brookpoint

Privacy Policy

Last updated 2 September 2026.

brookpoint is a recruitment service. Doing that work means handling personal data: yours if you contact us or visit this site, and candidates' data if we approach them about a role. This page says who holds it, what we hold, on what legal basis, who sees it, for how long, and how to make us stop.

It is organised by who you are, because the answer is not the same for a visitor, a candidate and a client contact.

Who is responsible

brookpoint is a trade name of Aurora Advisory SRL, registered in Belgium under company number 0770.413.095, VAT BE 0770.413.095, registered office Rue de la Croix 4, 1050 Ixelles, Belgium. That company is the controller of the data described here.

Write to privacy@brookpoint.eu. A person reads that inbox, not a ticketing system. We are not required to appoint a Data Protection Officer and we have not appointed one; that address reaches the people who decide.

If you visit this website

What we process. Your IP address, the date and time of your visit, the pages you open and basic browser information, so the site loads and stays available. If you accept measurement, aggregated statistics about how the site is used.

Legal basis. Our legitimate interest in operating and securing the site, Article 6(1)(f) GDPR. For measurement, your consent, Article 6(1)(a) GDPR, which you may withdraw at any time. See our Cookie Policy.

Who sees it. Our hosting provider, and Google Analytics only if you accepted.

If you fill in the contact form

What we process. Your name, your company, your email address and your message. They are sent to our own mailbox and nowhere else. The website stores nothing.

Legal basis. Steps taken at your request before entering into a contract, Article 6(1)(b) GDPR, and our legitimate interest in answering people who write to us, Article 6(1)(f).

How long. For as long as the commercial relationship is live, and for two years after our last contact.

If you complete the Express audit

What we process. The questionnaire asks about your hiring practice, not about you. Your answers stay in your browser while you fill it in, and reach our server only when you ask for your result. The result is stored without any name attached to it. If you then ask us to send you the report, we also hold your name, your company name and your email address.

Legal basis. Your consent, Article 6(1)(a) GDPR, given when you ask for the report. You may withdraw it at any time, which does not affect what was lawful beforehand.

How long. Results are deleted automatically 90 days after they are produced. Your contact details are kept until you ask us to remove them, or for two years after our last contact.

If we approach you about a role

This is the section that matters most, because we may hold data about you before you have ever heard of us.

Where we got it. From professional networks and sourcing tools, from publicly available professional information, from people who refer you to us, or from you directly if you applied. When we obtain your data from somewhere other than you, we tell you so at first contact, and in any case within one month, as Article 14 GDPR requires.

What we process. Your name, professional contact details, career history, the languages you work in, your education and qualifications, your availability and expectations where you have shared them, the outcome of our conversations, and our own notes about the roles you have been considered for.

Legal basis. Our legitimate interest in matching professionals with roles, Article 6(1)(f) GDPR, which is what a recruitment service is. Where we act at your request in a live application, Article 6(1)(b). You may object at any time, and we will stop and delete your file.

Special categories. We do not seek data revealing health, disability, trade union membership, political opinions, religion, ethnic origin or sexual orientation, and we do not record it. If you volunteer such information because it is relevant to a role, for instance an accommodation you need for an interview, we process it only with your explicit consent, Article 9(2)(a) GDPR, and only for that purpose.

Reference and background checks. We contact referees only with your prior agreement and only once you have named them. We do not run criminal record checks, credit checks or biometric identity verification. If a client requires a check of that kind, the client runs it, we tell you before it happens, and it is not part of what we hold.

Who sees your file. We share it with one client at a time, the one we are introducing you to, and only after telling you which client that is and getting your agreement. We do not sell candidate data, we do not publish it, and we do not circulate profiles to clients who did not ask.

How long. We keep a candidate file for two years after our last meaningful contact with you, then delete it. If you ask us to delete it sooner, we do, and we keep no copy.

If you are a contact at a client or a prospect

What we process. Your name, your role, your professional contact details, the record of our exchanges, your feedback on candidates, and the billing details of the company you work for.

Legal basis. Performance of a contract, Article 6(1)(b) GDPR, or our legitimate interest in doing business with the company you work for, Article 6(1)(f). For a prospect we have not yet worked with, that same legitimate interest, based on professional information about your role.

How long. For the duration of the relationship and three years afterwards. Accounting records are kept for ten years, as Belgian law has required since 1 January 2023.

If you are a supplier or a professional contact

What we process. Contract and contact details, and the accounting data needed to pay you.

Legal basis. Performance of the contract, Article 6(1)(b) GDPR, our legal obligations in accounting and tax matters, Article 6(1)(c), and our legitimate interest in managing the relationship, Article 6(1)(f).

Equal treatment

We recruit on skills and experience. We do not screen on age, sex, origin, belief, disability, family situation or any other protected ground, and we do not accept a client instruction that would ask us to. Where a client or the law requires anonymous diversity reporting, we provide aggregate figures that identify no one.

Software, artificial intelligence, and what a machine never decides

We use software, including large language models, to help us draft messages, translate them, summarise interviews and rank profiles against a role.

No decision that affects you is taken by a machine alone. A person reads every shortlist, every rejection and every message before it leaves. Scoring assists a human judgement, it does not replace it, and you are never subject to a decision based solely on automated processing within the meaning of Article 22 GDPR. If you want to know how a particular assessment was reached, ask us and we will tell you.

What we send to a language model is not used to train that model.

The tools we rely on

These providers process data on our behalf, under contract:

the European Union.

agree. See our Cookie Policy.

Some of these are established outside the European Economic Area. Where that is the case, transfers rely on the European Commission's standard contractual clauses, and for the United States on its adequacy decision for the EU-US Data Privacy Framework. A copy of the safeguards is available on request.

Legal obligations, disputes and change of ownership

We process and retain data where the law requires it, Article 6(1)(c) GDPR, and to establish or defend a legal claim, Article 6(1)(f). If our business is ever sold, merged or restructured, data may pass to the acquirer under the same protections, and we will say so on this page before it takes effect.

Security

Access to our systems is restricted to the two of us and protected by individual credentials. Data is held with the providers listed above, in the European Union unless stated. No system is beyond reach, and we do not pretend otherwise: if a breach ever affects your data and presents a risk to you, we will tell you and the supervisory authority, as the law requires.

Your rights

You may ask us for a copy of what we hold, to correct it, to delete it, to restrict what we do with it, or to object to it entirely. You may also ask for it in a portable format, and withdraw any consent you have given. Exercising these rights is free and does not disadvantage you as a candidate.

Write to privacy@brookpoint.eu. We answer within one month, usually much sooner.

One honest limitation. Our applicant tracking system does not currently let us delete a note through its interface. If you ask for erasure and a note is involved, we empty its content immediately and press the vendor for full deletion. We would rather tell you that than pretend otherwise.

If you think we have handled your data badly, you can complain to the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, autoriteprotectiondonnees.be.

Changes

If we change this page we update the date at the top. If a change matters to you, we tell you directly rather than expecting you to re-read it.