OkiOki app / Privacy policy

Last updated: October 12, 2020


OkiOki is your financial assistant and she goes to great lengths to simplify your administration. That does not alter the fact that she also takes your privacy into account and that she takes good care of everything she learns about you during the collaboration.

A short wrap-up

Only the data you want

Only data that you provide or give access to will be processed by her. The data that it receives from you is processed according to the legal rules and in a way that guarantees that the data is safe.

Data processing by OkiOki and by carefully selected third parties

Your data will be passed on to third parties if this is necessary to enable the services offered (e.g. to do OCR), with those parties OkiOki also has a contract that protects your rights. Of course, she will provide data to your accountant if you ask OkiOki to automatically share your data. You can also choose to do that manually (via a download), but do expect OkiOki to feel a lot less useful in that case.

Your data remains yours

You can also ask OkiOki what data she has stored and how she handles your data, you can even ask her to delete all your data if needed, she will do that.

If you want more details about her privacy approach and want to know what data she stores about you, read all the details below.

All the nitty-gritty details

Welcome! Thank you for your interest in our digital financial assistant and in our company in general.

We continuously strive to offer you a service at the highest standards. The protection of your personal data is therefore of our utmost concern. We are taking all necessary precautions to protect your personal data and in order to ensure you that you can continue to entrust us with your personal data. Hence, we are always handling your personal data in a safe and confidential manner. All reasonable protection measures have been taken in order to avoid loss, alterations, access by persons who are not authorized to obtain access, accidental dissemination among third parties and/or any other unlawful or illegitimate processing of the collected personal data.

The purpose of this privacy policy is to explain how we process personal data in connection with our financial assistance services.

1. Who are we?

33REASONS NV, is a Belgian company having its registered office at 9451 Haaltert, Hofstraat 58, and registered with the Crossroadbank of Enterprises under the number 0718.718.233 (hereinafter, “33REASONS” or “we”). Our company is specialized in providing financial assistance services.

You can contact us via the following contact details:

33REASONS nv
Hofstraat 58
9451 Haaltert
Belgium
hello@33reasons.be

Your personal data shall only be processed in accordance with the existing and applicable legal provisions concerning the protection of personal data, including the Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as ‘GDPR’) and the national implementing legislation.

Via the OkiOki App, we want to make your life easier and keep your financial administration on track. We can do this by (a) connecting with your accountant, bank, cloud and email, (b) collecting invoices and other relevant documents and (c) preparing your financial administration and booking proposals.

We only access your bank account details with your explicit consent. You decide which services your want to use and whether or not you want to share your bank account details.

2. Clarification of terms used

For the purposes of this privacy statement, the concept of ‘personal data’ refers to: any information relating to an identified or identifiable natural person (the ‘data subject’). A natural person shall be deemed ‘identifiable’ if he or she can be identified on a direct or indirect basis, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Hence, all information on the basis whereof a natural person can be identified must be taken into account. I.e.: amongst others the person’s name, date of birth, address, telephone number, e-mail address, bank account and IP-address are taken into account.

The term ‘processing’ has a broad scope and, amongst others, refers to the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of personal data.

3. Person responsible for the processing of your personal data (“controller”)

33REASONS is the legal person responsible for the processing of your personal data. This means that we determine the purposes and means of the processing of your personal data.

4. When do we collect your personal data?

When we help you with your financial administration and provide (financial) advisory services to you, we collect personal data  (either directly from you or indirectly, e.g. through your use of our services or via your accountant, bank, cloud storage, mailbox), amongst others, when you:

  • provide us with your contact-details via the OkiOki App or through our website;
  • register, access, log-into, browse and use the OkiOki App;
  • connect your  bank, cloud or e-mail services to allow the OkiOki App to perform its service;
  • conclude an agreement with us;
  • contact our customer service (e.g. via telephone or e-mail).

Furthermore, our IT-systems process certain personal data on an automatic basis. We make use of cookies when you visit our websites. Cookies are small files which contain certain information, and which are save on your tablet or mobile device to, inter alia, enhance the usability of our website in the most optimal manner. At any moment however, you can delete or switch off all cookies installed on your device through the settings of your browser. Please note that by altering your cookie-settings, our website may not function appropriately any longer. For more information about the cookies we use, please read our cookie policy. For more information about ‘cookies’ in general, please visit: www.youronlinechoices.com.

