Lecomte Alpinisme & Randonnée SA (« Lecomte », « we »), whose registered office is at Rue de Vergnies 27, 1050 Ixelles, registered under company number BE 0426.637.276, attaches particular importance to the protection of your personal data.
This policy describes what data we collect, why, on what legal basis, who we share it with and how long we keep it. It is written in accordance with Regulation (EU) 2016/679 (GDPR), the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, the Act of 21 March 2007 governing the installation and use of surveillance cameras, and the Belgian Code of Economic Law.
It covers our stores in Ixelles, Waterloo and Jodoigne, our warehouse, our tills, our online shop, our after-sales service, our loyalty programme and all the messages we send you.
Who is responsible for your data
The controller is Lecomte Alpinisme & Randonnée SA, whose registered office is at Rue de Vergnies 27, 1050 Ixelles, reachable on +32 2 201 92 97. Our post is handled at our offices: Rue de Piétrain 75A, 1370 Jodoigne.
To exercise your rights, go to our page Privacy. It explains what we hold and leads to a form requiring neither an account nor proof of identity. If you have a customer account, the Your data section of your personal area shows you directly what concerns you. You may also write to us at [email protected] or by post to our offices, Rue de Piétrain 75A, 1370 Jodoigne — in every case, your request opens a tracked file.
We respond within one month (art. 12.3 GDPR), extended to three months for a complex request — we then tell you so, with the reason, before the end of the first month.
The principles we apply
- Transparency — you know which data is processed, for what, and on what basis.
- Minimisation — we collect only what we need.
- Purpose limitation — data collected for one reason is not reused for another without telling you.
- Accuracy — you can correct your data at any time from your account.
- Storage limitation — each category has a duration, and we warn you before erasing.
- Security — TLS 1.2 or higher encryption in transit, role-based access restrictions, logging.
- Accountability — we keep an internal register of our processing activities (art. 30 GDPR).
What we process, why, and for how long
| Purpose | Data | Legal basis | Retention |
| Customer account and personal area | Identity, e-mail, encrypted password, addresses, telephone, language | Performance of the contract (6.1.b) | Duration of the relationship — warranties, after-sales, loyalty — then anonymisation if no purpose remains; immediate erasure at your request |
| Orders online and in store | Identity, billing and delivery addresses, items, amounts | Performance of the contract (6.1.b), then legal obligation (6.1.c) for retention | 10 years (Belgian accounting obligation) |
| Invoicing and accounting | Identity, tax address, VAT number where applicable, amounts | Legal obligation (6.1.c) | 10 years (Belgian accounting obligation) |
| Delivery and Click & Collect | Name, address, telephone, e-mail | Performance of the contract (6.1.b) | Duration of the order and of the claim period |
| Payment | Amount, transaction reference; no card data whatsoever | Performance of the contract (6.1.b) | With the payment provider |
| After-sales service, repair, warranty | Item, fault observed, photographs, exchanges, deposit signature, IBAN in case of refund | Performance of the contract (6.1.b) and legal warranty (6.1.c) | Duration of the warranty and of the limitation period |
| Loyalty programme | Identity, purchase history consolidated across stores and web, points, preferred store | Performance of the contract (6.1.b); legitimate interest (6.1.f) for personalisation | As long as your card is active |
| Events and workshops | Identity, contact, registration, attendance | Performance of the contract (6.1.b); consent (6.1.a) for invitations | As long as a claim remains possible |
| Commercial communications | E-mail, language, interests | Consent (6.1.a) | Until you withdraw your consent |
| Relationship messages and advice | Purchase history | Legitimate interest (6.1.f) and art. XII.13 §2 of the Belgian Code of Economic Law | Until you object |
| Satisfaction surveys | E-mail, answers, link to the order or the ticket | Legitimate interest (6.1.f) | Then anonymisation, the answer outliving the name |
| Product alerts (back in stock, price) | E-mail, item followed | Consent (6.1.a) | Until sent or withdrawn |
| Audience measurement of our websites | Pseudonymous identifiers | Consent (6.1.a) | 13 months |
| Advertising and campaign measurement | Pseudonymous identifiers | Consent (6.1.a) | 90 days |
| Browsing on our websites | Visitor identifier, pages viewed | Consent (6.1.a); legitimate interest (6.1.f) for security | 90 days if you are not identified, 13 months if you are |
| Live chat support | Transcript of the conversation, pages viewed | Legitimate interest (6.1.f) | 12 months |
| Security of our websites | IP address, session fingerprint | Legitimate interest (6.1.f) | Log retention period |
| CCTV in our stores | Image | Legitimate interest (6.1.f) and the Act of 21 March 2007 | 30 days maximum |
| Visitor Wi-Fi in store | MAC address, connection logs | Legal obligation (6.1.c) | 6 months |
| Job applications | CV, letter, exchanges, interview notes | Pre-contractual measures (6.1.b) | 24 months after the last exchange |
The messages we send you
Not all our messages fall under the same regime, and that matters: some are owed to you, others depend entirely on you.
