logo level
SME
Agency
Large enterprise
contactOperationalControl Panel

Privacy policy

Privacy is important to the data subject, but also to Level27 as both controller and processor. These privacy guidelines provide more information on how Level27 uses, stores, and protects personal data.

image

DATA CONTROLLER


Level27 bv

Via Media 4

3500 Hasselt

Belgium

VAT number: BE0890.439.412


If you as a customer have questions regarding these privacy policies, you can email Level27 at: [privacy@level27.be](mailto:privacy@level27.be). Level27 strives to provide a response within 30 days.


COMPLAINT


The client may at any time file a complaint with the Data Protection Authority if the client believes that Level27 has mishandled the personal data to be processed. This can be done via [www.gegevensbeschermingsautoriteit.be](http://www.gegevensbeschermingsautoriteit.be). Level27 requests that the client also send a copy of their opinion to [privacy@level27.be](mailto:privacy@level27.be).


YOUR PERSONAL DATA, OUR RESPONSIBILITY


At Level27 we collect your personal data because you use our services and/or because you provide it to us yourself. This data is managed by our company. The data is only used by Level27 or its partners for the execution of their tasks.


WEBSITE


When contacting Level27 via [https://level27.be/](https://level27.be/) we store:


* your email address if you enter it on this website

* all information you have voluntarily provided (for example contact details and/or information regarding the service).


This information is used:


* for carrying out a service you requested.


CONTROL PANEL


By using our Control Panel we store:


* your email address/username,

* your password (hashed in the database),

* billing information: company name, first and last name of contact person, address, VAT number, email address, phone number,

* all information you have voluntarily provided (for example contact details and/or information regarding the service),

* payment history,

* an overview of purchased products (domains, hosting packages, servers, applications, mailboxes),

* backups of your systems.


This information is used:


* for billing,

* for carrying out a service you requested.

CUSTOMER SATISFACTION SURVEYS

Level27 periodically conducts customer satisfaction surveys, including NPS (Net Promoter Score) measurements. For this purpose, we process:

  • your name and job title,
  • your email address,
  • your answers to the survey.

This information is used to follow up on and improve our services.

The legal basis for this processing is our legitimate interest in monitoring and improving the quality of our services.

LEGAL BASIS


For carrying out the work as well as managing billing, we need your personal data. Additionally, we have a legitimate interest in contacting our clients from a marketing perspective to communicate promotions, updates, or other relevant information.


In case of processing personal data on the client’s infrastructure, Level27 processes this data on behalf of the client and has no control over this personal data. Level27 follows the client’s instructions in this regard and may not process the personal data in any other way unless the client has given prior consent or instruction to Level27. Specific agreements and policies are laid down in a data processing agreement including annexes.


SHARING WITH THIRD PARTIES


Level27 does not provide the data to be processed from the client to third parties and will only provide it if necessary for the execution of our services or to comply with a legal obligation.


DATA RETENTION PERIOD


Level27 will not retain your personal data longer than strictly necessary to achieve the purposes for which your data is collected. As long as you are a client, we obviously keep the data. We also take into account the limitation period for contractual liability. All personal data are kept for up to 10 years after the termination date of services / last invoice. After possible termination and expiration of the last backup cycle plus a safety margin of 40 days, all data is physically removed from all systems.


SECURITY


Level27 takes the protection of personal data seriously and takes appropriate measures to prevent misuse, loss, unauthorized access, unwanted disclosure, and unauthorized alteration. When we receive your data, we always use encryption technologies recognized as standard within the IT sector. We have implemented necessary security measures to prevent loss, unlawful use, or alteration of the information we receive. When we receive or transmit certain critical information, such as financial information, we use a secure server. Only employees who need to perform work for you have access to your data in the context of the work to be performed.


ISO CERTIFICATION


In September 2017 Level27 obtained the ISO27001 and ISO9001 certificates. Without going into the details of the ISO implementation, this provides extra assurance to the client that the supplier as processor handles all aspects of the service securely. ISO9001 also provides additional guarantees that the supplier as processor has quality awareness embedded in the company’s DNA. ISO27001 describes obvious elements such as physical security, workstations, employee access to systems. But it also clearly describes how the supplier deals with encryption, data security, and firewalling.


CONFIDENTIAL INFORMATION


All databases, designs, process descriptions, market research, and all other company-unique data provided by the client that are marked as confidential by the client are accepted by Level27 as confidential information, property of the client.


Both the client and Level27 commit to keeping confidential any information acquired in the context of negotiations and execution of the agreement, both during and after the execution of this agreement.


The client commits to imposing the same confidentiality obligation on its employees and appointees who would gain access to Level27 software and/or other confidential data.


Unless otherwise agreed, Level27 has the right to use the client’s works or services delivered to the client as a reference for professional purposes.


POLICY ON THE RIGHTS OF THE DATA SUBJECT


As a controller, Level27 is also obliged to comply with the rights of the data subject. The data subject has the right to information, correction, addition, restriction of processing, data portability, deletion, and objection.


RIGHT TO INFORMATION


The data subject whose personal data are processed by Level27 via the control panel has the right to inspect that data. Level27 cooperates with the client when the data subject requests information. The data subject has the right to information based on the following questions:


* why the data are processed,

* what kind of data are processed,

* to which organizations personal data may be transferred,

* for how long the data are kept.


RIGHT TO CORRECTION AND ADDITION


The data subject whose personal data are processed by Level27 via the control panel has the right to have that data corrected and supplemented. The data subject has rights in the control panel to correct and/or supplement their own information. Level27 cooperates with the client when assistance is requested to correct and/or supplement data.


RIGHT TO RESTRICTION OF PROCESSING


This is the right to have less data processed. For example, if incorrect data are being processed, the data may not be used as long as they are not correct. If the data subject objects to the processing of their personal data, Level27 must stop this at the client’s request unless Level27 can demonstrate compelling legitimate grounds for the processing that override the interests and rights of the data subjects.


RIGHT TO DATA PORTABILITY


This is the right to transfer digital personal data. The data subject must be able to receive the personal data Level27 has available in the control panel. At the request of the data subject, Level27 must forward the data to another organization offering the same kind of service. Alternatively, the data subject can also ask Level27 to send the data directly to another organization. This does not concern paper data.


Level27 must make all personal data provided by the data subject available. So-called derived data, such as data Level27 generated itself through data analysis, do not have to be provided.


RIGHT TO DELETION


The data subject has the right to be forgotten. Level27 must delete personal data in certain cases if the data subject requests so. The data must be deleted if:


* Level27 no longer needs to process the personal data for the client,

* the data subject withdraws consent for processing,

* the data subject objects,

* Level27 processes the data unlawfully.


The right to deletion also applies to backup files.


RIGHT TO OBJECT


The data subject has the right at any time to object to the processing of personal data concerning them for reasons related to their specific situation. The client must notify Level27 of this objection and ask Level27 to stop processing the personal data unless Level27 demonstrates compelling legitimate grounds for the processing that outweigh the interests, rights, and freedoms of the data subject or relate to the establishment, exercise, or defense of legal claims.