BePark Privacy Policy

Article 1 β€” Identity of the data controller

In accordance with the General Data Protection Regulation (GDPR β€” EU Regulation 2016/679), BePark is the controller of your personal data.

Entity BePark SA (BE/LU) BePark SAS (FR)
Registered office Rue du Mail 50, 1050 Ixelles, Belgium 54 Rue de Paradis, 75010 Paris, France
GDPR contact info@bepark.eu info@bepark.eu

BePark does not currently have a designated Data Protection Officer (DPO). For any questions regarding your personal data, please contact BePark directly at info@bepark.eu. BePark undertakes to respond to your requests within a maximum of one month.

Article 2 β€” Personal data collected

2.1 Data provided directly by the User

When creating an account or using the Services, BePark collects the following categories of data:

Data category Data collected Purpose(s)
Identification Last name, first name Account creation, billing, communication
Contact Email address Login, notifications, communication
Contact Phone number Verification, support
Address Postal address Billing, identity verification
Security Password (hashed) Secure authentication
History Subscriptions, reservations, payments Contract performance, billing, support

2.2 Automatically collected data

When using the Platform, BePark also automatically collects certain technical data:

  • Browsing data: IP address (anonymised), browser type, operating system, pages visited, visit duration ;
  • Mobile application data: device model, OS version, device identifier ;
  • Cookie and tracker data (see Article 10).

2.3 Location data

The BePark mobile application may, with the User's prior and express consent, access the location data of their device on an ad hoc basis. This feature is used to locate the User on the map and to verify that the User is in the immediate vicinity of the car park in order to activate the digital remote control. This location data is not permanently stored by BePark and is only used at the time the application is in use.

BePark does not collect location data in the background. Location is only checked when the User activates the remote control feature in the application or carries out searches on the map. You may revoke your consent at any time in your device settings, which will result in the inability to open any car park door.

2.4 Payment data

BePark does not store the User's complete banking details. Transactions are processed securely via two certified payment service providers:

  • Adyen N.V. (Netherlands) β€” card payment processing, certified PCI-DSS Level 1. Only a transaction identifier and the last 4 digits of the card may be retained by BePark for tracking and support purposes.
  • GoCardless Ltd (United Kingdom) β€” SEPA direct debit processing. BePark retains direct debit mandate references (mandate identifier, partially masked IBAN) for contract management and tracking purposes.

Complete banking details (card number, full IBAN) are never stored on BePark's servers. They are processed directly and exclusively by Adyen or GoCardless in their certified secure environments.

Article 3 β€” Legal bases and purposes of processing

In accordance with Article 13 of the GDPR, the following are the legal bases on which each data processing activity carried out by BePark is based:

Purpose Data processed Legal basis (GDPR) Retention period
Account creation and management Name, email, phone, address Contract performance (Art. 6.1.b) 3 years after last activity
Processing of reservations and subscriptions Name, email, history, licence plate Contract performance (Art. 6.1.b) 3 years after end of contract
Billing and accounting Name, address, amounts Legal obligation (Art. 6.1.c) 10 years (accounting law)
Marketing email communications Name, email Legitimate interest (Art. 6.1.f) Until unsubscription
Transactional notifications Email, phone Contract performance (Art. 6.1.b) Duration of contract
Audience measurement and analytics Anonymised IP, browsing Consent (Art. 6.1.a) 13 months (cookies)
Location verification (mobile app) One-time GPS position Consent (Art. 6.1.a) Not stored
Fraud prevention and security IP, behaviour Legitimate interest (Art. 6.1.f) 13 months maximum
Dispute management All relevant data Legitimate interest / legal obligation 5 years (civil limitation)

3.1 Marketing email communications

BePark sends commercial email communications to its existing customers on the basis of legitimate interest (Art. 6(1)(f) GDPR), in accordance with the "soft opt-in" exception provided by Directive 2002/58/EC (ePrivacy). These communications concern products and services similar to those already purchased.

The User may object at any time to receiving these communications by clicking on the unsubscribe link in each email, or by contacting BePark at info@bepark.eu.

Article 4 β€” Retention periods

Personal data is retained for the following periods, in accordance with legal and regulatory requirements:

  • Account data (identity, contact): 3 years from the last activity on the account ;
  • Contractual data (subscriptions, reservations): 3 years after the end of the contractual relationship ;
  • Billing and payment data: 10 years in accordance with accounting and tax obligations ;
  • Analytical cookie data (Google Analytics): 13 months from deposit ;
  • Location data: not stored beyond the instant verification ;
  • Dispute-related data: 5 years after settlement of the dispute.

After these periods, data is securely deleted or anonymised.

Article 5 β€” Recipients and sub-processors

5.1 Data sharing

BePark never sells your personal data to third parties. Your data may be shared with:

  • Partners (car park owners/managers) to the extent strictly necessary for the performance of the subscribed Service (date and times of reservation/subscription) ;
  • Our technical sub-processors and service providers, listed below ;
  • Competent authorities (judicial, administrative, tax) upon legal requisition.

