Legal notice

Privacy Policy

How The After SRL collects, uses, shares and protects personal data, in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation) and Belgian law.

Version 2.0. Last updated 3 September 2026. This version replaces all earlier privacy statements.

I take privacy seriously, and not only because the law requires it. My work gives me access to what people inside an organisation actually think during a period of change. Handling that carefully is part of the job.

1. Who is responsible for your data

The data controller is:

The After SRL

Avenue JF Debecker 111, B-1200 Brussels, Belgium

Enterprise / VAT number: BE 0892.297.654

Email: dh@theafter.be

The After SRL is a small consultancy and is not required to appoint a Data Protection Officer under Article 37 GDPR. All privacy matters are handled directly by David Hachez at the address above.

When I work inside a client organisation on an assignment, that client is normally the controller for the personal data processed as part of the engagement, and I act as a processor on their documented instructions under a separate data processing agreement. This policy covers the data for which The After SRL is itself the controller.

2. Scope of this policy

This policy applies to personal data processed when you:

  • visit theafter.be;
  • contact The After SRL by email, telephone, LinkedIn or any other channel;
  • book an appointment through the online scheduling link;
  • are a client, a prospective client, or a contact person at either;
  • take part in a workshop, training session or lecture I deliver;
  • are a supplier, subcontractor or partner of The After SRL.

3. What data I process, and why

Website visitors

This website has no contact form, no login, no advertising and no analytics or tracking scripts. It sets no cookies of its own. Your web host inevitably records standard server logs (IP address, date and time, page requested, browser and operating system) for security and troubleshooting. See section 10 for third-party resources the pages load.

People who get in touch

Name, email address, telephone number, employer and role, plus the content of your message and any subsequent correspondence. Purpose: to answer you and, where relevant, to prepare a proposal.

Appointment bookings

Name, email address and any information you add to the booking, plus the date and time of the meeting. Purpose: to schedule and hold the meeting. Bookings are handled through Google Calendar Appointment Schedules (see section 6).

Clients and prospective clients

Contact details of the people I work with, correspondence, contractual documents, assignment notes and deliverables, time records, invoicing and payment data. Purpose: to negotiate and perform the contract, to invoice, and to meet accounting and tax obligations.

Workshop, training and coaching participants

Name, organisation, role, attendance, and any input you provide during a session. Where a session uses a psychometric instrument such as MBTI® or the Enneagram, the results are your results: they are shared with you, discussed with you, and are not disclosed to your employer in individual form without your explicit consent. Aggregated, non-identifying team-level observations may be shared with the sponsor of the assignment, and I will say so before the session begins.

Data I do not seek

I do not deliberately collect special categories of personal data (Article 9 GDPR) such as health data, political opinions, trade union membership, religious beliefs or data on sexual orientation. Please do not send me such data unless it is strictly necessary and we have agreed on how to handle it.

4. Legal bases for processing

Each processing operation described above relies on one of the following grounds:

  • Performance of a contract (Art. 6(1)(b) GDPR): delivering assignments, managing the client relationship, invoicing, and pre-contractual steps taken at your request.
  • Legal obligation (Art. 6(1)(c) GDPR): retaining accounting records and invoices under Belgian accounting and VAT legislation.
  • Legitimate interests (Art. 6(1)(f) GDPR): responding to enquiries, maintaining a modest professional contact list, protecting the security of my systems, and establishing or defending legal claims. I have weighed these interests against your rights and freedoms, and you may object at any time (see section 11).
  • Consent (Art. 6(1)(a) GDPR): where you have explicitly agreed, for example to being named as a reference, to the publication of a testimonial, or to individual psychometric results being shared with a third party. You may withdraw consent at any time, without affecting processing carried out before withdrawal.

5. Where the data comes from

Almost all of it comes from you directly. In a business development context I may also use publicly available professional sources, such as a company website, a public LinkedIn profile or a public register like the Belgian Crossroads Bank for Enterprises, to identify the right person to approach. Where I do, I will tell you on first contact.

6. Who receives your data

I do not sell personal data, and I do not share it for anyone else's marketing. Data is disclosed only to:

  • Service providers acting as processors, bound by contract under Article 28 GDPR. These are currently Google Ireland Ltd (Google Workspace for email, calendar and appointment scheduling, and document storage) and the provider hosting this website.
  • My accountant and, where required, my auditor, for bookkeeping, VAT and annual accounts.
  • Subcontractors or associate consultants, where an assignment requires it, and then only what they need and only under a confidentiality agreement.
  • Public authorities, where disclosure is required by law or by a court order.

