Privacy Policy
ARTICLE 1 – INTRODUCTION
The purpose of this Privacy Policy is to inform you about the processing of personal data carried out by Respace (hereinafter “Respace,” “we,” “us,” or “our”), as well as the rights you have with respect to such processing.
This Policy has been drafted in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”), as well as any applicable national legislation regarding the protection of personal data.
In particular, Respace provides coworking spaces, private offices, meeting rooms, event spaces, hospitality services, and related services for businesses, professionals, organizations, and individuals.
This Policy applies, in particular, when:
- you visit our website
- you contact Respace
- you request information about our services
- you schedule a tour of our spaces
- you become a prospect or customer
- you reserve an office, a meeting room, or an event space
- you attend an event
- you subscribe to a newsletter
- you provide a service to Respace
- you act as a supplier or partner
- you apply for a job or a collaboration opportunity
- you work for Respace as an employee, consultant, director, or collaborator
- you participate in a meeting, workshop, training session, or professional exchange involving Respace
ARTICLE 2 – DATA CONTROLLER
The data controller is:
RESPACE
Respace SA
Place Poelaert 6, 1000 Brussels
Company number: 1011.299.432
pierre.colaiacovo@respace.be
When this Policy refers to “Respace,” it should be understood to mean the data controller as defined by the GDPR.
ARTICLE 3 – CATEGORIES OF DATA SUBJECTS
The processing described in this Policy applies in particular to the following categories:
- website visitors
- prospects
- customers
- space occupants
- users of coworking spaces
- event participants
- job applicants
- employees
- administrators
- consultants and freelancers
- suppliers
- service providers
- partners
- co-contractors
- representatives of legal entities
- guests
- in-person visitors to Respace locations
- any person participating in a meeting, interview, or professional discussion with Respace
ARTICLE 4 – DATA PROCESSING BY RESPACE
4.1 Management of the Website and Information Requests
Purposes
Respace processes certain data in order to:
- enable navigation on the website
- respond to requests submitted via the website
- organize visits
- manage contact forms
- ensure the security of the website
- improve the user experience
- provide user support
Data Processed
Depending on the circumstances:
- last name
- first name
- email address
- phone number
- company
- job title
- content of requests
- information provided voluntarily
- technical browsing data
- IP address
- technical browser identifiers
Legal Basis
- Respace’s legitimate interest
- implementation of pre-contractual measures
- consent when required
4.2 Management of Prospects and Sales Activities
Purposes
Respace processes prospect data in order to:
- provide information
- prepare quotes
- schedule visits
- follow up on sales leads
- prepare offers
- expand business activities
Data Processed
- identity
- contact information
- represented company
- position
- interests
- contact history
- stated needs
- requests made
Legal basis
- legitimate interest
- pre-contractual measures
- consent when required
4.3 Management of Customers, Occupants, and Users of Spaces
Purposes
The data processed enables:
- the conclusion of contracts
- the management of reservations
- managing subscriptions
- access management
- managing services
- monitoring space occupancy
- billing
- customer support
Data Processed
- identification data
- contact information
- Company represented
- contractual information
- reservation history
- billing information
- communications with Respace
Legal basis
- performance of the contract
- legitimate interest
- legal obligations
4.4 Event Management
Purposes
Respace may process personal data in order to:
- organize events
- manage registrations
- to handle logistics
- manage access
- to communicate with participants
- to provide related services
Data Processed
- identity
- contact information
- company
- job title
- event details
- organizational needs communicated by the participants
Legal Basis
- performance of the contract
- legitimate interest
- consent when necessary
4.5 Accounting, Financial, and Administrative Management
Purposes
Respace processes certain data in order to:
- issue invoices
- receive payments
- to maintain its accounting records
- to comply with its tax obligations
- to comply with its legal obligations
Data Processed
- identity
- contact information
- billing information
- accounting information
- banking information
- administrative information
Legal Basis
- legal obligation
- performance of the contract
- legitimate interest
4.6 Management of Suppliers and Partners
Purposes
Respace processes data from suppliers and partners in order to:
