Privacy Policy
Last updated: April 2026
1. Data Controller
This website is operated by M28 Ventures BV, trading as Verdiso.
- Enterprise Number: BE 0683.940.268
- Address: Brixtonlaan 9, 1930 Zaventem, Belgium
- Email: hello@verdiso.eu
M28 Ventures BV is the data controller responsible for the processing of your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Belgian data protection laws.
2. What Data We Collect
We collect personal data in the following circumstances:
- Contact Form Submissions: When you submit our contact form, we collect your name, email address, company name, and any message content you provide.
- CSRD Questionnaire Responses: When you complete our free CSRD readiness questionnaire, we collect your responses regarding company size, industry, revenue, and sustainability practices. This data is used only to calculate your readiness score and provide recommendations.
- Email Subscriptions: When you subscribe to our newsletter, we collect your email address and any other information you provide.
- Cookies and Tracking: We use cookies to enhance your browsing experience and analyze site usage. This includes analytical cookies to understand how visitors use our site.
3. How We Use Your Data
Your personal data is processed for the following purposes:
- To respond to your inquiries and provide customer support
- To deliver CSRD readiness assessment services and recommendations
- To send you requested resources and newsletters (with your consent)
- To improve our website functionality and user experience
- To analyze site usage and optimize our services
- To comply with legal and regulatory obligations
4. Legal Basis for Processing
We process your personal data on the following legal bases under GDPR:
- Consent: For newsletter subscriptions, cookies, and optional data collection
- Legitimate Interest: For analyzing website usage and improving services
- Contract Performance: For delivering requested assessments and services
- Legal Obligation: When required by applicable Belgian or EU law
5. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes for which it was collected:
- Contact form submissions: Retained for 2 years or until you request deletion
- Newsletter subscribers: Retained until you unsubscribe
- Questionnaire responses: Retained for 1 year for analytical purposes only
- Cookie data: Retained according to each cookie's expiration settings
6. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you
- Right of Rectification: You can request correction of inaccurate or incomplete data
- Right of Erasure: You can request deletion of your data (subject to legal obligations)
- Right of Data Portability: You can request your data in a machine-readable format
- Right to Object: You can object to processing of your data for direct marketing or other purposes
- Right to Restrict Processing: You can request limitation of how we process your data
To exercise any of these rights, please contact us at hello@verdiso.eu with details of your request.
7. Cookies Policy
We use cookies to enhance your experience on our website:
- Essential Cookies: These are necessary for website functionality, including navigation, form submission, and security features. You cannot disable these without affecting site functionality.
- Analytics Cookies: We use Google Analytics to understand how visitors use our site, including page views, referral sources, and user behavior. These help us improve our content and services.
- Preference Cookies: These remember your settings, such as cookie consent preferences and language selection.
You can manage your cookie preferences through our cookie banner at the bottom of the page. You can also disable cookies in your browser settings, though this may affect site functionality.
8. Third-Party Sharing
We do not sell or rent your personal data to third parties. However, we may share your data with:
- Service Providers: Third parties who assist us in operating our website, conducting business, or serving our users (e.g., email service providers, hosting providers), bound by confidentiality agreements
- Legal Requirements: When required by law, court order, or government request
- Business Transfers: In the event of merger, acquisition, or sale of assets, your data may be transferred as part of that transaction
9. International Data Transfers
Verdiso is a Belgium-based company and your data is primarily stored and processed within the European Union. Any data transferred outside the EU is done with appropriate safeguards, including Standard Contractual Clauses approved by the European Commission.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include SSL encryption, secure server infrastructure, and restricted access to personal data.
However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
11. Contact for Privacy Matters
If you have questions about this privacy policy or how we handle your personal data, please contact:
- Email: hello@verdiso.eu
- Address: Brixtonlaan 9, 1930 Zaventem, Belgium
12. Supervisory Authority
If you believe we have violated your privacy rights under GDPR, you have the right to lodge a complaint with the Belgian Data Protection Authority:
- Website: www.autoriteprotectiondonnees.be
- Email: contact@apd-gba.be
13. Policy Updates
We may update this privacy policy from time to time to reflect changes in our practices or applicable law. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date above.