Privacy Policy - AnyShift.be
Last updated: 2 August 2026
At AnyShift BV, with registered office at Stenenbrug 117, 2140 Antwerpen (Borgerhout), Belgium, registered with the Crossroads Bank for Enterprises (KBO/CBE) under number BE 1019.746.053, we attach great importance to the protection of your personal data.
AnyShift is a licensed temporary employment agency in the Flemish Region (licence number VG.2458/U) that acts as an intermediary for flexi-jobs, student jobs and related forms of employment.
This privacy policy explains how we process personal data in accordance with:
- the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679);
- the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data;
- the Act of 5 December 1968 on collective bargaining agreements and applicable CBAs (including CBA No. 68 and CBA No. 109);
- all other applicable Belgian and European regulations.
1. Contact details and data controller
| Data controller | AnyShift BV |
|---|---|
| Address | Stenenbrug 117, 2140 Antwerpen (Borgerhout), Belgium |
| Company number (KBO/CBE) | BE 1019.746.053 |
| Licence number | VG.2458/U (Flemish Region) |
| General email address | hello@anyshift.be |
| Privacy-specific email address | privacy@anyshift.be |
| GDPR contact person | Sania Khan |
For all questions, requests or complaints regarding data protection, please contact our privacy officer at privacy@anyshift.be (state in the subject line: "Privacy question - GDPR").
AnyShift periodically assesses whether the appointment of a Data Protection Officer (DPO) within the meaning of Article 37 GDPR is required.
2. Who are "you" and "we"?
In this policy, "AnyShift", "we", "us" and "our" refer to AnyShift BV and its affiliated entities. "You" and "your" refer to:
- Shifters: employees (flexi-job workers, students, or other forms of employment) who search for and perform shifts via the AnyShift platform;
- Partners: employers, self-employed persons or organisations that post shifts via the platform;
- References: contact persons named by Shifters as a reference;
- Visitors: persons who visit the AnyShift website or applications without creating a registered account.
3. What personal data do we process?
3.1 Data you provide to us directly
Upon registration and profile creation (Shifters):
- Identification data: surname, first name, date of birth, gender
- Contact data: email address, telephone number, home address
- National register number (INSZ/NISS) - required for the DIMONA declaration and wage calculation
- Bank account number (IBAN) - for the payment of wages
- Copy of identity document or residence permit
- Diplomas, qualifications and work experience (CV data)
- Profile photo (optional)
- Student status and/or proof of enrolment (for student jobs)
- Proof of main occupation or pension status (for flexi-jobs)
Upon registration and profile creation (Partners):
- Company identification: name, KBO/VAT number, legal form
- Contact details of the responsible person(s): name, position, email, telephone
- Invoicing and payment information
- Sector, NACE code and joint committee (paritair comité) (relevant for flexi-job eligibility and wage scales)
- Functional information about shift needs and locations
When using the services:
- Shift requests, bookings and confirmations
- Ratings, feedback and performance information
- Communication via the platform (messages, notifications)
- Completed surveys or satisfaction questionnaires
3.2 Data generated automatically
- Location data: precise GPS location (only when the app is active and you have given your consent), approximate location via IP address
- Usage data: pages visited, features used, click behaviour, session duration
- Device information: device type, operating system, browser type, IP address, language
- Log data: server logs with timestamps, error messages, system activity
- Cookies and tracking technologies: see our Cookie Policy
3.3 Data received from third parties
- Social media (if you log in via a social media platform)
- Payment providers and financial institutions
- Government agencies (NSSO (RSZ), NEO (RVA), Dimona system) for verification purposes
- Our social secretariat Securex and its sub-processor Neembu (contract and payroll processing status, see section 8bis)
- References you provide yourself
- Publicly available sources (e.g. LinkedIn, KBO/CBE)
3.4 Special categories of personal data
In certain cases we process sensitive personal data within the meaning of Article 9 GDPR:
- Health data: e.g. fitness-for-work certificate, sickness absence - exclusively insofar as necessary for the performance of the employment contract or as required by law
- Nationality and residence status: to verify the applicability of labour law and social security law
We process this data exclusively on the basis of an explicit exception as provided for in Article 9(2) GDPR, and in compliance with the required additional safeguards.
