Privacy policy

Last updated: 18 August 2026

Pambe processes personal data in order to connect individuals with service providers in Belgium. This policy explains what data we collect, why, on what legal basis, who we share it with, how long we keep it and how to exercise your rights. It is drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and the Belgian Act of 30 July 2018.

1. Data controller

The controller of the data described in this policy is:

  • Name: Pambe
  • Legal form: private limited liability company (SRL/BV) under Belgian law
  • Registered office: Rue Edouard Valcke 45/2, 7500 Tournai, Belgium
  • Company number (CBE): 1021.266.181
  • Email: info@pambe.be
  • Phone: +32 467 64 47 14

2. Scope

This policy applies to the pambe.be website, the Pambe mobile applications, the emails and text messages we send you, and the public pages of the directory.

It does not apply to processing carried out by Providers on their own account: where a Provider collects data from their client outside the Platform in order to perform their service, they are the controller for that processing and answer for their own compliance.

Nor does it apply to third-party sites the Platform links to, which have their own policies.

3. Data we process

We do not knowingly collect special categories of data within the meaning of article 9 GDPR — health, opinions, beliefs, origin, biometric data. We invite you not to include any such data in your descriptions, your photographs or your messages.

  • Account and identity: surname and first name, email address, profile photograph, technical identifier, password — stored only in encrypted form by our authentication provider — and, where you sign in with Google or Apple, the identifier and email address transmitted by that provider.
  • Profile: professional headline, short and long biography, languages spoken, address and municipality, geographic coordinates, operating radius, company number (CBE), insurance reference, links to your social media, phone number and verification status, preferred display language.
  • Requests and services: title, description, address and geographic coordinates of the place of work, photographs, indicative budget, urgency, availability, accepted payment methods, declared at-risk trade and certification supporting documents.
  • Matching: enquiries sent and received, progress statuses, timestamps, average response time.
  • Messaging: message content, attachments, presence and read indicators. Messages and their attachments are encrypted at rest.
  • Reviews and ratings: scores, comments, date and identity of the author.
  • Reports and moderation: reason, description of the facts, history of measures taken, account moderation status.
  • Notifications: notification preferences, web push subscriptions and mobile device tokens.
  • Usage and technical data: IP address, device and browser type, pages viewed, searches performed, timestamps, technical logs and error reports, approximate city inferred from the IP address, campaign parameters and shortened links followed. In our mobile applications, and only if you consent to it, this also includes your device's advertising identifier (IDFA on iOS, Android advertising ID), together with install, launch and registration events.
  • Usage sessions: when you are signed in, the duration of your sessions in your personal area and in the mobile application — a session identifier, the timestamps of the session's start and last activity, the client type (website or application) and the display language. We carry out this measurement using our own means: it is not passed on to any third party and relies on no advertising tracker.
  • Newsletter and contact: email address, subscription status, and the content of messages sent through the contact form.
  • Professional data from public sources: for unclaimed listings, trade name, business address, business phone number, website, business identifiers and public review rating.

4. Purposes and legal bases

Where we rely on legitimate interest, we balance that interest against your rights and freedoms. You may object to such processing at any time under the conditions set out in article 11.

  • Creating and managing your account, authenticating you — performance of the contract (art. 6(1)(b) GDPR).
  • Publishing your requests and services, operating the matching and relevance ranking — performance of the contract.
  • Enabling you to exchange messages and receive notifications about your requests — performance of the contract.
  • Verifying your email address and phone number — performance of the contract and legitimate interest in account reliability.
  • Checking certifications for at-risk trades — legitimate interest in user safety.
  • Preventing fraud and abuse, moderating unlawful content — legitimate interest and legal obligation (Regulation (EU) 2022/2065 on digital services).
  • Publishing a service directory from public professional information — legitimate interest in building a useful directory, limited to professional contact details alone, with an immediate and unconditional right to object.
  • Measuring audience, improving usability and measuring the effectiveness of our advertising campaigns — consent. On the website it is collected through the cookie banner; in the mobile applications, through the consent screen shown on first launch, where audience measurement and advertising are accepted separately. On iOS, advertising measurement additionally requires your tracking authorisation (App Tracking Transparency); refusing it in no way degrades how the application works.
  • Measuring actual use of the Platform by our own means — number of active users, session duration — in order to guide our development priorities: legitimate interest (art. 6.1.f GDPR). This measurement concerns only signed-in users, does not leave our servers and serves neither advertising nor profiling purposes; you may object to it under the conditions set out in article 11.
  • Sending the newsletter — consent, with double opt-in on subscription and one-click unsubscribe.
  • Ensuring the security, availability and technical diagnosis of the Platform — legitimate interest.
  • Responding to your requests, complaints and appeals — performance of the contract or legitimate interest.
  • Complying with our accounting and tax obligations and responding to requests from authorities — legal obligation.

5. Automated processing and artificial intelligence

Matching relies on automated analysis of the text of your requests and services: those texts are transmitted to our language-model provider in order to produce a vector representation, categorise them and assess their relevance to a request.

We also use these models to offer assistance in drafting service descriptions and to translate content and messages into your display language.

Our provider acts as a processor, on our instructions alone, and undertakes contractually not to reuse your content to train its own models.

This processing does not constitute automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of article 22 GDPR: it produces suggestions that you remain free to follow or ignore. Any moderation decision restricting your account is taken or reviewed by a person and may be challenged.