- review their proposals
- enter into contracts with them
- manage services
- to monitor business relationships
- to manage payments
Personal Data Processed
- identity
- business contact information
- job title
- company
- contractual information
- billing information
Legal Basis
- performance of the contract
- legitimate interest
- legal obligations
4.7 Marketing Communications, Newsletters, and Invitations
Purposes
The data may be used to:
- send newsletters
- to provide information about Respace’s activities
- to promote new spaces
- to publicize events
- send invitations
Data Processed
- last name
- first name
- email address
- company
- communication preferences
- information regarding consent or objection
Legal basis
- consent
- legitimate interest in cases permitted by applicable law
4.8 Recruitment
Purposes
Candidate data is processed in order to:
- evaluate applications
- to schedule interviews
- to select candidates
- to maintain a recruitment pool when the candidate consents
Data Processed
- Resume
- cover letter
- degrees
- professional experience
- skills
- certifications
- identification information
- other information voluntarily provided
Legal Basis
- pre-contractual measures
- legitimate interest
- consent for the recruitment pool
4.9 Human Resources Management
Purposes
In its capacity as an employer or contracting entity, Respace processes the personal data of its employees, staff members, consultants, freelancers, directors, interns, and other members of its workforce in order to:
- to manage the hiring process
- to enter into and execute employment or collaboration contracts
- manage compensation and benefits
- manage schedules, absences, and time off
- to comply with social security and tax obligations
- manage insurance
- manage training
- to handle administrative tasks related to personnel
- to comply with the legal obligations imposed on the employer
- to ensure occupational health and safety
- manage the company’s internal organization
Data Processed
Depending on the circumstances:
- identification data
- personal and professional contact information
- administrative data
- compensation data
- banking information
- data related to absences
- career-related data
- training
- performance evaluations
- data necessary to comply with legal obligations
- data regarding equipment provided
- other data necessary for managing the professional relationship
Legal Basis
Data processing is based on:
- the performance of the employment or collaboration contract
- compliance with Respace’s legal obligations
- Respace’s legitimate interest
- consent, when required
4.10 Management of IT Tools and Internal Security
Purposes
To ensure the smooth operation of its activities, Respace uses various IT tools and collaborative platforms.
Personal data may be processed for the following purposes:
- create and administer user accounts
- manage access to systems
- to ensure IT security
- to prevent security incidents
- to protect the company’s assets
- secure document repositories
- manage backups
- to ensure the proper functioning of the tools used
- to ensure business continuity
Data Processed
Depending on the systems involved:
- last name
- middle name
- work email address
- user credentials
- connection information
- access history
- technical logs
- information about the devices used
- usage data for business tools
Legal Basis
The processing is based on:
- Respace’s legitimate interest
- the performance of the contract
- compliance with applicable legal obligations regarding information system security
4.11 Transcription, Archiving, and Document Management of Meetings
Purposes
As part of its activities, Respace may transcribe, summarize, classify, document, archive, and retain certain meetings, interviews, workshops, professional exchanges, or discussions.
This processing is carried out, in particular, for the following purposes:
- to ensure follow-up on decisions
- to document discussions
- preserving the organization’s memory
- to ensure business continuity
- to improve case management
- coordinate projects
- facilitate information sharing
- build structured professional archives
- improve operational efficiency
People Affected
The following may be affected:
- employees
- directors
- consultants
- freelancers
- customers
- residents
- partners
- service providers
- suppliers
- prospects
- meeting participants
- any other person involved in Respace’s activities
Data Processed
Transcripts may include, in particular:
- identification information
- business contact information
- project-related information
- contract-related data
- requests submitted
- decisions made
- actions to be taken
- comments or positions expressed by participants
- any other information communicated during the exchange
Possible Use of Recordings
In certain cases, audio or video recordings may be made to enable the creation of a transcript.
