Last updated: 11 August 2026
PIERSTONE
Privacy Policy – Website
1. Purpose and scope
1.1. This privacy policy (hereinafter the “Policy”) describes how PIERSTONE BV/SRL (hereinafter “Pierstone”, “the Firm”, “we” or “our”) collects, uses, stores, protects and, where applicable, transfers the personal data of its clients, prospective clients, partners, suppliers, job applicants, participants in its training courses and events, as well as visitors to the website accessible at www.pierstone.be (hereinafter the “Website”).
1.2. It applies to all data processing carried out by the Firm in the course of its legal practice, including advice and assistance in the areas of data protection, digital law, law governing associations, company law, commercial law, intellectual property law, regulatory law relating to artificial intelligence, the drafting of contracts and legal opinions, representation before courts and authorities, acting as an outsourced Data Protection Officer (DPO-as-a-service), organising training courses and events, sending newsletters, responding to calls for tenders, browsing the Website, and any other electronic or physical interaction with the Firm.
1.3. Pierstone processes personal data in accordance with Regulation (EU) 2016/679 of 27 April 2016 (hereinafter the “GDPR”), the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data (hereinafter the “Privacy Act”), Directive 2002/58/EC as transposed into Belgian law, in particular by the Act of 13 June 2005 on electronic communications, as well as the rules of professional conduct applicable to the legal profession, including professional secrecy as enshrined in Article 458 of the Criminal Code. Insofar as the Firm advises its clients on artificial intelligence systems or uses such systems in the course of its own activities, it also takes into account, where applicable, the requirements of Regulation (EU) 2024/1689 on artificial intelligence (the “AI Act”).
1.4. By using the Website, requesting a service from the Firm or communicating with us, you are deemed to have read this Policy. However, this does not constitute consent to the processing of your personal data, which is based on the legal grounds set out in Article 4.
2. Identity and contact details of the data controller
2.1. The data controller is PIERSTONE [BV/SRL], with its registered office at Avenue de la Toison d’Or 22 (1st floor), 1050 Brussels, registered with the Crossroads Bank for Enterprises under number BE 0760.585.611, and can be contacted by email at privacy@pierstone.com.
2.2. Pierstone is under no obligation to appoint a Data Protection Officer within the meaning of Article 37 of the GDPR, as its own activities do not fall within the circumstances requiring such an appointment. The firm has, however, appointed an internal contact person for matters relating to data protection, who can be contacted at the address set out in Article 2.1.
3. Categories of personal data processed
3.1. In the course of its activities, the Firm processes various categories of personal data, the nature of which varies depending on the relationship with the data subject and the assignment entrusted to it.
3.2. Identification and contact details include surname, first name, postal address, email address, telephone number, job title, employing company or organisation, company registration number and language of correspondence, as well as any equivalent data enabling the identification of a natural person or their representative.
3.3. Financial and administrative data cover bank details, information required for invoicing and proof of payment, the identity of beneficial owners, as well as data required for the purposes of combating money laundering and the financing of terrorism.
3.4. Data relating to cases handled by the Firm includes all information provided by the client or collected from third parties in the course of a consultation, a compliance audit, negotiations, a data protection officer’s assignment or legal proceedings, including documents, correspondence, evidence and any information relevant to the provision of legal services. By the very nature of the assignments entrusted to the Firm, particularly in the areas of data protection and regulatory compliance, this data may include personal data relating to third parties, such as opposing parties, witnesses, employees or users of the Firm’s clients.
3.5. Special categories of data within the meaning of Article 9 of the GDPR, such as health data, philosophical or religious beliefs, or data relating to sexual orientation, as well as data relating to criminal convictions and offences within the meaning of Article 10 of the GDPR, may be processed where this is necessary for the establishment, exercise or defence of a legal claim, in accordance with Article 9(2)(f) of the GDPR and Article 10 of the Privacy Act.
3.6. Data relating to applicants for a post, an internship or a collaboration within the Firm includes the curriculum vitae, the covering letter, qualifications, references and any information provided as part of the recruitment process.
3.7. Where the Firm acts as an outsourced data protection officer or carries out audit or compliance assignments, it may, incidentally and to the extent strictly necessary for the performance of its duties, become aware of personal data relating to clients, employees or users of its own clients. In such cases, the Firm acts on the client’s instructions and, where applicable, as a data processor within the meaning of Article 28 of the GDPR, without prejudice to its status as a data controller for its own purposes as described in this Policy.
4. Purposes, categories of data and legal bases for processing
4.1. In accordance with Article 5(1)(b) of the GDPR, every processing operation carried out by the Firm pursues a specific, explicit and legitimate purpose and is based on a specific legal basis provided for in Article 6 of the GDPR. In accordance with the principle of granularity, the table below identifies, for each purpose, the categories of data concerned and the specific legal basis associated with it, rather than linking all processing operations to a single legal basis.
4.2. Where a single ancillary processing operation serves several purposes based on different legal grounds (for example, case file data used both for the performance of the assignment and, subsequently, for the defence of a legal claim), each purpose is assessed and documented separately by the Firm, in accordance with its obligations to maintain a record of processing activities within the meaning of Article 30 of the GDPR.
