Privacy Policy
Last updated: 23 September 2026 · the French version is authoritative.
Privacy Policy — bloo.Cards
Last updated: 23 September 2026 — Version 1.1. The French version is the legal and original version and is authoritative (see Article 17).
At bloo.Cards, protecting your privacy is a priority. This Privacy Policy explains how we collect, use, share and protect your personal data, in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the "ePrivacy" Directive (2002/58/EC, as amended) and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
The bloo.Cards service ("the Platform", "the Service") is currently operated on the domain blcrds.com (backoffice, Wallet application, public cards). The domains bloo.cards, bloocards.com, mybloo.cards, wallet.bloo.cards and cards.blcrds.com are part of the same ecosystem.
Contents
- Article 1 — Data controller
- Article 2 — Categories of data collected
- Article 3 — Legal bases for processing
- Article 4 — Purposes of processing
- Article 5 — Data recipients
- Article 6 — Processors and service providers
- Article 7 — Retention periods
- Article 8 — Data security and protection
- Article 9 — International data transfers
- Article 10 — Cookies and tracking technologies
- Article 11 — Profile access and portability
- Article 12 — User rights (GDPR)
- Article 13 — Consent management
- Article 14 — Children and minors
- Article 15 — Changes to the Policy
- Article 16 — Contact and exercise of rights
- Article 17 — Reference language and language primacy
Article 1 — Data controller
The controller of your personal data is:
- MOLDEREZ-CONSULT SRL
- Company number (BCE): 0842.262.084
- Intra-community VAT number: BE 0842.262.084
- Registered office: Square Valère-Gille 13, box 5, 1050 Ixelles, Belgium
- Privacy / data protection contact: privacy@blcrds.com
- Legal contact: legal@blcrds.com
- General contact: hello@blcrds.com
As the data controller, Molderez-Consult SRL determines the purposes and means of the processing of your data. A dedicated data protection contact point is available at privacy@blcrds.com for any question relating to your personal data.
To date, Molderez-Consult SRL has not appointed a Data Protection Officer (DPO) within the meaning of Article 37 of the GDPR, as such appointment is not mandatory given the current nature and scale of our processing activities. A privacy contact point nevertheless ensures compliance monitoring and the handling of your requests.
Article 2 — Categories of data collected
2.1 Overview
We collect various categories of personal data depending on your use of the Platform. Here is a detailed overview:
| Category | Type of data | Source | Mandatory? |
|---|---|---|---|
| Identification data | First name, last name, e-mail address, phone number, profile photo | Registration, user profile | E-mail: yes — Others: no |
| Authentication data | Hashed password (Argon2id), hashed opaque session token (SHA-256), one-time e-mail verification code (OTC), OAuth identifiers (Google / Apple) | Registration, login | Yes |
| Company data | Company name, VAT number, postal address, country, billing details | Profile, B2B billing | No (except business billing) |
| Digital card data | Text, images (JPEG/PNG/WebP), videos (MP4/WebM), PDF, links, contact details | Card creation / editing | No |
| Audience data (card analytics) | Number of views, QR scans, NFC taps, device type, browser, referrer, city-level geolocation (no individual identification of visitors) | Consultation of public cards | No |
| Payment metadata | Dates, amounts, payment method, status, transaction identifier (via Mollie). No card number or CVV code is stored by bloo.Cards | Transactions via Mollie | Yes (if paid subscription) |
| Preference / consent data | Cookie consent choices, language (bloo-lang), theme (bloo-theme) | Browsing, user settings | Functional: yes — Analytics: no |
| Contact data (forms) | Content of requests sent via our forms | Contact forms | No |
| Wallet / Network data | Contacts saved by the user, interaction history (see Article 5.4) | Wallet application / Network feature | No |
| Technical data | IP address, User-Agent, access logs, timestamps | Servers, logs | Yes (infrastructure operation) |
2.2 Sensitive data (Article 9 GDPR)
We do not deliberately collect sensitive data within the meaning of Article 9 of the GDPR (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning sex life or sexual orientation).
