Login
Service Contact Lex4You
Login

Privacy Statement Social Secretariat Securex

Who are we?    

The Securex Social Secretariat and Group Securex, whose registered offices are located in Belgium, at 1040 Brussels, Avenue de Tervuren 43, VAT BE0401.086.981, RPR Brussels and who can be contacted by telephone at + 32 2 729 92 11 and by e-mail at info@securex.be 

Securex an international player in the field of social administration and HR for individuals, start-ups, the self-employed, SMEs and large companies. As a full-service HR partner, we focus on the well-being and talent of employees, collaborators, companies and the self-employed. Sustainable employability is important, for everyone. That is why we develop various solutions to support those involved preventively and proactively. 

In doing so, Securex also develops and manages HR management solutions that help companies and their employees to streamline their most important HR processes.  

Usually, in our services and the processes behind them, we act as controller of your personal data. You should then contact us with any questions or comments. When companies and/or their employees use our solutions and applications and upload or process personal data in these solutions, we may also act as a data processor on behalf of our clients. In that case, your employer is the first point of contact in case of questions or comments about this data. 

This privacy statement relates to the processing of personal data when using our tools and solutions in the context of payroll or other activities linked to payroll and/or social administration of employees and complements the privacy statement of your employer, which is to be regarded as the controller of personal data processing in the context of payroll and social administration. 

When processing your personal data, Securex can act both as a controller and as a processor for your employer. In doing so, we always attach great importance to the protection of your privacy, your personal data and your feedback.  

Purpose of processing personal data

With our tools, we offer a complete range for HR administration and payroll activities. 

  • MyWork : a complete and integrated mobile application for HR administration and payroll activities, designed for both employers and employees 
  • HR Accent: the solution for large companies in their management of payroll and HR administration    
  • Officient : the solution for SMEs and micro-enterprises to manage their payroll activities and data input 
  • MyDimona : a user-friendly tool for managing the workforce and declaring employment to underlying payroll engines and the government 
  • Isypass : an integrated solution for managing employee data and transmitting time entries and/or performance digitally  
  • HR Online Express : a user-friendly tool for digital transmission of employee performance data   

Personal data is processed by Securex in accordance with European Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter AVG) as a result of the use of our services and solutions by you or your employer.  

Your personal data will be processed for the following purposes:  

  • To comply with laws, regulations and instructions at regional, federal and international level on labour law, social security, tax law, including collective and individual labour agreements and your employer's labour regulations
  • To respond to your questions or requests 
  • Because of a legitimate interest of the controller or a third party to organise and/or improve services 
  • Because of a legitimate interest of the controller to monitor and evaluate the ease of use and performance of the application in order to continuously improve the service and user experience    

In more detail, we talk about the following possible purposes and processing: 

  • Your registration as a user of our tools and applications 
  • Managing your personnel file under your employment contract 
  • Processing performance data 
  • Payroll administration  
  • Statutory returns (DMFA, Dimona ASR, Belcotax...) 
  • Recording of arrivals and/or absences  
  • Service planning and organisation 
  • Automating training management  
  • Monitoring performance and evaluations 
  • Monitoring usage and ease of use 
  • Integration and exchange with various HR Partners of your employer 
  • HR Management reporting, insights, information and advice for both the employer and the individual concerned 
  • Targeted (internal) communication  

Legal basis for the processing

The legal basis for processing personal data of employees, whether or not they are users of our solutions, is based on: 

  • The execution of the agreement between your employer and Securex 
  • The performance of the agreement between you and your employer 
  • Your employer's legal obligation under employment and social security law 
  • Your use of one or more of our solutions and/or your request or consent to process or share data

The legal basis for the processing of personal data in the planning, organisation and quality improvement of services through, inter alia, the monitoring and evaluation of performance and training, is based on the legitimate interest of your employer to  

  • organise and manage operations optimally  
  • allow employees to work and develop themselves in optimal conditions

The legal basis for the analysis and evaluation of our tools and services by and with users is based on Securex's legitimate interest to optimally manage its services and products and gain insight into how they are experienced and used so that ease of use and performance can be optimised.  

The legitimate interest of Securex is also the legal basis for processing personal data of contact persons or representatives of the employer with regard to 

  • Customer Contract & Relationship Management: for business management and its optimisation  
  • Direct marketing activities: to promote the services of EDPB Securex, as well as the services of the other Securex entities, to its customers.

Securex will only send you general newsletters and/or e-zines if you have given your consent.   

Categories of data subjects

Securex processes personal data of employees of our member employers, users of the applications and contact persons of employers who use the applications and/or make use of this service. 

Categories of processed data

Personal data can be defined as any information relating to an identified or identifiable natural person (data subject). 

