Privacy Policy
Effective Date: January 1, 2026
At Insight Tax & Legal Connect, we are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (GDPR – EU Regulation 2016/679). This Privacy Policy explains how we collect, use, and protect personal information in the course of our business.
1. Who We Are
This website is managed by an independent headhunter operating under the name “Insight Tax & Legal” (hereafter “Controller”).
Data Controller: Lionel Wellekens
Contact: contact@insighttaxandlegal.com
While the Controller is currently operating from Mexico, we voluntarily and strictly adhere to the EU General Data Protection Regulation (GDPR) to protect the rights of our European candidates and clients.
2. What Personal Data We Collect
We may collect the following types of personal data:
Candidates: name, date of birth, contact details (address, email, phone number), studies, professional experience, qualifications, motivations, CV’s, compensation expectations, and any other information you voluntarily provide.
Clients: name, professional contact details, job descriptions, and feedback related to candidates.
Website Visitors: Technical data (IP address, browser type) and usage data via cookies (see Section 9).
LinkedIn connections: we may collect publicly available professional information or data shared through direct contact on the LinkedIn platform.
Email communications: information exchanged through emails sent or received via our Google Workspace account.
Sensitive Data: We do not request sensitive data (health, trade union membership, religion, etc.). Please do not include such information in your CV.
3. How We Use Your Data
We process your data only for specific purposes relying on the following legal bases (Art. 6 GDPR):
Direct Application: Processing your application for a specific role you applied for - Pre-contractual measures (Art. 6.1.b) taken at your request;
Sourcing (Headhunting): Identifying potential candidates on professional networks (e.g., LinkedIn) and making initial contact - Legitimate Interest (Art. 6.1.f) to conduct our business;
Talent Pool (CV Database): Keeping your data for future opportunities not yet identified - Consent (Art. 6.1.a). You may withdraw this consent at any time;
Business Administration: Invoicing, legal defense, and IT security - Legitimate Interest (Art. 6.1.f) or Legal Obligation (Art. 6.1.c).
We will never sell your personal data or use it for marketing purposes without your consent.
4. Data Retention
In accordance with the GDPR’s storage limitation principle, we retain personal data only as long as necessary for the purposes collected. In practice:
CVs and contact data: kept for up to 36 months from the date of submission or last meaningful contact. This reflects a reasonable timeframe for future job matching and aligns with guidance that data should not be held longer than needed.
Newsletter opt-in: We may offer an optional newsletter in the future. If you opt-in, we will keep only your name and email as long as you remain subscribed. You may unsubscribe at any time, and we will promptly delete your data upon request.
Client information is stored as long as our professional relationship remains active or as legally required.
5. Data Sharing
We do not sell or rent your personal data to anyone. We will only share your data in the following cases:
A. Service Providers (Processors)
We use trusted third-party service providers to operate our business. They process data only on our instruction and under strict confidentiality agreements.
Google Workspace: For secure email communication and encrypted document storage.
Squarespace: For website hosting and secure contact forms.
LinkedIn: For professional networking and initial contact.
AppSheet (via Google): For internal database management.
We have verified that these major providers comply with GDPR standards, notably through the use of Standard Contractual Clauses (SCCs).
B. Job Matching (With your Consent)
With your explicit and written consent and only after a preliminary interview, we forward your CV and contact information to a potential employer (client). You will always be informed and must approve this transfer.
C. International Access
While our data servers are secure (Google Workspace), please note that the Data Controller operates from Mexico. Therefore, your data may be accessed remotely from outside the European Economic Area (EEA). We ensure this access is strictly limited to the Controller and protected by secure authentication methods (2FA) and encryption. We rely on your explicit consent to having your data transferred.
D. Legal Requirements
We may disclose personal data if required by EU law or by a court order. Otherwise, no data is disclosed to authorities or other third parties without lawful basis or your permission.
6. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
Right of access: You can request confirmation of whether we process your data and obtain a copy of the information we hold.
Right to rectification: You can ask us to correct inaccurate or incomplete data (for example, a wrong email address).
Right to erasure (“right to be forgotten”): You can request deletion of your personal data when it is no longer needed for the purposes collected (e.g. after 36 months or if you withdraw your application).
Right to restrict processing: In certain cases, you can request we suspend processing of your data (for example, if you contest its accuracy).
Right to data portability: If you have provided data to us (such as in a CV), you can request it in a structured, machine-readable format to transfer to another service.
Right to withdraw consent: You may withdraw any consent you have given (e.g. for the newsletter) at any time; this does not affect processing carried out before withdrawal.
Right to object: You can object to our processing of your personal data if you believe it harms your rights. You have a specific right to object to any direct marketing, though we do not engage in unsolicited marketing without consent.
Right to lodge a complaint: If you believe our processing violates data protection laws, you have the right to file a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit/APD) or any EU supervisory authority.
These rights are guaranteed by the GDPR. To exercise any of them, please contact us via email. We will respond promptly and, in any event, within one month as required by law.
To exercise your rights, please contact us at: contact@insighttaxandlegal.com.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (APD/GBA).
7. Data Security
We implement enterprise-grade security via Google Workspace, utilizing:
Two-Factor Authentication (2FA) for all access.
Encryption at rest and in transit (TLS).
Strict access controls limited to the Controller.
We maintain up-to-date security practices (firewalls, antivirus, secure passwords) to prevent unauthorized access or data breaches. In the unlikely event of a breach, we will notify affected individuals and authorities if required.
8. Cookies and Tracking
Our website, hosted on Squarespace, uses cookies and similar technologies to function effectively and to help us understand how you use our site.
A. Types of Cookies We Use
Strictly Necessary Cookies: These are essential for the website to function properly (e.g., loading pages securely, remembering your session). They are always active and do not require consent.
Analytics & Performance Cookies: We use Squarespace Analytics cookies to collect information about how visitors interact with our site (e.g., traffic sources, most visited pages). This data helps us improve our content and user experience. These cookies identify your device but do not reveal your personal identity directly.
B. Your Consent and Control
Cookie Banner: When you first visit our website, you will see a cookie banner. Non-essential cookies (Analytics) are only placed on your device if you click "Accept". If you click "Decline" or close the banner without accepting, only strictly necessary cookies will be used.
Browser Settings: You can also control or delete cookies through your internet browser settings at any time.
By accepting our cookie banner, you consent to the processing of data about you by Squarespace in the manner and for the purposes set out above.
9. Newsletter and Communications
We offer an optional newsletter about industry news. You will receive it only if you explicitly opt in. We clearly ask for your consent before adding you to our mailing list. Every newsletter email includes instructions to unsubscribe. We never share your email with others for marketing.
10. Contact Information
If you have any questions about this Privacy Policy or how your data is processed, please contact the Controller at contact@insighttaxandlegal.com. You may also request access, correction, or deletion of your data via this email. We commit to cooperating with data protection authorities if needed.
11. Changes to this Policy
This Privacy Policy is updated as of January 1, 2026. We will revise it if practices or legal requirements change, always using clear, concise language. Any changes will be posted on this page with the revised effective date.