Messages relating to your purchases and requests
Order confirmation, invoice, delivery tracking, availability of an in-store collection, exchanges about a repair or a warranty, entry ticket for an event, information about your loyalty points and their expiry, safety recall concerning an item you have bought.
These messages are essential to the performance of our obligations towards you. They are sent to you even if you have unsubscribed from our commercial communications: failing to tell you that a repair is finished, that a safety recall concerns your equipment or that your points are about to expire would harm you. They contain no commercial offer.
The messages you choose to receive
The unsubscribe link at the bottom of each of our mailings takes effect immediately, with no justification required. Our messages break down as follows:
| Category | Content | Default |
| Newsletter | News, advice, new arrivals | Off |
| Sales and promotions | Commercial campaigns | Off |
| Events and workshops | Invitations to our in-store events | Off |
| Personalised offers and advice | Suggestions linked to your purchases — care for your equipment, loyalty benefits, seasonal selections | On |
| Product alerts | Back in stock, price drop on an item you follow | At your request |
| Surveys and reviews | Satisfaction after a purchase or a service | On |
The first three categories require your prior agreement: we never sign you up automatically. For the newsletter, that agreement is confirmed by a link sent to your address.
The last three are sent to you because you are a customer and because they concern products comparable to those you have bought, in accordance with article XII.13 §2 of the Belgian Code of Economic Law. You can switch them off at any time, in a single click, without affecting the others.
Every message carries a link leading straight to this page. Unsubscribing from one category unsubscribes you from no other.
Personalisation
We adapt the content of our messages to your purchase history, your favourite brands and categories, your preferred store, your language and the way you interact with our mailings. This is light profiling within the meaning of article 4.4 GDPR, intended for editorial relevance. It produces no automated decision having legal effect concerning you (art. 22). You may object to it from our Privacy page or by writing to [email protected]. our Privacy page or by writing to [email protected].
Frequency
Newsletter and promotions: two mailings a week at most, four during the sales or a major campaign. Personalised messages: a few mailings a year. Surveys: one per purchase or per service.
Cookies and trackers
When you arrive on our websites, a banner lets you accept or refuse non-essential cookies, category by category. Until you have chosen, no measurement or advertising cookie is placed, and the tools concerned operate in identifier-free mode.
Only strictly necessary cookies are placed without your agreement: they maintain your session and your basket, remember your language and time zone, protect the site against automated attacks, and store your cookie choice.
With your agreement, we use Google Analytics 4 to measure traffic, Google Ads to measure the effectiveness of our campaigns, and Google Tag Manager to orchestrate them. We also use Google reCAPTCHA, necessary to protect our forms.
We do not use a Meta pixel (Facebook, Instagram), TikTok or Pinterest, nor any session recording tool.
The detailed list of cookies, their issuer, their purpose and their duration can be consulted in the management panel, permanently available from the « Manage my cookies » link in the footer. You may change or withdraw your choice there at any time, as easily as you gave it.
Our processing activities in detail
This section runs through, service by service, what we collect and why.
Loyalty programme
Joining the loyalty programme entails the consolidation of your purchase history across our stores and our online shop, in order to calculate your points and benefits and to send you relevant recommendations.
Your points have a validity period. We warn you before they expire, so that you can use them — this message is sent to you whatever your position regarding our commercial communications.
As long as your card is active
After-sales service, repairs and warranties
Handling a request — repair, resoling, return, warranty, exchange — involves collecting the item concerned, the fault observed, any photographs and the tracking of the case. A signed deposit slip is drawn up when the equipment is handed over; the signature is collected directly on our terminal.
We pass this information to the manufacturer or the partner workshop when the repair requires it. If a refund is due to you, your IBAN is collected and used for that purpose only.
Payment
We keep no bank card data on our systems.
