1. Identification of the Data Controller
For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Data Protection Act 2018, and relevant member state legislation, the Data Controller responsible for the processing of your personal information is:
Digital Publishing & Financial Simulation Services
Operating Jurisdiction: Brussels, Kingdom of Belgium
Data Protection Contact: privacy@brutonaarnetto.be
2. Scope of Service & Zero-Retention Calculation Policy
brutonaarnetto.be is an independent digital calculation portal designed to provide Belgian gross-to-net salary simulations, wage tax estimates, and related fiscal educational information based on statutory legislation established by the Belgian Federal Public Service Finance (FOD Financiën / SPF Finances) and the National Social Security Office (RSZ / ONSS).
Our Zero-Retention Calculation Guarantee: We hold user confidentiality as a core principle. All salary figures, family composition inputs, tax deductions, and municipal parameters entered into our salary calculators are processed ephemeral client-side or transmitted strictly in-memory during server execution. We do not save, record, tie to an identity, or commercially exploit any financial compensation amounts entered into our tools.
3. Categories of Information Collected
We distinguish between data provided voluntarily by users and technical telemetry collected automatically during your visit:
3.1. Automatically Collected Technical & Server Telemetry
When you access the Service, our web servers automatically generate standard server log files (“Log Data”). This diagnostic data may include:
- Your Internet Protocol (IP) address (anonymized or pseudonymous where feasible);
- Browser type, configuration, and rendering engine version;
- Operating system and device architecture;
- Uniform Resource Locators (URLs) of referring and exit pages;
- Date, timestamp, and duration of page requests;
- HTTP status codes and data transfer volumes.
This technical telemetry is processed solely to ensure network stability, prevent malicious traffic, detect distributed denial-of-service (DDoS) attempts, and maintain technical infrastructure integrity under Article 6(1)(f) GDPR.
3.2. Voluntarily Disclosed Communications
If you communicate with our editorial or support desk via email, we collect your email address, your name (if provided), and the textual content of your inquiry. This information is retained solely to address your query and is deleted once resolved.
4. Google AdSense & Third-Party Advertising Technologies
In accordance with Google’s publisher compliance guidelines, users must be informed of the following operational realities:
- Use of Cookies & Web Beacons: Third-party vendors, including Google, use cookies (including the DoubleClick DART cookie) to serve advertisements based on a user’s prior visits to this website or other websites across the Internet.
- Personalized vs. Non-Personalized Advertising: Google’s use of advertising cookies enables it and its certified advertising network partners to serve tailored ads to you based on your navigational behavior across digital properties.
- Opting Out of Personalized Ads: You have the absolute right to opt out of personalized interest-based advertising at any time. You can manage and disable Google personalized advertising by visiting the Google Ads Settings Portal.
- Industry Consumer Opt-Out Platforms: Alternatively, you may opt out of third-party vendor tracking for interest-based advertising by visiting the Network Advertising Initiative (NAI) opt-out page at www.networkadvertising.org/choices/ or the Digital Advertising Alliance (DAA) at aboutads.info/choices, or the European Interactive Digital Advertising Alliance (EDAA) at www.youronlinechoices.eu/.
For detailed information on how Google manages and processes data in its advertising network, please inspect How Google uses information from sites or apps that use our services.
5. Cookies & Tracking Technologies
Cookies are minute textual records transmitted to and stored by your internet browser. We categorize cookies deployed on our platform into four operational classes:
| Category | Source | Purpose | Duration |
|---|---|---|---|
| Strictly Necessary | First-Party | Core site routing, security validation, and session integrity. | Session / Ephemeral |
| Functional | First-Party | Remembers user preferences such as Dark Mode settings and calculator state. | Up to 12 months |
| Performance & Analytics | First/Third-Party | Aggregated statistical measurements of page traffic and feature usage. | Up to 24 months |
| Advertising (AdSense) | Google / Third-Party | Frequency capping, ad measurement, fraud prevention, and behavioral targeting. | Up to 13 months |
For comprehensive configuration details, audit matrices, and browser-specific opt-out walk-throughs, please consult our dedicated Cookie Policy.
