Last updated
Who we are
EU Accounting Services is the data controller for the personal data described in this policy. You can reach us at info@euaccountingservices.com or by post at Boulevard Edmond Machtens 79/B23, 1080 Brussels, Belgium.
Where we process payroll, HR or accounting data on behalf of a client company, that client is the controller and we act as processor under a separate data-processing agreement.
What we collect
We collect only what we need to answer you and to deliver the services you engage us for.
- Contact details you submit through our forms: name, company, work email, phone number and country.
- Engagement data: the services you are interested in and anything you tell us in a message.
- Client service data: employee records, payroll inputs, invoices and ledgers, processed on your instruction.
- Technical data: anonymised page analytics and server logs used to keep the site running and secure.
Why we are allowed to process it
Enquiry data is processed on the basis of your consent, which you can withdraw at any time. Client service data is processed to perform our contract with you, and to meet legal obligations such as statutory filings and record retention.
Who we share it with
We share personal data only with parties needed to deliver the service: social secretaries, tax and social security administrations, and vetted software providers acting as sub-processors under contract. We never sell personal data.
International transfers
Part of our delivery team is based in Islamabad, Pakistan. Transfers outside the European Economic Area are covered by Standard Contractual Clauses together with a transfer impact assessment and the same technical and organisational controls applied to EU-side processing. A copy of the safeguards is available on request.
How long we keep it
Enquiry data is kept for twenty-four months from your last contact with us unless you ask us to delete it sooner. Client accounting and payroll records are kept for the statutory retention period in the relevant jurisdiction, which is typically seven to ten years.
How we protect it
Data moves over encrypted channels only, sits in access-controlled systems, and is visible to a named team on a least-privilege basis. Access is reviewed when people join, change role or leave, and every engagement is covered by a non-disclosure agreement.
Complaints
If you believe we have handled your data incorrectly, contact us first — we would rather fix it directly. You also have the right to lodge a complaint with the Belgian Data Protection Authority or the supervisory authority in your country of residence.
Your rights under the GDPR
You can exercise any of these by emailing us. We respond within one month.
- Access — ask what personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — ask us to delete data we no longer need to keep.
- Restriction and objection — limit how we process your data.
- Portability — receive your data in a machine-readable format.
- Withdraw consent — at any time, without affecting past processing.
