OneToSecure – IT Security and Service Management Consulting
Last updated: September 26, 2026
1. Introduction and commitment
OneToSecure SRL (hereinafter "we", "us" or "the Company") is firmly committed to protecting the privacy and personal data of its customers, prospects, visitors and business partners (hereinafter "you" or "users").
This Privacy Policy explains how we collect, use, process, store and protect your personal data when you:
• Visit our website: www.onetosecure.com
• Use our cybersecurity and managed services
• Contact us by email, phone or form
• Participate in our awareness campaigns or training sessions
As a cybersecurity service provider, we understand the crucial importance of data security and confidentiality. We fully comply with applicable regulations, including the General Data Protection Regulation (GDPR) and the Belgian Data Protection Act.
2. Data controller and contact
Data controller:
OneToSecure SRL
Sector: Cybersecurity and IT Services
Contact: +32.499.31.35.85
Email: [email protected]
Website: www.onetosecure.com
For any questions relating to the protection of your personal data or to exercise your rights (see section 9), you can contact us via:
Email: [email protected]
3. Personal data collected
3.1 Data collected directly from you:
During your interaction with us, we collect the following categories of data:
Identification and contact details
• First and last name
• Professional and personal email address
• Telephone number
• Postal address
• Company, sector of activity, position held
Contractual and commercial data
• Information on services requested or purchased
• Order and contract history
• Business correspondence
• Payment terms and billing information
Communication data
• Content of messages, calls and video conferences
• Logs of customer interactions
• Dates and times of communications
Technical and preference data
• Communication preferences (SMS, email, call)
• Preferred language
• Region/country
3.2 Data collected automatically via the website:
Navigation and technical data
• IP address
• Browser type and operating system
• Pages visited and visit duration
• Traffic source (direct, search engine, advertising campaign)
• Screen resolution and device information
• Cookie data and localStorage
3.3 Audit and security data (during service provision)
When we provide security audit, penetration testing, or infrastructure management services, we can access:
• System and server configurations
• IP addresses and network information
• Event logs and audit data
• File and database metadata (without access to sensitive content)
• User IDs and access roles
4. Legal basis for processing
We process your personal data only on the basis of one of the following legal grounds:
4.1 Performance of a contract (Article 6.1.b GDPR)
To provide the requested services (security audit, IT support, training, etc.), establish a contract, manage invoicing and customer follow-up.
4.2 Consent (Article 6.1.a GDPR)
For sending newsletters, marketing communications, or any other purpose for which you have explicitly given your consent. You can withdraw your consent at any time.
4.3 Legal obligations (Article 6.1.c GDPR)
To comply with applicable legal obligations in Belgium and Europe (taxation, regulatory compliance, legal archiving).
4.4 Legitimate interests (Article 6.1.f GDPR)
To secure our infrastructure, prevent fraud, improve our services, or pursue legal claims.
5. Purposes of processing your data
We use your data to:
5.1 Commercial and Contractual Management
• Process your requests for quotes or information
• Establish and manage service contracts
• Billing, payment and customer relationship management
• Order tracking and service delivery
5.2 Provision of services
• Perform security audits, penetration tests, and other requested services
• Provide IT technical support and maintenance
• Manage your cloud infrastructure and backups
• Provide cybersecurity training and awareness
5.3 Marketing and Sales Communications
• Send newsletters and updates about our services (with your consent)
• To inform about new products, special offers or promotions
• B2B sales prospecting with your prospects
5.4 Improvement and optimization
• Analyze website usage and improve the user experience
• Perform statistical and performance analyses
• Test new features
5.5 Security and compliance
• Prevent and detect fraud or misuse
• Secure the infrastructure and systems
• Comply with legal and regulatory obligations
• Manage legal requests and disputes
6. DATA SHARING AND DISCLOSURE
6.1 Partners and subcontractors
We share your data with our trusted partners and service providers only when necessary to provide our services. These include:
Infrastructure and hosting providers:
• OVH Cloud, Scaleway, Infomaniak (web and data hosting)
• Microsoft Azure, AWS (cloud services)
• Bitdefender (antivirus and cybersecurity solutions)
Business partners:
• Microsoft and Bitdefender network partners
• IT service providers (NextCloud, Redstor for backups)
Third-party tools and services:
• CRM platform and contract management
• Email marketing services (if applicable)
• Web analytics tools (Google Analytics with IP anonymization)
All our partners are bound by Data Processing Agreements (DPAs) guaranteeing security and confidentiality.
6.2 Legal Authorities
We may disclose your data if required by law, a court order, or a request from the competent authorities (tax, judicial, police).
