Privacy Policy — Data protection (GDPR) — COFIMAT website
1. Purpose
This Privacy Policy informs professional users of the website www.cofimat.com about the collection, use and protection of their personal data, in accordance with Regulation (EU) 2016/679 (GDPR), the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data and applicable legislation. COFIMAT processes data lawfully, fairly and transparently, strictly within the scope of its professional (B2B) activities.
2. Data controller
COFIMAT SRL — Chaussée de Waterloo 468 B9 — 1050 Brussels — Belgium — Company number / VAT: BE 0479 216 028 — contact@cofimat.com — +32 2 345 65 00.
3. Data collected
Data provided voluntarily when using the contact form, sending an email or making a telephone call: full name, company, position where applicable, email address, telephone number, content of the message.
Browsing data collected automatically: IP address, browser type, operating system, pages visited, date and time of visit, referring website. These data are collected via server logs and via the audience measurement tool described in the Cookie Policy, which sets no cookies and does not identify the user.
The Website does not collect any sensitive data and is not aimed at minors.
4. Purposes of processing
- Responding to contact and information requests
- Managing the professional relationship with prospects, clients, suppliers and partners
- Following up commercial and contractual exchanges
- Ensuring the security of the Website and preventing abusive submissions (anti-spam)
- Improving the content and operation of the Website (anonymous statistics)
- Complying with legal and regulatory obligations
5. Legal basis
Processing is based on the performance of pre-contractual steps taken at the user's request (Article 6(1)(b) GDPR) for contact requests, on COFIMAT's legitimate interest (Article 6(1)(f) GDPR) for the management of the professional relationship, the security of the Website and anonymous statistics, on consent (Article 6(1)(a) GDPR) for any non-essential cookies, and on compliance with legal obligations (Article 6(1)(c) GDPR).
6. Recipients of the data
The data are intended solely for COFIMAT's authorised personnel and for strictly necessary technical service providers (Website hosting, maintenance, email services, anti-spam service, audience measurement), acting as processors and bound by contractual confidentiality and security obligations. Data may be shared with COFIMAT's advisers (accountants, lawyers) where necessary. The data are not sold, rented or transferred to third parties for commercial purposes.
7. Transfers outside the European Union
The data are hosted and processed within the European Union. Should a service provider located outside the European Union be used, COFIMAT would ensure that appropriate safeguards compliant with the GDPR are in place (adequacy decision, European Commission standard contractual clauses).
8. Retention periods
- Contact requests not followed by a professional relationship: 3 years from the last exchange
- Client, supplier and partner data (contractual and accounting data): duration of the relationship, then the applicable statutory period (10 years for accounting and commercial matters)
- Server and form logs: 12 months maximum
- Audience measurement statistics: aggregated and anonymous data, without time limit
9. Security
COFIMAT implements appropriate technical and organisational measures to protect data against unauthorised access, loss, alteration or disclosure: secure hosting within the European Union, encrypted communications (HTTPS), access control, regular backups and awareness of the persons with access to the data.
10. Rights of data subjects
In accordance with the GDPR, users have the right of access, rectification, erasure, restriction of processing, objection and data portability, as well as the right to withdraw consent at any time for processing based on consent. These rights may be exercised by email to contact@cofimat.com or by post to the address of the data controller, with proof of identity. COFIMAT responds within one month, which may be extended by two months for complex requests.
11. Complaints
In the event of a disagreement, users may lodge a complaint with the Belgian Data Protection Authority (APD/GBA), Rue de la Presse 35, 1000 Brussels — www.dataprotectionauthority.be — or with the supervisory authority of their Member State of residence.
12. Changes to this policy
COFIMAT may amend this Privacy Policy at any time, in particular to reflect changes in legislation. The applicable version is the one published on the Website. Last updated: 14 September 2026.
Last updated: 14 September 2026