5.2 Sub-processors

BePark uses the following sub-processors, with whom data processing agreements (DPAs) are in place:

Sub-processor Role Country Safeguards
Adyen N.V. Card payment processing (PCI-DSS) Netherlands (EEA) EU Regulation, certified PCI-DSS Level 1
GoCardless Ltd SEPA direct debit processing United Kingdom European Commission adequacy decision for the UK (June 2021)
Google LLC (Analytics) Anonymised audience measurement EEA (EU servers) EU Standard Contractual Clauses, IP anonymisation
Amazon Web Services (AWS) Infrastructure hosting EEA (eu-west) EU Standard Contractual Clauses, ISO 27001 certified

Article 6 β€” International data transfers

BePark ensures that your personal data is processed and stored within the European Economic Area (EEA). No transfers to third countries outside the EEA are made directly by BePark.

In the case of sub-processors whose infrastructure is partially or fully located outside the EEA, BePark has put in place the appropriate safeguards provided for by the GDPR (Articles 44 to 49):

  • Google LLC and Amazon Web Services β€” hosting configured on European servers, covered by Standard Contractual Clauses (SCCs) approved by the European Commission ;
  • GoCardless Ltd (United Kingdom) β€” the UK is the subject of a European Commission adequacy decision since June 2021, guaranteeing a level of protection equivalent to that of the GDPR.

Article 7 β€” Rights of data subjects

In accordance with Articles 15 to 22 of the GDPR, you have the following rights regarding your personal data:

Right Description
Right of access (Art. 15) Obtain a copy of your personal data processed by BePark.
Right of rectification (Art. 16) Correct inaccurate or incomplete data about you.
Right to erasure (Art. 17) Request deletion of your data, subject to legal retention obligations.
Right to restriction (Art. 18) Request temporary suspension of the processing of your data.
Right to data portability (Art. 20) Receive your data in a structured, machine-readable format.
Right to object (Art. 21) Object to processing based on legitimate interest, including direct marketing.
Right to withdraw consent Revoke consent previously given at any time (e.g. cookies, location).

7.1 Exercising your rights

To exercise any of these rights, you may send a request to BePark:

  • By email: info@bepark.eu (stating "GDPR Request" in the subject line) ;
  • By post: BePark SA, Rue du Mail 50, 1050 Ixelles, Belgium (for BE/LU customers) ;
  • By post: BePark SAS, 54 Rue de Paradis, 75010 Paris, France (for FR customers).

BePark undertakes to respond to your request within one month of receipt. This period may be extended by two additional months in the case of complex or numerous requests, in which case you will be informed.

Proof of identity may be requested to verify your identity before your request is processed.

7.2 Right to lodge a complaint

If you believe that the processing of your personal data does not comply with applicable regulations, you have the right to lodge a complaint with the competent supervisory authority:

  • Belgium: Data Protection Authority (APD/GBA) β€” www.dataprotectionauthority.be β€” Tel.: +32 (0)2 274 48 00 ;
  • France: Commission Nationale de l'Informatique et des LibertΓ©s (CNIL) β€” www.cnil.fr β€” Tel.: +33 (0)1 53 73 22 22 ;
  • Luxembourg: Commission Nationale pour la Protection des DonnΓ©es (CNPD) β€” www.cnpd.lu.

Article 8 β€” Data security

BePark implements appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction or unauthorised disclosure. These measures include in particular:

  • Encryption of data in transit (TLS/HTTPS protocol) and at rest ;
  • Secure hashing of passwords (bcrypt algorithm) ;
  • Strict control of internal access based on the principle of least privilege ;
  • Infrastructure hosted on AWS (eu-west), certified ISO 27001 and SOC 2 ;
  • Monitoring and logging of system access ;
  • Security incident response and data breach plan.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, BePark undertakes to notify the competent supervisory authority within 72 hours and to inform you as soon as possible if this risk is high.

Article 9 β€” Minors' data

The BePark Platform is exclusively intended for adults (18 years of age and over). BePark does not knowingly collect personal data from minors. If BePark becomes aware that a minor has created an account, the relevant data will be immediately deleted.

Article 10 β€” Cookies and trackers

10.1 Definition and types of cookies

A cookie is a small text file placed on your device when browsing our website. The mobile application uses similar technologies (session identifiers, local storage).

BePark uses the following cookie categories:

Cookie type Purpose Consent required Max. duration
Essential / technical Site operation, authentication, basket No (legal exemption) Session / 1 year
Analytical (Google Analytics) Anonymised audience measurement Yes (consent banner) 13 months
Functional Storing user preferences Yes 1 year

10.2 Managing your cookie preferences

On your first visit to our site, a cookie management banner allows you to accept or refuse non-essential cookies. You may change your preferences at any time from your customer account, or from your browser settings.

BePark uses Google Analytics with the IP address anonymisation option enabled, in accordance with the recommendations of the CNIL and the DPA.

Article 11 β€” Amendments to the privacy policy

BePark reserves the right to amend this Privacy Policy at any time, in particular to adapt it to changes in services, regulations or decisions by data protection authorities. In the event of a material amendment, the User will be informed by email.

The version in force is that published on the Platform at the date of use. The update date is mentioned at the top of the document.

Article 12 β€” Contact for personal data enquiries

For any questions or requests regarding the protection of your personal data:

  • By email: info@bepark.eu (subject: "GDPR Request") ;
  • By post: BePark SA β€” Data Protection, Rue du Mail 50, 1050 Ixelles, Belgium ;
  • Or BePark SAS β€” Data Protection, 54 Rue de Paradis, 75010 Paris, France.

Your privacy matters to BePark. We are committed to processing your data in a transparent, secure manner and in strict compliance with the GDPR. To exercise your rights or for any questions, please do not hesitate to contact us at info@bepark.eu.

Β© BePark 2026 - All rights reserved.