08

Privacy policy

This policy transparently explains what personal data IBCSC processes, why it does so, how long data is kept and how you can exercise your rights.

Last updated · 31 August 2026

01

Scope

This policy applies to website visitors, form users, account holders, applicants, employers, advertisers, institutional contacts and persons referred to in a report or application. It covers processing carried out through ibcsc.be and its administration.

02

Controller and contact

The controller is the Institut Belge de Cybersécurité Citoyenne ASBL, with registered office at Rue André Lafaille 6, box 012, 6031 Monceau-sur-Sambre, Belgium, enterprise number 1039.889.191. IBCSC has not appointed a data protection officer at this time. Privacy requests may be sent to info@ibcsc.be.

03

Categories of data

The data processed depends on the service used. IBCSC limits collection to information relevant to the stated purpose and asks users not to submit excessive information.

  • Identity and contact data: name, email and telephone
  • Account data: identifier, hashed password, status, preferences and security data
  • Professional data: profile, skills, employer, CV, application and messages
  • Listing data: content, location, employment terms, price and images
  • Contact or report data: subject, description, URL and submitted evidence
  • Technical data: IP address and the approximate location derived from it, date, time, requested page, general browser and device characteristics, and security logs
  • Administrative data: moderation actions and back-office operations
04

Sources of data

Data mainly comes from the data subject when they submit a form, create an account, publish a listing or apply. Some information may be provided by another user in an application or report, or generated by the system for security and administration. IBCSC may consult public sources where a limited and legitimate verification is necessary.

05

Purposes and legal bases

Each processing activity relies on a legal basis appropriate to its purpose. IBCSC does not use personal data for behavioural advertising and does not sell it.

  • Accounts, publication, applications and requested services: performance of the service or pre-contractual steps
  • Enquiries, cooperation and referral: legitimate interest in handling the request or steps requested by the user
  • Security, abuse prevention, logs and legal defence: legitimate interests of the Institute and users
  • Moderation and reports: legitimate interest and, where applicable, legal obligation
  • Retention or disclosure required by an authority: legal obligation
  • Future optional service based on consent: separate, freely given and withdrawable consent
06

Public data

Published listings, professional profiles and contact details that a user chooses to display become visible to website visitors. Users should not publish a home address, identity document, national number, bank details, password or unnecessary sensitive data. IBCSC may hide or remove manifestly excessive data.

07

Recipients

Access to non-public data is limited to authorised persons who need it to administer the service. Depending on the service, information is disclosed to a listing author, applicant or chosen contact. Technical providers may process data for hosting, email, maintenance or security under instructions and confidentiality duties.

  • Authorised IBCSC members or contributors
  • Users receiving an application or message
  • Strictly necessary technical providers
  • Authorities or advisers where required by law or justified to defend a right
08

International transfers

The main operational infrastructure is administered in the European Union. IBCSC does not organise systematic transfers outside the European Economic Area. If a future service involves such a transfer, the Institute will verify an adequacy decision or put required safeguards in place and update this policy.

09

Retention periods

Data is kept for the time required for its purpose and is then deleted or anonymised, unless a legal duty, report, dispute or evidential need justifies limited additional retention.

  • Contact messages and reports: no more than twelve months
  • Unverified account: deletion after seven days
  • Verification link: twenty-four hours; reset link: one hour
  • Session cookie: until the browser closes or the user signs out
  • Published listing: ninety days unless closed early or renewed
  • Account, profile, applications and associated content: while the service is used, then deleted with the account subject to legal justification
  • Security, moderation and evidential logs: a period proportionate to the risk, relevant duty and applicable limitation periods
10

Security and confidentiality

IBCSC applies proportionate technical and organisational measures: encrypted communications, restricted access, private storage separated from the public website, password hashing, session protection, short-lived tokens, attempt limits, backups and logging of administrative actions. No system is absolutely secure; measures are reviewed against risk and service developments.

11

Data-subject rights

Subject to the GDPR, you may request access and a copy, rectification, erasure, restriction, portability where applicable, or object to processing based on legitimate interests. Where processing relies on consent, it may be withdrawn at any time without affecting earlier lawful processing.