If you choose to publish such data in the content of your card (text, images, videos), you assume full responsibility for it as the party responsible for that content, and you grant us a licence to host and display it, in accordance with our Terms of Use.
2.3 Optional data
Certain data are not necessary in order to use the Platform:
- profile photo;
- phone number;
- detailed company information (other than billing);
- card content (images, videos, PDF);
- audience data (analytics may be limited).
Refusing to provide this optional data does not affect access to the essential services.
Article 3 — Legal bases for processing (Article 6 GDPR)
We process your personal data only on the basis of one of the following legal bases provided for in Article 6 of the GDPR:
| Legal basis | GDPR Article | Type of processing | Examples |
|---|---|---|---|
| Performance of the contract | 6(1)(b) | Necessary to create and administer your account and provide the Service | Identification, authentication, hosting of card data, billing, sending invoices |
| Legitimate interest | 6(1)(f) | Securing, improving and maintaining the Service | Server logs, fraud and abuse prevention, security, technical diagnostics |
| Consent | 6(1)(a) | Processing requiring your prior agreement | Cookies and audience measurement (Google Analytics 4), any commercial communications |
| Legal obligation | 6(1)(c) | Compliance with Belgian and EU legal obligations | Archiving of invoices (7 years, Belgian tax law), responses to legitimate requests from authorities |
Important: for each processing operation, only one legal basis applies. Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
Article 4 — Purposes of processing
Your data are processed exclusively for the following purposes:
4.1 Contractual purposes (Art. 6(1)(b) GDPR)
- Account creation and management: registration, authentication, access to the Platform;
- Provision of the Service: creation, editing, customisation and sharing of digital cards;
- Subscription management: assigning the appropriate plan and managing feature limits;
- Billing and payments: issuing invoices, processing payments via Mollie, archiving for tax compliance purposes (7 years);
- Customer support: handling requests, technical assistance, incident resolution;
- Service communications: legal notices, changes to the Terms or the Policy, maintenance notices.
4.2 Purposes based on legitimate interest (Art. 6(1)(f) GDPR)
- Security and fraud prevention: detecting unauthorised access, monitoring abnormal behaviour, protecting accounts;
- Maintaining and improving the Service: technical diagnostics, bug fixing, performance optimisation;
- Handling complaints and disputes: dealing with disputes and defending our rights;
- Analysis of technical logs: detecting outages and attacks.
Balancing test: for processing based on legitimate interest, we have assessed that our interest in providing a secure, reliable and compliant Service prevails over your interests, rights and freedoms, in particular because you can object to such processing (see Article 12).
4.3 Purposes based on consent (Art. 6(1)(a) GDPR)
- Audience measurement: Google Analytics 4, activated only after your consent (opt-in);
- Any commercial communications: if we set up a newsletter or offers, these will only be sent to you after your consent, with the ability to unsubscribe at any time.
4.4 Purposes based on a legal obligation (Art. 6(1)(c) GDPR)
- Tax archiving: retention of invoices and transactions for 7 years (Belgian tax and VAT law);
- Requests from authorities: responding to court decisions and legitimate law enforcement requests;
- Legal declarations: accounting and tax obligations.
4.5 Purposes explicitly excluded
We never use your data for:
- the sale of your personal data to third parties;
- discriminatory profiling (origin, religion, sexual orientation, etc.);
- fully automated decisions producing legal effects or significantly affecting you (see Article 12.7);
- non-consented sharing with external marketing partners;
- credit scoring or assessment for insurance purposes;
- mass surveillance or behavioural cataloguing.
Article 5 — Data recipients
Your data may be disclosed to the following categories of recipients:
5.1 Internal recipients
- Technical team: access for support, debugging and infrastructure maintenance;
- Customer support: access to handle your requests;
- Compliance / legal: access to verify GDPR compliance and handle requests to exercise rights;
- Billing: access to invoice, payment and subscription data.
