O3 GROUP360° BRAND SERVICES
O3 Group
In effect since 12 July 2026

GDPR Compliance

The GDPR (General Data Protection Regulation, in force since 25 May 2018) governs how European companies collect and process personal data. At O3 Group, we take it seriously — not because we have to, but because it's part of the respect we owe you.

This page complements our Privacy Policy and our Cookie Policy by summarising our GDPR commitments.

1. Data controller

O3 Group BV
Industrieweg 5, 3001 Heverlee, Belgium
Company number / VAT: BE 0822.112.612
Privacy contact: privacy@o3.be

2. Legal bases for processing

  • Performance of a contract — to produce, deliver and invoice our services.
  • Pre-contractual measures — to reply to your quote or contact requests.
  • Legal obligation — to comply with accounting, VAT and invoice retention rules (Belgian Code of Economic Law).
  • Legitimate interest — to improve our site via anonymous statistics (Umami), manage our existing commercial relationship and secure our systems.

3. Retention periods

  • Quote requests / contact briefs: 3 years after the last exchange.
  • Client contracts & invoices: 7 years (Belgian accounting obligation).
  • Commercial emails: 3 years.
  • Technical logs / Umami analytics: 12 months.
  • Spontaneous job applications: 2 years, then deleted.

4. Subprocessors

We work with carefully selected subprocessors, all bound by a data processing agreement compliant with art. 28 GDPR:

  • Cloudflare / Lovable — website hosting (EU edge + global zones, covered by the European Commission's Standard Contractual Clauses for any international transfers).
  • Supabase — back office database. Region Frankfurt (EU).
  • Umami Cloud — cookieless anonymous analytics, EU-hosted.
  • Microsoft 365 — professional @o3.be email, EU tenant.
  • Logistics & production partners — only the data required to execute your order.

No structural transfer of personal data outside the European Union takes place. Occasional technical transits via our hosts are covered by the European Commission's Standard Contractual Clauses (SCC).

5. Security

  • HTTPS/TLS encryption on every page.
  • Database encrypted at rest, role-based access (RLS).
  • Back office authentication with secure sessions.
  • Regular automated backups.
  • Access to personal data restricted to strict operational necessity.

6. Your GDPR rights

You can ask us at any time to:

  • Access — know what data we hold about you.
  • Rectify — correct inaccurate data.
  • Erase (right to be forgotten) — subject to legal retention obligations.
  • Restrict processing.
  • Object to processing based on legitimate interest.
  • Portability — receive your data in an interoperable format.
  • Withdraw consent — when processing is based on consent.

An email to privacy@o3.be is enough. We reply within a maximum of one month (extendable by 2 months for complex requests).

7. Complaint

If you feel your rights are not being respected, you may lodge a complaint with the Belgian Data Protection Authority (DPA), Rue de la Presse 35, 1000 Brussels. But we'd rather sort it out over a coffee first ☕.

8. Data breach

In case of a data breach likely to pose a risk to your rights and freedoms, we notify the DPA within 72 hours and, if the risk is high, we inform you directly as soon as possible.

Questions?

privacy@o3.be — O3 Group BV, Industrieweg 5, 3001 Heverlee, Belgium.