical-log information
- email environment, website URL, platform and account information
- customer-portal, dashboard or webshop data supplied for a project
- content, photos, logos, test data and data sources supplied by you
- order, return, delivery, licence, serial-number and warranty information
- cookie preferences, analytics data and marketing-pixel events
We use this data to answer enquiries, prepare proposals, perform services and support, supply hardware or software, administer billing, warranties and disputes, and secure our website and systems.
The legal bases are pre-contractual steps, performance of a contract, legal obligations, consent for optional analytics and marketing, and our legitimate interests. Those interests are specifically: efficiently managing non-contractual enquiries, preventing and detecting abuse and security incidents, administering warranties and disputes, and showing public business projects as portfolio references. We balance each interest against your rights and reasonable expectations. You may object at any time; a portfolio reference will be removed on simple request unless consent is the applicable basis.
What data do we collect?
Analytics & tracking
We use the following services to understand how visitors use our website and to measure the effectiveness of our communications. All tracking is only loaded after your explicit consent via the cookie banner.
Google Analytics 4
Website analytics: page visits, click behaviour, device type and general location (country/region).
Processor: Google Ireland Limited. Data may be processed in the US under the EU-US Data Privacy Framework. See Google's privacy policy.
Retention: 14 months.
Google Tag Manager
Tag management: loads and manages analytics and tracking scripts. GTM itself does not set cookies, but manages which scripts are loaded after consent.
Processor: Google Ireland Limited.
Meta Pixel (Facebook)
Conversion tracking: measures whether visitors arriving via Facebook take an action (such as submitting a contact form). This helps us assess the effectiveness of any campaigns.
Processor: Meta Platforms Ireland Limited. Data may be processed in the US. See Meta's privacy policy.
Retention: Up to 180 days (Meta default).
What we collect via these services:
- Pages you visit
- How you arrived at our site (referrer, UTM parameters)
- Button clicks (CTAs, email links)
- General location (country/region level, not precise)
- Device type and browser
- Whether you submitted a form (conversion event)
What we don't collect:
- Your name or email (unless you contact us directly)
- Precise location. IP addresses may be processed briefly by analytics services for technical delivery of the service, but DeskCare does not use them to personally identify you.
- Any personal files or device information from IT sessions
Legal basis: Consent (Article 6.1.a GDPR). Tracking is only loaded if you explicitly consent.
For details about the cookies used and how to manage your preferences, see our Cookie Policy.
Contact and form data
If you email DeskCare, use WhatsApp, use the contact form, or submit a campaign form, we may collect:
- Your name
- Email address
- Phone number (optional)
- The selected help or service type
- Your preferred help mode: remote, on-site, pickup or drop-off
- The content of your message
- Any additional information you choose to submit, such as device details, provider, project scope or campaign-specific fields
Legal basis: Performance of a contract (Article 6.1.b GDPR) or at your request prior to entering into a contract. For a non-contractual enquiry, the basis may instead be our legitimate interest in managing communications efficiently.
Fields marked as required are needed to handle your request, prepare a proposal or perform a contract. Without them, we may be unable to respond, quote or provide the requested service. Other fields are optional. Some billing data is also required by law.
Retention period: We keep your contact data as long as needed for service delivery and up to 2 years after the last contact, unless legal obligations require longer retention.
Processors and channels: We use Resend as the email processor for form and contact emails. Resend is a US service provider; data may be processed outside the EU based on appropriate transfer mechanisms. If you contact DeskCare via WhatsApp or Facebook Messenger, your message and user data are also processed by Meta Platforms Ireland Limited under their own terms, and data may be processed outside the EU. For SMS or phone calls we rely on our telecom provider. For confidential or sensitive information, email is recommended. We do not sell your data and do not share contact details with third parties so they can contact you for their own marketing.
Remote sessions
During remote IT support sessions, I may temporarily see your screen to assist you. I do not record sessions or store any personal files. All screen sharing ends when the session ends.
Legal basis: Performance of a contract (Article 6.1.b GDPR).
Customer projects where DeskCare acts as processor
This privacy policy mainly describes how DeskCare processes personal data as controller for its own website, communications and services. In customer projects such as webshops, dashboards, portals, automation or support, DeskCare may process personal data on behalf of the customer. In that case DeskCare acts as processor and the arrangements in the data processing agreement or in the proposal/scope apply. The customer, as controller, determines the applicable Article 6 legal basis; being a processor is not a separate legal basis. DeskCare processes that data only on documented instructions under Article 28 GDPR.
Recipients, international transfers and safeguards
We may use hosting, domain, email, cloud, analytics, payment, accounting, project-management, telecommunications and remote-support providers. For this website and its communications, these include Google Ireland Limited (GA4/GTM), Meta Platforms Ireland Limited (Meta Pixel, WhatsApp or Messenger where used) and Resend for form email. Providers receive only the data needed for their service.
Some providers may process data outside the EU/EEA. A transfer only takes place under a valid mechanism such as an adequacy decision, the EU-US Data Privacy Framework where applicable, Standard Contractual Clauses or another appropriate safeguard. You can request information or a copy of the applicable safeguards via hello@deskcare.be. Where available, we also link to the provider's privacy policy or data processing agreement.
Retention
- Contact enquiries without an assignment: 24 months.
- Customer communications and project files: assignment term plus 5 years.
- Invoices and accounting records: 10 years.
- Delivery, purchase and warranty data: as long as needed for warranty, disputes or legal duties.
- Remote sessions: not recorded.
- Passwords and access tokens: not retained permanently and removed, transferred or changed when no longer needed.
- Cookie preferences: 180 days; analytics and marketing retention is detailed in the Cookie Policy.
- Backups and technical snapshots: temporary and purpose-limited.
- Processor data: according to customer instructions and the data processing agreement.
Security
We apply appropriate technical and organisational measures, including least-privilege access, secure transfer, two-factor authentication where available, temporary access, and removal of sensitive data and credentials when the assignment ends.
AI tools
AI tools are used internally for analysis, text, code or debugging. We do not voluntarily enter sensitive customer data, passwords, non-public personal data or confidential business information into public AI tools, unless this has been expressly agreed in writing and is arranged in a technically and legally appropriate way.
We remain fully responsible for reviewing the substance of any output shared with a customer or end customer.
Your rights
Under the GDPR, you have the following rights:
- Access: You can request what data we have about you.
- Rectification: You can have incorrect data corrected.
- Erasure: You can request deletion of your data ("right to be forgotten").
- Restriction: You can request temporary restriction of processing.
- Objection: You can object to processing based on legitimate interest.
- Data portability: You can request your data in a common format.
- Withdraw consent: You can withdraw previously given consent at any time.
To exercise your rights, contact us at hello@deskcare.be. We will respond within 30 days.
Sensitive or confidential data is not entered into public AI tools without an explicit agreement.
Complaints
If you believe we are not handling your data correctly, you can file a complaint with the Belgian Data Protection Authority (GBA): www.gegevensbeschermingsautoriteit.be
Changes
We may update this privacy policy. For significant changes, we will inform you via the website. Please check this page regularly.
Questions
Have questions about this privacy policy? Contact us at hello@deskcare.be.