4. Purposes and legal bases for processing (Art. 6 GDPR)
| Purpose of processing | Legal basis (Art. 6 GDPR) | Explanation |
|---|---|---|
| Creating and managing accounts | Art. 6(1)(b) - performance of a contract | Necessary to provide the service |
| DIMONA declaration and NSSO (RSZ) obligations | Art. 6(1)(c) - legal obligation | Act of 27 June 1969 (NSSO Act); Royal Decree on DIMONA |
| Wage calculation and payment (via Securex) | Art. 6(1)(b) + Art. 6(1)(c) | Performance of the employment contract + tax and social legislation |
| Matching Shifters with Partners | Art. 6(1)(b) - performance of a contract | Core function of the platform |
| Verification of employment law status (flexi-job, student) | Art. 6(1)(c) - legal obligation | Act of 16 November 2015 (flexi-jobs), as amended by the Act of June 2026 (Belgian Official Gazette of 2 July 2026); Act of 10 April 2025 (student quota) |
| Electronic contract handling (via Securex/Neembu) | Art. 6(1)(b) + Art. 6(1)(c) | Act of 24 July 1987; CBA 108 |
| Limosa notifications (foreign EU employees) | Art. 6(1)(c) - legal obligation | Royal Decree of 20 March 2007 concerning Limosa |
| Temporary employment agency obligations (licensed agency) | Art. 6(1)(c) - legal obligation | Act of 24 July 1987 on temporary work |
| Communication about shifts and services | Art. 6(1)(b) - performance of a contract | Necessary for service delivery |
| Commercial communication via email, SMS or WhatsApp | Art. 6(1)(a) - consent | Opt-in required; opt-out always possible via every message |
| Dispute resolution and fraud prevention | Art. 6(1)(f) - legitimate interest | Protection of platform integrity and users |
| Profiling for job matching (automated) | Art. 6(1)(b) + notification based on Art. 22 GDPR | See section 10 |
| Customer service and complaint handling | Art. 6(1)(b) + Art. 6(1)(f) | Performance of a contract + legitimate interest |
| Analysis and improvement of the services | Art. 6(1)(f) - legitimate interest | Internal use, anonymised statistics |
| Direct marketing (newsletter, offers) | Art. 6(1)(a) - consent | Opt-in required; opt-out always possible |
| Functional cookies | Art. 6(1)(b) - performance of a contract | Strictly necessary for operation |
| Analytical and marketing cookies | Art. 6(1)(a) - consent | Via cookie banner; see Cookie Policy |
| Compliance with accounting and tax obligations | Art. 6(1)(c) - legal obligation | Belgian accounting law (7 years) |
| Business transfer or due diligence | Art. 6(1)(f) - legitimate interest | Limited, under NDA; users informed 30 days in advance |
5. Retention periods
| Data category | Retention period | Legal basis |
|---|---|---|
| Account data (active user) | As long as the account is active + 2 years after inactivity | Contract |
| Wage and remuneration data | 7 years after the tax year | Belgian accounting law / tax law |
| DIMONA and NSSO (RSZ) declaration data | Minimum 5 years | Act of 27 June 1969 (NSSO Act) |
| Shift history and employment contracts | Minimum 5 years after end of employment | Labour law / limitation of claims |
| Invoices and payment documents | 7 years | Code of Companies and Associations |
| Communication data (platform messages) | 2 years | Legitimate interest (disputes) |
| Log data and server data | 12 months | Security and fraud detection |
| Consent for marketing | Until withdrawal of consent + 1 year as proof | Art. 7(1) GDPR |
| Application/profile data (not hired) | 6 months after last contact | Legitimate interest |
| Cookies (analytical/marketing) | See Cookie Policy (max. 13 months) | Consent |
Employment, wage and Dimona-related data is never deleted prematurely: Belgian labour and social security legislation requires that this data remains available for consultation for at least 5 years. After expiry of the applicable retention periods, data is deleted or anonymised in accordance with our internal retention policy.
The statutory archive of signed employment contracts and payslips is kept by Neembu (via our social secretariat Securex, see section 8bis) in accordance with the Act of 15 January 2018 on the electronic archiving of employment contracts. AnyShift itself only keeps operational references.
