Aller au contenu

Belgian company, your data stays in Europe

kitchen [at] foodit.be

Legal information

Hosting and security

FoodIt.Be servers are hosted in the Netherlands, in the European Union. Here are our sub-processors and our security measures, as the contract sets them out.

Last updated: 12 September 2026

Appendix 2. Sub-processors

This list is complete. The providers that do not process your customers’ data on behalf of ZIXAR are listed after the table.

Sub-processorServiceYour customers’ dataLocation and safeguard
Cyber Technology SRL, trading as StrictlyHosting (BE 0474.407.105), BelgiumHosting of servers, databases and backupsAllServers in the Netherlands, in the European Union
Brevo (Sendinblue SAS), FranceSending your shop’s emails to your customers: order confirmation and tracking, campaigns you launchName, email address, email contentEuropean Union

The following are not sub-processors within the meaning of this annex, because they do not process your customers’ data on behalf of ZIXAR:

  • Mollie B.V. (online payment of your first invoice) and Belfius Bank SA (direct debit of your monthly payments). They process your data as a customer of ZIXAR;
  • Odoo SA (invoicing and accounting of ZIXAR). Same remark;
  • OVH SAS or any other registrar, for the domain name registered in your name;
  • Brevo, if you provide us with your own account: your shop’s emails are then sent from that account, you contract directly with Brevo and you are the controller. In that case Brevo leaves the list above. As long as you do not provide an account, the emails are sent from ZIXAR’s account and Brevo remains its sub-processor;
  • your own payment provider (Mollie, Stripe or other). You choose it and you contract directly with it.

These providers are mentioned in ZIXAR’s privacy policy when they process your data.

Appendix 3. Security measures

ZIXAR implements the following measures.

  • Encryption of exchanges over HTTPS on the shop, the administration and the customer area, with automatic redirection and an automatically renewed certificate.
  • Passwords stored in hashed form, with a recognised algorithm (argon2id for shops, PBKDF2 for the customer area). They are never stored in plain text.
  • Each business’s data is stored in a separate database, with access rights granted table by table. A business cannot access another’s data, and this isolation is verified by an automated check.
  • Administrative access limited to the people who need it. Access to the server is by cryptographic key. The administration consoles are protected by a password, with lockout after several failed attempts and time-limited sessions.
  • The administration and the customer area only listen on the server’s internal network. Only the public web server is exposed to the internet.
  • The service uses no external dependency: it is written with the language’s standard library only. Components that use third-party libraries pin their versions in a lock file, and every addition is reviewed. Operating system patches are applied by our hosting provider.
  • Daily backups of the service data, kept for thirty days, with restore tests. The backup files can only be read by the service’s technical account. The server is also replicated every day at our hosting provider. These backups are not encrypted: the key would have to live on the server and would disappear with it, making the backup unusable at the very moment it is needed.
  • Logging of technical operations and errors, kept for twelve months. Web server logs, which contain IP addresses, are kept for thirty days by our hosting provider.
  • Confidentiality undertaking by the people who have access to the data.
  • Written procedure for handling incidents and personal data breaches.
  • Selection and supervision of sub-processors.
  • Test environments separate from production: test data is invented or anonymised, never copied from production.
  • No payment card data is stored by FoodIt.Be.
  • Secure erasure of data at the end of its retention period.