Value Added, Indirect Tax Services

Privacy and GDPR notice

Processing of personal data on Value Added Tax Portal

Last updated 30 August 2026

Controller

Value Added BV, trading as Euregio Law and Tax, is the controller for the personal data processed on this platform, within the meaning of Regulation (EU) 2016/679 (GDPR).

  • ·Registered office: [to complete: street, number, postcode, town]
  • ·Enterprise number (CBE): [to complete]
  • ·Contact for data protection matters: [to complete: e-mail address]
  • ·Data protection officer, where one is appointed: [to complete]

Data processed

  • ·Account data: last name, first name, e-mail address, role, activation and approval status, assigned manager.
  • ·Client file data: company name, VAT number, country, communication language, contact e-mail address, telephone number, and the name of the contact person.
  • ·Filing data: registration files, filing regimes, periods, deadlines, statuses, declared VAT amounts, filing references and settlement dates.
  • ·Documents: the files uploaded to the platform, or, where the document is held on your own infrastructure, only the reference to its location.
  • ·Technical data: authentication logs and the timestamps attached to the records created or modified.

Purposes and legal bases

The platform performs no profiling and takes no automated decision producing legal effects.

  • ·Performing the engagement between the firm and its client, and giving access to the platform: performance of a contract (Article 6(1)(b)).
  • ·Meeting the accounting and VAT obligations that rest on the firm and on its clients: compliance with a legal obligation (Article 6(1)(c)).
  • ·Securing access, tracing actions and preventing abuse: legitimate interests of the firm (Article 6(1)(f)).

Recipients

Data is accessible to the authorised staff of the firm, on a need to know basis. A manager only sees the clients assigned to them, and a client contact only sees their own company. That restriction is enforced in the database itself, not only in the interface.

  • ·Supabase, as processor, for the database, the authentication service and document storage, in a European region.
  • ·Vercel Inc., as processor, for hosting and serving the application.
  • ·The tax administrations concerned, where a filing or a formality requires it.

Transfers outside the European Union

The infrastructure is configured to keep data in a European region. Where a processor requires access from outside the European Economic Area for support purposes, that access takes place under the European Commission’s standard contractual clauses.

Retention

Filing data and supporting documents are kept for the statutory retention period applicable to accounting and VAT records in the country concerned, counted from the end of the engagement: [to complete: retention period applied by the firm].

Account data is deleted or anonymised within a reasonable period after the account is closed, subject to the retention obligations above.

Security

Access is protected by individual authentication. Rights are enforced by row level security policies in the database, so a query outside your scope returns nothing rather than being merely hidden from the screen. Uploaded documents live in a private bucket and are served through links that expire. Traffic is encrypted in transit.

Cookies

The platform uses no advertising cookie and no audience measurement cookie. It sets two categories of cookie only, both strictly necessary to the service.

  • ·Authentication cookies, set by Supabase, which keep you signed in for the duration of your session.
  • ·A language preference cookie, which stores the display language you selected, for one year.

Your rights

You have the right to access your data, to have it rectified or erased, to have its processing restricted, to object to processing, and to data portability. These rights are exercised at the contact address stated above, with proof of identity where there is reasonable doubt.

Where the firm acts as processor on behalf of a client company, a request from that company’s staff is forwarded to that company, which is the controller.

Complaints

You may lodge a complaint with the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, contact@apd-gba.be, without prejudice to any other administrative or judicial remedy.