The OkiOki App is solely available to users aged 18 or over, registered at the Crossroadbank of Enterprises and acting in the context of their professional activities. We do not and will not knowingly collect personal data regarding persons younger than 18 years old.

OkiOki's use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Retargeting
Retargeting or remarketing refers to technologies that serve to serve relevant advertisements to users who have previously visited certain web pages even after they have left those web pages. To do this, it is necessary to recognize the user again after leaving the company's website, which is enabled by the use of cookies from the relevant service providers. In addition, previous user behavior is taken into account. For example, if a user views certain products, advertisements about those or similar products may later appear on other web pages. This is personalized advertising that is tailored to the needs of individual users. For this personalized advertisement, it is not necessary for the user to be identified once they have been recognized. For this reason, data used for retargeting or remarketing is also not merged with other data.

We use such technologies to place advertisements on the internet. To display the ads, we use third-party providers. Among other things, we use offers from Google, which allow an automatic display of products of interest to internet users. This function is implemented by cookies. You can obtain additional information about this technology in Google's privacy policy at https://policies.google.com/privacy?hl=en. The installation of cookies for Google remarketing and Google AdWords Conversion Tracking can be prevented by configuring the browser software by accessing the website http://www.google.com/policies/privacy/ads/ and modifying the corresponding configuration.

5. What personal data do we process, why and on which legal basis?

33REASONS takes the data minimization principle very seriously. We therefore aim to only process that personal data which is strictly necessary to provide you our financial advisory services.

The schedule below provides which categories of personal data are processed by us (column 1), why such personal data is being processed (the ‘purposes’ – column 2) and on which legal basis such processing takes place (column 3).

The processing of personal data shall only take place for one or more specific purposes. Please note that the retention period for the different purposes can differ.

Furthermore, there is always a demonstrable legal basis for every processing of personal data. The numbering used in the column ‘legal basis’ has the following meaning:

  • Consent: you have given your (explicit) consent for the processing of personal data for one or more specific purposes;
  • Agreement: the processing of the personal data is necessary for the performance of a contract to which you are a contracting party;
  • Legitimate interests: the processing is necessary for the purposes of the legitimate interests pursued by 33REASONS or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data;
  • Legal obligation: the processing is necessary for compliance with a legal obligation to which 33REASONS is subject.

Categories of personal data

Purposes

Legal basis

First and last name, e-mail address, telephone number, work address, legal status, VAT or company registration number, activity type, contact details of your accountant

Registration to the OkiOki App

Agreement

First and last name, e-mail address, legal status, VAT or company registration number, activity type, invoices/receipts/e-mail messages, transaction information, other financial documents

Providing financial assistance services

Agreement

E-mail address and password

Authentication of the user via the OkiOki App

Agreement

Your bank account number, name of the beneficiary, beneficiary’s account number, notification or payment references, amount and date of transactions, other payment details

Providing financial assistance services

Explicit consent

E-mail address

Collection of product-feedback aiming at enhancing our products and services

Legitimate interests

Feedback from users

Development of the usability of our service

Legitimate interests

E-mail address

To inform you as a registered user about technical information concerning our services by means of a newsletter

Legitimate interests

E-mail address

To send you, as a registered user, marketing messages regarding other products or services of 33REASONS

Legitimate interests

E-mail address

To send you, as a prospective user, marketing messages regarding the products and services of 33REASONS

Consent

E-mail address, complaint

Addressing possible complaints regarding the services

Legitimate interests

Copy of the front side of your ID-card

Address a subject access request

Legal obligation

First and last name, legal status, VAT or company registration number, professional bank details, transaction details

33REASONS is bound by a number of legal obligations that require the processing of your personal data.

Legal obligation

6. Your privacy-rights

In order to give you more control regarding the processing of personal data, you have various rights at your disposal. These rights are inter alia discussed and provided in articles 15-22 GDPR.

You have the following rights:

Right of access to the processed personal data (art. 15 GDPR)

You have the right to obtain our confirmation as to whether or not your personal data is being processed, and, where that is the case, to obtain access to the personal data and the following information:

  • The purposes of the processing;
  • The categories of personal data concerned;
  • The recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
  • Where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  • The existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
  • The right to lodge a complaint with a supervisory authority;
  • Where the personal data are not collected from the data subject, any available information as to their source;
  • The existence of automated decision-making.

