Privacy Policy
Last updated 13 September 2026
1. Controller
INCORP BV, Wilbroek 15, 3583 Beringen, Belgium, company and VAT number BE 0741.695.949, is the controller for the personal data described in this policy. For any question or request, use the contact form on our website.
2. What we collect
Contact requests. When you contact us through this website or by email, we receive your name, company, email address and the content of your message.
Business contacts. In the course of an engagement or a commercial relationship we process the professional contact details of client and prospect representatives.
Technical data. Our hosting provider processes standard server data such as IP address, browser type and requested page in order to deliver and secure the website.
We do not use advertising or tracking cookies on this website, and we do not sell personal data.
3. Why we use it and on what legal basis
To answer your request and to prepare or perform a contract (Article 6(1)(b) GDPR); to manage our client relationship, invoicing and accounting, and to comply with legal obligations (Article 6(1)(c) GDPR); and to secure our website and communicate about our services with existing business contacts, based on our legitimate interest (Article 6(1)(f) GDPR).
4. Data we process for clients
During identity governance engagements we may process personal data belonging to a client's own systems — for example identities, accounts and entitlements. In that context the client is the controller and INCORP acts as a processor under a written data processing agreement in accordance with Article 28 GDPR. We process such data only on the client's documented instructions, prefer read-only and pseudonymised access, and delete or return it at the end of the engagement.
5. AI processing
Where AI agents are used, they operate on the data scoped to the engagement, under human oversight, with logging of actions and decisions. We do not use client data to train general-purpose AI models. Our AI governance follows the principles of ISO/IEC 42001, including documented purpose, risk assessment, human oversight and periodic review.
6. Who we share data with
We share personal data only with service providers who act for us — hosting, email, accounting and collaboration tools — and with authorities where the law requires it. These providers act under a contract and may process data only on our instructions.
Where a provider processes data outside the European Economic Area, the transfer relies on an adequacy decision or on the European Commission's Standard Contractual Clauses.
7. How long we keep it
Contact requests that do not lead to a relationship: up to 2 years. Client and supplier records: for the duration of the relationship and 10 years afterwards, as required by Belgian accounting law. Server logs: a limited period for security purposes. Client project data: as agreed in the data processing agreement.
8. Security
We apply technical and organisational measures appropriate to the sensitivity of identity data: least-privilege access, multi-factor authentication, encryption in transit and at rest, logging, and confidentiality commitments for everyone involved in an engagement.
9. Your rights
You have the right to access your personal data, to have it rectified or erased, to restrict or object to its processing, and to data portability. Where processing is based on consent, you may withdraw it at any time. Send your request through the contact form; we reply within one month.
You can also lodge a complaint with the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels — contact@apd-gba.be.
10. Changes
We may update this policy. The current version is always available on this page with its date of last update.