Internal access is limited to authorised persons only, on a need-to-know basis.
5.2 Public authorities and law enforcement
We may disclose your data:
- to data protection authorities, in response to investigation requests;
- to law enforcement and judicial authorities, upon a court decision, warrant or legal requisition;
- to tax authorities, as part of our accounting and tax obligations.
We only respond to such requests when we are legally required to do so and inform the user, except where the law prohibits us from doing so.
5.3 Visitors to your cards
When a third party consults your public digital card:
- they only see the data you have chosen to publish (text, images, links, contact details);
- audience statistics are aggregated (number of views, general city-level location) and do not individually identify visitors;
- if a visitor saves you via the Wallet application, the exchange of contact details is based on their own initiative.
5.4 Other users (Wallet / Network feature)
The Wallet application offers a "Network" feature (lightweight CRM) allowing a user to save and organise the contact details of contacts they have met, and to export them.
Allocation of roles (Articles 26 and 28 GDPR): for the third-party contact data thus saved, the card-holding user acts as the data controller: it is they who decide to save, retain and use these contact details, and who must have a legal basis for doing so (for example the voluntary exchange of a business card or the consent of the data subject). bloo.Cards acts as a processor on behalf of that user: we host and process these contacts according to their instructions and solely for the purposes of the Network feature, without using them for our own purposes.
If you are a person whose contact details have been saved by a bloo.Cards user and you wish to exercise your rights, please first contact that user (the data controller). We will relay your request to them and assist within the limits of our role as processor: privacy@blcrds.com.
Article 6 — Processors and service providers (Article 28 GDPR)
To provide the Service, we entrust certain processing operations to processors. A data processing agreement (DPA) governs each of these relationships:
| Processor | Function | Location | Safeguards |
|---|---|---|---|
| OVH (OVHcloud) | Hosting of the infrastructure and servers (including the MariaDB database and the logs) | European Union | DPA, GDPR, SCC (where applicable) |
| Mollie | Payment processing (Bancontact, cards, iDEAL, PayPal, SEPA); PCI-DSS certified | Netherlands (EU) | DPA, GDPR |
| AuthSMTP | Sending transactional e-mails (verification, invoices, notifications) | United Kingdom | EU adequacy decision + SCC, DPA |
| BlazingCDN | Content delivery network (CDN) — images and files | European Union | DPA, SCC |
| Google (Google Ireland / Google LLC) | Maps, Places, OAuth (SSO) and Google Analytics 4 (optional, subject to consent) | Ireland (EU) / United States | EU-US Data Privacy Framework + SCC |
| Apple Inc. | "Sign in with Apple" (optional SSO) | United States | EU-US Data Privacy Framework |
| ModernMT | Automatic translation of content (4 languages) | European Union | DPA, GDPR |
The MariaDB database and the application sessions are hosted on our infrastructure at OVH (EU); these are not separate third-party services but software components operated under our control.
6.1 Data processing agreements (DPA)
Our processors are bound by data processing agreements compliant with Article 28 of the GDPR, guaranteeing in particular:
- processing in accordance with our instructions only;
- the confidentiality and security of the data;
- the notification of data breaches;
- assistance with our GDPR obligations;
- the deletion or return of the data at the end of the contract.
6.2 Sub-processors (Article 28(2) and (4) GDPR)
Certain processors (in particular Mollie, Google and AuthSMTP) may use sub-processors. An up-to-date list is available on request at privacy@blcrds.com.
6.3 International transfers
Google and Apple (United States) as well as AuthSMTP (United Kingdom) may receive certain data. The applicable safeguard mechanisms are detailed in Article 9.
