1. Data Controller Identification
Refactored is committed to protecting the privacy and personal data of its clients, website visitors, and software users. This policy outlines our data collection, processing, and storage practices in accordance with the General Data Protection Regulation (GDPR / Regulation EU 2016/679).
- Data Controller: Refactored (Johnnie Eerlings)
- Registered Address: Opitterkiezel 225B, 3960 Bree, Belgium
- Enterprise / VAT Number: BE 0866.490.706
- Data Protection Inquiries: privacy@refactored.be or johnnie@refactored.be
2. Categories of Data Collected & Purpose
We collect and process only the minimal personal data necessary to provide our software platforms, fulfill orders, and meet statutory obligations:
- Contact Details: Name, email address, and optional company name when submitting inquiries, contracting bespoke engineering, or registering licenses. Purpose: customer communication, support, and contract execution.
- Billing & Transaction Records: Invoicing address, VAT number, and transaction logs. Purpose: tax compliance and legal bookkeeping requirements under Belgian fiscal law (mandatory retention period of 7 years).
- Technical Edge Logs: IP address, timestamp, and request headers captured at the edge layer via Cloudflare. Purpose: infrastructure security, DDoS prevention, and rate-limiting (legitimate interest).
3. Secure Payment Processing via Stripe
3.1. To execute secure online transactions, software licenses, and card payments, Refactored partners with certified payment institution Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland).
3.2. All sensitive payment details (including credit card numbers, CVV codes, and bank accounts) are processed directly on Stripe's encrypted servers using transport layer security (TLS/HTTPS). Refactored never receives, views, or stores raw payment card numbers on its servers.
3.3. Stripe maintains full compliance with the Payment Card Industry Data Security Standard (certified PCI-DSS Level 1 service provider). For further information on Stripe's data handling practices, please consult the Stripe Privacy Policy.
4. No Tracking Cookies or Third-Party Pixels
Refactored operates a clean, privacy-first website. We do not install commercial tracking cookies, advertising pixels, or cross-site behavioral tracking scripts. We utilize privacy-preserving, cookieless edge metrics via Cloudflare Web Analytics to monitor uptime and network performance without personal profiling.
5. Data Sharing & Sub-processors
Personal data is never sold or rented to third parties. We share data strictly with vetted technical providers essential for delivering our services:
- Payment Gateways: Stripe Payments Europe, Ltd. (payment settlement).
- Hosting & Security: Cloudflare, Inc. (global CDN and security mitigation).
- Accounting & Tax: Certified accounting software and tax authorities in accordance with Belgian legal obligations.
6. Your Rights Under GDPR
As a data subject within the EU, you are entitled to exercise the following rights:
- Right to access personal data held about you.
- Right to rectify inaccurate or incomplete records.
- Right to erasure ('right to be forgotten'), subject to mandatory statutory retention rules.
- Right to restrict or object to processing, and right to data portability.
To exercise any of these rights, contact us at privacy@refactored.be. You also maintain the right to lodge a formal complaint with the supervisory authority: the Belgian Data Protection Authority (GBA / APD) (Rue de la Presse 35, 1000 Brussels, dataprotectionauthority.be).