12

How to exercise your rights

Send a request to info@ibcsc.be or to the registered office, stating the right exercised and information identifying the relevant service. IBCSC may request proportionate proof of identity where reasonable doubt exists. A response is provided without undue delay and generally within one month; this may be extended in the cases allowed by the GDPR.

13

Complaint to the supervisory authority

You may request mediation or lodge a complaint with the Belgian Data Protection Authority: Rue de la Presse 35, 1000 Brussels, contact@apd-gba.be, +32 (0)2 274 48 00. Without limiting your rights, IBCSC invites you to contact it first so that the issue can be addressed.

14

Minors and sensitive data

The website is not designed to collect sensitive data or children’s data without necessity. A report may nevertheless contain special information. Submit only what is strictly necessary, redact irrelevant documents and identifiers, and avoid sharing third-party data without a legitimate basis.

15

Automated decisions and profiling

IBCSC does not make decisions producing legal effects solely by automated processing and does not carry out advertising profiling. Moderation decisions are reviewed by an authorised person against the content, these rules and available information.

16

Operational monitoring of visits

For the security, availability and operational monitoring of the site, IBCSC records visit events on the public pages. This record covers the page viewed, the date and time, the IP address and the approximate location derived from it, and general characteristics of the browser and device, such as device type, language, time zone, screen resolution and general technical capabilities. The approximate location is obtained by querying, from the visitor’s browser, an independent IP-geolocation service that receives the IP address for that sole purpose. The events are transmitted to an internal, secure monitoring channel of the Institute. This processing relies on the Institute’s legitimate interest in protecting, diagnosing and monitoring its service; it is not used for advertising or commercial profiling, and the data is not sold. A technical marker kept in the browser for the session limits repeated recording and is not a cookie. You may object to this processing based on legitimate interest by writing to info@ibcsc.be.

17

Cookies and policy changes

Cookies and local storage are described in the Cookie policy. IBCSC may update this policy when its activities, processing or applicable law change. Material changes will be communicated appropriately and the update date will be revised.

18

Employment service — data, purposes and recipients

To create and manage a candidate or employer workspace, IBCSC processes identity and contact details, the professional profile, CVs and attachments, preferences, applications and employer-verification information. The account, profile and each application are processed to provide the requested service or take requested pre-contractual steps. Optional visibility, job alerts and any disability information rely on the person’s choices and, where required, explicit consent.

  • Candidates choose their profile visibility and may make the profile non-searchable
  • The selected employer receives a file only after the candidate acts and confirms: the selected CV, motivation, answers and a minimal professional snapshot
  • Employer-verification documents are not public and are accessible only to authorised IBCSC personnel who need them
  • IBCSC does not sell personal data or use it for behavioural advertising
19

Employment service — retention and deletion

The candidate profile and private documents are kept while the account remains active and are then deleted with the account, unless a legal duty, dispute or evidential need justifies limited retention. Each submission creates a fixed copy of the application file and the platform immediately assigns it an expiry date.

  • IBCSC’s copy of the application file and associated platform record: no more than 730 days from submission, then deleted by the scheduled purge procedure
  • The recipient employer processes its own copy under its responsibility and must inform the candidate of its retention period
  • Withdrawal changes the application status; a request for earlier erasure may be sent to info@ibcsc.be and will be handled under the GDPR
  • Optional visibility and job-alert consents may be withdrawn; disability information relies on explicit consent and may be deleted
  • Employer-verification documents are kept only as long as needed for verification and operation of the service, then deleted or retained on a limited basis where a legal justification remains
20

Geographic access control

To limit service availability to the European Union, the United States and Canada, the server locally compares the directly received IP address with a GeoIP database installed on the infrastructure. No IP address is sent to an external provider for this check. The processing relies on IBCSC’s legitimate interest in defining and securing the service availability area.

  • Only the address received directly by the server is used; forwarding headers sent by the visitor are ignored
  • The allowed or denied result is not added to a visitor profile and is not used for advertising or profiling
  • GeoIP location remains approximate, especially when a VPN or relay is used; an error may be reported to info@ibcsc.be