When these recordings allow for the direct or indirect identification of individuals, they constitute personal data as defined by the GDPR.
Respace ensures that the retention period for recordings is limited to what is strictly necessary to:
- generate the transcript
- verify its accuracy
- correct any errors
Unless otherwise required, the recordings are deleted after the transcript has been produced and verified.
Access to Transcripts
Transcripts and documentary archives are accessible only to authorized individuals who need to access them as part of their duties or assignments.
Legal Basis
This processing is primarily based on Respace’s legitimate interest in:
- document its activities
- monitoring decisions
- preserving the organization’s memory
- manage its records effectively
- facilitate collaboration
- improve the quality of its services
- ensure the continuity of its operations
Respace considers this legitimate interest to be proportionate provided that:
- the individuals concerned are properly informed
- access to the data is limited
- the data retained is relevant
- appropriate retention periods are applied
- records are retained for a limited period when they are used solely to produce a transcript
ARTICLE 5 – RETENTION PERIODS
Respace retains personal data for a period no longer than is necessary to fulfill the purposes for which it was collected.
Retention periods are determined, in particular, based on:
- the nature of the processing
- applicable legal obligations
- contractual obligations
- statutes of limitations
- Respace’s operational needs
- the recommendations of the competent authorities
5.1 Website and Requests for Information
Data is retained for the time necessary to process the request and then for a maximum of three years from the last contact, unless required by law or in the event of a dispute.
5.2 Prospects
Prospect data is retained for a maximum of three years from the last contact or interaction with Respace.
5.3 Clients and occupants
Data is retained for the entire duration of the contractual relationship.
It may then be archived for as long as necessary to defend Respace’s rights and to comply with accounting, tax, or legal obligations.
5.4 Events
Data is retained for as long as necessary to organize and follow up on the event.
Certain data may be retained for a longer period when it is related to a contractual matter or a legal obligation.
5.5 Accounting and Taxation
Data required for accounting and tax obligations is retained for the periods mandated by applicable law.
5.6 Suppliers and Partners
Data is retained for the duration of the contractual relationship and thereafter for as long as necessary to protect Respace’s legitimate interests and to comply with its legal obligations.
5.7 Marketing Communications
Data is retained until consent is withdrawn or the right to object is exercised.
5.8 Recruitment
Candidate data is retained for the period necessary to evaluate their application.
If the candidate has agreed to be included in a recruitment pool, the data may be retained for a maximum of two years from the date of that agreement.
5.9 Human Resources
Employee data is retained for the duration of the employment relationship and thereafter for the periods required by applicable legal obligations.
5.10 IT Security
Data related to IT security and access logs are retained for a period proportionate to the objectives pursued and the applicable security requirements.
5.11 Transcripts and Documentary Records
Transcripts are retained for as long as necessary to manage the relevant file, project, or activity.
When included in a contractual, administrative, or operational file, they may be retained for the entire lifespan of the relevant file as well as for the applicable archiving periods.
Audio or video recordings used to generate transcripts are deleted as soon as they are no longer necessary for the creation and verification of the transcript, unless there is a specific need justifying longer retention.
ARTICLE 6 – LEGAL BASES FOR DATA PROCESSING
The processing carried out by Respace is based on one or more of the legal bases provided for by the GDPR.
These legal bases include, in particular:
a) The performance of a contract
When processing is necessary for:
- the conclusion of a contract
- the performance of a contract
- the management of a contractual relationship
b) Precontractual measures
When the data subject requests:
- a quote
- an offer
- a reservation
- commercial information
- an application
c) Compliance with a legal obligation
When Respace must comply with:
- tax obligations
- accounting obligations
- social security obligations
- regulatory obligations
- security obligations
d) Legitimate Interest
Legitimate interest constitutes the primary legal basis for several processing activities carried out by Respace, including:
- system security
- supplier management
- internal organization
- document management
- meeting minutes
- prevention of abuse
- request management
- defending Respace’s rights
e) Consent
Consent is used, in particular, for:
- certain electronic communications
- certain cookies
- the creation of a talent pool
- any other situation where regulations require prior consent
ARTICLE 7 – RECIPIENTS OF PERSONAL DATA
Respace ensures that access to personal data is limited solely to those individuals who need it to perform their duties.
