Skip to main content
FromNine
Menu

Privacy notice

Effective
Version
1.0
Last updated
Contents

This notice explains how personal data is handled when you visit this website or contact us through it. It covers this website only.

We have kept it short and specific. If anything is unclear, ask us using the contact details in section 1.

  1. Who is responsible

    The controller of the personal data described in this notice is LAAP Group, the company behind FromNine, with its registered office at Plantin en Moretuslei 299, 2140 Antwerpen, Belgium, and enterprise number 1036.676.216.

    For any question or request about your personal data, write to contact@fromnine.com. Mentioning “privacy” in the subject line helps us pass your message to the right person quickly.

    Company name
    LAAP Group
    Registered office
    Plantin en Moretuslei 299, 2140 Antwerpen

    A LAAP Group company

  2. What we process, why, and on what basis

    We process personal data in three situations. For each, we list the data, the purpose, the legal basis under the General Data Protection Regulation (GDPR) and how long we keep it.

    When you visit the website

    To deliver pages and keep the website secure, our hosting provider processes technical data each time your browser requests a page: IP address, date and time, the requested address, browser and operating system details, the referring page and the response status.

    Purpose: delivering the website, detecting and preventing abuse, and fixing faults. Legal basis: our legitimate interest in operating a secure, working website (Article 6(1)(f) GDPR). Retention: server logs are deleted after no more than 30 days, unless they are needed to investigate a specific security incident.

    We do not use analytics, advertising or social media tracking on this website. If that changes, we will update this notice first and ask for your consent where the law requires it.

    When you contact us

    If you use the contact form, we process your name, your email address, your organisation if you give it, the topic you choose, your message and the language version of the website you used.

    Purpose: answering your enquiry and, if you wish, continuing the conversation about a project. Legal basis: steps taken at your request before a possible contract (Article 6(1)(b) GDPR), and otherwise our legitimate interest in replying to messages sent to us (Article 6(1)(f) GDPR). Retention: we delete enquiries 12 months after our last contact with you, unless they lead to a business relationship, in which case the retention rules of that relationship apply.

    Your message is delivered to our team by email. The website does not store it in a database. Our operational logs record only a reference number and whether delivery succeeded, never your name, email address or message.

    To protect the form against abuse, we use a hidden spam check and limit the number of messages per sender. For that limit, your IP address and email address are converted into one-way hashed values that are kept in memory for at most 24 hours and then discarded.

    Preferences stored in your browser

    The website remembers your choice of theme and your animation setting in your browser, and your language and region if you use the switcher. The theme and animation choices stay on your device. The details are in the cookie policy.

  3. Who receives your data

    We share personal data only with service providers that process it on our behalf and under our instructions, bound by a data processing agreement: our hosting provider, which delivers the website and keeps the server logs; our email delivery provider, which delivers contact form messages to our team; and our email and collaboration platform, where our team reads and answers your message.

    Within LAAP Group, an enquiry may be passed to the colleagues or the group office best placed to answer it, based on our legitimate interest in handling your request properly. LAAP Group has offices in Antwerp, Ghent, Amsterdam and Cyberjaya (Malaysia); the next section explains how access from outside the European Economic Area is safeguarded.

    We do not sell personal data and do not share it for advertising.

  4. Transfers outside the European Economic Area

    We aim to process personal data within the European Economic Area (EEA). LAAP Group also has an office in Cyberjaya, Malaysia, which is outside the EEA. Where colleagues there, or a service provider outside the EEA, have access to personal data, we make sure that this access is covered by appropriate safeguards under Article 46 GDPR, in particular the Standard Contractual Clauses adopted by the European Commission, with additional measures where needed. Where the European Commission has adopted an adequacy decision for the country concerned, we may rely on that decision instead.

    You can ask for a copy of the relevant safeguards by writing to contact@fromnine.com.

  5. How we protect your data

    FromNine operates an information security management system certified to ISO/IEC 27001. Access to enquiries is limited to the people who need it to answer you, and data is encrypted in transit between your browser, our website and our mail systems.

  6. Your rights

    You can ask us for access to your personal data and for its rectification or erasure, or ask us to restrict its processing. You can object to processing that is based on our legitimate interests, and you have the right to data portability where processing is based on steps towards a contract. These rights are set out in Articles 15 to 21 of the GDPR.

    To use a right, write to contact@fromnine.com. We reply within one month. For complex requests this can be extended by two further months; we will tell you if that happens and why. We may ask you to confirm your identity first.

    We do not use automated decision-making or profiling that produces legal or similarly significant effects for you.

  7. Complaints

    If you think we handle your data incorrectly, please tell us first so we can put it right. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State where you live, where you work or where the alleged infringement took place (Article 77 GDPR).

    Because LAAP Group has its registered office in Belgium, our lead supervisory authority is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données). The European Data Protection Board (opens external site) lists the supervisory authorities of all Member States.

    Supervisory authority for this market

    Belgian Data Protection Authority (GBA/APD), lead supervisory authority

    www.dataprotectionauthority.be (opens external site)

  8. Changes to this notice

    We update this notice when our processing changes. The version and dates at the top of the page show which version you are reading. We announce significant changes on this page.

Questions about this page?Contact us