PRIVACY POLICY
Website foostix.com
Last updated : 27 May 2026

1. Identity of the data controller
This policy applies to the processing of personal data carried out by:
Foostix Lux S.à r.l.
Private limited liability company under Luxembourg law
Registered office : 5, rue Aldringen, L-1118 Luxembourg
RCS Luxembourg : B267225
Intra-community VAT number : LU34101152

Data protection contact : privacy@foostix.com.

2. Legal framework
The processing of personal data by Foostix is governed by:
• Regulation (EU) 2016/679 of 27 April 2016 ("GDPR") ;
• the Luxembourg Law of 1 August 2018 organising the Commission nationale pour la protection des données (CNPD) and the general data protection regime ;
• the amended Law of 30 May 2005 on electronic communications (cookies and other identifiers) ;
• the guidelines and recommendations of the Luxembourg supervisory authority (CNPD) and the European Data Protection Board (EDPB).

3. Data processed and purposes
Foostix processes your personal data only to the extent necessary to pursue the stated purposes. The data we process comes from:
you, when you create an account, place an order, leave a review or contact support ;
your device, when you use the website: we automatically collect certain technical information (IP address, device type, browser, operating system, connection parameters, anonymous session identifiers).

Below are the categories of data processed with their purposes, legal bases and retention periods:

Identification data (first name, last name, e-mail, hashed password)
Purpose: creation and management of your customer account
Legal basis : performance of contract (art. 6.1.b GDPR)
Retention : duration of the account + 3 years from last activity

Contact and delivery data (address, phone number, any delivery instructions)
Purpose: preparation, delivery and tracking of orders
Legal basis : performance of contract (art. 6.1.b GDPR)
Retention : 10 years (accounting and fiscal obligation)

Transaction data (order content, amounts, date, invoices)
Purpose: invoicing, traceability, accounting
Legal basis : fiscal and accounting legal obligation (art. 6.1.c GDPR)
Retention : 10 years from invoice

Payment data (card number, expiry)
Purpose: order payment — processed exclusively by our payment processor Stripe (PCI-DSS certified); Foostix does not store card numbers
Legal basis : performance of contract (art. 6.1.b GDPR)
Retention : in accordance with the payment processor's policy

IP address, device identifiers, connection logs
Purpose: security, fraud and abuse prevention, technical logging
Legal basis : legitimate interest (art. 6.1.f GDPR)
Retention : 13 months

Reviews and comments
Purpose: publication of reviews, service improvement
Legal basis : legitimate interest (art. 6.1.f GDPR)
Retention : as long as the content is useful for the purpose

Browsing data and cookies
Purpose: operation of the website (cart, session, language) — Foostix uses no audience measurement tool or advertising cookie
Legal basis : legitimate interest for strictly necessary cookies (Art. 6.1.f GDPR and Art. 5 §3 §2 of Directive 2002/58/EC); consent for preference cookies (Art. 6.1.a GDPR)
Retention : from 1 day to 13 months depending on the cookie (see Cookies Policy)

Contact form data
Purpose: responding to enquiries
Legal basis : legitimate interest (art. 6.1.f GDPR)
Retention : 3 years from last contact

Our website may contain links to third-party sites. This policy applies solely to the processing carried out by Foostix; we invite you to consult the privacy policies of the third-party sites you decide to visit.

4. Recipients and processors
For the purposes indicated in section 3, your data may be communicated:

4.1. For the performance of the contract and the delivery of the order:
Partner restaurant : responsible for preparation, receives the order content, your name, delivery address, phone number, any intercom instructions and the notes you entered — information necessary to prepare the order correctly and contact you if needed.
Independent courier : responsible for delivery, receives your name, delivery address, phone number, any access instructions and the order content, to the extent strictly necessary for correct delivery.

4.2. Technical service providers as processors (Art. 28 GDPR):
Technical platform operator, for ordering and application hosting, bound by a data processing agreement compliant with Art. 28 GDPR ;
Courier coordination service operator, bound by a data processing agreement compliant with Art. 28 GDPR ;
Stripe Payments Europe Ltd. (Ireland / United States) — PCI-DSS certified payment processor, acting as an independent controller for fraud prevention purposes ;
Transactional e-mail provider, established in the European Economic Area ;
Accounting advisory firm, established in Luxembourg, for keeping statutory accounts and fulfilling tax obligations.

