Privacy Policy
How we collect, use, and protect your personal data
Last updated: 1 September 2026
This Privacy Policy describes how EngiFlex ("we", "us", or "our") collects, uses, and shares your personal data when you visit our websites, apply for a role, use our services, or otherwise interact with us.
As a project sourcing consultancy agency, we process personal data of candidates, consultants, clients, and website visitors. We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (GDPR) and applicable Belgian data protection law.
1. Data Controller
The controller of your personal data is:
EngiFlex BVKleine Amer 15, 2870 Puurs-Sint-Amands, Belgium
Company and VAT number: BE0792584030
Email: info@engiflex.be
Website: engiflex.be
We have not appointed a Data Protection Officer (DPO). Questions about this policy and requests to exercise your rights reach our standing point of contact at info@engiflex.be.
2. Scope of This Policy
This policy covers every processing activity for which EngiFlex is responsible:
- the website engiflex.be, including the contact form;
- the vacancies site jobs.engiflex.be;
- the application page our vacancies link through to, which is hosted by the supplier of our applicant tracking system;
- our job alerts and other email communication with candidates and clients;
- the recruitment, selection, and project sourcing services themselves, including contact by email, by phone, or at a client site;
- the data of our own employees and freelance consultants during their employment or assignment (see section 3.4 and the retention periods in section 8).
This policy does not cover:
- the processing by a client after we have shared your profile as agreed with you: that client is an independent controller for it, under its own privacy policy (see section 6);
- third-party websites we link to.
3. Personal Data We Collect
We may collect and process the following categories of personal data:
3.1 Data you provide directly
- Contact details: name, email address, phone number, and company name when you complete our contact form or get in touch
- Candidate data: CV, work experience, education, skills, certifications, languages, availability, salary or rate expectations, and other information relevant to a placement, when you apply or register as a candidate
- Client data: company information, contact details of representatives, project requirements, and staffing needs
- Communication data: the content of emails, messages, and other correspondence with us, and the notes a recruiter adds to your file after a conversation
- Job alert preferences: the sectors, disciplines, and regions you want to hear about
3.2 Data collected automatically
- Server logs: our hosting provider records your IP address, the time, the page requested, the status code, your browser type, and your operating system. We use this to monitor the security of the site and to trace faults.
We use no analytics, marketing, or tracking cookies and do not measure individual browsing behaviour. See section 11 for what is stored on your device.
3.3 Data from other sources
Not all of your data comes directly from you. We may also obtain it from:
- publicly accessible professional profiles, job platforms, and CV databases, when we approach candidates ourselves;
- referrals from consultants, employees, or contacts in our network;
- VDAB and comparable employment services, when a vacancy runs through that channel;
- references from former employers or clients, in line with what we agreed with you in advance;
- public company and trade registers, for our client work.
If we approach you on the basis of such data, we tell you at first contact where we obtained it and point you to this policy.
3.4 Data we do not ask for
We do not ask you for data about health, religious or philosophical beliefs, political opinions, trade union membership, ethnic origin, or sexual orientation, nor for criminal record data. Some clients in pharmaceutical production impose additional conditions on people working at their site, such as a medical fitness declaration or an extract from the criminal record. Those documents pass directly between you and the client or the occupational health service; we keep no copy of them in your candidate file.
If you join us as an employee or start working for us as a freelancer, we additionally process the data required by employment, social security, and tax law: your national register number, bank account number, family situation for withholding tax, time and absence records, and the certificates the client requires for access to its site. The legal basis is the performance of your employment or service contract and our legal obligations; the retention periods are set out in section 8. From the occupational health service we receive only the conclusion whether you are fit for the work, never medical data itself.
3.5 Required or optional
Your name, email address, and CV are needed to handle your application and to present you to a client; without them we cannot. All other fields are optional, and leaving them out has no consequence other than a less precise match.