6. Flexi-jobs in all sectors
Since 1 July 2026, flexi-jobs are in principle permitted in all private and public sectors (Act containing various provisions on flexi-jobs, Belgian Official Gazette of 2 July 2026), whereby sectors may opt out in whole or in part via their joint committee (paritair comité). In this context, AnyShift processes the following data in order to comply with the legal conditions:
- Verification of main occupation or pension status: confirmation that the Shifter meets the eligibility conditions for flexi-job work (e.g. employment of at least 4/5 with another employer in the reference quarter, or retired status)
- Sector identification of the employer (Partner): registration of the Partner's NACE code and joint committee (paritair comité), also to check for a possible sectoral opt-out
- DIMONA type "FL": mandatory declaration with code FL for each flexi-job performance; for this purpose we process the Shifter's INSZ/NISS number and the shift data (start and end time, location)
- Flexi-job wage calculation: the flexi-wage and flexi-holiday pay are calculated on the basis of hours worked and the applicable hourly wage, within the legal limits
Limosa notifications (foreign EU employees)
If AnyShift places EU citizens who come to work in Belgium and are subject to the Limosa notification obligation, we process the required personal data (identity, nationality, work period, employer) for the declaration. The legal basis is a legal obligation (Royal Decree of 20 March 2007).
7. Belgian CBA obligations regarding monitoring and evaluations
CBA No. 68 - Camera surveillance in the workplace
When a Partner uses camera surveillance during the performance of a shift, this falls under Collective Bargaining Agreement (CBA) No. 68 (deposited with the National Labour Council). For other forms of electronic monitoring (badge registration, GPS tracking), the general principles of proportionality and transparency under the GDPR and labour law apply. In such cases, AnyShift processes the data supplied by the Partner (arrival, departure, hours worked) exclusively for:
- Verification of hours worked and wage calculation
- Compliance with labour and social legislation
AnyShift acts here as a processor for the Partner, who remains the data controller for workplace monitoring. The Partner guarantees that monitoring takes place in accordance with CBA No. 68 and the GDPR.
CBA No. 109 - Ratings, scores and deactivation of Shifters
AnyShift keeps rating and performance data (star ratings, feedback from Partners) that may contribute to decisions about the visibility or deactivation of a Shifter. In line with the duty-to-state-reasons principle of Collective Bargaining Agreement (CBA) No. 109 (in the context of termination) and the principle of good governance:
- Shifters are informed in good time of the criteria that determine their active status
- A deactivation is never carried out exclusively on automated grounds without human intervention (see also section 10)
- A Shifter has the right to request an explanation and a review via privacy@anyshift.be
8. Communication channels: email, SMS and WhatsApp
AnyShift communicates with Shifters and Partners via email, SMS and WhatsApp Business (via Brevo as a registered Business Solution Provider).
Commercial messages (promotions, offers, news) are sent exclusively after your explicit opt-in consent. You can unsubscribe at any time via:
- The unsubscribe link in every message
- Your account settings on the platform
- An email to hello@anyshift.be stating "Unsubscribe - [channel]"
Operational messages (shift confirmations, contract information, DIMONA information, legal notices) are sent on the basis of the performance of the contract (Art. 6(1)(b)) and cannot be disabled without interrupting the service.
Your telephone number and message content are processed by Brevo SAS (France) as a processor, on the basis of a concluded data processing agreement in accordance with the GDPR. For WhatsApp Business, Meta additionally acts as a (sub-)processor; see section 14 for the transfer mechanisms.
8bis. Electronic signing and payroll processing (Securex and Neembu)
Payroll processing and the electronic handling of employment contracts take place via our social secretariat Securex, which uses Neembu as a sub-processor for this purpose.
In concrete terms:
- AnyShift creates an employment via Securex and receives a contract key.
- The actual electronic signing of the employment contract and the creation of payslips take place at Neembu, via Securex. AnyShift only consults the signing status.
- AnyShift itself stores no signed employment contracts or payslips, only operational references (shift request, attendance, contract key, invoices, employment status).
- The verification code (OTP) within the AnyShift app is used exclusively for two-step verification when logging in and for password recovery, and is not part of the signing process.
For temporary agency employment contracts, an advanced electronic signature (AES) within the meaning of the eIDAS Regulation suffices, provided it guarantees the identity of the parties, consent to the content and the integrity of the document (Act of 24 July 1987; guidelines of the FPS Employment). The statutory archiving of electronically concluded employment contracts takes place in accordance with the Act of 15 January 2018.