The updated and named list of our processors, together with their respective Art. 28 GDPR agreements, is available on written request to privacy@foostix.com.

4.3. Recipients for legal obligations:
Luxembourg tax administration (AED) — DAC7 reports under Directive (EU) 2021/514 ;
• Judicial or administrative authorities, upon legally founded request.

4.4. Foostix does NOT use, on foostix.com:
• any third-party audience measurement tool (no Google Analytics, Hotjar, etc.) ;
• any third-party advertising pixel (no Meta/Facebook Pixel, no Google Ads, no Bing UET, no TikTok Pixel) ;
• any third-party cookie for advertising or profiling purposes.
This policy reflects the actual technical state on the date of publication; any future change will be subject to prior update of this policy.

5. Transfers outside the European Union
Some of our technical service providers may process data in third countries, in particular the United States (notably our payment processor). In such cases, the transfer is governed:
• by the EU-US Data Privacy Framework adequacy decision (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023), where the recipient is validly certified ; or
• by the standard contractual clauses adopted under Commission Implementing Decision (EU) 2021/914, supplemented where necessary by additional measures in accordance with the Schrems II judgment and EDPB Recommendations 01/2020.

You can obtain a copy of the applicable safeguards by writing to privacy@foostix.com.

6. Cookies and tracking technologies
Foostix uses only cookies strictly necessary for the operation of the website (session, cart, language) and functional preference cookies. We do not set any audience measurement, marketing or advertising cookie, which is why a granular consent banner is not required. The detailed and named list of cookies used is available in our Cookies Policy (foostix.com/cookies).

7. Your rights
In accordance with Articles 15-22 GDPR, you have the following rights:
• right of access to your data and to obtain a copy ;
• right of rectification of inaccurate or incomplete data ;
• right to erasure of your data in the cases provided for by Art. 17 GDPR ;
• right to restriction of processing ;
• right to portability in a structured, machine-readable format ;
• right to object to processing ;
• right to withdraw your consent at any time, without affecting the lawfulness of prior processing ;
• right not to be subject to a decision based solely on automated processing producing legal effects concerning you or significantly affecting you.

Foostix does not take decisions based solely on automated processing producing significant legal effects on you. Any decision affecting your contractual rights (e.g. account suspension or order refusal) is subject to human intervention.

To exercise your rights, write to privacy@foostix.com indicating your name, the e-mail address associated with your Foostix account and the right you wish to exercise. Your request will be processed within one month of verification of your identity, extendable by two months for complex requests (Art. 12.3 GDPR). We may request additional information to confirm your identity, strictly to the extent necessary to avoid disclosing your data to a third party (Art. 12.6 GDPR).

If you believe that your rights are not respected, you may lodge a complaint with the Commission nationale pour la protection des données (CNPD):
• address: 15 boulevard du Jazz, L-4370 Belvaux
• website: https://cnpd.public.lu

8. Service communications
Foostix does not send direct marketing communications or commercial newsletters. You will receive only the service communications strictly necessary for the performance of the contractual relationship: order confirmations, delivery status notifications, invoices and, where necessary, technical or security notices relating to your account.

Should Foostix in the future introduce commercial communications, this policy will be updated beforehand and an explicit separate consent (opt-in) will be requested, revocable at any time.

9. Security
Foostix implements technical and organisational measures to ensure the security of your data, proportionate to the risk (Art. 32 GDPR):
• encryption of communications in transit (TLS 1.2 or higher) ;
• encryption at rest of backups ;
• password hashing ;
• strict access management by profile (least privilege principle) ;
• logging of access to sensitive data ;
• regular backups and tested restoration procedure ;
• web application firewall ;
• internal breach notification procedure within the deadlines of Art. 33 GDPR.

10. Changes to this policy
Foostix may amend this policy to reflect a regulatory, technical or organisational development. Any material change will be brought to your attention via a notice on the website or, where applicable, by e-mail.

11. Contact
For any question relating to this policy:
• E-mail : privacy@foostix.com
• Postal address : Foostix Lux S.à r.l. — Privacy Service, 5, rue Aldringen, L-1118 Luxembourg