Weston NV's privacy statement & Cookie policy

1.    BACKGROUND

WESTON NV, a company incorporated under Belgian law, with its registered office at Gaston Geenslaan 80, 3200 Aarschot and enterprise number 0876344520 (‘Weston’), attaches great value and importance to your privacy and the secure processing of your personal data when using the website [www.weston.be]. We want to protect the data of our customers and visitors to our website (‘Customers/Visitors’) in the best possible way against loss, breaches, errors, unauthorised access and any other unlawful processing.

We therefore will process your personal data only in accordance with Regulation (EU) of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (‘GDPR’) and the Belgian Act of 30 July 2018 on the protection of individuals with regard to the processing of personal data.

With this Privacy Statement, Weston wishes to inform you as a data subject, within the meaning of the GDPR, about the processing operations and provide you with adequate information, including about your rights as a data subject. 

Weston wishes to point out that providing certain mandatory personal data is a prerequisite for performing our services. In the absence of these personal data, we cannot offer our services or can only do so inadequately.

Where necessary, we will ask you as a data subject for your informed, free, unambiguous and specific consent to perform certain processing operations.

Our privacy policy may be subject to adjustments and amendments in future. These will be made clear in this Privacy Statement. It is therefore your responsibility to consult this document regularly. Any substantial change will always be clearly communicated and must be the subject of new consent, if required.

2.    WHO PROCESSES THE PERSONAL DATA?

2.1.    Controller(s):

Under this Privacy Statement, which deals with the use of the Weston website [www.weston.be], WESTON must be regarded as the controller. After all, WESTON, either acting alone or in cooperation with others, determines the purpose and means of processing your personal data.

2.2.    Processor(s)

Weston acts as the processor of personal data for the purpose of its services. You can always reach us using these contact details: 

 

•    Weston NV 

•    Gaston Geenslaan 80, 3200 Aarschot

•    Enterprise number: 0876344520

•    Email: info@weston.be 

•    Website: www.weston.be

We may need to provide personal data to third parties for the purpose of our services to you.

To allow you to make optimal use of the website’s functionalities, your personal data may be supplied to the providers of these functionalities. Providing personal data is strictly limited to what is necessary to offer these functionalities. 

Other processors can always be communicated to you on request.

3.    WHICH PERSONAL DATA ARE PROCESSED?

When we process personal data, the general legal principles governing the processing of personal data will always be observed. 

In particular, in applying the principle of minimum data processing, Weston will process only those data that are strictly necessary for the purposes as set out in this Privacy Statement.

A list of categories of personal data that could be processed through your use can be found here:

•    Personal identification data

•    Electronic identification data

•    Financial identification data

4.    FOR WHAT PURPOSES ARE YOUR PERSONAL DATA PROCESSED?

Weston processes your personal data to correctly deliver the services you have requested or received, and to respond appropriately to your requests, where necessary. 

Weston also processes your personal data to provide you, as a Visitor to the website, with a safe, optimal and personal user experience and to offer the website functionalities correctly and intuitively.

Processing the personal data of Customers/Visitors is primarily aimed at these specific purposes:

•    To be able to pursue a proper customer management policy;

•    To adapt the website to your specific use;

•    To prevent fraud and abuse;

•    To enable us to optimise and adapt our services to our other customers;

•    To send out newsletters;

•    To enable us to individualise our services according to the specific behaviour you display when you purchase our goods and/or services.

The Visitor often provides us with their own personal data and can thus exercise certain control over their accuracy and minimisation. If certain data are incorrect or incomplete, we may decide to suspend certain functionalities pending their correction or completion. 

5.    TRANSFER OUTSIDE THE EUROPEAN ECONOMIC AREA?

Your personal data is stored exclusively within the European Economic Area.

6.    YOUR RIGHTS AS A DATA SUBJECT

6.1.    Ensuring compliance with the principles inherent to processing personal data

We process your personal data only:

•    In accordance with the purposes as determined here or in a manner compatible with this original purpose;

•    In a proper, lawful and transparent manner, with the processing based on these grounds, depending on the case: consent, legitimate interest, performing an agreement or a legal obligation;

•    In a manner proportionate to the intended purpose;

•    In a proper manner;

•    In principle, for a period of five (5) years after the last activity on the website or mobile application or for five (5) years after performing the agreement;

•    In the cases provided for by law, for a period equal to the statutory retention period; 

•    In a manner providing sufficient safeguards against unauthorised access, unlawful processing and/or accidental loss or damage.

6.2.        Right of access

Any Visitor who provides sufficient proof of their identity has a right to obtain confirmation about whether their personal data are being processed and, if so, to obtain access to the personal data. 

You also have the right to be informed about the processing purposes, the categories of personal data being processed, the recipients of the personal data, the period during which your personal data will be stored and the criteria for determining that period, and the rights you can exercise under the GDPR. 

If you wish to exercise your right of access, rectification or erasure, you will need to submit a request to the controller. The controller has one (1) month to respond to your request.

Incomplete or inaccurate personal data can be rectified or erased at any time. You can exercise your right to rectification by submitting an additional statement to the controller. The controller will give effect to this additional statement within one (1) month of receiving it. 

