PexxaFloor
Privacy and GDPR policy
This policy explains which personal data is processed, why, and what rights you have.
Last updated: 14 August 2026
Controller
Unisis Development SRL, trading under the PexxaFloor brand — Rue du Broek 114, 1082, BERCHEM-SAINTE-AGATHE, Belgique — company/VAT number BE 0871.407.121 — info@pexxafloor.be — +32 494 042 932.
For privacy questions or requests: info@pexxafloor.be.
Data processed
- Account and identity: name, email, identifier, login data and role.
- Orders and delivery: basket, products, prices, address, phone, history and status.
- PRO account: company, VAT number, activity, contact details and submitted documents.
- Quotes: configuration, project reference and customer information entered by the professional.
- Payment: identifiers and status supplied by Stripe; full card numbers are not stored.
- Technical data: security logs, IP address, device and language.
Purposes and legal bases
- Account, quotes, orders, delivery and support: contract or pre-contractual measures.
- Invoices, accounting, guarantees and authorities: legal obligation.
- Security, fraud prevention and service improvement: legitimate interests balanced against individual rights.
- Optional saved addresses and non-essential features: consent where required.
Recipients
Authorised PexxaFloor staff and, as needed, Supabase, Vercel, Stripe, Resend, Google Maps, carriers, accountants and legally authorised bodies receive only the data needed for their role.
International transfers
Where providers process data outside the EEA, transfers must rely on an adequacy decision, standard contractual clauses or another GDPR-recognised safeguard.
Retention
Data is retained only as long as needed. Order, invoice and accounting records are retained for the applicable statutory period, generally up to ten years. Accounts are retained while active and later deleted or anonymised unless required for law or disputes. Optional addresses remain until the customer deletes them.
Your rights
Where legal conditions are met, you may request access, correction, deletion, restriction, portability or object, and withdraw consent without retroactive effect. You may complain to the Belgian Data Protection Authority: dataprotectionauthority.be.
Security
Measures include role controls, Supabase RLS policies, encrypted communications, server-side secrets and restricted access. Incidents are handled in accordance with applicable obligations.
