GDPR
Privacy
How Bengoshi BV processes personal data of website visitors, clients and third parties in a file, and how to exercise your rights.
Translations are for information only. The Dutch versions of the terms, privacy policy and legal info prevail.
Last updated:
Who is responsible?
This statement explains how Bengoshi BV processes personal data. Bengoshi BV is the law firm of Mr. Nelson Vanlocke, a lawyer at the Ghent Bar. Address: Koerspleinstraat 94, 9040 Ghent, Belgium. Company number: BE 0726.907.211 (RPR Ghent).
Bengoshi BV is the data controller. You can send privacy questions to Mr. Nelson Vanlocke at privacy@nelsonvanlocke.be or by post to the address above, marked “Privacy”.
What applies to you depends on your situation. This statement therefore has four parts. Part 1: you visit our website. Part 2: you are a client. Part 3: we process data about you as a third party, for example as an opposing party, witness or expert in a client’s file. Part 4 applies to everyone: your rights and complaints.
1. If you visit our website
This website is a static website. We do not use cookies, analytics or tracking services, advertising or social network scripts. The pages do not load fonts, maps, videos or other content from other parties.
Storage in your browser
We store nothing in your browser: no cookies and no local storage. If you read the website in a language other than Dutch or English, we show a notice about the translation. If you close that notice, it only disappears until you reload the page or visit the website again.
Technical data
When your browser requests a page, our hosting provider Combell receives technical connection data, such as your IP address and the time of the request. This is needed to deliver and secure the website (legitimate interest, art. 6.1.f GDPR). Our website contains no technique to track or identify visitors. What Combell itself records is described in the Combell privacy policy.
Search statistics
We use Google Search Console to see how our website appears in search results. We place no code on the website for this. We only receive aggregated statistics, such as search terms and numbers of impressions, and no data about individual visitors.
Links to other websites
Our pages link to other websites, such as government sites, news items, WhatsApp, Google Maps and LinkedIn. Only when you click such a link does that party receive data from you, and its own privacy policy applies.
If you contact us
The contact form opens your own e-mail program with a message that you still send yourself. We only receive what you send: name, telephone number, e-mail address, optionally company name and VAT number, and your message. The same applies if you call, e-mail or WhatsApp us. Our e-mails run through the Combell mail server.
We use that data to reply to you and to schedule an appointment (art. 6.1.b GDPR for steps taken at your request before a contract, and art. 6.1.f GDPR for our legitimate interest in answering questions). We keep it no longer than necessary for that purpose. We do not use it for marketing and send no newsletters. If you become a client, part 2 applies.
2. If you are a client
This part applies to anyone who consults or instructs us as a lawyer, and to contact persons of clients that are a company or association.
Which data
Identification and contact details (such as name, address, telephone number, e-mail address, date of birth and national register number), financial data (such as bank account number and payments), data about your family and living situation, your profession, education, memberships and interests, and everything else you entrust to us for your case.
Depending on the case, this may also include data about your health, including mental health, or data about criminal offences and convictions.
Where we get data from
Mostly from you. For your case we also receive data from others: opposing parties and their lawyers, courts and other authorities, experts and public sources.
Why and on what basis
Handling your case and defending your interests. Basis: our agreement with you (art. 6.1.b GDPR). For contact persons of a company or association that is a client: our legitimate interest in providing our services to that client (art. 6.1.f GDPR). We process special categories of data, such as health data, because this is necessary for the establishment, exercise or defence of legal claims (art. 9.2.f GDPR). We process data about criminal convictions and offences to the extent that defending your interests requires it (art. 10 GDPR and art. 10 of the Belgian act of 30 July 2018).
Legal obligations. Identification and prevention of money laundering and terrorist financing, to the extent those rules apply to your assignment, and accounting and taxes (art. 6.1.c GDPR).
Our own rights and security. Collecting our fees, our defence in a dispute and the security of our office and systems (legitimate interest, art. 6.1.f GDPR).
We take no decisions based solely on automated processing, we do not build profiles, and we send no newsletters or advertising.
Who we share data with
Only where necessary for your case or required by law: courts and their registries, other authorities, the opposing party and their lawyer, experts and bailiffs. This happens on your instructions and within the limits of professional secrecy. We provide no data to other third parties, because professional secrecy forbids this.
Other lawyers who sometimes stand in for us only receive what is necessary for that task and are bound by the same professional secrecy.
