GDPR-Compliant CRM for Belgian Businesses

Built for EU privacy standards from day one. No compromises, no retrofitting.

GDPR-Compliant

Full compliance with EU data protection regulations

Encrypted Storage

End-to-end encryption for all sensitive data

EU Privacy Standards

Hosted in Europe, compliant with Belgian law

DPA Included

GDPR Article 28 compliant data processing agreement

Your GDPR Rights, Built Into Every Feature

Right to Access

GDPR Article 15

Export customer data in JSON/CSV format. One-click download includes all leads, quotes, invoices, and interactions.

How it works: Navigate to Settings → Data Export → Choose format → Download within 5 minutes

Right to Erasure

GDPR Article 17

30-day grace period protects your business. Blocks deletion during active subscriptions and unpaid invoices.

Business protection: Deletion paused until contracts fulfilled and invoices paid

Right to Rectification

GDPR Article 16

Customers update their own profiles. Self-service data correction reduces support burden.

How it works: Lead/client detail pages → Edit Profile → Update instantly

Data Portability

GDPR Article 20

Structured JSON export for easy migration. No vendor lock-in, switch anytime.

Format: Machine-readable JSON with full schema documentation

Right to Object

GDPR Article 21

Opt-out of marketing emails and cookie tracking. Granular consent management included.

Controls: Cookie banner + email unsubscribe + marketing preferences

Restrict Processing

GDPR Article 18

Pause data processing during disputes. Mark records for restricted use without deletion.

Use case: Customer disputes data accuracy while investigation ongoing

GDPR Article 28: Data Processing Agreement

Business customers (data controllers) require a DPA with data processors. We've got you covered.

What's Included in Our DPA:

  • Subject matter and duration - CRM data processing scope
  • Nature and purpose - Sales, marketing, customer management
  • Data categories - Contact info, interactions, financial records
  • Data subject categories - B2B contacts, employees
  • Security measures - Encryption, access controls, audits
  • Subprocessors - AWS, Stripe, OpenAI (all GDPR-compliant)
  • Data subject rights - How we assist with GDPR requests
  • Breach notification - 72-hour incident response plan
Download Full DPA (PDF)

Transparent Data Retention

We only keep data as long as necessary. Automated enforcement ensures compliance.

Active Accounts

Subscription + 1 year

Financial Records

7 years (Belgian tax law)

Email Logs

90 days

Deleted Accounts

30-day grace → anonymized

Why Belgian Businesses Choose Horizon CRM

Built for Belgian Market

  • Multi-language: Dutch, French, German, English
  • VAT compliance: Belgian VAT rate support (6%, 12%, 21%)
  • PEPPOL integration: E-invoicing for Belgian government
  • Belgian DPA: Belgian Data Protection Authority pre-approved
  • 7-year retention: Compliant with Belgian accounting law

Privacy-First Architecture

  • Data minimization: Only collect what's necessary
  • Purpose limitation: Data used only for stated purposes
  • Storage limitation: Automatic deletion after retention period
  • Accuracy: Self-service data correction tools
  • Accountability: Complete audit trail of admin actions

Enterprise-Grade Security

End-to-End Encryption

All sensitive data encrypted at rest and in transit. AES-256 encryption standard.

Access Controls

Role-based permissions, two-factor authentication, session management.

Audit Logging

Complete trail of admin actions, 1-year retention for compliance audits.

GDPR Compliance FAQs

Horizon CRM is built with GDPR compliance from day one. We implement: (1) Privacy by design and default, (2) Data minimization and purpose limitation, (3) Encrypted storage and secure transmission, (4) User data export and deletion tools, (5) Data Processing Agreement (DPA) for all business customers, (6) Transparent data retention policies with automated enforcement, (7) Incident response plan with 72-hour breach notification.

A DPA is required under GDPR Article 28 when a business (data controller) uses a service provider (data processor) to handle personal data. It defines the scope of data processing, security measures, and responsibilities. Horizon CRM provides a comprehensive DPA that covers all aspects of our data processing activities. Download it here.

Retention periods vary by data type: Active accounts (subscription + 1 year), Financial records (7 years per Belgian law), Email logs (90 days), Call recordings (6 months), AI logs (30 days), Deleted accounts (30-day grace period then anonymized). Our Celery Beat tasks automatically enforce these retention periods daily. View our full Data Retention Policy.

Yes, customers can request account deletion at any time via Settings → Delete Account. However, deletion is blocked if: (1) Active subscription exists, (2) Unpaid invoices outstanding, (3) Active legal disputes, or (4) Recent chargebacks (90-day hold). This protects both parties under GDPR Article 17(3) exceptions. Once all checks pass, a 30-day grace period begins, after which the account is anonymized (personal data deleted, financial records preserved for 7 years).

We have a comprehensive incident response plan: (1) Detection & Triage within 1 hour, (2) Containment within 6 hours, (3) Notification to Belgian DPA within 72 hours (if required), (4) Notification to affected users without undue delay. We maintain a SecurityIncident model to track all incidents, and our team is trained on GDPR breach notification requirements. View our Incident Response Plan.

Ready to Experience Privacy-First CRM?

Start your 30-day free trial. No credit card required. Full GDPR compliance from day one.

GDPR-compliant from day one | Encrypted data storage | DPA included