You also have the right to have your personal data erased without unreasonable delay. You may invoke this right only in these cases, which will be assessed by the controller:

•    If your personal data are no longer needed for the purposes for which they were collected or processed;

•    If you withdraw your consent and no other legal basis for the processing exists;

•    If you object to the processing and there are no overriding mandatory legitimate grounds for the processing;

•    If the personal data have been processed unlawfully;

•    If your data must be erased in accordance with a legal obligation.

6.3.        Right to restriction of processing / Right to object

You have the right to obtain restriction of processing if one of these elements applies:

•    You dispute the accuracy of the personal data;

•    The processing appears to be unlawful, and you oppose erasing the personal data;

•    The controller no longer needs your personal data for the purposes of the processing, but still needs them to establish, exercise, or defend legal claims;

•    The controller must assess the existence of the grounds for erasing the personal data during this period.

You also have the right to object to the processing of your personal data at any time on grounds relating to your particular situation. The controller will then cease processing your personal data, unless it can demonstrate compelling legitimate grounds for processing your personal data that override your right to object. 

You also have the right not to be subject to individualised and fully automated decision-making if it produces legal effects or if such decision could significantly affect you. However, you may always intervene in such decision-making yourself or request human intervention.

Lastly, you always have the right to object to the processing of personal data for direct marketing purposes.

If you wish to exercise your right to object or to restrict processing, you will need to submit a request to the controller. The controller has one (1) month to respond to your request.

6.4.        Right to data portability

You have the right to obtain the personal data you have provided in a structured, commonly used and machine-readable format. You also have the right to transmit these personal data to another controller if processing your personal data is based solely on your consent.

If you wish to exercise your right to data portability, you will need to submit a request to the controller. The controller has one (1) month to respond to your request.

6.5.        Right to be forgotten

Whenever you have justifiably requested the rectification, erasure or restricted processing of data, the controller will notify each recipient of these personal data, unless this proves impossible or would involve a disproportionate effort. You can also always receive information on these recipients.

6.6.        Right to withdraw your consent / Right to lodge a complaint

You always have the right to withdraw your consent. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal. You also have the right to complain about processing of your personal data to the competent supervisory authorities.

If you wish to withdraw your consent or exercise your right to complain, you will need to submit a request to the controller. The controller has one (1) month to respond to your request.

6.7.    Right to information and transparency

When you exercise your rights, the controller must always act in accordance with the GDPR and thus provide all information required by the GDPR in a concise, transparent, understandable and easily accessible format, which you will receive in plain language.

The periods for responding to your requests may be extended in exceptional circumstances, including because of the complexity and number of your requests. The controller must notify you of this extension and the reasons for it within one (1) month of receiving your request.

7.    SECURE PROCESSING

We recognise that personal data security is an essential part of data protection. We therefore implement appropriate technical and organisational measures to protect your personal data against unauthorised processing or unauthorised access to prevent abuse.

8.    COOKIES

When you use the website, ‘cookies’ may be placed on your device to remember certain choices when you return to the website or to offer you certain functionalities. Disabling cookies may prevent your user experience from being optimal or stop certain functionalities of our website from working.

A cookie is a small text and number file that we store in your browser or on your computer’s hard drive. This enables us to remember your preferences when you use the website.

Different types of cookies exist. Our website uses functional and analytical cookies. Functional cookies allow you to navigate and use our website in a personalised way, while analytical cookies track your visits to our website.

Third parties also use cookies. If you visit other websites while using our website, other cookies might be saved. Consult the cookie policy of these third-party websites for this purpose.

8.1.  Cookies on our Website    

We specifically use these cookies:

8.1.1.    .ASPXFORMAUTH (session cookie) 

Type: First party

Kind: Essential cookie

Lifetime: Session

Purpose: This cookie allows communication between the web server and browser and temporarily stores information from your session. For example, it ensures that you do not have to log in again on every page.

8.1.2.    language (Essential cookie) 

Type: First party

Kind: Essential cookie

Lifetime: One year after last visit

Purpose: To keep track of the user’s language choice

8.1.3.    cd-enabled (Essential cookie) 

Type: First party

Kind: Essential cookie

Lifetime: One year after last visit

Purpose: To keep track of the user’s cookie choice

8.1.4.    _ga (google analytics)

Type: Third party

Kind: Analytical cookie

Lifetime: Two years after session

Purpose: To measure anonymously how users use the website

8.1.5.    _gat (google analytics)

Type: Third party

Kind: Analytical cookie

Lifetime: One minute after last page display

Purpose: To limit the number of requests per minute.

8.1.6.    _gid (google analytics)

Type: Third party

Kind: Analytical cookie

Lifetime: 24 hours after the last session

Purpose: To distinguish website users anonymously

8.2.    Managing cookies    

You can always disable or delete all installed cookies from your computer or mobile device through your browser settings (usually under ‘Help’ or ‘Internet options’). Each browser type has its own settings for managing cookies. You can find all the necessary information on how to manage cookies online.