9. Record of processing activities and data protection impact assessment (DPIA)
Record of processing activities (Art. 30 GDPR)
AnyShift keeps an internal record of processing activities in accordance with Article 30 GDPR. For each processing operation, this record contains: the purposes, categories of data subjects and data, recipients, international transfers and retention periods. The record is available for inspection by the Data Protection Authority (GBA/APD). A summary is available on request via privacy@anyshift.be.
DPIA (Art. 35 GDPR)
Given the nature of our processing operations - large-scale processing of INSZ/NISS numbers, special categories of personal data and automated profiling - AnyShift acknowledges its obligation to carry out a Data Protection Impact Assessment (DPIA) for the high-risk processing operations in accordance with Article 35 GDPR, and carries out this process prior to or simultaneously with the further roll-out of the processing operations concerned.
Where necessary, we consult the Data Protection Authority (GBA/APD) prior to new processing operations with a high residual risk (Art. 36 GDPR - prior consultation).
10. Automated decision-making and profiling (Art. 22 GDPR)
AnyShift uses automated matching to link Shifters to suitable shifts. This system analyses:
- Availability, location and previously worked shifts
- Sector experience and skills profile
- Ratings from previous Partners
No fully automated decisions with legal effects: our matching algorithms support the service but do not lead to decisions based solely on automated processing that have legal effects for you. A human staff member is always involved in significant decisions (e.g. permanent deactivation of an account).
You have the right to:
- Request an explanation of how the matching system works
- Request human intervention in the event of a decision that is unfavourable to you
- Object to profiling (Art. 21(2) GDPR)
Requests can be addressed to privacy@anyshift.be (state: "Objection to profiling" or "Human intervention").
11. Joint controllership (Art. 26 GDPR)
In certain situations, AnyShift and a Partner act jointly as data controllers for personal data of Shifters, in particular for:
- Shift data that the Partner receives and processes internally (attendance registration, planning)
- Ratings and performance feedback entered by the Partner via the platform
In such cases, AnyShift and the Partner conclude a joint controllership arrangement in accordance with Article 26 GDPR. The essence of this arrangement is available to Shifters on request via privacy@anyshift.be.
For processing operations carried out exclusively by the Partner on its own systems (internal HR, own payroll), the Partner is the sole data controller and the Partner's privacy policy applies.
12. Recipients of personal data and sub-processors
We share your personal data exclusively with the following categories of recipients:
12.1 Within the platform
- Partners and Shifters among themselves: limited profile information necessary for the performance of a shift (name, photo, rating, contact details)
12.2 Main processors and sub-processors (Art. 28 GDPR)
We conclude a data processing agreement with all processors in accordance with Article 28 GDPR.
| Processor | Category | Server location | Purpose |
|---|---|---|---|
| Securex | Social secretariat | EU (Belgium) | Payroll processing, Dimona, contract management |
| Neembu (sub-processor via Securex) | Contract signing / archiving | EU (Belgium) | Electronic signing of employment contracts, payslips, statutory archive |
| DigitalOcean | Cloud / hosting | EU region | Server infrastructure of the AnyShift platform |
| Brevo SAS | Email / SMS / WhatsApp | EU (France) | Transactional and commercial communication |
| Meta Platforms (WhatsApp Business) | Communication | See section 14 | Messaging via WhatsApp |
We inform you of changes to our sub-processors via our website or by email (at least 14 days in advance).
12.3 Government agencies (legally required)
- NSSO (RSZ) / ONSS: wage declarations and social security contributions
- FPS Finance: tax forms (281.10, 281.20)
- DIMONA system: mandatory declaration of the start and end of employment
- Inspection services: Social Inspectorate, Supervision of Social Legislation
- Limosa database: for foreign employees
12.4 Other recipients
- References (contact details only, subject to your consent)
- Potential buyers or investors in the event of a business transfer - see section 13
- Judicial authorities where legally required
We never sell your personal data to third parties for commercial purposes.