4. Purposes and Legal Bases
We process your personal data for the following purposes, on the corresponding legal bases:
4.1 Performance of a contract and steps preceding it
- Matching candidates with suitable job opportunities and assignments
- Delivering project sourcing and consultancy services to clients
- Managing candidate profiles and applications
- Presenting your profile to a client for a specific assignment, in line with what we agreed with you in advance (see section 6)
- Communicating about opportunities, interviews, and placements
- Following up assignments, processing timesheets, and invoicing
4.2 Legitimate interests
- Answering questions and supporting candidates and clients
- Improving our websites and services and tracing faults
- Building and maintaining our talent pool for future opportunities
- Requesting references from a former employer or client, in line with what we agreed with you
- Promoting our services to existing clients, always with an opt-out
- Maintaining the security of our systems and preventing misuse
For each of these purposes we have weighed our interest against your rights and freedoms. You can object to these processing activities at any time (see section 10).
4.3 Legal obligations
- Meeting tax, accounting, social security, and reporting obligations
- Responding to lawful requests from authorities
4.4 Consent
- Sending job alerts and other marketing communication to a personal email address
You can withdraw your consent at any time. This does not affect the lawfulness of processing carried out before the withdrawal.
5. Use of Artificial Intelligence
We use AI assistance in our own applicant tracking system when processing applications. Specifically:
- Field extraction: structured data (education, work experience, skills, languages) is pulled from an uploaded CV so it does not have to be retyped by hand.
- Summarisation: a short overview of a profile, as an aid for the recruiter handling the file.
- Search and matching: profiles are ranked by substantive similarity to a vacancy, as a suggestion in the recruiter's search results.
This processing runs through AI providers acting as processors, under the conditions described in section 6.2. Some of them are established outside the European Economic Area (see section 7).
No automated decision-making. An AI suggestion is never a decision. Whether you are contacted, presented, or selected is always decided by a recruiter who reviews your full profile. There is therefore no decision based solely on automated processing within the meaning of Article 22 GDPR. You can object to this processing (see section 10).
6. Sharing With Third Parties
We do not sell your personal data and do not make it available for third parties' marketing purposes. We do share it with the following recipients:
6.1 Clients
Your profile is never circulated unasked. We agree with you in advance which client and which assignment we share your CV or profile for. We make that agreement per assignment.
Once a client receives your data, it becomes an independent controller for it: it decides for what and for how long it uses that data, under its own privacy policy. From that moment you can also exercise your rights directly with that client. We ask our clients to use your data only for the assignment concerned, but we have no control over their systems. On request, we will tell you which clients have received your profile.
6.2 Service providers
External suppliers that process solely on our behalf and on our instructions, bound by a data processing agreement. These fall into the following categories:
- the supplier of our applicant tracking system, including the application page where you submit your candidacy;
- the hosting providers of our websites and of our internal system;
- our email, calendar, and document environment;
- the AI providers described in section 5;
- our accounting and invoicing software and our payroll office.
A current list of the suppliers concerned, with their role and country of establishment, is available on request at info@engiflex.be.
6.3 References
We agree with you in advance which former employers or clients we may contact, and we limit ourselves to your professional performance. You can object at any time.
6.4 Other recipients
- Professional advisers: accountants, lawyers, insurers, and other advisers where necessary for running the business.
- Authorities and employment services: VDAB and comparable services when a vacancy or placement runs through that channel.
- Legal requirements: where required by law, by court order, or on a lawful request from an authority.
- Business transfer: in a merger, acquisition, or transfer of activities, with the acquirer bound by the same conditions.
7. Transfers Outside the EEA
All of our clients are currently established within the European Economic Area. Your profile is therefore not presented outside the EEA without us agreeing that with you in advance.
Some of our service providers are established outside it. In particular, the data in our applicant tracking system is stored on servers in the United States, and some of the AI services in section 5 and our email and document environment are US providers.
For these transfers we rely on the safeguards the GDPR provides: an adequacy decision of the European Commission where one exists (including the EU-US Data Privacy Framework for certified recipients) and otherwise the standard contractual clauses approved by the European Commission, supplemented with technical and organisational measures. An overview of the transfers and a copy of the safeguards used is available on request at info@engiflex.be.