6.3 International Transfers
Most of our services are provided within the EU. Some partners (Microsoft, AWS) operate internationally. For transfers outside the EEA, we use:
• European Commission adequacy decisions
• Standard Contractual Clauses (SCC)
• Certifications (e.g., Privacy Shield for some providers)
6.4 No data sales
We never sell, exchange, or rent your personal data to third parties, whether for payment or not.
7. Data retention period
We retain your personal data for as long as necessary to:
• Provide the agreed services (contract duration + 30 days after termination)
• Comply with legal obligations (retain billing/audit data for 7 years in accordance with Belgian law)
• Manage potential claims and disputes (5 years after the end of the relationship)
Specific shelf life:
Newsletter/marketing data
• Kept while you are subscribed; deleted after unsubscribing + 30 days
Website data (cookies, logs)
• Access logs: 90 days
• Analytical cookies: 13 months (configurable)
Audit data and penetration testing
• Reports: kept for 2 years after the end of the service
• Raw technical data: 30 days after the final report
Technical support data
• Tickets and history: kept for 2 years after closing
8. Data security and protection
As a cybersecurity provider, protecting your data is our top priority. We implement robust security measures:
8.1 Technical Measures
• TLS/SSL encryption for all communications (HTTPS)
• AES-256 encryption for data at rest
• Multi-factor authentication (MFA) for administrator access
• Firewalls and intrusion detection systems (IDS/IPS)
• Offsite and immutable backup of critical data
• System isolation and network segmentation
8.2 Administrative Measures
• Strict access control: access to data is linked to roles and permissions
• Confidentiality clauses in all contracts with employees and partners
• Ongoing staff training in good safety practices
• Regular audits of access and logs
• Strong password management policy
8.3 Security Incident
In the event of a data breach or security incident threatening your personal information, we will notify the relevant authorities (CNPD) and the affected persons within 72 hours, in accordance with the GDPR.
9. Your rights and how to exercise them
In accordance with the GDPR, you have the following rights regarding your personal data:
9.1 Right of access
You have the right to access your personal data and to obtain a copy of it in a structured and commonly used format.
9.2 Right of rectification
You can request the correction of inaccurate or incomplete data.
9.3 Right to erasure (“right to be forgotten”)
You can request the deletion of your data, unless we have a legal obligation to retain it.
9.4 Right to restriction of processing
You can request that we limit the processing of your data (storage without use) in certain circumstances.
9.5 Right to data portability
You have the right to receive your data in a structured format and to transfer it to another data controller.
9.6 Right to object
You can object to the processing of your data for direct marketing purposes. If you object, we will cease all marketing communications immediately.
9.7 Right to withdraw consent
If your treatment is based on consent, you can withdraw it at any time, without affecting previous treatments.
9.8 How to exercise your rights
To exercise any of these rights, please contact us by email ([email protected]) indicating:
• Your specific request (access, rectification, erasure, etc.)
• Your identity and contact information
• Proof of identity
• Details on the data involved
We will process your request within one month. This period may be extended by two months for complex requests.
10. Cookies and tracking technologies
10.1 What is a cookie?
Cookies are small text files stored on your device to recognize your browser and remember your preferences.
10.2 Types of cookies used
Essential cookies
• Necessary for the site to function (session, security, authentication)
• Always active, no opt-in required
Analytical cookies
• Google Analytics with IP address anonymization
• Usage analysis to improve the site
• Duration: 13 months
Marketing cookies (marketing/retargeting)
• Targeted advertising and conversion tracking
• Require your explicit consent
10.3 Cookie Management
You can :
• Accept or decline non-essential cookies via our consent banner
• Configure your browser to refuse cookies
• Delete existing cookies
11. Links to other websites
Our site may contain links to third-party websites. This privacy policy applies only to www.onetosecure.com. We are not responsible for the privacy policies of external websites. We encourage you to review their policies before sharing your data.
12. Protection of children's data
Our services are intended for professionals and businesses. We do not intentionally collect personal data from children (under 16 years of age). If we discover that a child has provided us with data, we will delete it immediately.
13. Amendments to this charter
We may modify this privacy policy at any time to reflect changes in our practices, technology, legal requirements, or other factors.
Significant changes will be communicated via email or a notification on our website. The date of the last update is indicated at the top of this document.
14. Contact and recourse
14.1 For any questions
Email: [email protected]
Telephone: +32.499.31.35.85
14.2 Competent Authority
If you believe your data protection rights are not being respected, you have the right to file a complaint with:
Data Protection Authority (DPA)
35 Rue de la Presse
1000 Brussels, Belgium
Email: [email protected]
Website: www.autoriteprotectiondonnees.be