Skip to content
Legal

Privacy Policy

Last updated: 16 June 2026

How Pixl SRL collects, processes and protects your personal data under the GDPR. Your rights, our sub-processors, and EU data hosting explained.

This document is provided for information purposes. It is not legal advice. Have it reviewed by qualified counsel before relying on it.

This Privacy Policy describes how Pixl SRL collects, processes and protects personal data in connection with the use of the Feen service. It is written in accordance with the General Data Protection Regulation (GDPR, EU 2016/679) and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data. This document is provided for information purposes; for any queries about your rights, contact us at contact@feen.be.

1. Data controller

The data controller is Pixl SRL, a Belgian private limited company, registered with the Crossroads Bank for Enterprises under number BE 0805.449.693, with its registered office in Brussels, Belgium. You may contact us at any time at contact@feen.be.

2. Categories of data collected

We collect and process the following categories of data: (i) account data (first name, last name, business email, hashed password, job title, VAT number and company name); (ii) financial documents and supporting documents you upload (invoices, expense notes, receipts) and metadata automatically extracted by OCR and AI; (iii) bank connection data via PSD2 (bank name, masked account identifiers, transaction descriptions and amounts) — we never store your banking credentials; (iv) public company data retrieved from the Crossroads Bank for Enterprises; (v) telemetry and usage data (pages visited, features used, technical logs), aggregated where possible; (vi) payment data processed exclusively by Stripe — Pixl never stores your card or bank details.

3. Purposes and legal bases for processing

Data is processed for the following purposes: (a) performance of the contract — provision of the Service, support and billing (GDPR Art. 6.1.b); (b) compliance with legal obligations, in particular accounting and tax obligations (GDPR Art. 6.1.c); (c) legitimate interest — improving and securing the Service, preventing fraud, producing anonymous usage statistics (GDPR Art. 6.1.f); (d) consent — non-essential marketing communications and non-strictly-necessary analytics cookies (GDPR Art. 6.1.a). Consent may be withdrawn at any time without prejudice to prior processing.

4. Retention periods

Accounting documents and related data are retained for ten (10) years in accordance with Article III.86 of the Belgian Code of Economic Law. Account data is retained for the duration of use and deleted, on request, within thirty (30) days, subject to legal retention obligations. Marketing data is retained for a maximum of three (3) years after the last contact. Technical logs are purged after twelve (12) months.

5. Recipients and sub-processors

We use carefully selected sub-processors bound by GDPR-compliant data processing agreements (DPAs). Our main sub-processors are: Stripe Payments Europe Ltd (Ireland) — subscription payment processing; PostHog Inc. (EU hosting) — product analytics and telemetry; Google Ireland Ltd — Google Analytics (acquisition and traffic measurement); Brevo (SAS Sendinblue, France) — transactional and marketing email delivery; Sentry (Functional Software Inc.) — application error monitoring; Netlify Inc. — hosting of the feen.be marketing site (European infrastructure available); Recommand.eu — certified Peppol Access Point for electronic invoicing; licensed PSD2 providers — secure bank connection. Your data may also be shared with your chartered accountant, if you explicitly choose to do so from your customer area.

6. International transfers

Our data is hosted and processed primarily within the European Economic Area (EEA). Where a sub-processor outside the EEA is exceptionally involved, Pixl ensures that the transfer is covered by Standard Contractual Clauses (SCCs) adopted by the European Commission, or by any other legally appropriate mechanism.

7. Your rights

You have the following rights over your data: right of access, right to rectification, right to erasure ("right to be forgotten"), right to data portability, right to restriction of processing, right to object, right to withdraw consent at any time, and right to give instructions regarding your data after your death. To exercise these rights, contact us at contact@feen.be; we will respond within one (1) month. You also have the right to lodge a complaint with the Belgian Data Protection Authority (see section 11).

8. Cookies

The use of cookies and similar technologies on the feen.be site is described in our Cookies Policy, available at feen.be/cookies. You can change your choices regarding non-essential cookies at any time from the consent banner or your browser settings.

9. Security measures

Pixl implements appropriate technical and organisational measures to protect your data: encryption in transit via TLS 1.2+, encryption at rest for databases and files, role-based access controls (RBAC), two-factor authentication for administrator access, audit logs, regular security reviews and penetration tests. In the event of a data breach likely to result in a high risk to your rights and freedoms, you will be notified without undue delay in accordance with Article 34 GDPR.

10. Privacy officer contact

For any questions relating to the protection of your personal data, contact our privacy officer at contact@feen.be. In the absence of a formally designated Data Protection Officer (DPO), this address centralises all GDPR requests and handles them within legal deadlines.

11. Supervisory authority

You have the right to lodge a complaint with the Belgian Data Protection Authority (APD/GBA), Rue de la Presse 35, 1000 Brussels, Belgium. Phone: +32 2 274 48 00. Email: contact@apd-gba.be. Website: www.dataprotectionauthority.be. This does not preclude any judicial remedy.

12. Changes to this policy

We may update this Privacy Policy to reflect technical, legal or operational changes. Any material change will be notified to you by email or via the Service at least thirty (30) days before it takes effect.