Millecam

Privacy Policy

Last updated: 8 September 2026

At Millecam, information security and privacy go hand in hand with the services we offer our clients. That is why we consider it important to explain transparently which personal data we process, why we do so, with whom we share data, and what rights you have in relation to that processing.

1. Who is responsible for your personal data?

Millecam is a sole proprietorship of Robin Millecam and acts as data controller for the personal data described in this privacy policy.

Millecam – Robin Millecam
Sinte Annalaan 34
9300 Aalst
Belgium

Company number / VAT: BE 1026.876.048

Email for privacy questions: privacy@millecam.be

This privacy policy applies when you visit our website, contact us, request a quote, are a client or supplier, or otherwise enter into a business relationship with Millecam.

2. What personal data do we process and why?

Which data we process depends on your relationship with Millecam.

ProcessingPossible personal dataPurposeLegal basis
Website and contact requestsName, company name, email address, phone number, subject and content of your messageAnswering questions and following up on requestsLegitimate interest and/or pre-contractual measures
Quotes and prospect contactsName, job title, organisation, business contact details, communications and quote detailsDiscussing potential collaborations and preparing quotesPre-contractual measures and legitimate interest
Client and contract managementName, job title, organisation, contact details, contract and project details, and business communicationsPerformance and management of our servicesPerformance of the contract and legitimate interest
Consultancy engagementsBusiness contact details and other personal data necessary for the engagementDelivery of GRC, cybersecurity and privacy consultancyPerformance of the contract and, depending on the situation, processing on the client's instructions
Invoicing and accountingName, address, contact details, company details, invoice and payment detailsInvoicing, accounting and tax administrationPerformance of the contract and legal obligation
Business communication and meetingsName, email address, job title, organisation, correspondence and meeting detailsCommunication, appointments and collaborationPerformance of the contract, pre-contractual measures and legitimate interest
Website security and technical operationIP address and technical request and log data where applicableKeeping the website available and secure, investigating errors and preventing abuseLegitimate interest
Website analyticsAnonymised/aggregated usage information such as page views, referrer, country/region, browser, operating system and device typeGaining insight into the use and performance of our websiteLegitimate interest

We do not knowingly collect more personal data than is necessary for the relevant purpose.

3. Where does your data come from?

In most cases, we receive personal data directly from you, for example when you:

  • fill in our contact form;
  • send us an email;
  • contact us via LinkedIn;
  • take part in a call or meeting;
  • request a quote or enter into an agreement.

In a business context, we may also receive contact details from your employer, client, colleague or another business contact person.

In addition, we may consult limited business data that is publicly available, for example via company websites, professional platforms such as LinkedIn, or public company registers.

4. Consultancy engagements and clients' personal data

In the course of our consultancy engagements in areas including GDPR, NIS2, ISO 27001 and CyberFundamentals, we may be given access to information that contains personal data.

This may, for example, involve data in policy documents, registers, audit evidence, risk analyses, incident information, or systems to which a client grants us access.

Our role under the GDPR depends on the specific processing in question.

Where Millecam itself determines the purpose and means of a processing activity, we act as data controller.

Where we process personal data solely on behalf of, and in accordance with the instructions of, a client, we may act as processor. In that case, the processing is governed by the applicable agreement and, where required, a data processing agreement. The client remains responsible for the information it must provide to data subjects in its capacity as data controller.

This public privacy policy mainly describes the processing activities for which Millecam itself is the data controller.

5. Who do we share personal data with?

We never sell or rent personal data.

To carry out our activities, however, we do use specialised service providers. Depending on the processing activity, personal data may be processed by, among others:

Microsoft 365

We use Microsoft Outlook for business email, Microsoft Teams for online communication and meetings, and OneDrive for storing and managing business documents.

Dexxter

We use Dexxter for our financial administration, including quotes, invoicing and bookkeeping.

De Ridder – Arijs Accountancy

Our external accountant may be given access to personal data necessary for accounting, tax and administrative services.

Vercel

Our website is hosted via Vercel. In providing and securing the website, technical data may be processed.

Resend

When you use the contact form on our website, Resend is used to technically send the message to Millecam.

OpenAI and Anthropic

In its professional operations, Millecam makes use of AI-assisted services from OpenAI and Anthropic. Where these services are used for information that contains personal data, this takes place within appropriate contractual and technical safeguards and with due regard for data minimisation and confidentiality.

