Privacy Policy - VIRTUA3000
Last updated: 08/06/2026
At VIRTUA3000, we highly value your privacy. We therefore handle your personal data with care and comply with the General Data Protection Regulation (GDPR). In this Privacy Policy, we explain what personal data we collect, why we collect it, how long we retain it, and what rights you have regarding your personal data.
1. Who Is Responsible for the Processing of Your Personal Data?
The controller responsible for the processing of personal data is:
VIRTUA3000
Bondgenotenlaan 122, 3000 Leuven, België
Email: [email protected]
Phone: 016/43.84.17
For online bookings, we work with Nostium.nl. This service provider processes your booking data on our behalf.
2. What Personal Data Do We Collect?
We only collect personal data that is necessary for the provision of our services and the operation of our business, including:
- Contact details: name, email address, and telephone number.
- Booking information: date, time, number of participants, and additional information (e.g. birthday packages).
- Payment information: where you make a payment online or on-site (through secure payment providers).
- Website data: IP address, cookies, and browsing behaviour (for website analytics and improvement purposes).
- CCTV footage: our locations are equipped with CCTV systems to help ensure the safety and security of visitors and staff.
3. Why Do We Process Your Personal Data?
We use your personal data only for legitimate purposes, including:
- Processing reservations and bookings.
- Sending booking confirmations and practical information.
- Processing payments and complying with tax and accounting obligations.
- Improving our website and services.
- Sending newsletters and promotional communications (only if you have given your consent).
- Ensuring safety and security (CCTV footage may be used in the event of incidents or upon request by competent authorities).
4. Use of Nostium.nl
For the processing of online reservations, we use Nostium.nl as our booking platform.
- What data is shared with Nostium.nl? Your name, contact details, booking information, and any additional comments or notes.
- Why is this data shared? To enable us to process and confirm your reservation correctly.
- How is your privacy protected? Nostium.nl processes this data on our behalf under a data processing agreement and secures it in accordance with the GDPR.
5. CCTV Surveillance
Our locations are equipped with CCTV surveillance systems. These systems are used to ensure the safety and security of our visitors, employees, and property.
- Retention period: CCTV recordings are retained for a maximum of 3 months, unless an incident has occurred that requires the footage to be retained for a longer period (for example, for an investigation or legal proceedings).
- Access: Access to CCTV footage is restricted to authorized personnel and competent authorities (such as the police).
6. How Long Do We Retain Your Personal Data?
We do not retain your personal data for longer than necessary for the purposes for which it was collected:
- Booking and contact information: up to 2 years after your visit.
- Newsletter subscription data: until you unsubscribe.
- Payment and invoice data: in accordance with the statutory retention period (7 years).
- CCTV footage: up to 3 months, unless an incident has occurred that requires longer retention.
7. With Whom Do We Share Your Personal Data?
We only share your personal data with third parties when this is strictly necessary:
- Nostium.nl (for our online booking system).
- IT and hosting providers (for our website, booking platform, and email systems).
- Payment service providers (for online payments).
- Public authorities (only where required by law, for example the police in the event of an incident).
We have entered into data processing agreements with these parties where required to ensure that your personal data is adequately protected.
8. Cookies
Our website uses cookies to:
- Ensure that the website functions properly.
- Analyse and improve the use and performance of the website (for example through Google Analytics).
You can disable cookies through your browser settings. However, certain features of the website may not function properly as a result.
9. Your Rights
Under the GDPR, you have the right to:
- Obtain access to the personal data we process about you.
- Request the correction or deletion of your personal data.
- Object to certain types of processing (such as direct marketing).
- Withdraw your consent for processing activities that are based on your consent.
- Lodge a complaint with the Belgian Data Protection Authority (DPA).
If you wish to exercise any of these rights, please contact us at [email protected].
10. Security
We implement appropriate technical and organisational measures to protect your personal data against loss, misuse, and unauthorised access. These measures include secure connections (SSL), access controls, and the secure storage of personal data.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The most recent version will always be available on our website and will include the date of the latest revision.
Contact:
For any questions or requests regarding this Privacy Policy, you can contact us.
[email protected] 016/43.84.17
Do you dare?