Article 7 — Retention periods
Your data are kept only for as long as necessary for the purposes pursued:
| Data category | Retention period | Justification |
|---|---|---|
| Active account (identification, authentication) | Duration of the account + 30 days after deletion | Access to the Service; grace period for recovery |
| Digital cards | As long as the account is active; deletion after a grace period following archiving | User content; period before permanent deletion |
| Payment metadata (Mollie) | Duration of the account + 3 years | Handling of disputes and refunds (no card data is stored by bloo.Cards) |
| Invoices | 7 years from the invoice date | Belgian legal obligation (tax and accounting law) |
| Audience data / analytics | Up to 24 months | Analysis of usage trends |
| Server logs (IP, User-Agent) | Up to 90 days | Security, debugging, attack detection |
| Cookie consent records | Up to 6 months | ePrivacy compliance, proof of consent |
| Transactional e-mails | Up to 90 days (excluding invoices kept for 7 years) | Traceability of communications |
| GDPR rights requests | 3 years | Proof of processing, defence in the event of a dispute |
| Wallet / Network data | Duration of the user's account | Network feature (the user is the controller) |
| Inactive accounts | Archiving after an extended period of inactivity, then deletion | Space management; possibility of recovery |
| Contact forms (non-customers) | 6 months | Handling of the request |
7.1 Permanent deletion
Upon expiry of the periods indicated:
- the data are irreversibly deleted from our production servers;
- backups containing this data are purged according to the backup retention cycle;
- anonymised or aggregated data (statistics without possible identification) may be kept indefinitely.
7.2 Requests for early deletion
You may request the early deletion of your data at any time (see Article 12.3). Certain data may nevertheless be retained where required by law (for example invoices, 7 years).
Article 8 — Data security and protection
8.1 Technical measures
We implement appropriate technical measures to protect your data:
- Encryption in transit: all communications are encrypted via HTTPS (TLS 1.2 minimum, TLS 1.3 targeted), with forced redirection to HTTPS and an HSTS header. The TLS certificate is issued by a recognised certification authority;
- Encryption at rest: encryption of data at rest (at the MariaDB database level and, for certain data, at the application level) is currently being rolled out and is not yet fully effective across all data. This page will be updated when this encryption is activated;
- Password hashing: passwords are hashed with Argon2id, an algorithm resistant to brute-force and GPU attacks;
- Authentication tokens: authentication relies on opaque, random tokens, stored server-side in hashed form (SHA-256). bloo.Cards does not use JWT tokens;
- Secure sessions: PHP sessions relying on a Secure, HttpOnly, SameSite=Lax cookie, with regeneration of the session identifier after login (session fixation prevention);
- Prepared statements (PDO): all SQL queries use prepared statements (SQL injection prevention);
- Security headers: HSTS, Content-Security-Policy (CSP), X-Frame-Options (DENY), X-Content-Type-Options (nosniff), Referrer-Policy and Permissions-Policy; the X-Powered-By header is removed;
- Rate limiting: limiting authentication attempts in "fail-closed" mode (protection against brute force);
- Anti-CSRF tokens: per-session token and origin check (Origin / Referer) on sensitive operations;
- File validation: checking the MIME type and "magic bytes" during uploads;
- Application firewall: a proprietary application firewall (WAF) filters requests upstream of the entry points;
- Content isolation: media files are served via a content delivery network (CDN) on a separate domain; public cards are protected against injection attacks (CSP, content escaping).
8.2 Organisational measures
- Limited access: data are only accessible to authorised staff, on a need-to-know basis;
- Enhanced authentication: the strengthening of authentication (2FA) for sensitive access is planned and currently being rolled out;
- Confidentiality: persons with access to the data are bound by a confidentiality obligation;
- Security reviews: regular internal security reviews and audits;
- Incident management: data breach notification procedure;
- Backups: regular backups of the infrastructure.
8.3 Data breach notification (Articles 33-34 GDPR)
In the event of a personal data breach (unauthorised access, loss, alteration):
- Notification to the authority: notification to the Belgian Data Protection Authority within 72 hours (Art. 33 GDPR) where the breach presents a risk;
- Notification to users: informing the users concerned as soon as possible in the event of a high risk (Art. 34 GDPR);
- Content: nature of the breach, data concerned, possible consequences, measures taken and contact points;
- Documentation: each incident is documented and retained.
