Logo

PexxaFloor

Privacy and GDPR policy

This policy explains which personal data is processed, why, and what rights you have.

Last updated: 14 August 2026

Controller

Unisis Development SRL, trading under the PexxaFloor brand — Rue du Broek 114, 1082, BERCHEM-SAINTE-AGATHE, Belgique — company/VAT number BE 0871.407.121 — info@pexxafloor.be — +32 494 042 932.

For privacy questions or requests: info@pexxafloor.be.

Data processed

  • Account and identity: name, email, identifier, login data and role.
  • Orders and delivery: basket, products, prices, address, phone, history and status.
  • PRO account: company, VAT number, activity, contact details and submitted documents.
  • Quotes: configuration, project reference and customer information entered by the professional.
  • Payment: identifiers and status supplied by Stripe; full card numbers are not stored.
  • Technical data: security logs, IP address, device and language.

Purposes and legal bases

  • Account, quotes, orders, delivery and support: contract or pre-contractual measures.
  • Invoices, accounting, guarantees and authorities: legal obligation.
  • Security, fraud prevention and service improvement: legitimate interests balanced against individual rights.
  • Optional saved addresses and non-essential features: consent where required.

Recipients

Authorised PexxaFloor staff and, as needed, Supabase, Vercel, Stripe, Resend, Google Maps, carriers, accountants and legally authorised bodies receive only the data needed for their role.

International transfers

Where providers process data outside the EEA, transfers must rely on an adequacy decision, standard contractual clauses or another GDPR-recognised safeguard.

Retention

Data is retained only as long as needed. Order, invoice and accounting records are retained for the applicable statutory period, generally up to ten years. Accounts are retained while active and later deleted or anonymised unless required for law or disputes. Optional addresses remain until the customer deletes them.

Your rights

Where legal conditions are met, you may request access, correction, deletion, restriction, portability or object, and withdraw consent without retroactive effect. You may complain to the Belgian Data Protection Authority: dataprotectionauthority.be.

Security

Measures include role controls, Supabase RLS policies, encrypted communications, server-side secrets and restricted access. Incidents are handled in accordance with applicable obligations.