top of page

Privacy Policy

Privacy Policy
Chinese Chamber of Commerce in Belgium and Luxembourg (CCCBL)
Prepared in accordance with the EU General Data Protection Regulation (GDPR)

This policy explains how the Chinese Chamber of Commerce in Belgium and Luxembourg ("CCCBL", "we" or "us") collects, uses, stores and protects your personal data, and which rights you have in relation to your data. It has been prepared in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and applicable Belgian law.
Please read this policy carefully before using this website, registering for our events, or submitting any personal information to us.

​1.Who is the data controller

For the personal data you provide through this website and in connection with our activities, the data controller is:

Name                          Chinese Chamber of Commerce in Belgium and Luxembourg, (CCCBL)

Registered address【Avenue Gustave Demey 131, 1160 Auderghem】

CBE number            【0627.665.620】

Email                         【cccbl@ccpit.org】

Phone                       【+32 2 67 57 86 5】​

2.What personal data we collect

​

2.1 Information you provide to us

Purpose                                                         Data collected

Event registration                                        Name, company, job title, e-mail address, telephone number, number of attendees, remarks

                                                                        (e.g. dietary requirements, accessibility needs)

Membership application / enquiry           Company name, contact person, job title, address, telephone, e-mail, business activities

Contact form                                               Name, e-mail, telephone (optional), your message

Newsletter subscription                            E-mail address

At our events                                               Attendance records; CCCBL events are usually photographed or recorded for our

                                                                       communications (see section 3)

Fields marked as mandatory are necessary to provide the service requested; all other fields are optional and you may decide freely whether to provide them.

​

2.2 Information collected automatically

  • Technical data: IP address, browser type and version, operating system, device type, language settings

  • Usage data: pages visited, time spent, click path, referring page

  • Cookies and similar technologies: see section 4

We do not collect special categories of personal data within the meaning of Article 9 GDPR (such as data revealing racial or ethnic origin, religious beliefs, political opinions, health data or biometric data). If you voluntarily provide health-related information to us in order to accommodate a specific need (e.g. dietary requirements or accessibility arrangements), we will use it solely for that purpose, on the basis of your consent, and delete it after the event.

3.Purposes and legal bases for processing

​

Under Article 6 GDPR, we process your personal data only where one of the following legal bases applies:

Purpose                                                                                                                                 Legal basis (Article 6 GDPR)

Processing event registrations; sending confirmations and event reminders          Art. 6(1)(b) — performance of a contract or steps prior

                                                                                                                                                to entering into a contract

Answering your enquiries; providing membership services                                         Art. 6(1)(b) — performance of a contract
                                                                                                                                                Art. 6(1)(f) — legitimate interests

Sending newsletters and event invitations (where you have subscribed)                 Art. 6(1)(a) — your consent, which you may withdraw at any time

Website security, troubleshooting and abuse prevention                                             Art. 6(1)(f) — legitimate interests

Website analytics                                                                                                                Art. 6(1)(a) — your consent, obtained through the cookie consent 

                                                                                                                                               mechanism

Photographs and video at events, used for CCCBL communications                       Art. 6(1)(a) — your express consent: sought separately for each

                                                                                                                                               event; you may freely agree or refuse, and refusing does not affect

                                                                                                                                               your attendance

Compliance with accounting, tax and other legal obligations                                    Art. 6(1)(c) — compliance with a legal obligation

During events organized by the Chamber, we may take photographs or record videos for the Chamber's promotion, event reporting, and publication on our official website, social media, or press releases. Such image processing is based on our legitimate interest. The images are generally of the overall atmosphere or group settings, and individuals are normally not the focus.

If you do not wish your image to appear in the above public materials, you may contact us at any time (email: cccbl@ccpit.org) to request withdrawal, blurring, or removal of the relevant images, and we will act within a reasonable time. You also have the right to object to such processing at any time.

3.1 No automated decision-making

​

We do not take decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you.

4.Cookies and similar technologies

​

This website uses cookies and similar technologies, which fall into the following categories:

Category                                                                          Purpose                                                                                   Consent required

Strictly necessary cookies              Core site functionality, security and session management                No (exempt under GDPR)

Functional cookies                           Remembering language preferences, form input, etc.                        Yes

Analytics / statistics cookies         Measuring traffic and understanding how pages are used                 Yes

On your first visit you will be asked to make a choice through our cookie consent banner. You can change or withdraw your consent at any time via your browser settings or the "Cookie Settings" link in the website footer. Refusing non-essential cookies will not affect your ability to use the website.

​

Note: this website is hosted on the Wix.com platform. Wix and its partners place cookies that are necessary for the operation and security of the site. Analytics are enabled only once you have given your consent.

5.Who we share your data with

​

We do not sell, rent or trade your personal data. We share it only in the following circumstances:

  • Service providers (processors): website hosting platform Wix.com Ltd.; e-mail delivery and communications services; analytics services (such as Google Analytics, enabled only with your consent). These providers process data solely on our instructions and under a data processing agreement.

