Overseas

Privacy policy

1. Introduction

Overseas Distribution Company NV (“ODC”, “we”, “us”, or “our”) is committed to protecting the personal data of everyone who interacts with us – whether as a visitor to our website, a customer on our B2B ordering platform, a business contact in our CRM, or a guest at one of our events.

This Privacy Policy explains which personal data we collect, why we collect it, how long we keep it, with whom we share it, and what rights you have as a data subject. It applies across all our processing activities and all channels through which we interact with you.

We process personal data in accordance with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)
  • The Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data
  • Any other applicable national implementing legislation

2. Data Controller

The controller responsible for your personal data is:

Overseas Distribution Company NV

Mexicostraat 3

2000 Antwerp, Belgium

Company number: BE0423.161.708

Email: overseas@overseas.be

Website: www.overseas.be

ODC has appointed a Data Protection Officer (DPO):

Quinten Huyghe

Data Protection Officer

Overseas Distribution Company NV

Email: dpo@overseas.be

You may contact the DPO directly for any questions or concerns relating to the processing of your personal data or the exercise of your rights.

3. Scope of This Policy

This policy covers all personal data processing activities carried out by ODC, including:

  • Visitors to our corporate website (www.overseas.be)
  • Users of Bluebird, our proprietary B2B ordering platform
  • Guests invited to ODC-hosted events and receptions
  • Business contacts in our Microsoft Dynamics 365 CRM
  • Contacts and transactional records in Microsoft Dynamics 365 Business Central
  • Any other context in which we receive or generate personal data in connection with our business activities

This policy does not apply to the processing of personal data of ODC employees, for which a separate HR Privacy Policy applies.

4. Personal Data We Collect and Why

4.1 Corporate Website (www.overseas.be)

Contact form

When you submit an enquiry through our website contact form, we collect:

  • First and last name
  • Email address
  • Company name
  • The content of your message

Purpose: To respond to your enquiry and provide any necessary follow-up.

Legal basis: Art. 6(1)(b) GDPR – processing is necessary for pre-contractual steps taken at your request, or for the performance of a contract.

Retention: Up to 24 months after the last contact. Where a contact leads to a commercial follow-up and the person is added to our CRM as a lead or contact, their data is retained under our CRM retention policy (10 years from last commercial contact).

Website tracking tools

Our website uses third-party tracking tools, including social media tracking pixels, to support our marketing activities and measure the reach of our communications.

Purpose: To measure the reach of our marketing communications and improve our website.

Legal basis: Art. 6(1)(a) GDPR – your prior consent, given via our cookie banner.

Retention: See our Cookie Policy at www.overseas.be/cookies for cookie-specific retention periods.

4.2 Bluebird – B2B Ordering Platform

Bluebird is our proprietary B2B ordering platform, hosted on Microsoft Azure (West Europe). When you register or transact on Bluebird, we process:

  • Company name
  • Contact name
  • Email address
  • Login credentials (username; passwords are stored in hashed form)
  • Order history and transaction records

Purpose: To provide and manage the B2B ordering service, process orders, manage your account, and provide customer support.

Legal basis: Art. 6(1)(b) GDPR – performance of a contract (or pre-contractual steps at your request). Art. 6(1)(f) GDPR – legitimate interest for account security and platform improvement.

Retention: For the duration of the business relationship and for 10 years thereafter.

Account deactivation: To request deactivation of your Bluebird account and deletion of your personal data, please contact us at overseas@overseas.be.

4.3 Events and Receptions

ODC organises trade events, receptions, and hospitality occasions. Invitations and registrations for these events are managed through Neolively, a third-party event management platform hosted on Microsoft Azure (West Europe), which processes contact information on our behalf.

The personal data processed in this context may include:

  • Name and job title
  • Business email address
  • Dietary requirements or accessibility needs (where provided)
  • Attendance confirmation

Purpose: To organise and manage events, send invitations and logistics communications, and maintain attendance records.

Legal basis: Art. 6(1)(b) GDPR – performance of a contract (event participation). Art. 6(1)(f) GDPR – legitimate interest in maintaining business relationships and organising professional events.

Processor: Neolively acts as a data processor on our behalf under a signed Data Processing Agreement. Data is stored within the EEA (Azure West Europe) and is not transferred outside the EEA.

Retention: Up to 24 months after the event, unless the contact relationship continues in our CRM.

4.4 Microsoft Dynamics 365 – CRM

We use Microsoft Dynamics 365 as our CRM to manage relationships with current and prospective business partners, customers, and suppliers. Data is collected through direct interactions (meetings, email exchanges, business cards) or via the platforms described above.

Personal data in the CRM includes:

  • Name, job title, and company
  • Business email address and telephone number
  • History of commercial interactions
  • Notes from meetings or calls

Purpose: To manage business relationships, follow up on leads and opportunities, and maintain commercial records.

Legal basis: Art. 6(1)(f) GDPR – legitimate interest in maintaining and developing business relationships. Where processing supports a contract, Art. 6(1)(b) GDPR applies.

Retention: For the duration of the business relationship and for 10 years thereafter.

4.5 Microsoft Dynamics 365 Business Central

ODC uses Microsoft Dynamics 365 Business Central for ERP operations (financial management, purchasing, sales administration). Personal data processed includes contact persons at customer and supplier organisations, invoice recipients, and authorised signatories.