8.4 Limitation
Despite rigorous security measures, no IT security is absolute. We cannot guarantee total protection against, in particular: "zero-day" vulnerabilities, advanced persistent threats, compromise on the user's side (phishing, malware), acts of malicious third parties, or cases of force majeure.
Article 9 — International data transfers (Chapter V GDPR)
9.1 Identification of transfers
Certain processors are established outside the European Union, resulting in international transfers within the meaning of Chapter V of the GDPR:
- Google (United States): Maps, Places, OAuth, Analytics (optional);
- Apple (United States): "Sign in with Apple";
- AuthSMTP (United Kingdom): transactional e-mails.
9.2 Safeguard mechanisms
| Provider | Safeguard mechanism | Status |
|---|---|---|
| Google, Apple | EU-US Data Privacy Framework (DPF) | European Commission adequacy decision (2023) |
| AuthSMTP (United Kingdom) | EU-UK adequacy decision + standard contractual clauses (SCC) | Adequacy in force; SCC as additional safeguard |
| All non-EU providers | Standard contractual clauses (SCC) — Art. 46(2)(c) GDPR | Additional safeguard |
9.3 EU-US Data Privacy Framework
Google and Apple adhere to the EU-US Data Privacy Framework, recognised by the European Commission's 2023 adequacy decision. This framework aims to guarantee a level of protection substantially equivalent to that of the GDPR, with avenues of redress and independent oversight.
9.4 Derogations (Article 49 GDPR)
In the absence of an applicable safeguard mechanism, certain transfers may rely on the derogations of Article 49: your explicit consent, the necessity for the performance of the contract, or the establishment/defence of legal claims.
9.5 Your rights
- request a copy of the standard contractual clauses or safeguard mechanisms (privacy@blcrds.com);
- be informed of the risks associated with international transfers;
- refuse certain non-essential transfers (for example Google audience measurement) without affecting access to the essential services.
9.6 Regulatory monitoring
We follow the recommendations of the European Data Protection Board (EDPB) relating to transfers. Should the applicable legal framework change, we will implement the additional measures necessary to ensure compliance.
Article 10 — Cookies and tracking technologies
10.1 Definition and classification
Cookies are small files placed on your device; certain information is also stored in the browser's local storage (localStorage). A dedicated Cookie Policy describes these trackers in more detail.
We currently use the following categories:
| Category | Examples | Purpose | Consent | Duration |
|---|---|---|---|---|
| Essential cookies | PHP session cookie; cookie storing your consent choice | Authentication, security, storing consent | Not required (exempt) | Session / up to 6 months for the consent choice |
| Functional preferences (localStorage) | bloo-lang (language), bloo-theme (light/dark theme) | Remembering your display preferences | Not required (user preference) | Until erased by the user |
| Audience measurement | Google Analytics 4 (_ga, _ga_<ID>) | Understanding and improving site usage | Yes (opt-in) | Up to 24 months |
Marketing / advertising cookies: to date, bloo.Cards uses no marketing cookies, no advertising pixels (for example Meta-type), and no remarketing or targeted advertising tools. Should such trackers be introduced in the future, they would only be activated after your explicit consent and this Policy would be updated beforehand.
10.2 Consent management
A consent banner is displayed on your first visit. It lets you accept or refuse audience measurement, the only category subject to consent. Google Analytics 4 is only loaded after you accept: as long as you have not made a choice, or if you refuse, no Google Analytics script is loaded and no data is sent to Google. Your acceptance applies only to audience measurement: Google's advertising signals remain refused.
10.3 Related technologies
- localStorage / sessionStorage: storing preferences (language, theme) on the browser side;
- Google Analytics 4: audience measurement, only after consent;
- we do not use aggressive browser "fingerprinting".
