Data protection

Privacy policy

Prepared in accordance with Regulation (EU) 2016/679 (GDPR) and Belgian law. Last updated: 6 September 2026.

1. Data controller

The controller of your personal data is:

M. Corporation SRL
Registered office: Bld. Louis Mettewie 312 bte 10, 1080 Brussels, Belgium
Email: info@mcorporation.eu

Data Protection Officer: v.mettewie@mcorporation.eu.

2. Data we collect

  • Contact form: your name, email address, subject and the content of your message.
  • Investor file: name, email, mobile, postal address, agreements, investments, payments and relevant correspondence.
  • Identification and tax: national-register or company number, ID-card expiry date and, when required for the file, a copy uploaded exclusively through the portal.
  • Banking: IBAN and BIC needed to pay net interest and principal. Complete details are viewed and changed in the portal and are never requested by email.
  • Security: sign-in logs, devices, IP address and audit events used to protect the portal.

3. Purposes and legal bases

  • To respond to your enquiries and manage our correspondence — legal basis: our legitimate interest and/or steps taken at your request.
  • To form, perform and close loan agreements and make payments — legal basis: performance of a contract.
  • To identify the beneficiary and report Belgian withholding tax correctly — legal basis: tax and accounting obligations.
  • To maintain demanding identification, anti-fraud and relationship checks. M. Corporation is not part of the financial sector, but voluntarily applies comparable KYC and AML quality standards — legal basis: legitimate interest, without prejudice to applicable legal duties.
  • To ensure the security and proper functioning of the website — legal basis: legitimate interest.
  • To send investment opportunities — legal basis: consent. Active investors receive their contractual priority; other consenting contacts receive at most two opportunities per year. Any objection prevails immediately.

4. Recipients

M. Corporation is the sole controller of the portal. Access is limited to authorised staff and necessary processors: OVHcloud (hosting), Dropbox (document imports), Brevo (email delivery through its HTTPS API), the configured SMS provider, professional advisers and competent public authorities. Data is never sold.

5. Retention

  • IBAN, BIC, ID-card copies and operational data: no later than twelve months after the final payment, dispute or other contractual obligation.
  • Tax and accounting records: ten years where legally required.
  • Email: no automatic archive copy is sent to a BCC mailbox. Brevo technical logs are deleted through its HTTPS API when due: immediately for OTPs, temporary passwords and secret links, after twelve months for ordinary operational/identity mail, and after twenty-four months for marketing. Email that forms tax or accounting evidence is stored separately, encrypted at rest, for ten years; its Brevo log is deleted after no more than twenty-four months. A legal hold suspends deletion.
  • The portal remains readable after an agreement ends. Six months after the latest maturity, its owner may request closure in the portal.
  • A marketing objection removes the address from the list; only a non-reversible cryptographic digest remains to prevent re-import. A signed ledger kept separately from active backups contains only this digest and the purge/hold events needed to reapply rights after a restore.

6. International transfers

Services are configured for processing and hosting within the European Union. Any exceptional transfer could occur only with the safeguards required by the GDPR.

7. Your rights

You may access and correct portal data, request restriction, portability or erasure where permitted, and object to marketing at any time. Use the portal or contact the DPO at v.mettewie@mcorporation.eu.

You also have the right to lodge a complaint with the Belgian Data Protection Authority — Autorité de protection des données / Gegevensbeschermingsautoriteit, Rue de la Presse 35, 1000 Brussels — www.autoriteprotectiondonnees.be.

8. Cookies

The portal uses only storage required for authentication and security. Audience measurement is configured without advertising profiling.

9. Portal security

The portal is not public: every file is isolated server-side and protected by password and a second factor. Documents and the central workbook are encrypted at rest; IBAN and BIC are field-encrypted in PostgreSQL. Email contains only masked bank references and directs users to the secure portal.

10. Changes

This privacy policy may be updated to reflect legal or operational changes. The current version is always the one published on this page.

← Back to home