6. Recipients and processors

Your data is not sold, rented or exchanged. It is accessible to other Users to the extent described in article 7, to our authorised staff bound by confidentiality, and to the following technical providers, which act as processors and are bound by a contract compliant with article 28 GDPR:

  • Auth0 (Okta) — authentication and account management.
  • Mistral AI — language models for semantic analysis, categorisation, drafting assistance and translation (France, European Union).
  • Resend and Brevo — sending transactional emails, text messages and the newsletter.
  • Google (Places) — verification and enrichment of addresses and business listings (United States).
  • MapTiler — map display and geocoding (Switzerland, country covered by an adequacy decision).
  • IPinfo — estimating the city from the IP address in order to pre-fill the search (United States).
  • Microsoft Clarity — audience measurement and usage analysis, with your consent only (United States).
  • Meta Platforms — pixel and conversions interface on the website, and a software development kit (SDK) in the mobile applications, to measure our advertising campaigns and identify which ads bring in new users, with your consent only (United States). Meta reuses this data for its own advertising targeting and acts as a joint controller in that respect. We do not send Meta your name, your email address or your phone number.
  • Sentry — collection of technical error reports.
  • Upstash — queueing and technical caching.
  • Expo — delivery of push notifications to the mobile applications (United States).
  • Our hosting provider and our file storage provider — hosting of the application, the database and the photographs (European Union).

7. What is public and what is not

Service listings, provider profiles, reviews and average ratings are public: they can be viewed without an account, may be indexed by search engines and reproduced in social media previews.

Public in particular are: your display name, your photograph, your professional headline, your biographies, your languages, your municipality, the service area of your services, your service photographs, your social links, and the reviews concerning you. The professional contact details you choose to display on a service listing — phone, email, website — are also public.

Not public are: your account email address, your personal phone number, your exact address, your requests and your messages. Your requests are not published in the directory: they are communicated to the providers approached to respond to them.

You may modify or remove this information at any time from your profile. Its disappearance from search engine results nevertheless depends on the re-indexing pace of each engine.

8. Transfers outside the European Union

Some of our processors are established outside the European Economic Area, mainly in the United States.

These transfers are governed either by an adequacy decision of the European Commission — in particular the EU–US Data Privacy Framework where the provider is certified under it — or, failing that, by the standard contractual clauses adopted by the Commission, supplemented by technical and organisational measures such as encryption in transit and minimisation of the data transmitted.

You may obtain a copy of the applicable safeguards by writing to info@pambe.be.

9. Retention periods

  • Account and profile: for the entire life of the account, then erasure or anonymisation within 30 days of its closure.
  • Requests and services: for the life of the account; a closed request is kept for a maximum of 3 years for evidential and follow-up purposes.
  • Messages and attachments: 3 years from the last exchange, or erasure on account closure if that occurs earlier.
  • Reviews: kept for the reliability of collective information, and anonymised when their author closes their account.
  • Reports and moderation measures: 3 years from the decision, in order to handle repeat offences and appeals.
  • Technical and security logs: 12 months.
  • Audience measurement trackers: 13 months maximum (see the cookie policy).
  • Usage sessions: 13 months, then automatic deletion.
  • Newsletter: until you unsubscribe; your address is then kept on a suppression list so that we no longer contact you.
  • Accounting records and supporting documents: 7 years, in accordance with Belgian law.
  • Unclaimed listings: until they are claimed, until a removal request, or until it is established that the business is no longer active.

10. Security

We implement appropriate technical and organisational measures: encryption of exchanges in transit (TLS), encryption at rest of messages and their attachments using keys specific to each conversation, passwords never stored in clear text, environment separation, access to production data restricted to authorised persons and logged, regular backups and monitoring of vulnerabilities in our dependencies.

No system is infallible, however. In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will inform you and notify the Data Protection Authority, in accordance with articles 33 and 34 GDPR.

11. Your rights

You can exercise most of these rights directly from your account area: edit your profile, delete a request or a service, manage your notification preferences, withdraw your cookie consent and delete your account.

For any other request, write to info@pambe.be. We respond within one month, extendable by two months for complex requests, in which case we will inform you. We may ask you for proof of identity in the event of reasonable doubt about it.

If you consider that your rights are not being respected, you may lodge a complaint with the Data Protection Authority, rue de la Presse 35, 1000 Brussels (contact@apd-gba.be), or with the supervisory authority of your country of residence.

  • Right of access: obtain confirmation that your data is being processed and receive a copy of it.
  • Right to rectification: correct inaccurate or incomplete data.
  • Right to erasure: obtain the deletion of your data in the cases provided for by the GDPR.
  • Right to restriction: freeze the use of your data while a verification is carried out.
  • Right to object: object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest — in particular to the publication of an unclaimed listing, which we act on unconditionally.
  • Right to portability: receive the data you provided to us in a structured, machine-readable format.
  • Right to withdraw your consent at any time, without affecting the lawfulness of processing already carried out.
  • Right to give directions concerning the fate of your data after your death.

12. Professionals listed without an account

If your business appears in the directory without your having created an account, you may at any time, free of charge and without having to create an account, claim the listing to take control of it, request its rectification, or request its permanent removal.

Simply use the link communicated to you, or write to info@pambe.be stating the name and address of the business. A removal request does not need to be justified and puts an end to the processing.

13. Minors

The Platform is reserved for adults. We do not knowingly collect data relating to minors. If you become aware that an account has been created by a minor, report it to info@pambe.be: the account and the associated data will be deleted.

14. Cookies and trackers

The use of cookies and equivalent technologies, together with how your consent is collected and withdrawn, is described in our cookie policy, accessible from the footer.

15. Changes to this policy

We may develop this policy, in particular to reflect new features or legal developments. Any substantial change is notified to you by email or through a notice displayed on the Platform before it takes effect. The date of the last update appears at the top of the document.

A question about this document?

A real team reads every message. Write to us at info@pambe.be or use the contact form.

Contact us
Join Pambe

Find the right person. Or become the one everyone’s looking for.