10.4 Third-party cookies
When a holder embeds a Google Maps map in their bloo.Cards card, it only loads after the visitor clicks "Show the Google map"; that click constitutes consent to Google Ireland Ltd placing its own cookies. Without a click, only a frame hosted by bloo.Cards and a link to Google Maps are displayed. We invite you to consult Google's privacy policy and Google's cookie policy.
10.5 User control
- Change your preferences: via the "Manage cookies" link at the bottom of every page, which reopens the choice panel;
- Withdraw your consent: at any time, as easily as you gave it;
- Browser settings: you can block or delete cookies via your browser settings.
10.6 ePrivacy compliance (Directive 2002/58/EC)
- prior consent before placing any non-essential tracker (Art. 5(3));
- clear information and refusal as easy as acceptance;
- exemption for strictly necessary trackers;
- reasonable consent retention period (up to 6 months);
- facilitated withdrawal of consent.
Article 11 — Profile access and portability (Article 20 GDPR)
11.1 Access to your profile
From your area (backoffice), you can at any time view and modify your data (identity, e-mail, language), and request a copy of your data (see 11.3).
11.2 Rectification and updating
You can rectify inaccurate or outdated data. If incorrect data affects a calculation (for example the country for VAT), we correct it and recalculate the applicable amounts where relevant.
11.3 Right to data portability (Article 20 GDPR)
You may request the portability of the data you have provided to us, in a structured, commonly used and machine-readable format (JSON, CSV, vCard), where the processing is based on the contract or consent and carried out by automated means. This may include:
- account data (e-mail, name, preferences, language);
- the content of your digital cards and their configuration;
- billing history;
- Wallet / Network data (contacts you have saved).
Formats offered: JSON (full export, recommended), CSV (tabular data), vCard (contacts), or a ZIP archive combining the files. The request is handled within the time limits provided for in Article 12(3) GDPR (see Article 16).
Article 12 — User rights (Articles 15-22 GDPR)
The GDPR grants you rights over your personal data. Unless stated otherwise, these rights are exercised with privacy@blcrds.com.
12.1 Right of access (Article 15)
You can obtain confirmation that your data are being processed and receive a copy, as well as information on the purposes, recipients, retention periods and your rights. The first copy is free.
12.2 Right to rectification (Article 16)
You can have inaccurate data corrected or incomplete data completed, directly from your area or on request. Where relevant, we inform the recipients of the data of the rectification, unless this proves impossible or requires disproportionate effort.
12.3 Right to erasure / right to be forgotten (Article 17)
You may request the erasure of your data, in particular where: it is no longer necessary; you withdraw your consent; you successfully object to the processing; or the processing is unlawful.
Exceptions: the right to erasure does not apply where retention is necessary for freedom of expression and information, compliance with a legal obligation (for example invoices kept for 7 years), or the establishment, exercise or defence of legal claims.
12.4 Right to restriction (Article 18)
You may request the temporary freezing of a processing operation (without deletion), in particular during verification of the accuracy of your data or the examination of an objection.
12.5 Right to data portability (Article 20)
See Article 11.3. You may also request, where technically feasible, the direct transmission of your data to another controller.
12.6 Right to object (Article 21)
You may object, on grounds relating to your particular situation, to processing based on our legitimate interest. You may object at any time and without justification to any commercial solicitation.
12.7 Automated individual decision-making (Article 22)
You are not subject to decisions producing legal effects or significantly affecting you based solely on automated processing. Certain automated checks (for example fraud detection, feature limits according to the plan, or a payment refusal decided by the payment provider) may exist; you have the right to obtain human intervention, to express your point of view and to contest the decision.
12.8 Withdrawal of consent
Where a processing operation is based on your consent, you can withdraw it at any time, without affecting the lawfulness of the consent-based processing carried out before its withdrawal.
Article 13 — Consent management
13.1 Consent (Article 7 GDPR)
For processing based on consent (audience measurement, any commercial communications), we obtain freely given, specific, informed and unambiguous consent:
- Unambiguous: through a clear affirmative act (unticked opt-in); refusal is as easy as acceptance;
- Prior: before any relevant processing;
- Informed: after information about the purpose, duration and right of withdrawal;
- Revocable: you can withdraw it at any time, without penalty.