5. Recipients of the data
5.1. Personal data is processed within the Firm by those who need it to carry out their duties, including solicitors, associates, trainees and administrative staff, who are bound by professional secrecy and a general duty of confidentiality.
5.2. Pierstone Brussels is part of an international alliance of lawyers with offices in Brussels, Prague and London. In the context of cross-border assignments, certain data may be shared with the other offices within the Pierstone network, to the extent strictly necessary for the performance of the assignment and in compliance with equivalent confidentiality obligations.
5.3. To the extent necessary for the proper performance of the assignments entrusted to us or to comply with legal obligations, data may be disclosed to opposing parties and their advisers, to courts and administrative authorities (including the Data Protection Authority and, depending on the case, other European supervisory authorities), to notaries, bailiffs, experts, sworn translators and other judicial officers, to financial and insurance organisations, to the President of the Bar and the disciplinary bodies of the relevant Bar, as well as to any person expressly designated by the client.
5.4. Certain data is also disclosed to tax, social security and judicial authorities where required by law, in particular in connection with the reporting obligations set out in the Act of 18 September 2017 on the prevention of money laundering.
5.5. The Firm also uses technical data processors, the categories of which are specified in Article 8.
6. Transfers outside the European Economic Area
6.1. Pierstone gives preference to service providers established within the European Economic Area or applying safeguards equivalent to those provided for by the GDPR.
6.2. However, certain tools used by the Firm involve the transfer of data to countries outside the European Economic Area, in particular to the United Kingdom, in the context of coordination with the London office of the Pierstone network, as well as, where applicable, to the United States of America in the case of certain hosting, email or collaborative tool providers. These transfers are governed, as appropriate, by an adequacy decision of the European Commission (including that relating to the United Kingdom and, for certified entities, the EU-US Data Privacy Framework), or by the implementation of standard contractual clauses adopted by the European Commission, supplemented, where necessary, by additional technical, organisational or contractual measures, in accordance with Articles 44 to 49 of the GDPR and Recommendation 01/2020 of the European Data Protection Board.
6.3. A copy of the appropriate safeguards may be obtained on request sent to the address referred to in Article 2.1.
7. Retention periods
7.1. Personal data shall not be retained for longer than is necessary in view of the purpose for which it is processed, the applicable legal obligations and the ethical rules governing the legal profession.
7.2. Client files and related documents are retained for the duration of the client relationship and then archived for five years from the date the file is closed, without prejudice to any longer retention periods imposed by law, by the rules of the relevant bar association, or justified by the nature of the file (in particular in the case of a long-term appointment as a data protection officer).
7.3. Accounting records, invoices and supporting documents are retained for ten years.
7.4. Data processed for the purposes of combating money laundering and the financing of terrorism is retained for ten years from the end of the business relationship or the one-off transaction, in accordance with Article 60 of the Act of 18 September 2017.
7.5. Data relating to prospective clients and individuals who have expressed an interest in the Firm’s services without entering into a contractual relationship shall be retained for three years from the date of the last active contact.
7.6. Data relating to newsletters is retained until consent is withdrawn or the right to object is exercised, plus a reasonable technical period to allow the request to be effectively processed.
7.7. Job applications not followed by an offer of employment are retained for two years from the date of the last correspondence, unless the candidate requests their deletion earlier.
7.8. At the end of the aforementioned retention periods, the data is either securely deleted or irreversibly anonymised, unless there is a legal obligation to retain it for a longer period.
8. Data processors
8.1. Pierstone engages technical service providers to carry out its activities; these act as data processors within the meaning of Article 28 of the GDPR. Each of them is bound to the Firm by a contract setting out the safeguards required by that provision, in particular regarding confidentiality, security, further sub-processing, assistance in the exercise of data subjects’ rights and notification of data breaches.
8.2. The main categories of data processors used by the Firm as at the date of this Policy are the Website host, the provider of the collaborative suite and business email service, the case management and invoicing software, the accounting tools, the videoconferencing tools and, where applicable, AI-assisted transcription services, as well as providers of data backup and newsletter distribution services.
8.3. An up-to-date list of data processors may be obtained on request by writing to the address set out in clause 2.1.
9. Cookies and similar technologies
9.1. The Website uses cookies and similar technologies; details of these, their purpose, duration and provider are set out in the cookie policy available on the Website.
9.2. Cookies that are strictly necessary for the functioning of the Website are placed without prior consent, in accordance with Article 129 of the Act of 13 June 2005 on electronic communications.
10. Data security and professional secrecy
10.1. Pierstone implements appropriate technical and organisational measures, within the meaning of Article 32 of the GDPR, to ensure a level of security appropriate to the risks that the processing operations pose to the rights and freedoms of data subjects. These measures include, in particular, controlling access to premises and systems, user authentication, the encryption of communications and backups, access logging, regular software updates, and the ongoing awareness-raising and training of persons authorised to access the data.