Personal data may be disclosed to the categories of recipients described below.
Such disclosure occurs only when necessary to achieve Respace’s purposes, to comply with a legal obligation, or to protect its legitimate interests.
7.1 Authorized Respace Personnel
Personal data may be accessible to Respace staff to the extent necessary for the performance of their duties.
Depending on the situation, this may include, in particular:
- management
- operational managers
- administrative teams
- sales teams
- marketing teams
- finance teams
- human resources teams
- facilities management staff
- document management staff
- event planners
- IT administrators
Respace staff members are subject to confidentiality obligations appropriate to their roles.
7.2 Service Providers and Subcontractors
Respace may engage various external service providers acting as subcontractors.
These subcontractors may be involved in the following areas, among others:
- IT hosting
- cloud services
- email services
- document management
- management of collaborative workspaces
- IT maintenance
- IT security
- CRM solutions
- marketing solutions
- HR tools
- application management
- accounting
- billing
- payment
- website development and maintenance
- event management
When these service providers access personal data on behalf of Respace, they are contractually bound to comply with strict confidentiality, security, and data protection obligations in accordance with applicable regulations.
7.3 Suppliers and Operational Partners
Certain personal data may be disclosed to partners or suppliers when such disclosure is necessary for the performance of the requested services.
This may be the case, in particular, for:
- event organization
- reception services
- technical services
- audiovisual services
- catering services
- security services
- maintenance services
- services related to the spaces provided
The data provided is limited to that which is strictly necessary for the performance of the relevant services.
7.4 External Consultants
Respace may disclose certain data to its external consultants when necessary for the management of its activities.
These recipients may include, in particular:
- attorneys
- auditors
- auditors
- certified public accountants
- insurers
- specialized consultants
These individuals are themselves subject to confidentiality obligations.
7.5 Public Authorities
Personal data may be disclosed to the competent authorities when:
- required by law
- an administrative authority is carrying out its legal duties
- a judicial authority requests it
- such disclosure is necessary to defend Respace’s rights
ARTICLE 8 – DATA TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA
In the course of its activities, Respace prioritizes, as much as possible, the use of services and infrastructure located within the European Economic Area.
However, certain technology providers, cloud services, or software vendors used by Respace may involve the transfer of personal data to countries outside the European Economic Area.
When such transfers take place, Respace ensures that they are carried out in accordance with the requirements of the GDPR.
8.1 Safeguards in Place
When a transfer to a third country is made, Respace ensures that at least one of the following safeguards applies:
- an adequacy decision adopted by the European Commission
- standard contractual clauses approved by the European Commission
- binding corporate rules
- any other safeguard recognized as valid under applicable regulations
8.2 Additional Information
Any data subject may request further information regarding international data transfers by contacting Respace in accordance with the procedures described in the section on the exercise of rights.
ARTICLE 9 – DATA SECURITY AND CONFIDENTIALITY
Respace implements appropriate technical and organizational measures to protect personal data against:
- accidental or unlawful destruction
- accidental loss
- alteration
- unauthorized disclosure
- unauthorized access
- any other form of unauthorized or unlawful processing
These measures are regularly reviewed and adapted in light of evolving risks and available technologies.