  • Event partners: co-organisers, venue providers and similar parties, where necessary for the organisation of the event (e.g. attendance lists) and limited to that purpose.

  • Public authorities: where required by law or by a lawful request from a competent authority.

  • Professional advisers: accountants, auditors and legal advisers, to the extent necessary to comply with legal obligations or to protect our legitimate interests.

6.International transfers

​

Your data is stored primarily within the European Economic Area (EEA). Some of our service providers may process data outside the EEA — for example, Wix.com Ltd. is based in Israel and parts of its infrastructure are located in the United States and elsewhere.

For such transfers we ensure that the safeguards required by Articles 44 et seq. GDPR are in place, including:

  • an adequacy decision adopted by the European Commission; or

  • the European Commission's Standard Contractual Clauses (SCCs), supplemented by appropriate technical and organisational measures such as encryption and access control.

You may request a copy of the relevant safeguards by contacting us using the details in section 14.

7.Data retention

​

We keep your personal data only for as long as necessary for the purposes described above:

Data                                                    Retention   period

Event registration records             24 months after the event (for statistics and future invitations)

Membership records                       Duration of the membership and 5 years after its termination

Enquiries / messages                     12 months after the enquiry has been handled

Newsletter e-mail address             Until you unsubscribe (withdraw consent)

Accounting and tax records          7 years, as required by Belgian law

Website access logs                       Generally no longer than 12 months

​

When the retention period expires, or where the purpose has been fulfilled and no legal obligation requires further retention, we securely delete or anonymise your data.

8.Your rights

​

Under Articles 15 to 22 GDPR you have the following rights:

  • Right of access (Art. 15) — to obtain confirmation as to whether we process your data, information about the purposes, categories, recipients and retention periods, and a copy of your data.

  • Right to rectification (Art. 16) — to have inaccurate data corrected or incomplete data completed.

  • Right to erasure (Art. 17) — to have your data deleted in the circumstances provided for by law (the "right to be forgotten").

  • Right to restriction of processing (Art. 18) — to require us to suspend processing in certain circumstances.

  • Right to data portability (Art. 20) — to receive the data you provided in a structured, commonly used, machine-readable format and, where technically feasible, to have it transmitted to another controller.

  • Right to object (Art. 21) — to object to processing based on legitimate interests. For direct marketing you may object at any time and without conditions, and we will stop immediately.

  • Right to withdraw consent (Art. 7(3)) — at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal.

  • Right not to be subject to automated decision-making (Art. 22) — we do not carry out such processing (see section 3.1).

9.How to exercise your rights

​

Please send your request using the contact details in section 14. To protect your data, we may need to verify your identity.

  • We will respond within one month of receiving your request. Where the request is complex, this period may be extended by up to two further months; we will inform you of the extension and the reasons for it.

  • Exercising these rights is free of charge in principle. Where a request is manifestly unfounded or excessive, in particular because of its repetitive nature, we may charge a reasonable fee or refuse to act, and will explain why.

  • To unsubscribe from our newsletter, you can use the "unsubscribe" link at the bottom of every e-mail or simply let us know by e-mail.

10.Right to lodge a complaint

​

If you believe that our processing of your personal data infringes the GDPR or applicable law, you have the right to lodge a complaint with a supervisory authority. The competent authority in Belgium is:

​

Authority            Belgian Data Protection Authority
                            Autorité de protection des données / Gegevensbeschermingsautoriteit(APD-GBA)

Address             Rue de la Presse 35 / Drukpersstraat 35, 1000 Bruxelles, Belgium

Telephone         +32 2 274 48 00

Email                  contact@apd-gba.be

website             autoriteprotectiondonnees.be

You may also lodge a complaint with the supervisory authority of your habitual residence or place of work in the EU, or bring proceedings before the competent courts.

11.Data security

​

We implement appropriate technical and organisational measures as required by Article 32 GDPR, including encryption in transit (HTTPS/TLS), access control and least-privilege authorisation, regular backups, and due diligence and contractual safeguards for our processors.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by law. Where the breach is likely to result in a high risk to you, we will also inform you without undue delay.

12.Children

​

Our services are aimed mainly at businesses and professionals. This website is not intended for children under 16, and we do not knowingly collect personal data from them. If we learn that we have collected data from a child without the required parental consent, we will delete it promptly.

13.Changes to this policy

​

We may update this policy because of legal changes or changes to our services. The updated version will be published on this page with a revised "last updated" date. Where changes materially affect the purposes or legal bases of processing, we will inform you separately by appropriate means, such as a website notice or an e-mail.

14.Contact us

​

If you have any questions, comments or requests regarding this policy or our processing of your personal data:

Email【cccbl@ccpit.org】

Telephone【+32 2 67 57 86 5】

Address【Avenue Gustave Demey 131, 1160 Auderghem】

bottom of page