Privacy Statement for Harbour Platform(“Platform”)

Last revised: July 2023

Introduction

Harbour is the tool Deloitte is using with respect to our Contractor Management.

Who this privacy statement applies to and what it covers?

This Privacy Statement applies to all Belgian entities of the DTTL network (referred to below as “Deloitte”, “we”, “us” or “our”). We are committed to protecting your privacy and handling your information in an open and transparent manner.

This privacy statement sets out how we will collect, handle, store and protect information about you when providing services to you and your employer through this Platform(“Services”).

This privacy statement also contains information about when we share your personal data with other third parties (for example, our service providers).

In this privacy statement, your information is sometimes called “personal data” or “personal information”. We may also sometimes collectively refer to handling, collecting, protecting and storing your personal information as “processing” such personal information.

What information we collect?

We will collect or obtain the following personal data about you as part of the Platform:

The Platform uses strictly necessary cookies i.e. cookies that are necessary for the website to function and do not store any personal data. They are only set in response to your request to login.

Cookies are text files containing small amounts of information, which are downloaded to your device when you visit a website. Cookies are useful because they allow a website to recognise your device, preferences and can be used to improve your online experience. You can find more information about cookies at www.aboutcookies.org.

How we use information about you?

We may also use your personal data for the purposes of, or in connection with:

The legal grounds we use for processing personal information

We are required by law to set out in this privacy statement the legal grounds on which we rely in order to process your personal data.

As a result, we use your personal data for the purposes outlined above because of our legitimate interests in providing you access to the Platform and in the effective and lawful operation of our business so long as such interests are not outweighed by your interests (Art. 6.1, f GDPR).

Where we are legally required to obtain your explicit consent to provide you with certain marketing materials, we will only provide you with such marketing materials where we have obtained such consent from you. If you do not want to continue receiving any marketing materials from us, you can click on the unsubscribe function in the communication or e-mail.

Who we disclose your information to?

In connection with one or more of the purposes outlined in the “How we use information about you?” section above, we may disclose personal data about you to competent authorities (including courts and authorities regulating us) or our advisers and your advisers.

We may also need to disclose your personal data if required to do so by law, a regulator or during legal proceedings.

When we share your personal data as mentioned above, the third parties with whom we share the personal data may be in the European Economic Area (“EEA”) or in countries outside the EEA, including countries where the legislation may not offer the same level of data protection. In the latter cases, we will ensure that there are sufficient safeguards to protect your personal data that meets our legal obligations (for example through standard provisions for the transfer of personal data).

For more information about the third parties we work with and how they treat your personal data, or for information on the appropriate measures we take with regard to data transfers to countries outside the EEA where laws do not offer the same level of data protection, please contact the Privacy Office by sending an email to belgiumprivacy@deloitte.com.

Protection of your personal information

We use a range of physical, electronic and managerial measures to ensure that we keep your personal data secure, accurate and up to date. These measures include:

Although we use appropriate security measures once we have received your personal data, the transmission of data over the internet (including by e-mail) is never completely secure. We endeavor to protect personal data, but we cannot guarantee the security of data transmitted to us or by us.

How long we keep your information for?

We will hold your personal data on our systems for the longest of the following periods: (i) as long as is necessary for the relevant activity or services, which means as long as your account on the Platform remains active.; (ii) any retention period that is required by law; or (iii) the end of the period in which litigation or investigations might arise in respect of the Platform.

Your rights

You have various rights in relation to your personal data. In particular, you have a right to:

However, your rights are not absolute. There are cases where applicable laws or legal requirements limit these rights and allow or oblige us to refuse to meet your request, such as confidentiality obligations, the privacy rights of others, the protection of our legitimate business interests or the interests of our employees or clients.

We do everything reasonably possible to ensure that your personal data is correct for the intended use. It is your responsibility to inform us of changes to your personal data.

To exercise your rights, or in case of questions about this Privacy Statement or our use of your personal data as part of the Platform, you can contact the Privacy Office at belgiumconfidential@deloitte.com. When you exercise your rights, please note that the Privacy Office may ask you for specific information to enable them to confirm your identity and the existence and scope of your invoked right.

Right to complain

If you are not satisfied with the way we have processed your personal data, or with the way we have handled your privacy question or request, you have the right to file a complaint with the Belgian Data Protection Authority:

Data protection authority - Authority for protection of data - Data Protection Authority Drukpersstraat 35

1000 Brussels

https://www.gegevensbeschermingsautoriteit.be

Changes to this privacy statement

We may modify or amend this privacy statement from time to time.

To let you know when we make changes to this privacy statement, we will amend the revision date at the top of this page. The new modified or amended privacy statement will apply from that revision date. Therefore, we encourage you to periodically review this statement to be informed about how we are protecting your information.