13. Business transfer, merger or investment
In the context of a possible or actual business transfer, merger, acquisition or due diligence procedure, personal data may be shared with potential acquirers or investors. The following safeguards apply:
- The transfer is limited to the data strictly necessary for the evaluation
- The recipient is bound by a non-disclosure agreement (NDA) and by the GDPR obligations
- In the event of an actual transfer, data subjects are informed at least 30 days in advance by email, stating the identity of the new data controller
- The new data controller assumes the obligations of this privacy policy, or data subjects receive a new policy with the option to object or to have their data deleted
14. International transfer of data (Art. 44-49 GDPR)
Our core processing takes place within the European Economic Area. If a service provider exceptionally processes data outside the EEA (e.g. Meta for WhatsApp Business), we guarantee an adequate level of protection by means of:
- Adequacy decision of the European Commission (e.g. UK, Switzerland, EU-US Data Privacy Framework)
- Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision 2021/914)
- Additional technical measures: encryption, pseudonymisation, access control
You can request a copy of the applicable SCCs via privacy@anyshift.be (state: "International transfer - GDPR").
15. Security of personal data (Art. 32 GDPR)
Technical:
- TLS/SSL encryption of all data transmission
- Hosting within the EU region with an infrastructure provider with ISO 27001 and SOC 2 certification at infrastructure level
- Access control based on the least-privilege principle ("need-to-know")
- Two-factor authentication for administrator accounts, where available
Organisational:
- Internal privacy policy and confidentiality agreements for staff
- Staff training on data protection
- Procedure for reporting data breaches (internally within 24 hours, Data Protection Authority (GBA/APD) within 72 hours in accordance with Art. 33 GDPR)
We continuously evaluate and strengthen our technical and organisational measures in line with the risks. In the event of a breach involving a high risk to your rights and freedoms, data subjects are informed without delay in accordance with Art. 34 GDPR.
16. Minors
The AnyShift services are not aimed at persons younger than 16 years. Additional legal rules apply to student jobs (16-17 years); in that case, the consent of a parent or legal guardian is required upon registration.
We do not knowingly collect personal data from children under the age of 16. If you suspect that we have accidentally collected data from a minor, please contact us immediately via privacy@anyshift.be.
17. Your rights as a data subject (Art. 15-22 GDPR)
You have the following rights. You can exercise them via privacy@anyshift.be (state: "GDPR request - [type of right]"). We respond within 30 calendar days (extendable by 2 months for complex requests, subject to notification).
| Right | Content | GDPR article |
|---|---|---|
| Right of access | Request which data we hold about you | Art. 15 |
| Right to rectification | Have inaccurate or incomplete data corrected | Art. 16 |
| Right to erasure | Deletion of your data (subject to legal restrictions) | Art. 17 |
| Right to restriction of processing | Temporarily suspend processing while a dispute is ongoing | Art. 18 |
| Right to data portability | Receive or transfer your data in a machine-readable format (JSON/CSV) | Art. 20 |
| Right to object | Object to processing based on legitimate interest or profiling | Art. 21 |
| Right to withdraw consent | Withdraw consent given at any time (without retroactive effect) | Art. 7(3) |
| Right regarding automated decision-making | Request human review of automated decisions | Art. 22 |
| Right to an explanation of profiling | Insight into the logic and consequences of the matching system | Art. 22(3) |
Please note: Exercising certain rights may affect your ability to use (parts of) our services, e.g. if legally required data is no longer available. Deletion of employment, wage or Dimona-related data is only possible after expiry of the statutory retention periods (see section 5); in that case, you will be informed of the legal basis and the expected deletion date.
We verify your identity before handling a request, via your registered account or a valid identity document (whereby you may redact the document number and photo yourself).
18. Cookies
AnyShift.be uses cookies and similar technologies:
- Strictly necessary cookies: required for the operation of the website and the platform (no consent required)
- Analytical and marketing cookies: exclusively after consent via the cookie banner
Which analytical and marketing cookies are in use is exhaustively described in our Cookie Policy, which serves as the sole reference for the currently active cookies. You can adjust your cookie preferences at any time via the cookie preference manager.
19. Complaints
If you are not satisfied with the way we process your personal data, you have the right to lodge a complaint with:
Data Protection Authority (GBA/APD)
Drukpersstraat 35, 1000 Brussels
Email: contact@apd-gba.be
Website: www.gegevensbeschermingsautoriteit.be
However, we ask that you contact us first via privacy@anyshift.be, so that we can resolve your concern as quickly as possible.
20. Changes to this privacy policy
AnyShift reserves the right to amend this policy. The date of the last change is stated at the top.
In the event of material changes, we will inform you at least 30 days in advance via email or a notification on the platform. By continuing to use our services after a change, you agree to the amended policy.