Note on training and certification bodies: where a session uses a licensed instrument such as MBTI® or a Prosci® programme, the licensor may process participant data as a separate controller under its own privacy notice. I will identify the body concerned before the session.

7. Transfers outside the European Economic Area

My tooling is contracted with EU-established entities where possible. Some providers, notably Google, may process data on servers outside the EEA, principally in the United States. Where that happens, the transfer is covered by one of the safeguards in Chapter V GDPR: an adequacy decision of the European Commission (such as the EU–US Data Privacy Framework, where the provider is certified under it) or the European Commission's Standard Contractual Clauses together with supplementary measures. You may request a copy of the relevant safeguards at the address in section 14.

8. How long data is kept

I keep personal data only as long as necessary for the purpose it was collected for:

Category Retention period Why
Enquiries that do not lead to an engagement2 years from last contactFollow-up and legitimate interest
Client files and correspondence10 years after the end of the engagementBelgian limitation period for contractual claims
Invoices and accounting records7 years from the close of the financial yearBelgian accounting and VAT law
Training and workshop participant lists3 years after the sessionCertification, follow-up and quality
Individual psychometric resultsDeleted at your request; otherwise 2 yearsCoaching continuity
Web server logsPer the host's standard policy, typically under 12 monthsSecurity and troubleshooting

At the end of the applicable period, data is deleted or irreversibly anonymised.

9. Security

I apply measures appropriate to the risk: encryption in transit (HTTPS) and at rest on managed platforms, multi-factor authentication on all business accounts, full-disk encryption and automatic locking on my devices, a password manager, least-privilege access to client material, and regular backups. No system is perfectly secure; if a breach occurs that is likely to result in a risk to your rights and freedoms, I will notify the Belgian Data Protection Authority within 72 hours and inform you directly where the law requires it.

10. Cookies and third-party resources on this website

This website sets no cookies of its own and runs no analytics, advertising or social tracking scripts. There is therefore no cookie banner, because there is nothing to consent to.

For technical reasons the pages currently load two third-party resources, a stylesheet framework and a web font, from external content delivery networks. Requesting a file from any external server necessarily discloses your IP address and browser details to that server. These resources set no cookies and are not used to track you. If you would prefer not to make those requests at all, a browser extension that blocks third-party requests will prevent them; the site remains fully readable without them.

If analytics or a contact form are added in future, this section will be updated and, where the law requires it, prior consent will be requested through a proper consent banner.

11. Your rights

Under the GDPR you have the right to:

  • Access: obtain confirmation of whether I process data about you, and a copy of it (Art. 15).
  • Rectification: have inaccurate or incomplete data corrected (Art. 16).
  • Erasure: have data deleted where one of the grounds in Article 17 applies. This does not override my legal duty to keep accounting records.
  • Restriction: have processing limited while a dispute about accuracy or lawfulness is resolved (Art. 18).
  • Portability: receive data you provided, in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible (Art. 20).
  • Objection: object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 21). Where you object to direct marketing, I will stop without exception.
  • Withdraw consent at any time, where processing is based on consent (Art. 7(3)).
  • Not be subject to automated decision-making: I take no decisions about you by automated means, and carry out no profiling within the meaning of Article 22.

To exercise any of these rights, write to dh@theafter.be. I will reply within one month of receipt, and will tell you if that period needs to be extended by up to two further months because the request is complex. Exercising your rights is free of charge. I may ask you for proof of identity where I have reasonable doubt about who is making the request.

12. Complaints

If you believe your data has been handled improperly, please raise it with me first, because most issues are resolved quickly that way. You also have the right, at any time, to lodge a complaint with the supervisory authority:

Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit)

Rue de la Presse 35, 1000 Brussels, Belgium

+32 (0)2 274 48 00  ·  contact@apd-gba.be

www.dataprotectionauthority.be

If you are resident in another EU or EEA country, you may also complain to your own national supervisory authority.

13. Changes to this policy

This policy may be updated when my processing activities, tooling or legal obligations change. The version number and date at the top of this page always identify the current text. Material changes affecting you will be communicated directly where I hold your contact details.

14. Contact

Any question about this policy, or about how your data is handled: dh@theafter.be, or by post to The After SRL, Avenue JF Debecker 111, B-1200 Brussels, Belgium.