Goudsmederij Van den Bosch & Van Ranst ("VdB&VR", "we", "us", "our company") is committed to protecting the personal data of everyone we deal with - customers, suppliers, business partners, website visitors, and job applicants - in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Belgian data protection law.
This commitment sits alongside our obligations as an RJC (Responsible Jewellery Council) Member, whose Code of Practices requires lawful and ethical business conduct, including the responsible handling of personal data collected during Know Your Customer (KYC) and Know Your Supplier (KYS) due diligence.
Scope
This policy applies to the personal data of natural persons that we process in the course of our business as a jewellery manufacturer: representatives of our wholesale customers and suppliers, prospective business partners, visitors to our website, job applicants, and individuals whose data is collected as part of KYC and KYS due diligence conducted under our Supply Chain Policy and RJC obligations.
It does not cover the personal data of our own employees, which is addressed separately under our internal HR policies.
Who we are
Goudsmederij Van den Bosch & Van Ranst BV is the data controller for the personal data described in this policy.
Given the scale and nature of our processing activities, we have assessed that the appointment of a statutory Data Protection Officer under Article 37 GDPR is not required. Questions, requests, and complaints regarding personal data should be addressed to compliance@vdbvr.be, which we treat as our privacy contact point.
What personal data we process, and why
We collect only the personal data needed for the purposes below, and no more.
Title
Title
Title
Title
Who
Data we collect
Why we process it
Legal basis (GDPR Art. 6)
Customer and supplier contacts
Name, job title, business email, business phone, employer
Managing the wholesale relationship - orders, quotes, invoicing, correspondence
Performance of a contract / legitimate interest in running the business relationship
Prospective business partners
Name, job title, business contact details, company affiliation
Evaluating and pursuing new distributor or wholesale relationships (including market entry activity)
Legitimate interest in business development
KYC / KYS due diligence subjects
Identity details, proof of business registration, beneficial ownership information, sanctions and watchlist screening results
Verifying the identity and legitimacy of customers and suppliers, as required by our Supply Chain Policy, RJC Code of Practices, and applicable anti-money-laundering obligations
Legal obligation / legitimate interest in responsible sourcing and fraud prevention
Website visitors
Standard technical data (IP address, browser type, pages visited)
Operating and securing the website
Legitimate interest
Job applicants
CV contents, cover letter, interview notes
Recruitment
Steps prior to entering into a contract
Where we rely on legitimate interest, we have considered that interest against the rights and freedoms of the individuals concerned and concluded our interest is not overridden.
Know Your Customer and Know Your Supplier due diligence
As part of our RJC membership and our own Supply Chain Policy, we carry out due diligence on the businesses we buy from and sell to. This may involve verifying the identity of the business and its representatives, confirming beneficial ownership, and screening against publicly available sanctions and adverse-media sources. This processing is limited to what is necessary to confirm the legitimacy of the business relationship and to meet our sourcing and compliance obligations; it is not used for any other purpose.
Who we share personal data with
We share personal data only where necessary, with: professional advisors (accountants, auditors, legal counsel) bound by confidentiality; IT service providers who host or process data on our behalf under data processing agreements; RJC-appointed auditors, to the extent required to demonstrate compliance during certification audits; and public authorities, where disclosure is required by law (for example, anti-money-laundering or hallmarking authorities). We do not sell personal data, and we do not share it with third parties for marketing purposes.
International transfers
Our business is conducted primarily within Belgium and the European Economic Area. Where a service provider is located outside the EEA, we ensure an appropriate safeguard is in place, such as the European Commission's Standard Contractual Clauses, before any personal data is transferred.
How long we keep personal data
We retain personal data only for as long as necessary for the purpose it was collected for. As a general rule: business contact data is kept for the duration of the business relationship and a reasonable period afterward for legal and administrative purposes; accounting and invoicing records are kept for the statutory period under Belgian law (generally seven years); KYC/KYS due diligence records are kept for the period required under applicable anti-money-laundering rules (generally up to ten years after the end of the business relationship); and job applicant data is deleted within twelve months of the application unless the candidate consents to it being kept longer. [Retention periods should be confirmed with legal counsel before publication.]
Data security
We apply appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse, proportionate to the sensitivity of the data concerned.
Your rights
Under the GDPR, you have the right to access the personal data we hold about you, to have inaccurate data corrected, and to request erasure or restriction of processing in certain circumstances. You may object to processing based on our legitimate interest, and where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal. Where technically feasible, you may also request that we transfer your data to another controller.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels, www.gegevensbeschermingsautoriteit.be).
Changes to This Policy
We review this policy annually, in line with our other RJC compliance documents, and update it whenever our processing activities or legal obligations change materially.
Approval
This policy has been reviewed and approved for implementation.