Privacy policy

Version: 9 September 2026

Thank you for visiting our website and app.

The protection of your privacy and personal data is of utmost importance to us. We aim to protect your privacy and ensure that you can safely entrust us with your personal data. As such, we undertake to handle your personal data securely and discreetly. Furthermore, we take appropriate security measures to avoid loss, alteration, access by unauthorised persons and any other unlawful processing of your personal data.

This privacy policy covers the processing of personal data by us via our website selfstoragelock.com and the SELFSTORAGELOCK mobile application. We aim to be transparent about how we process your personal data and what we do with them. This policy provides more detail about those processes.

1. Who we are

SELFSTORAGELOCK BV, with registered office at Bosdel 58/2, 3600 Genk, Belgium and registered with the Belgian Crossroads Bank of Enterprises under company number 1035.376.416 (RLE Antwerp, section Tongeren-Borgloon), is referred to in this policy as SSL, we or us.

Privacy contact: Brent Casters
brent@bremo.be
+32 470 19 90 70

We process your personal data in accordance with the applicable legal provisions regarding privacy and the protection of personal data, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, the GDPR) and applicable national implementing legislation.

2. Definitions

Personal data means all information about an identified or identifiable natural person, the data subject. An identifiable natural person is someone who can be identified directly or indirectly, in particular through an identifier such as a name, identification number, location data, online identifier, or factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity. In other words, it is information that can be used to identify a person. This includes, for example, your surname, first name, date of birth, telephone number, email address and IP address.

Processing is a broad term and covers, among other things, collecting, recording, organising, storing, updating, modifying, retrieving, consulting, using, disseminating, combining, archiving and deleting data.

3. Controller

SSL is responsible for the processing of your personal data. We are what the GDPR refers to as the data controller. In concrete terms, this means that SSL, possibly together with other entities, determines the purpose and means for processing your personal data.

4. Data we process

Each processing activity below states which categories of personal data we process, why we process them, the legal basis for that processing and how long we retain them. All processing involving your personal data takes place for one or more specific purposes and only where we can rely on a valid legal basis.

The legal bases used below mean:

  • Consent: you have given consent for the processing of personal data for one or more specific purposes.
  • Agreement: processing is necessary for the performance of a contract to which you are a party, or to take steps at your request before concluding a contract.
  • Legitimate interest: processing is necessary to protect our legitimate interests or those of a third party, except where those interests are overridden by your interests or fundamental rights and freedoms.
  • Legal obligation: processing is necessary to comply with a legal obligation to which we, as the data controller, are subject.

Website access

Personal data
Device information
Purpose
To allow you to access our website
Legal basis
Agreement
Retention
Until the end of your visit to our website

General questions, messages and complaints

Personal data
Personal identification information, contact information, the contents of your message and attached files, if any
Purpose
To answer your question, message or complaint sent to the contact email address on our website
Legal basis
Consent
Retention
For the duration of the processing of your question or message

Support requests

Personal data
Personal identification information, contact information, the contents of your message, information about the system you use or device information for application issues, attached files, if any, and your feedback
Purpose
To respond to your support request sent to the support email address on our website
Legal basis
Agreement
Retention
For the duration of the processing of your support request

Application diagnostics and improvement

Personal data
Usage statistics, crash data, performance diagnostics data and application interactions
Purpose
To improve our application through performance analysis and crash reporting
Legal basis
Legitimate interest in product improvement
Retention
For the entire duration of the customer relationship with you

Requests to exercise privacy rights

Personal data
Personal identification information, contact information, company details if you represent a company, information about your relationship with us, the contents of your request and related information, ID-card details and signature
Purpose
To manage your request to exercise your rights
Legal basis
Legal obligation under Article 12(2) GDPR
Retention
10 years for the request or, in the event of judicial proceedings, until the proceedings end

Legal defence

Personal data
Personal identification information, contact information and any other information relating to you that may be necessary to defend and protect our rights
Purpose
To defend and protect our rights
Legal basis
Legitimate interest in legal defence
Retention
The applicable limitation period, as explained under “Retention of your personal data” below

5. Minors

We do not intend to collect any personal data from persons younger than 16 years old.

6. Your privacy rights

To give you more control over the processing of your personal data, you have various rights at your disposal. These rights are laid down in the GDPR.

Access

You have the right to be informed by us at any time whether or not we are processing your personal data. If we are, you have the right to access those personal data and receive additional information about:

  1. The purposes of the processing
  2. The categories of personal data concerned
  3. The recipients or categories of recipients, particularly recipients in third countries
  4. The retention period or, if that is not possible, the criteria used to determine it
  5. The existence of your privacy rights
  6. The right to lodge a complaint with the supervisory authority
  7. The source of personal data obtained from a third party
  8. Whether we use automated decision-making in respect of you

If we cannot give you access to your personal data, for example because of legal obligations, we will explain why. You can also obtain a free copy of the processed personal data in an understandable format. We may charge a reasonable fee to cover our administrative costs for any additional copy you request.