10.2. The Firm’s attorneys are bound by professional secrecy as enshrined in Article 458 of the Criminal Code, which may, in certain cases, limit the scope of information that may be disclosed to data subjects, whilst respecting the rights of a client, a third party or the proper administration of justice.
10.3. In the event of a personal data breach likely to pose a risk to the rights and freedoms of data subjects, the Firm shall notify the Data Protection Authority within seventy-two hours of becoming aware of the breach and, where the risk is high, shall also inform the data subjects, in accordance with Articles 33 and 34 of the GDPR.
11. Automated decision-making and profiling
11.1. The Firm does not carry out any decision-making based solely on automated processing, including profiling, which produces legal effects concerning data subjects or similarly significantly affects them, within the meaning of Article 22 of the GDPR. The occasional use of artificial intelligence tools (for example, for the transcription or summarisation of meetings) remains subject to human supervision and does not result in any automated decision-making in relation to data subjects.
12. Rights of data subjects
12.1. In accordance with Articles 15 to 22 of the GDPR, Article 7(3) of the GDPR and the corresponding provisions of the Privacy Act, data subjects have the rights described below, subject to the limits and conditions laid down by the regulations.
12.2. Right of access (Article 15 of the GDPR). You have the right to obtain confirmation as to whether personal data concerning you is being processed, as well as information relating to such processing and a copy of the data being processed.
12.3. Right to rectification (Article 16 of the GDPR). You have the right to have any inaccurate personal data concerning you rectified, and to have any incomplete personal data completed.
12.4. Right to erasure (Article 17 of the GDPR). You have the right to obtain, under the conditions set out in the GDPR, the erasure of data concerning you, in particular where such data is no longer necessary in relation to the purposes for which it was collected, where the consent on which the processing was based has been withdrawn, or where the processing is unlawful. This right may not be exercised in respect of processing necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.
12.5. Right to restriction of processing (Article 18 of the GDPR). You may request that the processing of your data be restricted, in particular where you contest its accuracy, where the processing is unlawful, or where you have objected to the processing, for the time necessary to verify the grounds put forward.
12.6. Right to data portability (Article 20 of the GDPR). Where the processing is based on your consent or on the performance of a contract and is carried out by automated means, you have the right to receive your data in a structured, commonly used and machine-readable format, and to request that it be transmitted to another data controller where this is technically feasible.
12.7. Right to object (Article 21 of the GDPR). You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on the Firm’s legitimate interests. You may also, without having to give reasons, object to processing for marketing purposes.
12.8. Right to withdraw consent (Article 7(3) of the GDPR). Where processing is based on your consent, you may withdraw it at any time, without this withdrawal affecting the lawfulness of processing carried out prior to such withdrawal.
12.9. Right not to be subject to automated decision-making (Article 22 of the GDPR). You have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you, subject to the exceptions provided for in the GDPR.
12.10. Post-mortem instructions. In accordance with Belgian law, you may provide general or specific instructions regarding the handling of your personal data following your death.
13. Exercising your rights
13.1. Requests to exercise rights may be sent by email to the address specified in Article 2.1 or by post to the registered office address specified in Article 2.1. To enable the Firm to verify the identity of the applicant and to prevent any misuse, the request must be accompanied by any information reasonably necessary for such verification, without requiring a disproportionate amount of information.
13.2. The Firm shall respond to the request within one month of receipt, a period which may be extended by two months due to the complexity or number of requests, in accordance with Article 12.3 of the GDPR. In the event of a refusal, the reasons for the refusal shall be provided and the available remedies specified.
13.3. The exercise of these rights is free of charge, except in the case of a request that is manifestly unfounded or excessive, in particular because it is repetitive, in which case the Firm may require payment of reasonable costs or refuse to comply with the request.
13.4. The exercise of certain rights may be restricted, in whole or in part, in order to preserve solicitor-client privilege, the rights of a client or a third party, or the Firm’s own interests in the context of legal proceedings, in accordance with Article 23 of the GDPR and Articles 11 et seq. of the Data Protection Act.
14. Right to lodge a complaint
14.1. You have the right, at any time and without prejudice to any other administrative or judicial remedy, to lodge a complaint with the Data Protection Authority, located at Rue de la Presse 35, 1000 Brussels, which can be contacted by telephone on +32 (0)2 274 48 00, by email at contact@apd-gba.be and via the website www.autoriteprotectiondonnees.be.
14.2. The Firm nevertheless invites the data subject to contact it prior to making any complaint, in order to enable the request to be dealt with promptly and amicably.
15. Amendments to the Policy
15.1. This Policy may be amended to reflect changes in the Firm’s activities, the tools used and the applicable legal framework. The date of the last update appears at the top of the document. Substantial amendments will be brought to the attention of data subjects by any appropriate means, including via the Website or newsletters.
16. Contact
16.1. Any queries regarding this Policy or the Firm’s processing of personal data may be addressed to PIERSTONE BV/SRL by email at the address set out in Article 2.1.
16.2. Postal address: PIERSTONE, Avenue de la Toison d’Or 22 (1st floor), 1050 Brussels.