Online as in store, payments are processed by Mollie B.V. (Netherlands), a PCI-DSS level 1 certified provider, which brings together Bancontact, Visa, Mastercard, Maestro, American Express, PayPal, Klarna, Apple Pay and Google Pay. Our in-store terminals operate under the same framework.
For an instalment payment, the provider concerned becomes the controller for that transaction and its own policy applies in addition.
Delivery and Click & Collect
To deliver your order, we pass your name, address and telephone number to the chosen carrier: bpost or Sendcloud, which coordinates several carriers. For an in-store collection, the pick-up point receives your identity and the contents of your order.
Events and workshops
This data is kept for as long as an insurance claim or a dispute remains possible, and as long as it lets us know whether you have been before.
When photographs are taken at an event, a sign informs you on site. You may refuse to be photographed or ask afterwards for an image in which you are identifiable to be removed.
Browsing on our websites
When you browse our websites, we record the pages viewed in order to understand journeys and improve our catalogue. If you are logged in to your account, this history is attached to your profile.
These records are kept for 90 days if you are not identified, 13 months if you are, then deleted.
Our live chat service keeps conversations for 12 months. The operator answering you sees the pages you are viewing during the exchange. Please never share banking details through this channel.
CCTV in store
Our stores and our warehouse are fitted with cameras, in accordance with the Act of 21 March 2007 and the GDPR, for the safety of people and property, the prevention of theft and the handling of disputes.
- A standardised pictogram is displayed at every entrance.
- Images are kept for 30 days at most, unless they help establish an offence or damage.
- Only authorised staff have access; the authorities may access them upon requisition.
- The installation has been declared via police-on-web.
- You may request access to the images concerning you from our Privacy page or to [email protected], stating the approximate date, time and place.
Visitor Wi-Fi
Our stores offer a visitor Wi-Fi network. MAC addresses and connection logs are kept for 6 months in accordance with the applicable obligations, then destroyed. No content of your browsing is inspected.
Minors
Our online services are not intended for children under 13, the threshold set by the Belgian Act of 30 July 2018. Creating an account or joining the loyalty programme between 13 and 18 requires a parent's authorisation.
Job applications
Unsolicited applications and responses to our vacancies are kept for a maximum of 24 months from the last exchange, then destroyed or anonymised. You may ask for their immediate destruction at any time.
Who we share your data with
Some providers act on our behalf, on our instructions and bound by contract to the same obligations as ours (art. 28 GDPR):
| Provider | Role |
| Cloudpepper | Hosting of our ERP and our websites |
| Mailgun | Delivery of our e-mails |
| bpost, Sendcloud | Delivery |
| Cloudflare | Delivery and security of our websites |
| Usercentrics (Cookiebot) | Collection and evidence of your cookie choice |
| Odoo SA | Additional application services |
Others decide for themselves what they do with the data we pass to them. They are responsible for it and answer to their own legal obligations; for that part, you may also exercise your rights directly with them:
| Recipient | Role |
| Mollie B.V. | Online payment and in-store terminals. A financial institution, subject to its own retention obligations |
| Google Ireland | Audience measurement, advertising and form protection, only if you accepted the corresponding cookies |
We also pass your data to the public authorities where the law requires us to, and, in the event of a transfer of the business, to the acquirer, who takes over the commitments of this policy.
We never sell your data.
Hosting and transfers outside Europe
Your data is hosted in France, within the European Union, on the infrastructure of our host Cloudpepper. Our e-mail sending is handled on our provider's European infrastructure.
Some of our technical providers are established in the United States (Google, Cloudflare). Transfers to these recipients are governed by the EU–US Data Privacy Framework where the recipient is certified under it, and by the standard contractual clauses adopted by the European Commission (decision (EU) 2021/914). No transfer to any other third country takes place without one of these safeguards.
Retention and anonymisation
The durations appear in the table above. Each duration follows from the purpose it serves — we do not apply a uniform period, because data erased too early would prevent us from providing the service we owe you.
This deadline is subject to an annual review, carried out by a person and not by an automated job: erasing or anonymising a file is an irreversible act, and we would rather it were decided than triggered. The periods given are maximums — you may ask for your data to be erased at any time without waiting for the deadline, and we handle that request within the month.
- The data required to perform a contract is kept for its duration and the applicable limitation period.
- Accounting and tax data is kept for 10 years, a legal period imposed on us, regardless of your account activity.
- Your customer file — orders, repairs, warranties, loyalty — is kept for as long as the relationship justifies it.
- Browsing and measurement data follows its own, short duration, given in the table.
