This policy applies to website visitors, form users, account holders, applicants, employers, advertisers, institutional contacts and persons referred to in a report or application. It covers processing carried out through ibcsc.be and its administration.
02
Controller and contact
The controller is the Institut Belge de Cybersécurité Citoyenne ASBL, with registered office at Rue André Lafaille 6, box 012, 6031 Monceau-sur-Sambre, Belgium, enterprise number 1039.889.191. IBCSC has not appointed a data protection officer at this time. Privacy requests may be sent to info@ibcsc.be.
03
Categories of data
The data processed depends on the service used. IBCSC limits collection to information relevant to the stated purpose and asks users not to submit excessive information.
Identity and contact data: name, email and telephone
Account data: identifier, hashed password, status, preferences and security data
Professional data: profile, skills, employer, CV, application and messages
Listing data: content, location, employment terms, price and images
Contact or report data: subject, description, URL and submitted evidence
Technical data: IP address and the approximate location derived from it, date, time, requested page, general browser and device characteristics, and security logs
Administrative data: moderation actions and back-office operations
04
Sources of data
Data mainly comes from the data subject when they submit a form, create an account, publish a listing or apply. Some information may be provided by another user in an application or report, or generated by the system for security and administration. IBCSC may consult public sources where a limited and legitimate verification is necessary.
05
Purposes and legal bases
Each processing activity relies on a legal basis appropriate to its purpose. IBCSC does not use personal data for behavioural advertising and does not sell it.
Accounts, publication, applications and requested services: performance of the service or pre-contractual steps
Enquiries, cooperation and referral: legitimate interest in handling the request or steps requested by the user
Security, abuse prevention, logs and legal defence: legitimate interests of the Institute and users
Moderation and reports: legitimate interest and, where applicable, legal obligation
Retention or disclosure required by an authority: legal obligation
Future optional service based on consent: separate, freely given and withdrawable consent
06
Public data
Published listings, professional profiles and contact details that a user chooses to display become visible to website visitors. Users should not publish a home address, identity document, national number, bank details, password or unnecessary sensitive data. IBCSC may hide or remove manifestly excessive data.
07
Recipients
Access to non-public data is limited to authorised persons who need it to administer the service. Depending on the service, information is disclosed to a listing author, applicant or chosen contact. Technical providers may process data for hosting, email, maintenance or security under instructions and confidentiality duties.
Authorised IBCSC members or contributors
Users receiving an application or message
Strictly necessary technical providers
Authorities or advisers where required by law or justified to defend a right
08
International transfers
The main operational infrastructure is administered in the European Union. IBCSC does not organise systematic transfers outside the European Economic Area. If a future service involves such a transfer, the Institute will verify an adequacy decision or put required safeguards in place and update this policy.
09
Retention periods
Data is kept for the time required for its purpose and is then deleted or anonymised, unless a legal duty, report, dispute or evidential need justifies limited additional retention.
Contact messages and reports: no more than twelve months
Unverified account: deletion after seven days
Verification link: twenty-four hours; reset link: one hour
Session cookie: until the browser closes or the user signs out
Published listing: ninety days unless closed early or renewed
Account, profile, applications and associated content: while the service is used, then deleted with the account subject to legal justification
Security, moderation and evidential logs: a period proportionate to the risk, relevant duty and applicable limitation periods
10
Security and confidentiality
IBCSC applies proportionate technical and organisational measures: encrypted communications, restricted access, private storage separated from the public website, password hashing, session protection, short-lived tokens, attempt limits, backups and logging of administrative actions. No system is absolutely secure; measures are reviewed against risk and service developments.
11
Data-subject rights
Subject to the GDPR, you may request access and a copy, rectification, erasure, restriction, portability where applicable, or object to processing based on legitimate interests. Where processing relies on consent, it may be withdrawn at any time without affecting earlier lawful processing.