Securex only processes what is strictly necessary for the services and/or purposes and, in function of the application or solution, processes or can process the following data, among others:  

  • Identification data (including name, national register number, date of birth, nationality...) 
  • Contact details (address, phone number, e-mail address...) 
  • Family data (status, partner, children...) 
  • Financial & payroll data (wages, bank details, expenses...) 
  • Entry and exit dates  
  • Data relating to statute and joint committee 
  • Data related to the job or work post and/or career (position, location,...)  
  • Performance and evaluation data  
  • Arrivals and absences  
  • Training courses followed and professional qualifications 
  • Personal characteristics (e.g. shoe size and/or clothing size) 
  • If applicable, data relating to memberships or other relevant administrative-medical data 
  • Commuting data 
  • If applicable, details of company car and (other) benefits of all kinds 
  • Contracts and other documents necessary or useful for the employment relationship   
  • Anonymised or pseudonymised application usage data and statistics   

Some data is only processed to grant you, through your employer, a benefit. 

Personal data can either be provided by you yourself or by or through your employer: your employer can either provide us with personal data directly or can do so through integration with other HR Partners or service providers.   

Data retention period

Securex will not store your personal data for longer than strictly necessary for processing purposes and for as long as required by law. 

Unless otherwise required by law, we keep (certain) data for 10 years after the close of the financial year in which the last payroll calculation was granted. 

Confidentiality and data protection

In accordance with current legislation, Securex ensures an adequate level of protection for personal data. These measures include the technical and organisational measures necessary to protect personal data against accidental or unauthorised destruction, against accidental loss, as well as against the modification of, access to, and any other unauthorised processing of personal data. 

Nevertheless, Securex points out that no security system can guarantee 100% security. However, one can always contact us for any questions regarding the confidentiality and security of your personal data. 

Data recipients

Your personal data will be processed and shared only in function of the purposes provided: 

  • Certain of these data may hereby be passed on to subcontractors, who provide certain services in the strict context of a subcontracting agreement and for the sole purpose of providing Securex with the necessary technical assistance. 
  • Through our applications and solutions, your personal data in your personnel file can be shared with your employer, who is finally responsible for this processing and the management of your personnel file. 
  • Depending on the choices or request of your employer and if in accordance with legal provisions, at the request of your employer or at your request, some data may also be shared with your colleagues or other third parties.  

However, in exceptional cases, it may also happen that Securex must pass on certain personal data to the supervisory authorities, to our lawyers, to our experts or to judicial bodies.   

Transfer of data to third countries

Securex does not transfer personal data outside the European Economic Area.  

If a data transfer to a country outside the EEA should nevertheless be necessary for the performance or provision of services, Securex will implement appropriate safeguards in accordance with data protection legislation and ensure that enforceable rights and effective remedies are available to data subjects.  

To ensure enforceable rights and effective remedies for data subjects, the processing and transfer can then only take place under one of the following conditions:  

  • the transfer is to countries offering an adequate level of protection based on European Commission adequacy decisions 
  • the transfer is to a (sub-)processor to which Binding Corporate Rules apply. These corporate rules guarantee an adequate level of protection  
  • the transfer is to a (sub-)processor with whom an additional model agreement has been concluded (Standard Contractual Clauses, cf (EU) 2021/914 of 4 June 2021) and for which an additional risk analysis has also been carried out beforehand. The contractual provisions and any additional measures following a prior risk analysis or data transfer impact assessment must then offer the necessary guarantees in terms of data protection.    

If there are no appropriate guarantees about the level of protection, Securex will not transfer (or have transferred) personal data to such third countries, unless after consent of the data subject. 

Your rights

Through certain of our tools (e.g. MyWork and Employee Selfservice ), you can access your data and, where necessary and or possible, correct it yourself. 

You can also learn about the data processed by Securex and, if necessary, have it corrected by means of a dated and signed request, sent together with a copy of the recto of the identity card via e-mail to the address privacy@securex.be or by post to Group Securex, Data Protection Officer, Avenue de Tervuren 43, 1040 Brussels.  

You can also oppose the data processing or request that such processing be restricted according to the same modalities, and within the limits set by the AVG. You can also request that your data be deleted or transferred. More information can be obtained at the same address. 

Therefore, although we take your rights and freedoms seriously, they do not apply in all circumstances and there may be circumstances where we cannot comply with your request, for example where this would mean that we would not comply with our own legal or contractual obligations with, for example, your employer, as data controller. In these cases, we will always let you know why we cannot comply and whether you need to check with your employer, for example.  

If you believe there is a breach of processing or your rights, you can complain to the Data Protection Authority if necessary.