Version 1.0
Date: 14 July 2026
1 Identity and contact details of the data controller
This privacy policy applies to all personal data processed by BV NightSkyOptics, with registered office at Mariakerksesteenweg 114/C, 9031 Gent, with company number 1035.688.497, which is the data controller of this website.
The data controller attaches great importance to your privacy and therefore processes your personal data in accordance with European Regulation 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (hereinafter “GDPR”), as well as any future or supplementary legislation implementing it, insofar as applicable.
For further questions or comments regarding the way in which we handle your personal data, you can al-ways contact us, either by e-mail to info@nightskyoptics.eu or by post letter to the aforementioned postal address.
2 What does “processing personal data” mean?
The processing of personal data (hereinafter “data”) covers any processing of data that can identify you as a natural person. Which data this concerns is explained in this Privacy Policy. The term ‘processing’ is very broad and covers, among other things, the collection, storage and use of your data, or the sharing thereof with third parties.
3 What data do we process?
Below we explain which data we may process about you. Depending on the specific situation, your prefer-ences and the way in which you contact us, we do not process all of the data listed below.µ
3.1 General
From all our contacts, we may process the following data:
– Electronic identification and usage data (e.g. IP address, browser type, location data);
– Identification data (e.g. copy of your identity card in the context of a GDPR request);
– Contact details (e.g. surname, first name, address, billing address, e-mail address, telephone num-ber, etc.);
– Contact history (e.g. e-mails, messages sent via web forms, etc.);
– Security camera footage (e.g. for monitoring and securing our business premises).
3.2 Main activity
From our customers in the context of our commercial activities, we may additionally process the following data:
– Order and payment data (payment data may be processed directly by our payment provider)
– Aftersales data
– Feedback, testimonials and promotional content such as photos and videos
A distinction is made, however, depending on whether or not you have a customer account:
– If you have a customer account, we process a username, e-mail address and hashed password, as well as additional optional profile data.
– An account is not required for data processing; even if you do not have an account, order data from a guest order can be processed.
3.3 Suppliers – service providers
From our suppliers and service providers, we may additionally process the following data:
– Contractual data (e.g. company name, address, VAT number, agreement, etc.);
– Payment and invoicing data (e.g. payment card details, invoices, etc.);
– Account data for platforms (e.g. registration data for account creation);
– Feedback, testimonials, quotes, promotional content such as photos and videos (e.g. reviews and experiences relating to our (co)operation, testimonials, quotes, presence at events, etc.).
3.4 Job applicants
From job applicants, we may additionally process the following data. This will, of course, largely depend on which data you yourself wish to provide to us in connection with your application.
– Personal details;
– Work-related data;
– Personality data;
– Photos.
4 For which purposes do we process your data?
We process your data for the purposes described below and do not collect or process more data, or other types of data, than are necessary for these purposes.
The personal data are processed exclusively within the context of the business and, in particular, for the following purposes:
– Maintaining our webshop, processing customer orders, handling aftersales matters, and maintain-ing the overall commercial relationship with our customers.
– General and specific marketing activities to promote our products and services
– Organising events, competitions and meetings
– Participating in trade fairs
– Complying with administrative and tax obligations
– Communication with customers and prospects
– Employee recruitment procedures
– Improving our webshop and services
5 On which legal bases do we process your data?
We only process your data insofar as this is based on one of the legal bases listed in the GDPR, as set out below.
5.1 Legal obligation
Certain data are processed by us in order to comply with legal or regulatory obligations that apply to us. For example in the context of tax and accounting obligations or in the field of data protection.
5.2 Necessary for the performance of the agreement
Certain data are processed by us because it is necessary for entering into, performing or terminating an agreement with you as a data subject. For example for contacting, scheduling, responding to a request or requesting information in the context of entering into a contractual relationship, as well as the actual per-formance of the contractual assignment within the context of our main activity, in order to be able to pro-vide you with our services or to receive yours.
5.3 Legitimate interest
Certain data are processed by us on the basis of our legitimate interests, which in specific cases outweigh any possible disadvantage to your rights. For example for promoting our activities to business contacts; improving the quality of our services; training employees and evaluating and maintaining data and statistics relating to our activities, in the broad sense; retaining and using evidence in the context of liability, proceed-ings or disputes and with a view to archiving our activities; and ensuring security, both online on this website and within our business premises.
5.4 Consent
Certain data are processed by us on the basis of your consent. For example for promoting activities to po-tential business contacts; the use of certain analytical or marketing cookies; the posting of photos contain-ing personal data on our website and social media channels. Data of job applicants will only be retained after the recruitment procedure with consent.
6 Origin of the data
Most of the data we process about you have also been obtained directly from you. Within the context of our services, it is possible that we obtain data about you via external service providers or public sources.
7 With whom do we share your data?
We do not disclose your data to third parties, unless this is strictly necessary in light of the purposes men-tioned above, or if we are legally obliged to do so.