Service providers who support us process data only on our instructions: our e-mail and website provider Combell, a cloud storage provider and our external accountant Stemafisk (invoicing and bookkeeping). We provide a list of these recipients on simple written request.
Transfers outside the European Economic Area
We ourselves do not send data to countries outside the European Economic Area, except exceptionally correspondence with a lawyer or authority in another country, on your instructions. With cloud storage providers, data may also be processed outside the European Economic Area. This then takes place on the basis of an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework, or on the basis of standard contractual clauses.
How long we keep data
File. Ten years after the file is closed, plus a verification period of one year, on paper and digitally. In this we follow the guidelines of the Flemish Bar Association (OVB): that is how long a client can still bring a contractual claim against us. Documents that are the result of our own intellectual work and remain useful for later files, such as submissions, applications and court decisions, we may keep longer.
Data we must keep longer by law. Identification data and supporting documents under the anti-money-laundering rules, to the extent they apply to your assignment, we keep for ten years after the end of the business relationship. They are then erased. Accounting and tax documents we keep for as long as the law requires.
Afterwards. On your request we return your documents. What we no longer need to keep, we erase from our computers and shred on paper.
Security
We take appropriate technical and organisational measures. Paper files are kept in a locked cabinet in a locked office. Our computers are protected with a firewall and antivirus, and only we have access to our systems and files.
Professional secrecy
We are bound by professional secrecy (art. 352 of the Criminal Code and the Code of Ethics for Lawyers). This secrecy protects you. We therefore cannot invoke it to refuse you the data in your own file.
3. If we process data about you as a third party
This part applies to anyone who is not a client but whose data we process in a client’s file, for example an opposing party, witness, expert, bailiff, magistrate, relative or contact person of a client.
Which data and from whom
Identification and contact details, your role in the file, your statements, financial data needed for the case and, if the case requires it, special categories of data or data about criminal offences. We receive that data from our client, from the opposing party and their lawyer, from court documents, from authorities and experts and from public sources.
Why and on what basis
To defend our client’s interests and to exercise or establish rights. Basis: our legitimate interest in being able to assist our client (art. 6.1.f GDPR). For special categories of data this is art. 9.2.f GDPR, and for criminal data art. 10 GDPR and art. 10 of the Belgian act of 30 July 2018. We only process what is necessary for that and for as long as necessary.
We share your data only with courts, authorities or other parties on our client’s instructions, and with the service providers named in part 2. We do not use it for marketing.
Why you are sometimes informed later or not at all
In principle we must inform you when we receive data about you (art. 14 GDPR). That duty does not apply where the data must remain confidential because of our professional secrecy (art. 14.5.d GDPR). Towards our client we are bound by professional secrecy (art. 352 of the Criminal Code). That is why we do not always provide this information earlier.
Where this is possible without breaching professional secrecy, we include this information in our first written communication with you, such as a formal notice. This page gives it to you in general terms in any case.
How long we keep your data
For as long as the client’s file is kept and no longer than necessary to protect the client’s interests. The periods are set out in part 2, under “How long we keep data”.
Your rights and their limits
You can exercise the rights set out in part 4. We assess each request individually. A right may be limited where it would harm professional secrecy or the rights and freedoms of others, including our client (including art. 15.4 GDPR). We will then explain why.
4. Exercising your rights and complaints
This part applies to everyone whose data we process.
Your rights
You can ask us for access to your data and a copy, to correct inaccurate data, to erase data, to restrict processing and to object to processing based on our legitimate interest. On your request we explain our balancing of interests.
The right to data portability applies only to data you provided yourself and that we process by automated means on the basis of a contract. Erasure is not possible to the extent that we must keep data by law or need it for a legal claim.
How to submit your request
E-mail privacy@nelsonvanlocke.be or write to Bengoshi BV, attn. Privacy, Koerspleinstraat 94, 9040 Ghent. If we doubt your identity, we may ask for proof of identity, so that we do not give data to the wrong person. We reply within one month at the latest and free of charge, unless your request is manifestly unfounded or excessive.
Lodging a complaint
If you are not satisfied, please contact us first. You can then lodge a complaint with the Belgian Data Protection Authority through its online complaints portal.
Changes
We may amend this statement. The date at the top shows the latest change. The current version is always on this page.
Need legal assistance?
Contact us to discuss your case. For urgent criminal matters call or WhatsApp: 24/7.