6. Legal Bases for Processing under the GDPR
We process personal data only when lawful justifications under Article 6(1) of the GDPR exist:
- Legitimate Interests (Art. 6(1)(f) GDPR): Processing technical server logs to prevent fraud, ensure IT security, maintain website stability, and deliver accurate computational simulations.
- User Consent (Art. 6(1)(a) GDPR): Required for non-essential cookies, individualized analytics, and Google personalized advertising. Consent may be revoked at any time.
- Legal Obligations (Art. 6(1)(c) GDPR): Compliance with statutory legal mandates, judicial directives, or requests from law enforcement authorities.
7. Your Data Protection Rights under European Union Law
If you reside within the European Economic Area (EEA), United Kingdom, or Switzerland, you possess enforceable statutory rights under Articles 15 through 22 of the GDPR:
- Right to Access (Art. 15): Obtain confirmation of whether your personal data is processed and request copies.
- Right to Rectification (Art. 16): Demand correction of incomplete or inaccurate records.
- Right to Erasure (“Right to be Forgotten”, Art. 17): Request deletion of your personal data when no longer necessary.
- Right to Restrict Processing (Art. 18): Restrict processing under specified legal conditions.
- Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): Object to processing grounded in legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw previously granted consent without affecting past processing lawfulness.
To exercise any statutory right, submit a formal notice to privacy@brutonaarnetto.be. We respond to all verified requests within thirty (30) calendar days at zero expense.
8. Notice to California Residents (CCPA / CPRA Disclosures)
The California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.), as amended by the California Privacy Rights Act of 2020 (“CPRA”), grants California consumers specific rights regarding their personal information:
- Right to Know & Access: You may request disclosures regarding categories of personal information collected, sources, business purposes, and specific pieces of data held.
- Right to Delete: You have the right to request deletion of personal information collected from you.
- Right to Opt Out of Sale or Sharing: We do not sell personal information for monetary remuneration. However, disclosures of identifiers via advertising cookies (such as Google AdSense) may constitute a “share” under California law. You may opt out via cookie settings or Global Privacy Control (GPC) browser signals.
- Right to Non-Discrimination: We will not discriminate against you in pricing, service availability, or functionality for exercising statutory privacy rights.
9. Technical Security Safeguards & International Transfers
We enforce robust administrative, technical, and physical safeguards to safeguard technical telemetry against unauthorized access, destruction, alteration, or disclosure. All data transmissions across the Service are fortified using Transport Layer Security (TLS 1.3 / HTTPS encryption).
Where third-party partners (such as Google LLC) transfer data beyond the borders of the European Economic Area, such transfers are governed by the European Commission’s Standard Contractual Clauses (SCCs) or adequacy decisions such as the EU-U.S. Data Privacy Framework.
10. Children’s Privacy (COPPA Compliance)
The Service is dedicated to general adult audiences, working professionals, students, and businesses. We do not knowingly solicit, collect, or process personal data from children under the age of sixteen (16). If you believe a minor has submitted personal information through our platform, contact us immediately at privacy@brutonaarnetto.be to effect prompt deletion.
11. Amendments to this Privacy Policy
We reserve the right to periodically modify this Privacy Policy to reflect changes in regulatory statutes, Belgian fiscal reporting procedures, technical infrastructure, or Google AdSense publisher policies. When revisions occur, the “Last Updated” timestamp at the top of this document will be revised. Continued engagement with our Service constitutes acceptance of the modified terms.
12. Contact Information & Supervisory Authority
If you maintain inquiries, concerns, or complaints regarding our data stewardship practices, please contact our Privacy Team directly:
Email: privacy@brutonaarnetto.be
Website: https://brutonaarnetto.be
Location: Brussels, Kingdom of Belgium
Under Article 77 of the GDPR, you retain the statutory right to lodge an official complaint with the national supervisory authority in Belgium:
Drukpersstraat 35, 1000 Brussels, Belgium
Telephone: +32 (0)2 274 48 00
Website: www.gegevensbeschermingsautoriteit.be