Deletion

In certain cases, you can ask us to delete your personal data. Your right to be forgotten is not absolute. We may continue to store your personal data where this is necessary for, among other things, the performance of an agreement, compliance with a legal obligation, or the establishment, exercise or substantiation of a legal claim. We will explain this in more detail in our response.

Rectification

If your personal data are incorrect, out of date or incomplete, you can ask us to correct those inaccuracies or complete the information.

Data portability

Subject to certain conditions, you have the right to have personal data you provided to us for the performance of an agreement, or for which you gave consent, transferred to another controller. Insofar as technically possible, we will provide your personal data directly to the new controller.

Restriction

You may ask us to restrict the processing of your personal data when:

  1. You dispute the accuracy of those data, for the time needed to verify their accuracy
  2. The processing is unlawful
  3. We no longer need the data for our purposes, but you need them to establish, exercise or substantiate a legal claim
  4. No decision has yet been taken on your objection to the processing

Objection

You can object to the processing of your personal data on the basis of your particular situation if we process them on the basis of legitimate interests or a task in the public interest. We will cease the processing unless we can demonstrate compelling and legitimate grounds that outweigh your own, or where the processing is related to establishing, exercising or substantiating a legal claim.

Automated decision-making

You have the right not to be subject to a decision made exclusively on the basis of automated processing that significantly affects you or has legal consequences and is made without substantial human involvement. This right does not apply where automated decision-making is legally permitted, based on your explicit consent, or necessary for entering into or performing a contract.

Withdrawal of consent

Where processing is based on your consent, you may withdraw that consent at any time.

Complaint

You have the right to lodge a complaint with a supervisory authority. A list of supervisory authorities in the European Union is available from the European Data Protection Board. In Belgium, the competent authority is:

Data Protection Authority
Drukpersstraat 35, 1000 Brussels, Belgium
www.dataprotectionauthority.be
+32 (0)2 274 48 00
contact@apd-gba.be

7. Exercising your rights

To exercise these rights, contact us using the details in section 1. To verify your identity, we may ask you to send a copy of the front side of your identity card. We do not retain the national register number or the image on your electronic identity card. We strongly advise you to black out both before sending a copy.

You can exercise these rights free of charge unless a request is manifestly unfounded or excessive, for instance because it is repetitive. In such cases, we may charge a reasonable fee or refuse to respond to the request.

8. Retention of personal data

We retain personal data only for as long as necessary to achieve the intended purpose. Numerous legal retention periods may require personal data to remain stored. Where no retention obligation applies, data are routinely deleted once the purpose for which they were collected has been fulfilled.

We may also store your personal data if you have consented to this or if we may need the data in connection with a legal claim. For this purpose, we retain certain personal data in accordance with the applicable limitation period. This can be up to 30 years, although the usual limitation period for personal claims is 10 years.

9. Sources of personal data

We process personal data that you provide to us voluntarily. If more personal data are required, we will tell you whether you are obliged to provide them and what the consequences are if you do not. Failure to provide personal data may mean that we cannot provide our services to you. In particular, we may obtain your personal data from your storage company.

10. Recipients

Within our organisation, we ensure that your personal data are accessible only to those who need them to fulfil contractual and legal obligations. We disclose personal data to third parties only in accordance with statutory provisions or where you have consented. In certain cases, our employees are supported by external service providers. We do not otherwise transfer personal data to third parties unless we are legally obliged to do so, for example to supervisory or law-enforcement authorities.

In particular, we identify these categories of recipients:

  1. Governmental or regulatory authorities when requested in order to comply with a judgment or decree, legislation, regulation, standard or legal process
  2. External service providers that enable us to provide website and application functionality to you, including cloud infrastructure providers
  3. External legal and financial advisers and consultants
  4. Parties involved in a business transfer connected with a merger, acquisition or sale of assets, following notice to you

11. Transfers outside the EEA

We transfer personal data to processors or controllers in countries outside the European Economic Area only insofar as we are legally entitled to do so. Where a transfer is necessary, we take the measures required to ensure that your personal data are highly protected and that the transfer takes place lawfully.

12. Security

The security of your personal data is an important concern for us. We take reasonable and adequate technical and organisational measures to protect them against accidental or intentional manipulation, loss, destruction or access by unauthorised persons. In particular, we use:

  1. Encryption of data in transit using TLS/SSL
  2. Secure token-based authentication for API requests
  3. Passwords stored using strong, salted hashing algorithms
  4. Regular security audits and access controls on our servers

Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal data, we cannot guarantee the security of personal data transmitted to us via the internet. Any transmission is at your own risk.

13. Questions or complaints

We aim to securely protect your privacy and personal data. If you have questions or complaints about how we process your personal data, contact us using the details in section 1.

14. Amendments

In response to feedback, or to reflect changes in our processing activities, we may amend this privacy policy from time to time. We therefore invite you to consult the most recent version on this website.