Where necessary, we make use of external service providers (processors) to support our operational pur-poses, such as the management of our websites and IT systems. These external service providers carry out certain data processing activities on our behalf, where applicable. We will only share your data with these external service providers to the extent necessary for the relevant purpose. They may not use the data for other purposes. Moreover, these service providers are contractually bound to safeguard the confidentiality of your data by means of a “data processing agreement” concluded with these parties.
Essentially, this means that we share your data, insofar as relevant to your situation, with the following third parties for the following purposes, whereby these third parties in certain cases act as processors on our behalf:
– Postal, transport and delivery companies and related service providers if we need to send you something by post, or vice versa;
– Payment service providers if we receive payments from you, or vice versa;
– External representatives and consultants or any other parties involved in the context of our main or ancillary activities;
– Processors that assist us in IT matters in operating our organisation, with a view to safe and effi-cient digital data management within our organisation;
– Government bodies, judicial authorities and practitioners of regulated professions such as account-ants and lawyers, with a view to complying with our legal obligations and defending our interests, insofar as required.
8 How long do we retain your data?
We do not retain your data for longer than necessary for the purpose for which the data were collected or are processed. Since the period for which the data may be retained depends on the purposes for which the data were collected, the storage period may vary from situation to situation. Sometimes specific legislation will require us to retain the data for a certain period. Our retention periods are always based on legal re-quirements and a balancing of your rights and expectations against what is useful and necessary to fulfil the purposes.
For example:
– Contractual information such as the details of your order, invoices, and related communication, is retained for ten years after the placement of your order.
– For as long as you remain a customer, your account data will be retained. If you can no longer be considered an active customer, your account data will be deleted, except where such data may or must be retained on other grounds. You are no longer an active customer if you have not logged in-to our webshop for two years, even after prior notification by us.
Once the retention period has expired, your data will be erased or anonymised.
9 Where do we store your data and how is it protected?
We implement appropriate technical and organisational security measures to prevent, within the context of our activities, the destruction, loss, falsification, alteration, unauthorised access to or unlawful disclosure to third parties, as well as any other unauthorised processing of this data.
In addition, we also ensure that the processors we engage likewise take appropriate security measures to limit the risk of incidents as much as possible.
The data we process always remain within the European Economic Area (EEA). If your data are processed outside the European Economic Area (EEA) when using specific services or software tools, this will only take place in/to countries for which the European Commission has confirmed that they guarantee an adequate level of protection for your data, or measures will be taken to ensure the lawful processing of your data in these third countries.
10 What are your rights?
You have various rights with regard to the data we process about you. If you wish to exercise any of the following rights, please contact our GDPR officer using the contact details provided under the first heading of this Privacy Policy.
10.1 Right to access and copy
You have the right to access your data and to receive a copy of it. This right also includes the possibility of requesting further information regarding the processing of your data, including the categories of data pro-cessed about you and the purposes for which this is done.
10.2 Right to rectification
You have the right to have your data corrected if you believe that we hold inaccurate data.
10.3 Right to erasure (right to be forgotten)
You have the right to request that we erase your data without undue delay. However, we will not always be able to grant such a request, including where we still need the data in connection with an ongoing agree-ment, or where the retention of certain of your data for a specific period is legally required.
10.4 Right to restriction of processing
You have the right to restrict the processing of your data. This means that processing is temporarily sus-pended until, for example, there is certainty about its accuracy.
10.5 Right to withdraw your consent
Where processing is based on your consent (see headings 5 and 6 above), you have the right to withdraw this consent at any time by contacting us. For marketing messages that you receive from us by e-mail on the basis of your consent, you can easily withdraw this consent by clicking on the unsubscribe link at the bottom of such a message.
10.6 Right to object
You have the right to object to the processing of your data that is based on legitimate interest. This must be done on the basis of specific grounds relating to your situation. You may also object to the use of your data for direct marketing purposes. Marketing messages sent by e-mail will always include an opt-out option.
10.7 Right to data portability
You have the right to obtain, in electronic form, the data you have provided to us yourself on the basis of your consent or in the performance of an agreement. This allows the data to be easily transferred to anoth-er organisation. You also have the right to request that we transfer your data directly to another organisa-tion, where this is technically feasible.
10.8 Right to lodge a complaint with your supervisory authority
If you believe that we are processing your data incorrectly, you always have the right to lodge a complaint with your supervisory authority for data protection.
Belgian Data Protection Authority (DPA)
Drukpersstraat 35
1000 Brussels
contact@apd-gba.be
11 How can you exercise your rights?
You can exercise your rights by contacting us, either by e-mail to info@nightskyoptics.eu or by postletter to Mariakerksesteenweg 114/C, 9031 Ghent, enclosing a copy of the front of your identity card or another document by which you can be identified. The copy will only be used to identify you in accordance with the GDPR.
12 Amendments
We reserve the right to amend this Privacy Policy. The most recent version is always available on our websites. The date on which this Privacy Policy was last amended can be found at the top. In the event of a substantial amendment to the Privacy Policy, we will, where possible, inform directly those data subjects who may be affected by it.