If we stop hearing from you
You stay in control of our mailings. Every commercial message carries an unsubscribe link that takes effect immediately, and you can ask us at any time to stop writing to you. Your account and your history are not deleted as a result — you will find them intact if you come back to see us.
We do not erase your file on a fixed date, and that is deliberate. As long as the relationship exists — a warranty we manage for you, a resoling to come, loyalty points, a possible purchase — the file serves a purpose, and erasing it would deprive you of the service. The retention period therefore follows the purpose: it runs for as long as we can be useful to you in respect of what you have bought.
You decide on erasure. You may request it at any time, without reason and without waiting for any deadline: we handle it within the month, item by item, and we tell you exactly what has been erased and what the law obliges us to keep. It is the act that takes precedence over all others.
On our side, we carry out a periodic review of the files that no longer serve any purpose — a contact with no purchase, no live warranty and no interaction — in order to anonymise them. It is carried out by a person, never by an automated job: anonymising is irreversible and touches accounting entries; it is decided, not triggered.
You may ask for your data to be erased at any time without waiting for these deadlines: see the next section.
Security
We implement measures proportionate to the risk: TLS 1.2 or higher encryption in transit, role-based access control, logging of access to sensitive data, encrypted backups, regular patching, staff awareness. Our providers are contractually bound to the same commitments.
You are responsible for keeping your password confidential. Report any unauthorised access you suspect to us immediately.
Your rights
You have the following rights at all times, exercisable from our Privacy page :
- Access (art. 15) — obtain a copy of the data we hold about you.
- Rectification (art. 16) — correct inaccurate or incomplete data.
- Erasure (art. 17) — subject to our legal retention obligations.
- Restriction of processing (art. 18).
- Portability (art. 20) — receive your data in a structured, machine-readable format.
- Objection (art. 21) — in particular to personalisation and direct marketing.
- Withdrawal of consent (art. 7.3) — at any time and without reason, for the processing that depends on it.
- Post-mortem instructions — decide what happens to your data after your death.
We respond within one month of receipt. For a complex request, this period may be extended by two months, and we tell you so with the reasons within the first month. Our responses are free of charge.
What an erasure request erases, and what it does not
We would rather tell you before you ask: an erasure is necessarily partial, and our answer will give you the detail item by item.
- We cannot erase your accounting data. Invoices, payments and related entries are kept for 10 years under Belgian accounting law. Article 17.3.b of the GDPR sets aside the right to erasure where processing is necessary to comply with a legal obligation. The orders, deliveries and stock movements that justify these entries follow the same rule.
- You decide about your service files. Your repair and warranty files and your loyalty points can be erased if you wish, but we will not do so without telling you what you lose: without a history, we can no longer enforce your warranties with the brands, including the commercial warranties we manage for you beyond the two statutory years. We present you with the list, item by item, and you choose.
- Your gift cards are never deleted. They remain valid and usable with their code. They will, however, no longer be attached to your account: we will no longer be able to give you the code or the balance, so keep them safe.
- An e-wallet balance is refunded to you before erasure — it is money that belongs to you.
- The rest is erased or anonymised: subscription to our communications, wish list, browsing, open-rate measurements, conversations.
We communicate every erasure to our recipients (art. 19) and tell you who they are if you ask.
If we cannot act on your request, we give you the reasons within the month, together with your right to lodge a complaint with the Data Protection Authority and to seek a judicial remedy.
In the event of a data breach
If a data breach is likely to give rise to a risk to your rights and freedoms, we notify the Data Protection Authority within 72 hours (art. 33 GDPR). Where the risk is high, we inform you directly and as soon as possible (art. 34).
Changes to this policy
This policy evolves with our processing activities and with regulation. The date of the last update appears at the top of the document. Substantial changes are announced by e-mail to account holders.
Contact us
| Channel | Detail |
| Questions about your data | Privacy · [email protected] |
| General contact | [email protected] |
| Telephone | +32 2 201 92 97 (Monday to Friday, 9:30–17:30) |
| Live chat | On our websites, Monday to Friday, 9.30 am–5.30 pm |
| Post | Lecomte Alpinisme & Randonnée SA, Rue de Piétrain 75A, 1370 Jodoigne |
Supervisory authority
If you believe a processing activity is not compliant, you may lodge a complaint with the Data Protection Authority:
Rue de la Presse 35, 1000 Brussels — [email protected] — +32 2 274 48 00 — www.autoriteprotectiondonnees.be