GDPR
Privacy statement
Advocatenkantoor Nir Zeltzer - Orechdin BV
This statement explains how ORECH/DIN handles personal data: that of visitors to this website, of people who contact the office, of clients, and of other people involved in a client’s matter. It follows Articles 13 and 14 of the General Data Protection Regulation (GDPR) and the Belgian Data Protection Act of 30 July 2018. Personal data means any information about an identifiable person, such as a name, an address or a description of a situation.
Version 2.0, last updated 06/10/2026
Who is responsible
The controller is Advocatenkantoor Nir Zeltzer - Orechdin BV, a private limited company (BV) at Lange Herentalsestraat 122, 2018 Antwerp, Belgium, registered under company number 0879.210.671 and entered in the Antwerp business court (RPR Antwerpen).
For anything concerning personal data you can contact the office directly, at info@orechdin.be or on 03/227.50.57.
Professional secrecy comes first
An advocate is bound by professional secrecy under Article 458 of the Criminal Code. What a client or a prospective client tells the office is confidential, and that duty does not end when the file closes.
This shapes your data protection rights. Where answering a request would reveal information covered by professional secrecy, in particular information belonging to another person involved in a case, the office must decline to disclose it. In that situation we tell you that the request has been limited, and explain why as far as secrecy allows.
Inside the office, files are open only to the people who need them for the work, and the duty of secrecy applies to everyone who works for the office.
Whose data, and where it comes from
The office processes personal data of:
- Visitors to this website. Technical data that every website receives when a page is requested.
- People who contact us. By the contact form, email, telephone or WhatsApp.
- Clients and prospective clients. People whose matters the office handles or may handle.
- People involved in a matter. Such as opposing parties, their lawyers, witnesses, experts and relatives named in documents.
Most data comes from you. The rest comes from public sources and registers, from courts and public authorities, from other lawyers and professionals, and from the documents in a case.
What data we process
Depending on who you are, the following:
- Visiting the site. Your IP address and technical request data (the page asked for, the time, the type of browser), processed by our hosting provider to deliver the pages and keep the service secure. We keep no visitor analytics.
- Contacting us. The name, email address, telephone number and description of your matter that you choose to send through the contact form, by email or by telephone. The form reaches the office by email and is not stored on the website. To limit abuse, it applies short-lived technical limits per address, which are not linked to your message.
- WhatsApp. If you write to the office on WhatsApp, WhatsApp (Meta) also processes your number and your message under its own terms. For anything confidential, please call or email instead.
- Becoming a client. Identification and contact details, a copy of your identity document where the law requires it, bank details for payments and refunds, and everything you tell us or hand us about your matter, together with the invoices and correspondence in the file.
- People involved in a matter. Name, role in the matter and the information found in the documents of the case, to the extent needed to act for the client.
- Sensitive data. A file can contain health data, data about minors, or data about offences and convictions. The office processes these only where the matter needs it.
Why, and on what legal basis
Each purpose rests on one of the grounds in Article 6 GDPR:
- Performing our engagement, Article 6(1)(b). Answering your enquiry, assessing whether we can act for you, carrying out the work once we do, and invoicing it.
- Legal obligations, Article 6(1)(c). Identification and record keeping under the anti money laundering rules, accounting and tax duties, and the professional rules of the Bar.
- Legitimate interests, Article 6(1)(f). Keeping the website secure and available, checking for conflicts of interest, recovering fees, and establishing or defending legal claims, including our own. It also covers acting for a client against another person, whose data we then process as far as the matter requires.
- Consent, Article 6(1)(a). Optional cookies. You may withdraw consent at any time, without affecting what was done before.
- Special categories and criminal data, Articles 9 and 10. A file may contain health data, or data about offences and convictions. The office processes these where necessary for the establishment, exercise or defence of legal claims, the ground Article 9(2)(f) provides for legal work.
Direct marketing
The office does not send newsletters or marketing messages. If it ever contacts former clients about its services or about legal developments, it will do so only where the law allows, and you can object at any time, free of charge.
Who receives your data
The office does not sell personal data and does not share it for anyone else’s marketing. Data goes only to:
- Our hosting provider. Easyhost, which hosts the website, as a processor.
- Our email provider. Easyhost, which hosts the office’s email and carries messages sent from and to the office, as a processor.
- Professional service providers. Such as our accountant and IT support, only where they need access to do their work.
- Parties to your case and authorities. Courts, opposing parties and their lawyers, bailiffs, notaries, experts, the Bar and public authorities, including the tax authorities, where acting for you or the law requires it.
Processors act only on our instructions and under a written agreement. Disclosure to anyone else happens only with your consent, or where the law requires it.
Transfers outside Europe
The office keeps personal data within the European Economic Area wherever it can. Some services used by this website, in particular the Google Maps frame, may process data outside the EEA. Where that happens it takes place under the safeguards Chapter V GDPR requires, such as an adequacy decision or standard contractual clauses. In a case with a foreign element, data goes to a foreign court, authority or lawyer only as far as that specific matter requires.
How long we keep it
Personal data is kept no longer than its purpose requires. In practice:
- Case files. Five years after the engagement ends, as the rules on lawyers’ files provide, and longer where the law or a dispute that is still going on requires it.
- Accounting and identification records. Accounting records for ten years after the end of the financial year, and identification records under the anti money laundering rules for ten years after the business relationship ends.
- Enquiries that do not become a matter. Up to one year, so we can recognise a conflict of interest if you return, then deleted.
- Cookie consent. Six months, after which we ask again.
Security
The website is served over an encrypted connection. Files are open only to those who need them for the work, and everyone working for the office is bound by confidentiality. No system is perfect. If a breach ever puts your rights at serious risk, we will inform you and the Data Protection Authority as the GDPR requires.
Automated decisions
The office takes no decision about you by automated means alone. Whether the office can act for you, and any advice you receive, is decided by an advocate.
Your rights
Under the GDPR you can ask us to:
- Access. Tell you whether we hold data about you, and give you a copy.
- Rectification. Correct data that is wrong or incomplete.
- Erasure. Delete data, where no legal duty and no legal claim requires us to keep it.
- Restriction. Pause the use of data while a dispute about it is resolved.
- Portability. Hand over, in a machine readable form, the data you gave us on the basis of consent or a contract.
- Objection. Stop processing based on our legitimate interests, unless compelling grounds override your objection.
- Withdrawal of consent. Take back consent you gave, at any time.
Send your request to info@orechdin.be. We answer within one month, and may first ask for proof of identity so that we do not hand your data to someone else.
These rights are not absolute. Professional secrecy, a legal retention duty, or the rights of another person can require us to limit a request, and where a case file is concerned that limit is the rule rather than the exception. We always explain what we can.
Complaints
If you believe your data is not being handled properly, tell us first so we can put it right. You also have the right to complain to the supervisory authority:
Data Protection Authority (Gegevensbeschermingsautoriteit)Drukpersstraat 35, 1000 Brussels
+32 2 274 48 00
contact@apd-gba.be
gegevensbeschermingsautoriteit.be
Complaints about the conduct of an advocate can also be addressed to the President of the Bar of the judicial district of Antwerp.
Changes
This statement carries a version number and a date. When it changes materially we publish the new version here, and where the change concerns something you consented to, we ask for your consent again.