In the event that we cannot provide you access to the personal data (for example in the event of a legal obligation to restrict the data subject from access to such information), we shall inform you of the reasons of such an inability.

Furthermore, you can also request a copy of the personal data undergoing processing free of charge. Please note however, that we are entitled to charge reasonable fee based on administrative costs for each additional copy you request.

The right to be forgotten or to request erasure of personal data (art. 17 GDPR)

In certain instances, you may request us to erase your personal data. Be aware however that under such circumstance, we will not be able to provide you with our services any longer. Furthermore, we ask you to bear in mind that the ‘right to be forgotten’ is not an absolute right.

We shall have the right to continue to store your personal data, inter alia, in the following cases: (i) where such storage is necessary for the performance of a contract to which you are a contracting party, (ii) where such storage is necessary for compliance with a legal obligation, or (iii) where such storage is necessary for the establishment, exercise or defence of legal claims. We shall inform you of the reasons for the storage of your personal data in our response to your request of erasure.

The right to rectification (art. 16 GDPR)

In the event that your personal data are inaccurate, dated or incomplete, you can request us to rectify or complete your personal data.

The right to data portability (art. 20 GDPR)

Under certain conditions, you shall also have the right to request us to transmit the personal data you provided us with and for which you have given us your consent, to another controller. We shall transmit such personal data directly to the new controller in so far as such transmission is technically feasible.

Right to restriction of processing (art. 18 GDPR)

You shall have the right to obtain the restriction of processing where one of the following applies:

  • You contest the accuracy of the personal data (in such an event the use of the personal data shall be limited for a period enabling us to verify the accuracy of the personal data);
  • The processing of the personal data is unlawful;
  • We no longer need the personal data for the purposes of the processing, but you require them for the establishment, exercise or defence of legal claims;
  • Pending the verification whether the legitimate grounds for the processing of the personal data override those of the data subject, you may request us to limit the usage of the personal data.

The right to object (art. 21 GDPR)

You have the right to object, on grounds relating to your particular situation, the processing of your personal data in case that such processing is done for the performance of a task carried out in the public interest or for the purposes of the legitimate interests pursued by us. In such an event, we shall no longer process the personal data unless (i) there are compelling legitimate grounds for the processing which override your interests, rights and freedoms, or (ii) the processing of the personal data is done for the  establishment, exercise or defence of legal claims.

Automate individual decision-making, including profiling (art. 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or which may significantly affect you in a similar manner.

Such right can however not be invoked in the following circumstances:

  • If the decision is authorised by law (for example: in order to prevent tax fraud);
  • If the decision is based on the data subject’s explicit consent; or
  • If the decision is necessary for entering into, or performance of, a contract between the data subject and the data controller (note that in such instances, we shall always make a case by case assessment of whether less privacy intrusive methods can be applied to facilitate the entry into, or performance of the contract).  

The right to withdraw your consent (art. 7 GDPR)

Where the processing of personal data is based on consent, you shall have the right to withdraw such consent at any time through a simple request. For example, the decision to share your payment details with us, is based on your explicit consent.

7. The exercise of your rights

To exercise the rights listed above, you can contact us via e-mail on the following e-mail address: hello@33reasons.be.

In order to verify your identity, we ask you attach a copy of the front side of your ID-card to your e-mail.

All rights can be exercised free of charge, unless your request is manifestly unfounded or disproportionate (for example: due to the repetitive character of your request). In such cases, we have the right to charge you with a proportional fee or to refuse to adhere to your request.

8. Transfer of personal data

Only with your explicit consent, we can access your bank account information such as receipts, payment details and account balances, to the extent that this information is necessary to perform our agreement. If you do not provide your consent, your account data will remain with your bank and will not be shared with us. This will limit the scope of our services.

To perform our agreement, we may send documents and transaction details to your accountant/bookkeeper.

We may send your personal data to third parties whose intervention as data processor, on behalf and under control of 33REASONS, is required for the purposes indicated above. These data processors are natural persons or legal entities that process the personal data on behalf of 33REASONS. These processors were carefully selected by us and offer all the adequate guarantees with regard to technical and organizational security measures regarding the processing of your personal data. The GDPR also applies to these third parties.

