DIGIT 89, a public limited company operating under the trade name Clearzi, with its registered office at Square des Martyrs 1, 6000 Charleroi, and registered with the Crossroads Bank for Enterprises under number 0775.289.227, attaches great importance to the protection of the personal data of users of its online platform offering an innovative financing solution to eligible debtors and suppliers, as well as, more generally, to the personal data of its partners and contacts.
In accordance with the European General Data Protection Regulation No. 2016/679 (“GDPR”), DIGIT 89, operating under the trade name Clearzi (hereinafter “Clearzi”), acts as an independent data controller in respect of the personal data it collects and processes in the course of its activities.
1. What data are we referring to?
The personal data collected and processed by Clearzi may vary depending on the circumstances and may include, without limitation, surname, first name, profession/function, (electronic) contact details, images, cookies, data relating to connection to and use of the online platform (such as access codes), including, where applicable, data relating to the management of any disputes.
Most of the time, these data are obtained directly from the data subjects, either through the relevant forms for prior and mandatory registration as an eligible supplier or debtor, or through other (electronic) means of communication used.
Certain supplier data are provided in advance by debtors in order to enable Clearzi to offer its financing solution to those suppliers.
2. For what purposes?
The processing of these data is necessary to enable Clearzi, depending on the circumstances:
- (i) to respond to contact and/or registration requests received by it;
- (ii) to send newsletters and/or any other information relating to Clearzi's activities;
- (iii) to promote the activities of Clearzi and/or its partners;
- (iv) to carry out statistical analyses;
- (v) to perform the contract to which the relevant debtor or supplier is a party and/or to take pre-contractual measures at their request, and more specifically to manage the financing solutions implemented through the online platform, invoicing and any related recovery, and to meet the legitimate needs of its financial partner, in particular in relation to anti-money laundering requirements.
In such cases, the relevant data will be retained for the entire duration of the contract and for the applicable statutory retention and limitation periods, in particular in accounting, tax and anti-money laundering matters.
If such personal data are not available, Clearzi may be unable to fulfil all or part of the purposes set out above.
Personal data are retained only for as long as necessary to fulfil the purposes for which they were collected and processed, subject to retention periods imposed by applicable laws and regulations.
The processing of these data is therefore based, as applicable, on the performance of the relevant contract, compliance with applicable legal obligations, the consent of the data subject and/or the pursuit of the legitimate interests of Clearzi or a third party.
With regard more specifically to debtors and suppliers eligible for the financing platform, the processing activities and data, as well as the corresponding legal bases, are as follows:
(a) Registration on the platform: Clearzi collects the surname, first name, username, (electronic) contact details, address, nationality, date and place of birth of the relevant users, as well as a copy of the identity documents required to comply with applicable anti-money laundering obligations, such as a copy of the identity documents of ultimate beneficial owners and their authorised representatives.
These data are necessary for the registration and identification of the relevant debtors and suppliers and are clearly identified on the relevant registration page. This data processing is carried out on the basis of Article 6(1)(b) (performance of a contract) and, where applicable, Article 6(1)(c) (compliance with a legal obligation) of the GDPR.
(b) Invoice management: Clearzi collects and communicates to the relevant partners the personal data necessary for the preparation, management and recovery of the relevant invoices. This data processing is carried out in particular on the basis of Article 6(1)(b) (performance of a contract) and, where applicable, Article 6(1)(c) (compliance with a legal obligation) of the GDPR.
(c) Statistics and marketing activities: data relating to the use of the online platform may be processed for statistical purposes in order to enable Clearzi to study and understand how its users use the platform and its financing solution. This processing is carried out on the basis of Article 6(1)(f) (legitimate interests) of the GDPR.
Marketing activities are carried out in accordance with the applicable legal bases, and data subjects may object at any time to the use of their personal data for direct marketing purposes.
3. What rights do the data subjects have?
Each data subject may exercise their statutory rights of access and rectification free of charge. Where the conditions set out in the GDPR are met, they may also request the erasure of their personal data or the restriction of its processing.
They may also object to the processing of their personal data where the processing is based on a legitimate interest and, at any time, where their data are used for direct marketing purposes.
Where processing is based on consent, the data subject may withdraw their consent at any time, without affecting the lawfulness of processing carried out before such withdrawal.
Finally, in certain cases, the data subject may receive the personal data they have provided to Clearzi in a structured, commonly used and machine-readable format and transmit those data to another data controller.
To exercise any of these rights, a request may be sent to Clearzi by post to its registered office or by email to compliance@clearzi.com. Clearzi may request the information necessary to verify the identity of the applicant where there are reasonable doubts concerning their identity.
Finally, each data subject has the right, where applicable, to lodge a complaint with the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels.
4. To whom may these data be disclosed?
Personal data may, depending on the circumstances, be disclosed:
- (i) to the data subjects themselves;
- (ii) to Clearzi's partners in the circumstances disclosed to the data subjects, in particular to ensure the operation and follow-up of the financing solution between the relevant debtors and suppliers, including the relevant financial partner(s) and credit insurer(s), strictly to the extent necessary and subject to appropriate confidentiality and data protection commitments;
- (iii) to the relevant parties in the event of a merger, transfer, acquisition or any other event of a similar nature;
- (iv) to public, tax and social security authorities or other competent authorities, to the extent necessary to comply with the legal obligations applicable to Clearzi; and
- (v) to Clearzi's processors and other professional service providers, such as its IT service providers, to the extent necessary for the performance of their respective assignments and subject to appropriate contractual safeguards.
5. Where and how are these data stored?
As a general rule, the relevant data are not transferred outside the European Economic Area (“EEA”).
If certain data were to be transferred to a country outside the EEA, Clearzi would ensure that such transfer is carried out in accordance with the requirements of the GDPR and, where necessary, on the basis of appropriate safeguards.
Data subjects may contact Clearzi to obtain further information about the safeguards applicable to such transfers.
In all circumstances, Clearzi implements appropriate technical and organisational measures to protect personal data against destruction, loss, alteration, unauthorised disclosure or unauthorised access.
This means, in particular, that the IT systems used by Clearzi have appropriate backup, filtering and security measures in place and that its employees are made aware of the risks associated with personal data breaches and the processing of personal data. Access to personal data is restricted to persons authorised to access such data in the performance of their duties.