MANAGEMENT AND PROTECTION OF PERSONAL DATA
Privacy Policy and Personal Data Protection
We place great importance on respecting privacy and protecting your personal data (PD). The protection of your personal data is an essential component of our relationship, whether you are a client or a user of our services and websites. This relationship is founded on the principle of transparency aimed at respecting your privacy in accordance with the regulations in force in Belgium and Europe, in particular pursuant to the Data Protection Act (Loi Informatique et Libertés) and the General Data Protection Regulation (GDPR). This section informs you about the categories of personal data we process, how we use it, the categories of recipients to whom we disclose it, and the rights you hold.
What Does the PD Held by SRL Aster Communication Graphique Consist Of?
It consists solely of the surnames, first names, job titles, email addresses, registered office addresses, and professional phone numbers (and mobile numbers if provided or included in email signatures) of individuals who have had a commercial relationship with SRL ACG. For telephone contacts, this data sometimes includes a photograph of the face, retrieved from the Internet, in order to personalize and humanize communication (putting a face to a voice).
How Is This Data Collected?
The data collected by SRL Aster Communication graphique comes primarily from actual clients (historical clients and those contacting me to order drawings) and potential clients or prospects (via a request for a quote or information, or following an exchange of business cards during events). These may also include potential clients mentioned during professional relationships whose contact details are available on the Internet. If data were to be collected outside of a personal contact, the prospects concerned would be notified immediately (in accordance with the measures provided for in Art. 14).
Why Is This Data Important to SRL ACG?
This is commercial personal data intended to facilitate the follow-up of actual or potential collaborations with existing clients or prospects who have expressed an interest in the work of SRL ACG. In their own interest, it allows them to be informed of any (temporary) cessation of business or any major updates likely to interest them. It guarantees the author of the drawings—which constitute the corporate purpose of SRL ACG—the sustainability of his activity, thanks to a sufficiently broad potential client base, in order to maintain the quality of ongoing and future collaborations.
How Is the PD Used?
This PD is mainly used to ensure the follow-up of collaborations and their accounting processing. It allows actual—and, to a lesser extent (for example, in the case of business relaunch), potential—clients (prospects) to be notified of a major change of direction or the release of new services. There is currently no intention to use this data for a newsletter or direct mailing, and if this were to occur, it would be in full compliance with the GDPR. Data collected within the framework of the publishing activity "Mémoires ardennaises" may be used to offer purchasers of previous editions new works on the same theme or in the same collection.
Since When Has PD Been Systematically Collected in Compliance with the GDPR?
The implementation of the GDPR policy for SRL ACG was partially finalized on May 13, 2018. Systematic notification (or permission requests) for clients has been in place since June 6, 2019. The existing database, established since the beginning of the author's professional activity on August 15, 1999, is currently being updated and brought into compliance, primarily for recent relations (since the conversion into a company in 2008).
Who Is the Data Controller at SRL ACG?
The Managing Director, Jean-Philippe Legrand (Sous Wérimont 22 - 4970 Stavelot - Belgium), is the sole person authorized to manage the PD.
Who Handles This PD?
Only the aforementioned Managing Director collects, uses, and deletes this data. It is neither transmitted nor exchanged.
Right of Access to PD Held by SRL ACG
Any client, prospect, or recipient has the right to request access to their own data held by SRL ACG (by email, mail, or telephone), to request its rectification, or to obtain its permanent erasure, unless such data is required for legal purposes or accounting obligations. Other measures in favor of complying with Arts. 15, 16, and 17 apply. Pursuant to Art. 19, permanent erasure will be notified to the recipient who explicitly requested it.
How Long Is the PD Retained?
Given that there is no date associated with data collected before 06/06/2019, nor any advanced automated processing, no period has been set for its automatic deletion after a specified timeframe. However, SRL ACG considers that after 15 years from the last commercial contact, this data may be permanently erased. This measure applies to data collected from 06/06/2019 onwards.
What Processing Is Applied to Your PD?
No specific processing, no assignment, no transfer. Only an intervention by the public administration can justify opening the client listing to a third party.