13.2 Cookie consent (ePrivacy)
Consent to non-essential trackers is managed via the consent banner (accept / refuse). Your choice is stored (up to 6 months) and can be changed or withdrawn at any time via the "Manage cookies" link in the footer; withdrawal deletes the _ga and _ga_<ID> cookies.
13.3 Commercial communications
If we offer a newsletter or offers, your subscription will be based on your consent (opt-in) and each message will include a simple and immediate unsubscribe link. You can also manage your preferences from your area.
13.4 Service communications
Communications strictly related to the operation of the Service (legal notices, changes to terms, maintenance notices, billing information) are necessary for the performance of the contract and do not constitute solicitation: they cannot therefore be refused as long as you have an account.
Article 14 — Children and minors
14.1 Target audience
The Platform is aimed at an adult and professional audience. The minimum age required to create an account and take out a subscription is 18 years.
14.2 Age of digital consent
In accordance with the Belgian Act of 30 July 2018 (Art. 7), the age of consent for information society services is set at 13 years in Belgium. We do not knowingly collect data concerning children who have not reached this age without the consent of the holder of parental authority.
14.3 Deletion
If we learn that an account has been created by a minor in breach of these terms, or that a child's data has been collected without the required consent, we delete the account and the data concerned as soon as possible. You can report such a situation to us at privacy@blcrds.com.
Article 15 — Changes to the Policy
15.1 Right to modify
We may amend this Policy to reflect legal or operational developments (new processors, infrastructure), or to improve its clarity.
15.2 Notification of changes
Significant changes are notified by e-mail to the address associated with your account and/or by a notification in your area, within a reasonable time before they take effect. The date of the last update and the version number appear at the top and bottom of this page.
15.3 Continued use
Continued use of the Platform after the changes take effect constitutes acknowledgement of them. If you do not accept a substantial change, you may terminate your account without penalty.
Article 16 — Contact and exercise of rights
16.1 Contact details
Molderez-Consult SRL — Privacy & Data
- Address: Square Valère-Gille 13, box 5, 1050 Ixelles, Belgium
- Privacy / GDPR rights: privacy@blcrds.com
- Legal contact: legal@blcrds.com
- General contact: hello@blcrds.com
- Company number (BCE): 0842.262.084 — VAT: BE 0842.262.084
16.2 How to exercise your rights
To exercise a right (access, rectification, erasure, restriction, portability, objection), send us an e-mail at privacy@blcrds.com specifying the subject of your request. In order to protect your data, we may ask you to confirm your identity (for example via the registered e-mail address) before taking action.
16.3 Response times
We respond to your request as soon as possible and, in any event, within one month of receipt (Art. 12(3) GDPR). This period may be extended by a further two months in the event of complexity or a large number of requests; we will then inform you within the month. We strive to handle routine requests more quickly.
16.4 Requests by a third party
A legal representative or authorised agent may exercise your rights on your behalf upon presentation of proof of their authority (mandate, power of attorney or proof of the legal relationship).
16.5 Right to lodge a complaint (Article 77 GDPR)
If you consider that the processing of your data does not comply, you may lodge a complaint with the Belgian Data Protection Authority:
- Data Protection Authority (APD / GBA)
- Rue de la Presse 35, 1000 Brussels, Belgium
- Tel.: +32 (0)2 274 48 00
- E-mail: contact@apd-gba.be
- Website: www.autoriteprotectiondonnees.be
You may lodge a complaint with the APD without having contacted us beforehand. You also have the right to a judicial remedy before the competent Belgian courts.
Article 17 — Reference language and language primacy
The French version is the legal and original version; the Dutch, German and English versions are courtesy translations; in the event of any discrepancy, the French version prevails.
This Privacy Policy (Version 1.2) takes effect as of 23 September 2026. We invite you to consult this page regularly to keep informed of any updates.