PRIVACY POLICY

PRIVACY POLICY

Last updated: 21 September 2027

NANO IT Cyber Security Consulting / JERA Consulting SRL (“NANO IT Cyber Security Consulting”, “JERA Consulting”, “we”, “us” or “our”) is committed to protecting the privacy and personal data of individuals who visit our website, communicate with us, use our services, or otherwise interact with us.

This Privacy Policy explains how we collect, use, store, protect and disclose personal data in accordance with applicable data protection legislation, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Belgian legislation.

By using our website or providing us with personal information, you acknowledge that you have read and understood this Privacy Policy.


1. Data Controller

The entity responsible for the processing of your personal data is:

JERA Consulting SRL
Trading / commercial name: NANO IT Cyber Security Consulting
Company registration number: BE0792.561.264
VAT number: BE0792.561.264
Email: privacy@nanoit.be

For questions concerning the processing of your personal data or the exercise of your rights, you may contact us using the contact details above.

Where applicable, JERA Consulting SRL acts as the Data Controller for personal data processed through this website and in connection with our consulting, recruitment, business development and professional services.


2. Personal Data We May Collect

Depending on how you interact with us, we may collect the following categories of personal data:

Identification and contact information

This may include:

  • First and last name
  • Professional title or position
  • Company or organisation
  • Email address
  • Telephone number
  • Business address
  • Country or region

Professional information

Where relevant to our consulting or recruitment activities, we may process:

  • CVs and professional profiles
  • Employment history
  • Professional qualifications
  • Certifications
  • Skills and expertise
  • Education and training
  • Professional references
  • Availability
  • Professional preferences
  • Information provided during recruitment or consulting engagements

Communication information

We may process information contained in communications you send to us, including:

  • Emails
  • Contact forms
  • Requests for information
  • Meeting-related information
  • Business correspondence
  • Feedback

Website and technical information

When you visit our website, certain technical information may automatically be collected, including:

  • IP address
  • Browser type and version
  • Device type
  • Operating system
  • Language preferences
  • Approximate geographic location
  • Pages visited
  • Date and time of access
  • Referring website
  • Technical logs
  • Website usage information

This information may be collected through server logs, cookies or similar technologies.


3. How We Collect Personal Data

We may collect personal data through:

  • Our website and online forms
  • Email communications
  • Telephone or video communications
  • Business meetings
  • Recruitment applications
  • Professional networking platforms
  • Events and conferences
  • Direct interactions with clients, candidates, suppliers and partners
  • Publicly available professional sources
  • Referrals from business contacts
  • Contractual and commercial relationships

We only collect personal data that is reasonably necessary for the purposes described in this Privacy Policy.


4. Purposes of Processing

We may process personal data for the following purposes:

Business and consulting services

To:

  • Provide IT consulting and professional services
  • Manage client relationships
  • Prepare proposals and statements of work
  • Manage projects and assignments
  • Communicate with clients and partners
  • Provide technical or advisory services
  • Manage contractual obligations

Recruitment and talent management

Where applicable, we may process professional information to:

  • Assess professional profiles
  • Identify suitable candidates for assignments or opportunities
  • Communicate with candidates
  • Manage recruitment processes
  • Present candidate profiles to clients where legally permitted and appropriate
  • Maintain professional talent databases
  • Manage future professional opportunities

Business development

We may process professional contact information to:

  • Identify potential clients or partners
  • Communicate about our services
  • Send relevant professional information
  • Organise meetings
  • Develop commercial relationships

Where required by law, we will obtain appropriate consent before sending direct marketing communications.

Website operation and security

We may process technical information to:

  • Operate our website
  • Maintain website security
  • Detect and prevent fraudulent or malicious activity
  • Diagnose technical problems
  • Improve website performance
  • Protect our IT infrastructure

Legal and regulatory compliance

We may process personal data where necessary to:

  • Comply with legal obligations
  • Respond to lawful requests from public authorities
  • Establish, exercise or defend legal claims
  • Maintain appropriate business records
  • Prevent fraud or abuse

5. Legal Basis for Processing

Depending on the circumstances, we rely on one or more of the following legal bases under the GDPR:

Performance of a contract

Processing may be necessary to enter into or perform a contract with you.

Legitimate interests

We may process personal data where necessary for our legitimate business interests, provided that these interests do not override your fundamental rights and freedoms.

Examples may include:

  • Managing professional relationships
  • Business development
  • IT and information security
  • Fraud prevention
  • Website security
  • Managing professional networks
  • Improving our services

Consent

Where required, we may rely on your consent, for example for certain marketing communications or non-essential cookies.

You may withdraw your consent at any time.

Legal obligation

We may process personal data where necessary to comply with applicable legal or regulatory requirements.


6. Cookies and Similar Technologies

Our website may use cookies and similar technologies.

Cookies may be used for purposes such as:

  • Essential website functionality
  • Security
  • Website performance
  • Analytics
  • Understanding how visitors use our website
  • Remembering preferences
  • Marketing, where applicable

Where legally required, non-essential cookies will only be activated following your consent.

You may manage or withdraw your cookie preferences through our cookie management mechanism or through your browser settings.

Further information may be provided in our Cookie Policy, where applicable.