9.1 Organizational Measures
The organizational measures implemented may include, in particular:
- restricting access to data
- assigning individualized access rights
- authorization management
- staff awareness training
- internal procedures regarding confidentiality
- managing clearances
- security incident management
- supervision of subcontractors
9.2 Technical Measures
The technical measures implemented may include, in particular:
- secure authentication
- encryption of communications
- regular backups
- access logging
- antivirus protection
- firewalls
- incident detection mechanisms
- infrastructure security
- access segmentation
- data recovery mechanisms
9.3 Security of Document Repositories
The document repositories used by Respace to store data and meeting transcripts are subject to specific measures designed to:
- control access
- limit access
- prevent unauthorized access
- ensure the integrity of the documents
- secure digital archives
9.4 Security Incident Management
Respace has implemented procedures to:
- identify security incidents
- document them
- to limit their impact
- to make the required notifications to the relevant authorities
- to inform affected individuals when required by applicable regulations
ARTICLE 10 – PROCESSING BY THIRD PARTIES
When Respace engages a processor as defined by the GDPR, it ensures that the processor provides sufficient guarantees regarding the implementation of appropriate technical and organizational measures.
Processors may process personal data only upon documented instructions from Respace and in strict compliance with applicable obligations.
Agreements in accordance with Article 28 of the GDPR are put in place when required.
ARTICLE 11 – PRINCIPLE OF DATA MINIMIZATION
Respace ensures that it collects only personal data that is adequate, relevant, and limited to what is necessary in light of the purposes pursued.
Each new processing operation is subject to an analysis aimed at:
- limit the volume of data collected
- avoid the collection of unnecessary data
- reduce retention periods
- limit access
- reduce risks to data subjects
ARTICLE 12 – ACCURACY OF DATA
Respace takes reasonable measures to ensure that the personal data processed is:
- accurate
- complete
- updated when necessary
Data subjects are encouraged to notify Respace of any changes to their data.
ARTICLE 13 – ACCOUNTABILITY
In accordance with the principle of accountability set forth in the GDPR, Respace implements measures designed to demonstrate its compliance with applicable regulations.
To this end, Respace may, in particular:
- maintain a record of processing activities
- establish internal policies and procedures
- train individuals who process personal data
- document decisions related to data protection
- conduct risk assessments
- conduct internal or external audits
ARTICLE 14 – YOUR RIGHTS
In accordance with applicable data protection regulations, you have various rights regarding your personal data processed by Respace.
Subject to the conditions and limitations set forth in applicable regulations, you have the following rights, among others:
14.1 Right of Access
You have the right to obtain confirmation as to whether or not Respace is processing personal data concerning you.
If this is the case, you have the right to access this data as well as certain information relating in particular to:
- the purposes of the processing
- the categories of data concerned
- the recipients
- retention periods
- the safeguards applicable in the event of an international transfer
- the source of the data when it was not collected directly from you
14.2 Right to Rectification
You have the right to have inaccurate personal data about you corrected.
You also have the right to request that incomplete data be completed.
14.3 Right to erasure
You may request the erasure of your personal data when:
- the data is no longer necessary
- you withdraw your consent when it constitutes the legal basis for the processing
- you validly object to the processing
- the data has been processed unlawfully
- a legal obligation requires its deletion
The exercise of this right remains subject to the limitations set forth in applicable regulations.
14.4 Right to Restriction of Processing
You may request the restriction of the processing of your personal data, particularly in the following situations:
- when you contest the accuracy of the data
- when the processing is unlawful but you do not wish to have the data erased
- when Respace no longer needs the data but you still need it to exercise or defend your legal rights
- while a request to object is being reviewed
14.5 Right to Object
When processing is based on Respace’s legitimate interest, you have the right to object to such processing for reasons related to your particular situation.
Respace will then cease the processing in question unless it demonstrates compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or where the processing is necessary for the establishment, exercise, or defense of legal claims.
14.6 Right to Object to Marketing Communications
You have the right at any time to object to receiving commercial communications or marketing messages.
This right is free of charge and may be exercised:
- by using the unsubscribe link provided in the communications
- by contacting Respace directly
14.7 Right to Data Portability
When processing is based on your consent or a contract and is carried out by automated means, you may request:
- the disclosure of your personal data in a structured, commonly used, and machine-readable format
- the direct transmission of this data to another data controller, where technically feasible
14.8 Right to Withdraw Your Consent
When processing is based on your consent, you may withdraw it at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.
