Aller au contenu

Belgian company, your data stays in Europe

kitchen [at] foodit.be

Informations légales

Privacy policy

Only what is strictly necessary, and nothing more: a contact form, audience measurement that starts only if you accept it, protection against automated submissions, and the technical logs of the server. Here is exactly what happens on it.

Dernière mise à jour : 20 August 2026

Data controller

ZIXAR SRL, Rue de la Rosière 32, 7141 Carnières, Belgium. Company number BE 1032 903 114. Food It Be is a trading name of ZIXAR SRL.

For any question about your data: kitchen [at] foodit.be.

What this site does, and what it does not do

The site www.foodit.be is a static site. The pages are files that are already built, served as they are. In practical terms, this means:

  • no advertising pixel, no retargeting tool, no advertising;
  • no social network button, no embedded video, no interactive map;
  • no resource loaded from a third-party server: the fonts and the images are served by the site itself, from a European server.

As long as you have not answered the banner, your browser contacts nothing but www.foodit.be. The measurement script is not even downloaded before you agree.

Audience measurement

If you accept it, Google Analytics measures the pages viewed and the route by which you arrived. The legal basis is your consent, within the meaning of Article 6.1.a, and you can withdraw it at any time as simply as you gave it. Refusing takes away no functionality.

Google Analytics is a service of Google LLC, established in the United States. The transfer is framed by the **EU-U.S. Data Privacy Framework** and by the standard contractual clauses. The details, the cookie names and their duration are set out in the cookie policy, together with the means to change your mind.

The contact form

What is collected

The name of your business, your name, your postcode, your telephone number, your email address, and optionally your type of cuisine, the platforms you already use and a free-text message.

Why, and on what basis

Solely to answer your enquiry in writing. The legal basis is the performance of pre-contractual measures taken at your request, within the meaning of Article 6.1.b GDPR: you write to us to obtain an offer, we reply to you.

Your contact details serve no other purpose. They are not resold, not assigned, not rented out, not passed on to a third party, and they are not added to a mailing list. No automatic email sequence is triggered by the sending of the form.

Where this data goes

The form generates an email sent to our own mailbox, on servers located in the European Union and rented from **Cyber Technology SRL**, our hosting provider, which acts as a processor in that respect. The message passes through no other external service: no sending service, no form hosted by a third party, no contact management tool. No transfer outside the European Union takes place for this processing. The only transfer the site makes is the audience measurement described above, and it starts only with your agreement.

For how long

Enquiries that come to nothing are deleted from the inbox after twelve months. If your enquiry leads to a contract, your contact details are kept for as long as the business relationship lasts. The seven-year accounting period applies only to documents that evidence a transaction: an invoice, not an email exchange.

Protection against automated submissions

The form is protected against robots by two means, both designed to avoid trackers.

A proof of work, computed at your end

Your browser solves a small cryptographic calculation before the form can be sent. That calculation takes a few tenths of a second, it is invisible, it sets no cookie and calls on no third-party service. It collects nothing about you: it only checks that a real browser has spent time on the page. It is a deliberate alternative to systems of the captcha type, which pass your browsing data on to a foreign operator.

A limit on the number of submissions

To prevent mass sending, the number of messages is limited per IP address. Your For that check, your IP address is never stored in clear text: it is turned into an irreversible SHA-256 fingerprint, and that fingerprint is deleted after one hour. It does not make it possible to identify you and is not linked to any other data.

In the email that reaches us, the IP address appears in truncated form: the last block is removed. That is a minimisation choice. The legal basis for these two measures is our legitimate interest in protecting our means of communication against abuse, within the meaning of Article 6.1.f.

Server logs

Like any web server, ours technically records the requests it receives, which includes the IP address, the date, the page requested and the browser used. Those logs serve security and fault diagnosis only, are not used for audience analysis, and are purged within thirty days at most. The legal basis is our legitimate interest in protecting the service, under Article 6.1.f.

Your rights

You have a right of access, rectification, erasure and restriction, a right to portability, and a right to object to processing based on our legitimate interest. You can also withdraw the consent given for audience measurement at any time, as easily as you gave it. To exercise them, write to kitchen [at] foodit.be. We reply within one month. No proof of identity will be asked of you if your request comes from the email address you gave us, unless there is serious doubt about who you are.

You may also lodge a complaint with the Data Protection Authority, rue de la Presse 35, 1000 Brussels.

Automated decision-making

No decision producing legal effects is taken by automated means on the basis of your data. There is neither profiling nor commercial scoring.

The service sold to merchants

This policy covers this showcase site. When a merchant subscribes to Food It Be, the online ordering shop delivered to them processes the data of their own customers. In that relationship, the merchant is the data controller and ZIXAR acts as data processor, within the meaning of Article 28 GDPR. A separate data processing agreement frames those obligations, and it is handed over at the signing of the contract.

Amendment

Any amendment to this policy is published on this page, with an update to the date shown at the top.