7. Third-Party Services

Our website or business operations may rely on third-party providers, such as:

  • Website hosting providers
  • Cloud service providers
  • Email and communication providers
  • IT security providers
  • Analytics providers
  • Recruitment or professional platforms
  • CRM or business management systems
  • Video conferencing services
  • Professional social networking platforms

These providers may process personal data on our behalf or independently, depending on the nature of their services.

Where a provider acts as a processor on our behalf, we take appropriate contractual and organisational measures to ensure that personal data is processed in accordance with applicable data protection requirements.


8. Sharing of Personal Data

We do not sell personal data.

We may disclose personal data where necessary to:

  • Clients and prospective clients
  • Professional partners
  • Suppliers and service providers
  • IT and cloud service providers
  • Professional advisers
  • Legal or regulatory authorities
  • Courts or law enforcement authorities where legally required
  • Other parties where you have provided appropriate authorisation

Where candidate or consultant information is shared with a potential client, we seek to ensure that the disclosure is relevant, proportionate and consistent with applicable data protection requirements.


9. International Data Transfers

Some of our service providers or business partners may process personal data outside the European Economic Area (EEA).

Where personal data is transferred outside the EEA, we will take appropriate measures to ensure that the transfer is carried out in accordance with applicable data protection law.

Depending on the circumstances, this may include:

  • An adequacy decision of the European Commission
  • Standard Contractual Clauses approved by the European Commission
  • Appropriate technical and organisational safeguards
  • Other lawful transfer mechanisms recognised under the GDPR

10. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including:

  • Providing services
  • Managing contractual relationships
  • Managing recruitment and professional opportunities
  • Maintaining business records
  • Complying with legal obligations
  • Resolving disputes
  • Protecting our legitimate business interests

Retention periods may vary depending on the type of information and the applicable legal or contractual requirements.

When personal data is no longer required, we will delete, anonymise or securely archive it where appropriate.


11. Data Security

We take reasonable technical and organisational measures to protect personal data against:

  • Unauthorised access
  • Accidental loss
  • Destruction
  • Alteration
  • Unauthorised disclosure
  • Cybersecurity threats

Security measures may include access controls, authentication mechanisms, encryption where appropriate, backups, monitoring, secure communications and other appropriate information security practices.

However, no internet transmission or information system can be guaranteed to be completely secure.


12. Your Rights Under the GDPR

Subject to applicable legal conditions, you may have the following rights:

Right of access

You may request confirmation as to whether we process your personal data and request a copy of that information.

Right to rectification

You may request correction of inaccurate or incomplete personal data.

Right to erasure

You may request deletion of your personal data in certain circumstances.

Right to restriction

You may request that processing of your personal data be restricted in certain circumstances.

Right to object

You may object to certain processing activities, including processing based on legitimate interests or direct marketing.

Right to data portability

Where applicable, you may request your personal data in a structured, commonly used and machine-readable format.

Right to withdraw consent

Where processing is based on consent, you may withdraw your consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.


13. Exercising Your Rights

To exercise your rights, please contact us at:

Email: [privacy@domain.com]

Please include sufficient information to allow us to identify your request and verify your identity where necessary.

We will normally respond to valid requests within the timeframe required by applicable data protection legislation.

We will not normally charge a fee for exercising your GDPR rights. However, applicable law may allow us to charge a reasonable fee or refuse a request where requests are manifestly unfounded or excessive.


14. Right to Lodge a Complaint

If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with the competent data protection supervisory authority.

For Belgium, the relevant authority is the:

Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit)

You may contact the Belgian Data Protection Authority through its official website.

This right is without prejudice to any other administrative or judicial remedy available to you.


15. Children’s Privacy

Our website and professional services are not intended specifically for children.

We do not knowingly collect personal data from children where such collection would be prohibited by applicable law.

If you believe that a child has provided personal data to us unlawfully, please contact us so that we can take appropriate action.


16. Third-Party Websites

Our website may contain links to third-party websites, platforms or services.

We are not responsible for the privacy practices, security or content of third-party websites.

We recommend reviewing the privacy policies of any third-party website before providing personal information.


17. Professional and Recruitment Information

Where we operate recruitment, talent sourcing or professional placement activities, individuals may provide us with professional information such as CVs, qualifications, certifications, employment history and professional preferences.

Such information will be used only for legitimate professional purposes, including evaluating profiles, communicating about opportunities and, where appropriate and legally permitted, presenting relevant profiles to clients.

Individuals may request access, correction or deletion of their professional information at any time, subject to applicable legal and contractual requirements.


18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes in our services
  • Changes in our website
  • Changes in technology
  • Changes in applicable legislation
  • Changes in our data processing activities

The updated version will be published on this page with an updated “Last updated” date.

We encourage you to review this Privacy Policy periodically.


19. Contact Us

If you have any questions regarding this Privacy Policy or the way we process personal data, please contact:

Nano IT Cyber Security Consulting / JERA Consulting SRL
+32.2.342.07.40 (Office)
Bureau & Studio
Boulevard de France 9,
1420-Braine-l’Alleud, Belgium.

Ethical Hacking & Critical Security
Security Essentials & Clearance
Pentesting & Vulnerability
Legal & Cyber Recovery Data

www.nanoit.be


Nano IT Cyber Security Consulting / JERA Consulting SRL
IT Consulting | Cybersecurity | Governance | Risk | Digital Transformation | Project & Programme Management

error: Content is protected !!