14.9 Right not to be subject to automated decision-making
You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you, except in cases provided for by applicable regulations.
ARTICLE 15 – EXERCISING YOUR RIGHTS
You may exercise your rights or ask any questions regarding the protection of your personal data by contacting Respace through one of the following methods:
By mail
RESPACE SA
Place Poelaert 6
1000 Brussels
By email
In order to process your request, Respace may need to verify your identity when necessary.
Respace will respond to your request within the timeframes set forth in applicable regulations.
ARTICLE 16 – COMPLAINTS TO THE SUPERVISORY AUTHORITY
If you believe that the processing of your personal data does not comply with applicable regulations, you have the right to file a complaint with the competent supervisory authority.
In Belgium, the competent authority is:
Data Protection Authority
Rue de la Presse 35, 1000 Brussels
Website: https://www.autoriteprotectiondonnees.be/
This right may be exercised without prejudice to any other administrative or judicial remedy.
ARTICLE 17 – COOKIES AND SIMILAR TECHNOLOGIES
17.1 Principle
The Respace website uses cookies and similar technologies to ensure it functions properly, to improve your user experience, and to ensure the security of its services.
A cookie is a small file stored on your device when you visit a website.
Cookies can be temporary or persistent and are used, among other things, to:
- secure browsing
- to remember certain preferences
- to improve the website’s functionality
- measuring website traffic
- to ensure certain technical functions
17.2 Strictly Necessary Cookies
Certain cookies are essential for the website to function.
These cookies may, in particular, allow:
- maintain the user’s session
- to ensure the security of the site
- to ensure pages display correctly
- enable certain essential features
These cookies are used based on Respace’s legitimate interest or when they are strictly necessary to provide the requested service.
17.3 Audience Measurement Cookies
Respace may use cookies or statistical tools to:
- analyze website traffic
- understand how visitors use the site
- improve the content offered
- optimize functionality
When required by law, these cookies will only be placed after obtaining your prior consent.
17.4 Marketing Cookies
If Respace uses marketing or advertising cookies, they will be placed only after obtaining your consent when required by applicable regulations.
17.5 Managing Your Preferences
You may at any time:
- accept cookies
- reject certain cookies
- withdraw your consent
- change your preferences
You can also configure your browser to block or delete certain cookies.
However, blocking certain cookies may affect the website’s functionality.
17.6 Cookie declaration
The list below is automatically generated and updated by Cookiebot. It includes all cookies currently detected on our website:
ARTICLE 18 – USE OF GOOGLE reCAPTCHA
To protect its website against automated access, malicious bots, fraud attempts, and abuse, Respace uses Google reCAPTCHA v3. This use is expressly mentioned in the policy currently published on the Respace website.
Google reCAPTCHA may process certain technical data such as:
- the IP address
- browser characteristics
- information about the device used
- certain interactions performed on the website
- information used to determine whether the observed behavior is that of a human or an automated program
The processing of this data is based on Respace’s legitimate interest in ensuring the security of its digital services and protecting its website against abuse.
For more information regarding Google’s processing of this data, please refer to Google’s published documentation on data protection.
ARTICLE 19 – CHANGES TO THE PRIVACY POLICY
Respace reserves the right to amend this Privacy Policy at any time to reflect, in particular:
- changes in its business activities
- changes in its services
- changes in its IT tools
- changes in laws or regulations
- new recommendations from the relevant authorities
The most recent version of the Privacy Policy will always be available on the platforms provided by Respace.
In the event of a substantial change, Respace may take appropriate measures to notify the individuals concerned.
ARTICLE 20 – EFFECTIVE DATE
This Privacy Policy took effect on July 22, 2026.
It supersedes any previous version relating to the same subject matter.
ARTICLE 21 – CONTACT
If you have any questions regarding this Privacy Policy or how Respace processes your personal data, please contact:
RESPACE
Place Poelaert 6
1000 Brussels
pierre.colaiacovo@respace.be