In addition, we may disclose data to government authorities, supervisory authorities or other parties where this is legally required.

6. AI within our services

Millecam uses AI as a supporting tool for certain professional activities.

In doing so, we apply the principle of data minimisation: personal data and confidential client information are only processed by an AI service when this is appropriate and necessary for the intended purpose, and where appropriate technical and contractual safeguards are in place.

AI is used as a support tool and does not simply replace the professional judgement expected of Millecam.

7. Website analytics

We use Vercel Web Analytics to gain insight into the use of our website.

Vercel Web Analytics operates without cookies. The analytics service is designed to provide aggregated usage statistics without tracking visitors across different websites or days.

This allows us to gain insight into, for example:

  • the number of page views;
  • pages visited;
  • referring websites;
  • country or region;
  • browser and operating system;
  • device type.

We use this information solely to understand and improve the use and performance of our website.

More information about the use of cookies and similar technologies can be found in our separate cookie policy.

8. International transfers

Some of the service providers we work with operate internationally. As a result, personal data may in certain cases be processed outside the European Economic Area (EEA).

When personal data is transferred to a country outside the EEA, we ensure that a valid legal basis for the transfer exists in accordance with the GDPR, for example:

  • an adequacy decision of the European Commission;
  • Standard Contractual Clauses (SCCs) of the European Commission; or
  • another legally recognised safeguard.

Where necessary, we also assess which additional measures are appropriate for the relevant processing.

9. How long do we keep personal data?

We do not retain personal data for longer than necessary for the purpose for which it was collected, unless a longer retention period is legally required or justified.

As a general rule, we apply the following:

DataRetention period
Contact requests that do not lead to a collaborationA maximum of 2 years after the last relevant contact
Quotes that do not lead to an engagementA maximum of 2 years after the last relevant contact, unless a longer period is justified
Client, contract and project administrationFor the duration of the collaboration and thereafter for as long as necessary for contractual or legal obligations and the defence of legal claims
Invoices and accounting documentsFor the applicable statutory retention period
Business email and correspondenceFor as long as necessary for the business relationship, the file, or applicable legal obligations
Technical website dataNo longer than necessary for security, troubleshooting and technical operation

When data is no longer needed, it is deleted or anonymised where reasonably possible.

10. How do we secure personal data?

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, disclosure or misuse.

The measures are tailored to the nature of the data, the processing activity and the associated risks.

Where relevant, we apply principles such as access restriction, strong authentication, secure communication, careful supplier management, data minimisation and secure storage.

However, no information system can guarantee absolute security.

11. Automated decision-making and profiling

Millecam does not make decisions with legal or similarly significant effects on individuals that are based solely on automated processing as referred to in Article 22 of the GDPR.

We also do not use personal data for advertising profiling or behaviour-based marketing.

12. Your rights

Depending on the processing activity and the applicable legal basis, you have, among others, the following rights under the GDPR:

  • to obtain access to your personal data;
  • to have inaccurate or incomplete data corrected;
  • to have your personal data erased where the legal conditions are met (right to erasure);
  • to have the processing restricted;
  • to object to certain processing activities, including processing based on legitimate interest;
  • to withdraw your consent at any time where a processing activity is based on consent;
  • to receive personal data in a structured, commonly used and machine-readable format, or to have it transferred, in certain cases (right to data portability);
  • to lodge a complaint with a supervisory authority.

These rights are not absolute. Certain legal obligations or exceptions may mean that we cannot fulfil a request, or can only fulfil it in part.

13. How to exercise your rights

Send your request to:

privacy@millecam.be

Please provide sufficient information so that we can determine which data your request relates to.

Where we have reasonable doubts about your identity, we may request additional information to prevent personal data from being disclosed to an unauthorised person.

We handle requests within the time limits prescribed by the GDPR.

14. Complaints

Do you have questions or concerns about how we process your personal data? Please contact us first, preferably via privacy@millecam.be, so that we can look into your query.

You also have the right to lodge a complaint with:

Belgian Data Protection Authority
Drukpersstraat 35
1000 Brussels
Belgium

www.gegevensbeschermingsautoriteit.be

15. Changes to this policy

Our services, systems and legal obligations may change. We may therefore update this privacy policy from time to time.

The date at the top of this page indicates when the policy was last updated. In the event of significant changes, we will provide additional communication where appropriate.