Privacy policy

Version 2.0 — in force since 2026-08-20

How your personal data is handled on the public websites of savethemall.eu, under Regulation (EU) 2016/679 (GDPR) and the Belgian Act of 30 July 2018.

On this page
  1. 1. Who processes your data
  2. 2. What this policy covers
  3. 3. What we process, why, and on what legal basis
  4. 4. Who has access
  5. 5. Transfers outside the European Union
  6. 6. Your rights
  7. 7. Lodging a complaint
  8. 8. Security
  9. 9. In the event of a data breach
  10. 10. Children
  11. 11. Automated decisions and profiling
  12. 12. Cookies
  13. 13. Changes to this policy

1. Who processes your data

The data controller is Frédéric Guariento, a natural person established in Belgium, publisher of the public websites under the savethemall.eu domain and its subdomains.

Any question about your personal data, and any request to exercise your rights, goes to a single address: gdpr@savethemall.eu.

Appointing a Data Protection Officer is not required here (Article 37 GDPR): this is neither a public authority, nor large-scale systematic monitoring, nor large-scale processing of special categories of data. The contact point above serves that function towards you.

2. What this policy covers

It covers the public websites published under savethemall.eu and any site displaying our consent banner.

It does not cover:

3. What we process, why, and on what legal basis

The guiding principle is data minimisation: nothing is collected "just in case". No data is used for advertising, and no commercial profile is built.

ProcessingDataPurposeLegal basisRetention
Web analytics
self-hosted Matomo
Pages viewed, referring page, device and browser type, anonymised IP address (last two octets masked before any storage) Understand which pages are visited and fix what does not work Consent — Art. 6(1)(a) 180 days (automatic purge)
Operation and security Web server logs: IP address, timestamp, requested URL, response code, browser identifier Serve the pages, detect and block abuse (scans, intrusion attempts) Legitimate interest — Art. 6(1)(f) 30 days maximum (automatic rotation)
Storing your choice Consent preference stored in your browser (see the cookie policy) Avoid asking again on every page and be able to demonstrate consent Obligation arising from consent — Art. 7(1) 6 months, then asked again
Contact and rights requests E-mail address, message content, any attachments Reply to you and keep a record of how the request was handled Legal obligation — Art. 12; legitimate interest for evidence 3 years after the request is closed
Orders
shop sites using our banner
Identity, contact details, order details. Payment data never reaches us: it is handled directly by the payment provider Fulfil and deliver the order, meet accounting obligations Performance of a contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) 7 years (Belgian accounting retention)

Once a retention period expires the data is deleted or irreversibly anonymised — not merely set aside.

4. Who has access

Your data is never sold, rented or traded. There is no ad network, no social network, and no third-party analytics service (Google Analytics or equivalent) on these sites.

5. Transfers outside the European Union

None. The servers hosting these sites and the analytics are located in Belgium, with a technical relay in France. Both are within the European Economic Area.

Should a transfer outside the EEA ever become necessary, it would only take place under an adequacy decision or the European Commission's standard contractual clauses, and this page would be updated before the transfer, not after.

6. Your rights

The GDPR grants you the following rights, which you may exercise at any time:

How to exercise them

Write to gdpr@savethemall.eu, stating your request. You will get a reply within one month, extendable by two months for a complex request — in which case you are told within the first month, together with the reason.

Exercising your rights is free of charge. Proof of identity is requested only where there is reasonable doubt about who you are, limited to what is needed to dispel that doubt, and destroyed afterwards.

7. Lodging a complaint

If our answer does not satisfy you, you may lodge a complaint with the Belgian authority:

Data Protection Authority (APD/GBA)
Rue de la Presse 35, 1000 Brussels, Belgium
+32 (0)2 274 48 00 — contact@apd-gba.be
dataprotectionauthority.be

If you live in another Member State, you may instead contact the authority of your country of residence. A judicial remedy remains available in all cases.

8. Security

Technical and organisational measures are designed and reviewed against the ISO/IEC 27001:2022 framework and its Annex A controls. To be precise: the infrastructure is not certified — the standard is used as a working framework and review grid, not claimed as a label.

No measure reduces risk to zero. These measures aim at a level of security appropriate to the risk within the meaning of Article 32 GDPR, and are reviewed whenever the infrastructure changes significantly.

9. In the event of a data breach

A breach posing a risk to your rights is notified to the Belgian DPA within 72 hours of becoming aware of it (Art. 33). Where the risk is high, you are informed directly, in plain language, of the nature of the breach, its likely consequences and what you can do (Art. 34). An internal breach register is maintained, including for breaches that do not require notification.

10. Children

These sites are not aimed at children and do not knowingly collect their data. In Belgium, consent to information society services is valid from the age of 13 (Act of 30 July 2018, Art. 7); below that age it must come from the holder of parental responsibility. Any child's data brought to our attention is deleted without delay.

11. Automated decisions and profiling

None. No processing produces legal or similarly significant effects on you based solely on automated processing within the meaning of Article 22 GDPR. Analytics is aggregated: it counts visits, it does not evaluate people.

12. Cookies

The exact list of trackers, their lifetime and how to refuse them is set out in the cookie policy, which forms an integral part of this policy.

13. Changes to this policy

This policy carries a version number and an effective date, shown at the top of the page. A substantial change — a new purpose, a new recipient, a longer retention period — triggers a new version and, where the processing relies on consent, a fresh consent request through the banner. Earlier versions are available on request.