This privacy policy applies to (i) the personal data collected by STVV NV, with registered office at Tiensesteenweg 168, 3800 Sint-Truiden and registered with the K.B.O. under number VAT BE0845.049.251 (hereinafter: "STVV" or "we") via the website www.stvv. com (hereinafter: "Website") and/or as a result of offline counter sales of "tickets/subscriptions (Season Pass)" and "dining at Stayen" and (ii) their use for e.g. execution of the concluded agreement and/or (personalised) marketing purposes by STVV.
We have appointed Maetzler Rechtsanwalts GmbH & Co KG as our Data Protection Officer (DPO) in accordance with Article 37 GDPR. Our DPO can be contacted at privacy@stvv.com .
What are your rights?
You have the following rights:
- Right of access, rectification, erasure, restriction, objection and transferability of personal data.
- If the processing of your personal data is based on your prior consent, you naturally have the right to withdraw that consent.
- To exercise your rights, simply contact us either by contact page (https://prighter.com/q/12396155) or by post to Tiensesteenweg 168, 3800 Sint-Truiden. We will make every effort to answer you as soon as possible and at the latest within 30 days. Additional identification may be requested for this purpose.
Where can you lodge a complaint?
You have the right to lodge a complaint with the Belgian Data Protection Authority, Rue du Printing Press 35, 1000 Brussels, Tel +32 (0)2 274 48 00, e-mail: contact@apd-gba.be.
What personal data do we collect from you?
Personal data that you communicate to us:
- When you visit the Website, we obtain, among other things, your IP address and your choice of language ("technical information"),
- When registering for the STVV newsletter: your name and e-mail address;
- When registering for "tickets/subscriptions (Season Pass)" (via Website and offline counter sales), we obtain your surname and first name, address details, date of birth, e-mail address and telephone number;
- When using the "cashless" feature on your subscription (season ticket, cashless card, Binken card, Mobile app), we access financial data (card balance) and consumption behaviour;
- When registering for "dining at Stayen" (via Website and offline counter sales), we obtain your surname and first name, address details, e-mail address, telephone number and any specific food requirements;
- When entering the stadium, we may obtain images and video material, which may include your personal data. To avoid unauthorised entry to the stadium, we may also process personal data relating to criminal convictions.
The personal data mentioned above may also be obtained from minors. STVV recognises that personal data of minors must be protected with a higher degree of protection and STVV is committed to processing personal data of minors with utmost vigilance.
How do we collect personal data from you?
We collect your personal data in several ways:
- Through cookies (see Cookie policy),
- Through a registration form or order form (for the STVV newsletter, "tickets/subscriptions (season ticket, cashless card)" and "dining at Stayen"),
- By using the "cashless" function on your season ticket (Season ticket, Cashless card, Binkenkaart, Mobile app);
- By using access controls at the stadium.
Why do we collect personal data from you? (Purposes)
We collect technical information for looking after and improving the Website and compiling anonymous visitor statistics.
We collect your personal data (e.g. identity data, financial data, ...) with a view to (i) delivering and invoicing your order ("tickets", "dining at Stayen", "cashless") and/or (ii) sending you a newsletter and/or (personalised) marketing.
We will therefore process personal data to be able to conclude and perform a contract with you as well as to keep you informed about STVV. If you cannot provide the necessary personal data, STVV cannot guarantee that it will be able to conclude and execute a contract with you nor that STVV can keep you informed through newsletters and through marketing.
We process data on criminal convictions to ensure security at the stadium.
May we process your personal data? (legal basis)
We may process your technical information because, on the one hand, you consent to this via the "cookie banner" (Cookie policy) and, on the other hand, because it is in our legitimate interest to continuously improve our Website and services.
We may process your personal data in order to execute the agreement. In addition, as a football club, we are required by law to be able to identify every spectator at the stadium. We process your personal data relating to criminal convictions based on the performance of the contract, including the house rules applicable when you purchase a ticket and enter the stadium. If no contract was concluded, we base such processing on the legitimate interests of maintaining security and order and preventing crimes.
We may process your personal data to send you a newsletter and/or (personalised) marketing:
If you have subscribed to the STVV newsletter via the Website, you have given us permission to send the newsletters. This consent can be withdrawn at any time.
If you have purchased a subscription (Season Ticket) we will send you a newsletter and a subscription magazine based on our legitimate interest.
If you made a reservation for "Dining at Stayen" and/or purchased "tickets" and/or registered for the "Cashless" platform, we will send you a newsletter based on our legitimate interest.
Do we share your personal data with third parties (whether or not outside the EU)?
If it is necessary to achieve the predefined purposes, your personal data will be shared with third recipients: think for example the creator/host of our Website, the bank/payment service provider, the caterer, the printer. We guarantee that all third-party recipients will take the necessary technical and organisational measures to protect your personal data.
STVV will not sell, rent or make your personal data commercially available to third parties (including STVV's commercial partners) except with your prior consent.
To the extent that you have consented to us forwarding your personal data to Pro League SA for its direct marketing purposes, you take note that we, together with Pro League SA, will act as 'joint controllers' for this specific processing. This processing consists of the joint controllers forwarding your personal data to each other, if you have explicitly consented to this (via an opt-in box), via the CRM database. As regards the rights you can exercise under the AVG in relation to this processing (including under Articles 13 and 14 AVG), you can contact us to exercise them.
Your personal data may also be shared outside Europe. STVV undertakes to appoint only data controllers and/or processors outside the European Economic Area who provide sufficient guarantees of personal data security and protection in accordance with applicable privacy legislation. The complete and updated list of the decisions on the appropriate nature of Data Protection in the third countries approved by the EU Commission can be consulted at https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_nl. A copy of the personal data can always be requested at privacy@stvv.com.
Finally, we may be required to share your personal data with government agencies (including the police, prosecuting authorities, the judiciary, the Ministry of the Interior, etc.), mainly in case of possible criminal convictions.
For how long do we keep your personal data?
Your personal data will only be processed for as long as necessary to achieve the purposes. They will therefore be kept for the period necessary to fulfil the purposes or to comply with legal requirements (including in the field of accounting or under specific football legislation).
What about links to third-party websites, e.g. online fan shop?
STVV's online fanshop is operated by a third party ('Belgoshop'). The privacy conditions can be found at https://shops.topfanz.com/nl/service/privacy-policy/.
STVV is not responsible for the content of the websites linked from STVV by the administrator or visitors. Visitors are aware that the privacy of other websites may differ from STVV.
What technical and organisational security measures have we taken to protect your personal data?
We have developed technically and organisationally appropriate security measures to avoid the destruction, loss, falsification, alteration, unauthorised access or erroneous notification of personal data to third parties, as well as any other unauthorised processing of this personal data: e.g. an SSL certificate, access to personal data is restricted to the administrator account, etc.
Under no circumstances can STVV be held liable for any direct or indirect damage resulting from the incorrect or unlawful use of personal data by a third party.
You must comply with the security rules at all times. You are therefore solely responsible for the use made from the Website of your computer, IP address and of your identification data, as well as for their confidentiality.
Version: 19 April 2021