How Is Joint Responsibility Exercised?
The provision of Art. 26 on joint responsibility applies concretely when the author collaborates with a partner who possesses PD:
- In the case of an agency: As part of a live drawing session or an order for drawings, the data controller of the agency is required to contact us to clarify the procedure, given that it is the agency sharing its data. Failing this, the contact details of the end clients involved in the operation will be treated as if they were new potential clients: direct contact will inform them that SRL ACG holds these details. However, out of commercial ethics, SRL ACG will not attempt to develop commercial relations outside the involvement of the agency that introduced them, even if the request comes from the end client. If preparation includes lists of participants associated with their PD, these lists will not be retained, processed, or used beyond the period during which they were necessary (e.g., the day of the event).
- In the case of a colleague: (Illustrator, entertainer, or any artist) who requests SRL ACG or just Aster as an author for a joint operation, the provisions set out in the previous point apply.
- In the case of a collaborator or subcontractor of SRL ACG: As part of a joint operation, the client will be informed of the data transmission (with the option to object), while said collaborator will be required to destroy this data after the joint operation.
- If the exchange of data presents commercial opportunities: (List of potential clients), special permission will be requested from their initial holder after verifying with the data protection officer that the listed clients have given their consent for this exchange. If not, the data will be destroyed. If, on the other hand, it is in the interest of the listed individuals (for example, access to or delivery of drawings created live during an event, which is generally desired by participants), after agreement from the initial holder of the listing, the file may be used with appropriate GDPR compliance notices.
What Guarantees Must Subcontractors Offer?
Subcontractors involved in any operation requested by SRL ACG have a duty to comply with the provisions of the GDPR. PD must be destroyed after the duration of the contract, in particular highly personal data collected during the creation of caricatures. Contracts entered into with a subcontractor in this scenario now contain the following statement:
"In compliance with Regulation (EU) 2016/679 on Personal Data Protection (GDPR), which requires compliance by all EU companies since 25/05/2018, and in particular subcontractors (Art. 28), any personal data (as defined in Art. 4) transmitted by SRL ACG or by its end client may not be stored, processed (within the meaning of Art. 4), or used beyond the scope strictly intended for the mission defined in our exchanges and stipulated on documents such as quotes and invoices. In other words, all data must be erased, including the identification data of the end client, which may under no circumstances be used for direct marketing operations (commercial ethics recommending the intermediation of SRL ACG for any new collaboration opportunity). The subcontractor must take all measures to guarantee the protection and confidentiality of the exchanged data."
A major subcontractor of SRL ACG is the internet solutions provider OVH. This company maintains a serious approach to personal data protection (see www.ovh.com/fr/protection-donnees-personnelles).
Which Is the Supervisory Authority for Data Protection in Belgium?
It is the Data Protection Authority / APD (Autorité de protection des données - http://www.autoriteprotectiondonnees.be/).
What Technical Measures Are Taken to Protect PD?
The hosting of our portable data is provided by the company OVH, which offers excellent technological guarantees regarding the protection of digitized content. Our computers are protected by the services of Syforce (Drève Richelle 167, 1410 Waterloo), and only one person has access to them. Our premises are protected by a Verisure alarm system. The confidential content of client companies is systematically erased following the completion of a mission.
What Happens in the Event of a Breach or Leak of the Client File?
To begin with, it should be considered that SRL ACG's client file does not contain sensitive data or data that could not be found by scanning the Internet. It consists exclusively of contact information, the leak of which should not pose a threat to the rights and freedoms of the natural persons concerned. In the event of a breach of this file, a notification would be sent to the APD as soon as possible.
How Long Is Data Retained?
In accordance with the principle of the "right to be forgotten", data is retained for 15 years from the date of the request (in the case of a quote request), initial contact (in the case of a prospect), or last contact (existing client). The reason for this duration: in my line of work, requests can be rare and infrequent.
Article 4 of Regulation (EU) 2016/679: Definitions
- "Personal data": Any information relating to an identified or identifiable natural person (hereinafter referred to as the "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- "Processing": Any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Text: © Jean-Philippe Legrand) – Last revised: August 2026