Your personal data shall only be transferred to third parties in conformity with the legal provisions in that regard, when you have provided us with your consent to do so, or when such transfer is necessary to ensure the provision of our services (on the basis of our legitimate interests). No personal data shall be transferred to third parties under any other circumstances, unless we are obligated to do so on the basis of compulsory legal or regulatory provisions (e.g.: the transfer of personal data to external bodies or authorities, such as law enforcement authorities).

We ensure that your personal data will not be rented nor sold in personally identifiable form to anyone but trusted and reputable third party processors described under this title. All third party processors are bound to keep your information confidential. All information provided to third party processors is used by them only to carry out the service they are providing for us.

9. Categories of recipients

Your personal data shall only be accessible within our company to those persons who require access to the personal data in order to comply with the contractual and legal obligations.

In some circumstances, our employees and staff are assisted by external service providers in the execution of their tasks. In order to protect your personal data, we have concluded an agreement with all such external service providers in order to guarantee the safe, respectful and cautious management and administration of your personal data.

10. Transfer of personal data to third countries

Your personal data shall only be transferred or disclosed to processors or controllers in third countries in so far as we are legally authorised to do so.

In so far as such disclosure or transfer is necessary, we shall take appropriate measures to ensure that your personal data shall be significantly protected and that all disclosures or transfers of personal data outside of the EEA take place in a lawful and legitimate manner. In the event that a disclosure or transfer takes place to a country outside of the EEA, for which the European Commission has not determined that this country does not maintain an equivalent level of protection of the personal data, such disclosure or transfer shall always be subject to contractual or other legally binding instruments which under the terms and conditions for the transfer of personal data to third countries, such as the approved standard terms and provisions for the transfer of personal data to third countries as established by the European Commission.

11. Protection of your personal data

We have taken all reasonable and suitable technical and organizational measures in order to protect your personal data as well as possible against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. As such, we store your personal data on one central and secured place on our server in order to ensure that third parties shall not have access to your personal data.

When you register as a user, we have implemented a two-step verification procedure to ensure a strong customer authentication. First, we verify that you are the account holder on the basis of a two-factor-authentication. Subsequently, we ask your explicit consent to use your account information.

12. Storage of personal data

We store your personal data for the period of time necessary for achieving the purpose for which such personal data is processed. Please note that we must take into account a number of (legal) storage periods (time limits) which oblige us to continue to store your personal data. In the event that no obligation or duty to store the personal data exists, the personal data shall be erased and destroyed on a routine basis once the purpose for which the personal data is collected has been achieved. Furthermore, we may store your personal data if you have given us your consent to do so or where such storage is necessary for the establishment, exercise or defence of legal claims. In this last instance, certain personal data shall be used for evidence purposes. Such personal data shall therefore be stored in line with the legal prescription period, which can amount up to a period of thirty years; the usual limitation period in relation to actions in personam amounts up to ten years.

13. Complaints?

The protection of your personal data is our primary concern. As such, we aim to take all necessary measures in order to guarantee the protection of your personal data. Should you have a complaint regarding the manner in which your personal data is processed, please feel free to contact us. We shall try to live up to your expectations and meet your concerns as soon as practically possible.

You may also file your complaint to the supervisory authority for personal data protection. The authority assigned to supervise our organization is the Belgian Data Protection Authority:

Website:
https://www.dataprotectionauthority.be

Contact details:

Data Protection Authority
Rue de la Presse 35, 1000 Brussels
+32 (0)2 274 48 00
contact@apd-gba.be

14. Security incident reporting

When you want to inform us of a potential security incident, please contact us via e-mail: hello@33reasons.be

In case you send us a potential incident report, please make sure to add your contact details (e-mail address or mobile phone number) and a description of the potential security breach and the date and time that you first noticed it (if possible).

15. Do you have any further questions?

Please feel free to contact us (hello@33reasons.be). We are happy to be of any further assistance.

16. Amendments

In order to take action on the basis of your feedback or to clarify changes made in our processing activities, this Privacy Policy may be amended from time to time. Therefore, we invite you to consult the latest version of this Policy on our website.