Privacy Policy & GDPR Commitment

Effective date: 13 May 2025
Last updated: 8 September 2026

Taurix is a brand of Van Sanden BV, Belgium.

This policy explains how we process personal data through our website and in connection with our IT services, and how we protect personal data when processing it on behalf of customers.

Our website is https://www.taurix.net.

What We Process

Depending on how you interact with Taurix, we may process information that you provide to us, such as:

  • your name;

  • company name;

  • email address;

  • telephone number;

  • information submitted through our contact forms or other communications;

  • information required to provide or administer an agreed service.

We may also process limited technical information generated when you use our website, such as IP addresses, browser information and cookies where applicable.

We process personal data only where it is necessary for a defined business or service purpose.

Why We Process Personal Data

Personal data may be processed where necessary to:

  • respond to enquiries;

  • prepare or perform agreements with customers;

  • provide and support our IT services;

  • administer customer and supplier relationships;

  • operate and secure our website and systems;

  • meet legal obligations;

  • protect our legitimate business and security interests where permitted by law.

The applicable legal basis depends on the processing activity and may include performance of a contract, compliance with a legal obligation, consent or legitimate interests.

Customer Systems and Customer Data

Taurix provides IT services including infrastructure management, hosting, storage, monitoring, technical support, software and website development, security services and data recovery.

As part of these services, Taurix may have technical access to systems containing personal data controlled by a customer.

Where Taurix processes personal data on behalf of a customer:

  • we process it only to provide the agreed service and in accordance with the customer’s documented instructions;

  • we do not use customer personal data for unrelated purposes;

  • access is limited to authorised persons who need it for their work;

  • we avoid accessing personal data where a technical task can reasonably be completed without doing so;

  • applicable confidentiality obligations apply;

  • where Article 28 GDPR requires it, the processing is governed by a Data Processing Agreement.

The customer remains responsible for determining the purposes and legal basis of the underlying processing where Taurix acts as processor.

Security

We apply technical and organisational security measures appropriate to the service, systems involved and identified risks.

Depending on the environment, these measures may include:

  • authentication and access control;

  • restricted administrative access;

  • secure system configuration;

  • network security;

  • encryption where appropriate;

  • backups and recovery measures;

  • logging and monitoring;

  • vulnerability and patch management;

  • incident detection and response.

Not every measure applies identically to every customer environment. Controls are selected according to the actual service and risk.

Data Minimisation

We limit personal-data processing to what is necessary for the relevant purpose.

Technical access to a system does not automatically justify viewing the personal data stored in it. Access to customer data should be limited to what is required to perform the authorised task.

Comments

If comments are enabled on our website and you leave a comment, we may collect the information entered in the comment form together with the visitor’s IP address and browser user-agent information for security and spam-detection purposes.

Where Gravatar is used, an anonymised hash derived from your email address may be sent to the Gravatar service to determine whether you use that service. If your comment is approved, a profile picture associated with Gravatar may be displayed with your comment.

Media

If the website allows users to upload images, uploaded files may contain embedded metadata such as EXIF location information.

Users should remove location information they do not wish to disclose before uploading images.

Cookies

Our website may use cookies necessary for website functionality and administration.

Where WordPress account, comment or publishing functionality is available, WordPress may use cookies to:

  • remember information entered when leaving comments;

  • maintain authenticated sessions;

  • remember login preferences;

  • store administrative interface preferences;

  • identify recently edited or published content.

Cookies that are not strictly necessary will only be used where permitted under applicable requirements.

Embedded Content

Pages on our website may contain embedded content from third-party websites, such as videos or other media.

Embedded content can cause the third party to receive technical information about your visit and may allow that third party to use cookies or other tracking technologies.

The third party’s own privacy rules apply to its processing.

Sharing Personal Data

We do not sell or rent personal data.

Personal data may be disclosed where this is necessary to:

  • provide an agreed service;

  • use a supplier or subprocessor required for that service;

  • comply with a legal obligation;

  • protect the security or lawful interests of Taurix, our customers or other persons where permitted by law.

Where a third party processes personal data on our behalf and the GDPR requires a processor agreement, appropriate contractual requirements apply.

Subprocessors

When Taurix processes customer personal data as a processor and another provider is required to process that data as part of the service, applicable GDPR and contractual requirements concerning subprocessors apply.

We do not classify every supplier as a subprocessor. This applies only where the supplier actually processes relevant personal data.

International Transfers

Where personal data is transferred outside the European Economic Area, or is made accessible from outside the EEA, we assess whether the GDPR requirements for international transfers apply.

Where required, an appropriate transfer mechanism must be in place.

Retention

We retain personal data only for as long as necessary for the relevant purpose, subject to legal, contractual and evidentiary requirements.

For customer data processed on behalf of a customer, retention and deletion follow the applicable agreement, documented customer instructions and legal requirements.

If website comments are enabled, comments and their associated metadata may be retained so that follow-up comments can be recognised and managed.

If registered user accounts exist, profile information may be retained for as long as the account is required.

We do not retain customer personal data indefinitely merely because Taurix previously had technical access to it.

Personal Data Breaches

If Taurix becomes aware of a personal-data breach involving customer data processed on behalf of a customer, we notify the relevant customer without undue delay.

Where Taurix acts as controller, we assess whether notification to the competent supervisory authority or affected individuals is required under the GDPR.

Your Rights

Where Taurix acts as controller, you may have rights under the GDPR including:

  • the right to information;

  • access to your personal data;

  • correction of inaccurate personal data;

  • deletion where the applicable conditions are met;

  • restriction of processing;

  • objection to processing;

  • data portability where applicable;

  • withdrawal of consent where processing is based on consent.

These rights depend on the nature and legal basis of the processing and are therefore not absolute in every situation. The Belgian Data Protection Authority describes these rights and the applicable conditions in its GDPR guidance.

Where Taurix processes personal data solely on behalf of a customer, requests concerning that data are normally handled by the customer as controller, with assistance from Taurix where required.

Exercising Your Rights

To exercise a privacy right or ask a question about our processing of personal data, contact us through:

https://www.taurix.net/contact

We may need sufficient information to identify the relevant data and verify the identity of the person making the request.

GDPR requests must generally be answered within one month, subject to the extensions and exceptions provided by the GDPR.

Complaints

If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with the competent supervisory authority.

For Belgium:

Gegevensbeschermingsautoriteit / Autorité de protection des données

You may also contact Taurix first so that we can investigate the matter.

Contact

This website and Taurix services are operated by:

Van Sanden BV
Belgium
Trading under the name Taurix

Website: https://www.taurix.net
Privacy enquiries: https://www.taurix.net/contact