8. Retention
We keep your personal data no longer than necessary for the purposes for which it was collected. Unless stated otherwise, the periods below run from your last meaningful contact with us:
- Candidate data, applications, and talent pool: up to 3 years. A conversation, a new application, a response to a job alert, or a message from you restarts that period. You can request earlier deletion at any time.
- Consultants placed through us: for as long as the employment or assignment runs, plus the terms imposed by social security, tax, and accounting law. For social documents, 5 years after the end of the employment. Clients in the pharmaceutical sector are required by their own quality rules to keep the CV and training record of anyone working at their site for longer; that retention is their responsibility.
- Client data: for the duration of the business relationship. We then keep contract files for 10 years, the limitation period for contractual claims, and accounting records for 7 years.
- Contact forms: up to 2 years, unless longer retention is needed for ongoing communication.
- Job alerts: until you unsubscribe, and at most 1 year afterwards to be able to show the unsubscribe was carried out.
- Server logs: for as long as our hosting provider keeps them, a maximum of 12 months.
Two exceptions apply. Where a law requires us to keep data longer, we follow that law. And where a complaint, dispute, or claim is pending or can reasonably be expected, we keep the data concerned until the matter is finally settled and the limitation period has expired. The GDPR expressly provides for this in order to establish, exercise, or defend legal claims.
9. Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
No method of transmission over the internet or electronic storage is, however, 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
10. Your Rights
Under the GDPR you have the following rights in relation to your personal data:
- Right of access: you can request a copy of the personal data we hold about you.
- Right to rectification: you can ask us to correct inaccurate or incomplete data.
- Right to erasure: in certain circumstances you can request deletion of your data (the "right to be forgotten").
- Right to restriction of processing: you can ask us to limit the use of your data.
- Right to data portability: in certain circumstances you can request your data in a structured, commonly used, machine-readable format.
- Right to withdraw consent: where processing rests on your consent, you can withdraw it at any time.
Right to object. Where we process your data on the basis of our legitimate interest (for example to keep your profile in our talent pool), you can object at any time on grounds relating to your particular situation. Where it concerns direct marketing, you do not have to give reasons and we stop immediately.
To exercise any of these rights, contact us at info@engiflex.be. We respond within one month. If your request is complex, or if we receive several from you, we may extend that term by two months; we will tell you within the first month. Where we have reasonable doubts about your identity, we may ask for additional information, never more than is needed to identify you.
If you believe we have not handled your data properly, you have the right to lodge a complaint with the Belgian Data Protection Authority:
GegevensbeschermingsautoriteitDrukpersstraat 35, 1000 Brussels
www.gegevensbeschermingsautoriteit.be
11. Cookies and Similar Technologies
Cookies are small text files stored on your device when you visit a website. Our websites use only storage that is strictly necessary to make the site work the way you have set it. Under the ePrivacy Directive no consent is required for this, which is why we show no cookie banner.
| Name | Purpose | Duration | Type |
|---|---|---|---|
ef_lang | Remembers your language preference (Dutch, English, or French) | 1 year | Essential cookie |
ef_theme | Remembers whether you view the site in light or dark mode | Until you clear it | Functional local storage |
We use no analytics, marketing, or tracking cookies, no advertising networks, and no social media pixels. No personal data whatsoever is collected through cookies.
Our brand typeface is served from our own servers, so no request goes to an external provider for it. Our hosting provider records technical data about your visit, as described in section 3.2. No cookies are set for that either.
You can manage cookie preferences through your browser settings. Note: if you delete the language preference cookie, the website will detect your language automatically on your next visit.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in legal requirements. We will post the updated policy on this page with a new "Last updated" date. We encourage you to review this policy regularly.
For material changes that substantially affect your rights, we will make reasonable efforts to inform you, for example by email or a notice on our website.
13. Contact
If you have questions about this Privacy Policy or about our data practices, please contact us:
EngiFlex BVKleine Amer 15, 2870 Puurs-Sint-Amands, Belgium
Email: info@engiflex.be
Website: Contact page