  • Name and job title
  • Business contact details (email, phone, address)
  • Financial transaction records (invoices, payments, purchase orders)

Purpose: Financial and operational administration; compliance with accounting and tax obligations.

Legal basis: Art. 6(1)(b) GDPR – performance of a contract. Art. 6(1)(c) GDPR – compliance with a legal obligation (Belgian accounting law, VAT obligations).

Retention: Financial records are retained for 7 years as required under Belgian accounting legislation. Contact data is retained for as long as the business relationship subsists.

5. Sharing Your Personal Data

We do not sell your personal data. We do not share it with third parties for marketing purposes. We may share your data with the following categories of recipients, strictly for the purposes described in this policy:

Technology and platform providers: Microsoft (Microsoft 365, Azure, Dynamics 365 CRM and Business Central) and Neolively (event management). Third-party tracking tools active on our website (to be listed once confirmed by IT) also act as processors. These parties act as data processors on our behalf under signed Data Processing Agreements.

Professional advisors: Lawyers, auditors, and accountants who are bound by professional confidentiality obligations.

Competent authorities: We may disclose personal data to courts, regulators, or law enforcement where required by law or court order.

Group entities: Where relevant for the management of our business, data may be shared with affiliated entities within the ODC group, under appropriate internal data sharing arrangements.

6. International Data Transfers

ODC uses technology providers whose infrastructure is based within the European Economic Area (EEA). Where transfers outside the EEA may nevertheless occur, the following safeguards apply:

  • Microsoft (Azure, M365, Dynamics 365, Business Central): All ODC data is hosted on Azure West Europe (EU). Where incidental transfers outside the EU may occur (e.g. for global support operations), these are covered by the EU Standard Contractual Clauses (SCCs) included in the Microsoft Products and Services DPA, which ODC has accepted.
  • Neolively: Data is hosted on Azure West Europe. No transfers outside the EEA occur.

You may request a copy of the applicable transfer safeguards by contacting us at overseas@overseas.be.

7. Data Retention

We retain personal data for no longer than is necessary for the purposes for which it was collected, or as required by law:

  • Website contact form data: up to 24 months (or 10 years from last commercial contact if the person is added to the CRM as a lead or contact)
  • Bluebird platform data: duration of the business relationship + 10 years
  • Event data: up to 24 months after the event
  • CRM (Dynamics 365) contact data: duration of the business relationship + 10 years
  • Business Central financial records: 7 years minimum (Belgian legal requirement)

After the applicable retention period, personal data is securely deleted or irreversibly anonymised.

8. Your Rights as a Data Subject

Under the GDPR, you have the following rights in relation to your personal data:

  • Right of access (Art. 15): You may request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): You may ask us to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17): You may request deletion of your data where no legal basis or retention obligation applies.
  • Right to restriction (Art. 18): You may request that we temporarily restrict processing of your data in certain circumstances.
  • Right to data portability (Art. 20): Where processing is based on consent or contract and carried out by automated means, you may request your data in a structured, machine-readable format.
  • Right to object (Art. 21): You may object at any time to processing based on legitimate interest (Art. 6(1)(f)). We will cease processing unless we demonstrate compelling legitimate grounds.
  • Right to withdraw consent (Art. 7(3)): Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Right not to be subject to automated decision-making (Art. 22): ODC does not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

To exercise any of these rights, please contact us at:

overseas@overseas.be

We will respond within one month of receipt of your request. In complex cases, this period may be extended by a further two months; we will inform you if this is the case.

9. Right to Lodge a Complaint

If you believe that ODC has processed your personal data in violation of applicable law, you have the right to lodge a complaint with the competent supervisory authority. In Belgium, this is:

Gegevensbeschermingsautoriteit (GBA)

Drukpersstraat 35, 1000 Brussels

Tel: +32 2 274 48 00

Website: www.gegevensbeschermingsautoriteit.be

Email: contact@apd-gba.be

If you are located in another EU/EEA member state, you may also contact the supervisory authority in your country of residence.

10. Security

ODC implements appropriate technical and organisational security measures to protect personal data against accidental loss, unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Access controls and role-based permissions
  • Encryption of data in transit (TLS/HTTPS) and at rest
  • All ODC data hosted on Microsoft Azure benefits from Microsoft’s enterprise-grade security infrastructure
  • Confidentiality obligations included in the employment contracts of all ODC employees

ODC has a documented internal procedure for detecting, reporting, and managing personal data breaches. In the event of a breach that is likely to result in a risk to your rights and freedoms, we will notify the GBA within 72 hours of becoming aware of it and, where required, notify affected individuals without undue delay.

11. Cookies

Our website uses cookies. For a full explanation of the cookies we use, their purpose, and how to manage your preferences, please see our Cookie Policy.

12. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, our services, or applicable law. The current version is always available on our website at www.overseas.be. Material changes will be communicated to affected data subjects where practicable.

Version: 1.0

Date of last revision: June 2026

13. Contact Us

For any questions about this Privacy Policy or to exercise your rights, please contact us:

Overseas Distribution Company NV

Mexicostraat 3, 2000 Antwerp, Belgium

Email: overseas@overseas.be