12
How to exercise your rights
Send a request to info@ibcsc.be or to the registered office, stating the right exercised and information identifying the relevant service. IBCSC may request proportionate proof of identity where reasonable doubt exists. A response is provided without undue delay and generally within one month; this may be extended in the cases allowed by the GDPR.
13
Complaint to the supervisory authority
You may request mediation or lodge a complaint with the Belgian Data Protection Authority: Rue de la Presse 35, 1000 Brussels, contact@apd-gba.be, +32 (0)2 274 48 00. Without limiting your rights, IBCSC invites you to contact it first so that the issue can be addressed.
14
Minors and sensitive data
The website is not designed to collect sensitive data or children’s data without necessity. A report may nevertheless contain special information. Submit only what is strictly necessary, redact irrelevant documents and identifiers, and avoid sharing third-party data without a legitimate basis.
15
Automated decisions and profiling
IBCSC does not make decisions producing legal effects solely by automated processing and does not carry out advertising profiling. Moderation decisions are reviewed by an authorised person against the content, these rules and available information.
16
Operational monitoring of visits
For the security, availability and operational monitoring of the site, IBCSC records visit events on the public pages. This record covers the page viewed, the date and time, the IP address and the approximate location derived from it, and general characteristics of the browser and device, such as device type, language, time zone, screen resolution and general technical capabilities. The approximate location is obtained by querying, from the visitor’s browser, an independent IP-geolocation service that receives the IP address for that sole purpose. The events are transmitted to an internal, secure monitoring channel of the Institute. This processing relies on the Institute’s legitimate interest in protecting, diagnosing and monitoring its service; it is not used for advertising or commercial profiling, and the data is not sold. A technical marker kept in the browser for the session limits repeated recording and is not a cookie. You may object to this processing based on legitimate interest by writing to info@ibcsc.be.
17
Cookies and policy changes
Cookies and local storage are described in the Cookie policy. IBCSC may update this policy when its activities, processing or applicable law change. Material changes will be communicated appropriately and the update date will be revised.
18
Employment service — data, purposes and recipients
To create and manage a candidate or employer workspace, IBCSC processes identity and contact details, the professional profile, CVs and attachments, preferences, applications and employer-verification information. The account, profile and each application are processed to provide the requested service or take requested pre-contractual steps. Optional visibility, job alerts and any disability information rely on the person’s choices and, where required, explicit consent.
Candidates choose their profile visibility and may make the profile non-searchable
The selected employer receives a file only after the candidate acts and confirms: the selected CV, motivation, answers and a minimal professional snapshot
Employer-verification documents are not public and are accessible only to authorised IBCSC personnel who need them
IBCSC does not sell personal data or use it for behavioural advertising
19
Employment service — retention and deletion
The candidate profile and private documents are kept while the account remains active and are then deleted with the account, unless a legal duty, dispute or evidential need justifies limited retention. Each submission creates a fixed copy of the application file and the platform immediately assigns it an expiry date.
IBCSC’s copy of the application file and associated platform record: no more than 730 days from submission, then deleted by the scheduled purge procedure
The recipient employer processes its own copy under its responsibility and must inform the candidate of its retention period
Withdrawal changes the application status; a request for earlier erasure may be sent to info@ibcsc.be and will be handled under the GDPR
Optional visibility and job-alert consents may be withdrawn; disability information relies on explicit consent and may be deleted
Employer-verification documents are kept only as long as needed for verification and operation of the service, then deleted or retained on a limited basis where a legal justification remains
20
Geographic access control
To limit service availability to the European Union, the United States and Canada, the server locally compares the directly received IP address with a GeoIP database installed on the infrastructure. No IP address is sent to an external provider for this check. The processing relies on IBCSC’s legitimate interest in defining and securing the service availability area.
Only the address received directly by the server is used; forwarding headers sent by the visitor are ignored
The allowed or denied result is not added to a visitor profile and is not used for advertising or profiling
GeoIP location remains approximate, especially when a VPN or relay is used; an error may be reported to info@ibcsc.be