Privacy Policy - AnyShift.be
Last updated: 3 August 2026
1. Who we are
AnyShift is a licensed Belgian temporary employment agency, with its registered office at Stenenbrug 117, 2140 Borgerhout, Belgium. AnyShift processes personal data as a data controller within the meaning of the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679).
| Data controller | AnyShift |
|---|---|
| Address | Stenenbrug 117, 2140 Borgerhout, Belgium |
| Licence number | VG.2458/U |
| Company number (KBO) | 1019.746.053 |
| Contact point for privacy requests | privacy@anyshift.be |
| Data protection contact person | Sania Khan - privacy@anyshift.be |
2. What data we collect
Depending on your capacity (flexi-worker, student, client, candidate, website visitor), we process, among other things:
- Identity data: name, date of birth, national register number, address
- Contact data: telephone number, email address
- Financial data: IBAN account number for wage payments
- Employment data: student/flexi status, remaining hours quota, work permit (for non-EU employees), position, work schedule
- Contractual data: signed employment contracts (AES/SMS-OTP e-signature), Dimona confirmations
- Performance data: hours worked, time registrations, payslips
- Client data: company details (KBO number, joint committee), invoicing details, contact persons
- Technical data: IP address, cookies (see our separate Cookie Policy)
We do not collect special categories of personal data (e.g. health data, ethnic origin) unless this is strictly necessary and legally permitted (e.g. in the context of incapacity for work).
3. Legal bases for processing (Art. 6 GDPR)
| Purpose of processing | Legal basis (Art. 6.1 GDPR) |
|---|---|
| Concluding and performing temporary agency work contracts | (b) Performance of a contract |
| Dimona declaration, compliance with labour and social security legislation | (c) Legal obligation |
| Payroll processing via the social secretariat (Securex) | (b) Performance of a contract / (c) Legal obligation |
| Matching employees with assignments | (b) Performance of a contract |
| Identity verification and electronic signing | (c) Legal obligation / (f) Legitimate interest (fraud prevention) |
| Invoicing and client management | (b) Performance of a contract |
| Transactional communication (shift offers, contract confirmations) | (b) Performance of a contract |
| Marketing communication | (a) Consent |
| Platform security, fraud prevention | (f) Legitimate interest |
| Reporting and improvement of the services (at aggregated level) | (f) Legitimate interest |
| Defence in disputes or inspections (e.g. social inspection) | (f) Legitimate interest / (c) Legal obligation |
4. Retention periods for personal data
We do not keep personal data longer than necessary for the purpose for which it was collected, and we comply with the following statutory retention periods under Belgian law:
| Data category | Retention period | Legal basis |
|---|---|---|
| Dimona declarations/confirmations | 6 months after receipt | Royal Decree of 5 November 2002 |
| Social documents (individual account, DMFA declarations) | 5 years | Royal Decree No. 5 of 23 October 1978 |
| Tax documents (withholding tax, wage statements) | 10 years | Belgian tax legislation |
| Employment contracts | Duration of the employment + limitation period (in principle 1 year, up to 10 years where an offence is suspected, e.g. non-payment of wages) | Employment Contracts Act; Civil Code |
| Candidate/prospect data (not placed) | Maximum 2 years after last contact | Legitimate interest, proportionality |
| Accounting data of clients | 7 years | Code of Economic Law / accounting legislation |
| Cookies and technical data | See Cookie Policy | - |
After expiry of the applicable retention period, data is deleted or irreversibly anonymised.
5. With whom we share your data
We share personal data exclusively with the following categories of recipients, in each case limited to what is necessary for their specific function:
| Recipient | Purpose | Data category |
|---|---|---|
| Securex (social secretariat) | Payroll processing | Identity, employment and performance data |
| Electronic signature provider | Contract signing (AES/SMS-OTP) | Identity data, telephone number |
| Brevo (communication platform) | Sending notifications (WhatsApp/email/SMS) | Name, telephone number, email address |
| DigitalOcean (hosting provider) | Hosting of the platform (EU region) | All categories mentioned above |
| NSSO/NEO/Belgian government agencies | Statutory declarations (Dimona, social security) | Identity and employment data |
| External legal and accounting advisers | Compliance and dispute resolution | Limited, case by case |
We conclude a data processing agreement (Art. 28 GDPR) with every processor. We never sell personal data to third parties.
6. International data transfers
Our data is primarily processed and hosted within the European Economic Area (EEA). If a processor were exceptionally to process data outside the EEA, this is done exclusively on the basis of an adequacy decision of the European Commission or appropriate safeguards (e.g. Standard Contractual Clauses), in accordance with Art. 44-49 GDPR.
7. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection to the processing of your personal data, in accordance with Art. 15-22 GDPR. You can exercise these rights by contacting privacy@anyshift.be.
We respond within one month of receiving your request; this period may be extended by two months for complex requests, of which you will be informed within the first month.
Erasure takes place immediately where legally permitted; if a statutory retention period applies (see section 4), you will be informed of the legal basis and the expected deletion date.
8. Minors
AnyShift mediates, among other things, student jobs. For employees who are minors (younger than 18 years) and who are permitted to work under Belgian labour law, additional care is applied, including, where legally required, the consent of the parents or legal representative.
9. Complaints
You have the right to lodge a complaint with the Belgian Data Protection Authority (GBA/APD):
Data Protection Authority (GBA/APD)
Drukpersstraat 35, 1000 Brussels
Email: contact@apd-gba.be
Website: www.gegevensbeschermingsautoriteit.be
10. Security
We take appropriate technical and organisational measures to protect your data, including encryption in transit (TLS) and function-based access restriction ("need-to-know").
11. Changes to this policy
We may update this privacy policy from time to time. The date of the last change is stated at the top of this document.
