← Back to home

Privacy and Personal Data Protection Policy

Procedures for the collection, processing, securing, and retention of your personal data, in compliance with the GDPR and the Belgian law of July 30, 2018.

Last updated : August 26, 2026

This English version is provided for convenience. In case of discrepancy, the French version prevails.

Article 1: Preamble and Scope

This Privacy Policy is intended for visitors to the website operated under the MASSIV brand (hereinafter the "Site"), as well as for prospects and clients (hereinafter "Users" or "You") subscribing to the web design, brand design, SEO, and hosting services offered by Seventh Trade SRL.

It sets out in a strict and exhaustive manner the procedures for the collection, processing, securing, and retention of Personal Data, in full compliance with Regulation (EU) 2016/679 of April 27, 2016 (hereinafter "GDPR") and the Belgian Law of July 30, 2018, on the protection of natural persons with regard to the processing of personal data.

This document is distinct from our General Terms and Conditions of Sale (GTCS) and our Cookie Management Policy.

Article 2: Identity of the Data Controller

Within the meaning of Article 4.7 of the GDPR, the Data Controller who determines the purposes and means of data processing is:

  • Company name: Seventh Trade SRL (operating the commercial brand MASSIV)
  • Legal form: Private Limited Liability Company (SRL) under Belgian law
  • Registered office: Rue Hautmont 40, 4990 Lierneux, Belgium
  • Company Number (BCE) / VAT: BE1006544056
  • Data Protection Contact Point: hello@massiv.digital

Article 3: Categories of Data Collected

In the context of operating the Site and providing our services in the SaaS/WaaS (Website as a Service) model, Seventh Trade SRL collects and processes the following categories of data, in accordance with the principle of data minimization (Art. 5.1.c GDPR):

  • Identification and Contact Data: Surname, first name, professional or personal email address, telephone number, postal address of the registered office or residence.
  • Language Preferences: We store your choice of language (French or English) via the massiv-lang cookie to personalize your navigation and issue our communications (emails, invoices) in the language of your choice.
  • Professional Project-Related Data: Company name, company/VAT number, position, business sector, URL of the existing website, links to social networks, project description, technical constraints, and deadlines.
  • Transaction and Billing Data: Invoice history, payment methods, partial bank details. Full processing of credit cards is outsourced to our PCI-DSS certified partner, Stripe. Seventh Trade SRL does not store any credit card numbers in plain text on its servers.

Article 4: Purposes of Processing and Legal Bases (Art. 6 GDPR)

Your data is only processed for specific, explicit, and legitimate purposes. Each processing operation is based on a strict legal basis:

  • Management of Contact Requests and Quotes (technical audit, requirement qualification, response to inquiries) — identification, contact, and professional data — Art. 6.1.b: execution of pre-contractual measures at the request of the data subject.
  • Contract Execution and Subscription Management (site creation, maintenance, technical support, updates, sending invoices in the chosen language) — identification, contact, professional, technical, and linguistic data — Art. 6.1.b: execution of a contract to which the data subject is a party.
  • Billing and Compliance with Accounting Obligations (issuing invoices, bookkeeping) — identification, transaction, and billing data — Art. 6.1.c: compliance with a legal obligation (Belgian accounting law).
  • Site Security and Fraud Prevention (detection of attacks, blocking malicious requests) — technical and navigation data (logs) — Art. 6.1.f: legitimate interest of Seventh Trade SRL in securing its network infrastructure.
  • Continuous Service Improvement and Loyalty (sending information on platform developments, SEO tips) — identification and contact data — Art. 6.1.f: legitimate interest, with the right to object at any time.

Article 5: Data Recipients and Processors

Within the limits of their respective duties, the following may have access to your data:

  • Authorized internal staff of Seventh Trade SRL, subject to a strict confidentiality obligation.
  • Our technical processors, acting on our documented instructions (Art. 28 GDPR), selected for their compliance guarantees:
  • Stripe: Payment infrastructure, subscription management, and billing.
  • Lovable: Hosting of the front-end web infrastructure.
  • Supabase: Hosting of the relational database and authentication.

Prohibition of Resale: Seventh Trade SRL formally prohibits renting, selling, or transferring your personal data to data brokers or third parties for commercial prospection purposes.

Article 6: Data Transfers Outside the European Economic Area

The Cloud services used by Seventh Trade SRL (notably Lovable, Supabase, and Stripe) rely on global infrastructures that may involve data transfers outside the European Union, particularly to the United States. To ensure the legality of these transfers, Seventh Trade SRL ensures that:

  • The provider adheres to the Data Privacy Framework (EU–US data protection framework validated by the European Commission).
  • Failing that, the provider has signed the Standard Contractual Clauses (SCC) of the European Commission, accompanied by additional technical security measures (encryption).

Article 7: Retention Periods (Art. 5.1.e GDPR)

Your data is kept for the time strictly necessary to achieve the aforementioned purposes, increased by the legal limitation periods applicable in Belgium:

  • Prospects (non-converted requests): 3 years from the last incoming contact.
  • Clients (data related to subscription and service): for the duration of the contractual relationship, then intermediate archiving for 5 years (common law limitation period for contractual liability).
  • Billing and Accounting Documents: 10 years from the end of the relevant financial year, in application of Belgian tax and accounting law.
  • Technical and Security Logs: erasure or anonymization after 6 rolling months.

Article 8: Security Measures and Breach Protocol

In accordance with Article 32 of the GDPR, Seventh Trade SRL implements robust technical and organizational measures to protect your data against alteration, destruction, or unauthorized access, including:

  • Encryption of data flows via SSL/TLS (HTTPS) protocols.
  • Hosting of databases in isolated and secure environments (Supabase).
  • Application of the principle of least privilege for access to client databases.

Breach Notification (Art. 33 and 34 GDPR): In the event of a security breach leading to a personal data violation likely to result in a high risk for your rights, Seventh Trade SRL undertakes to notify the Data Protection Authority (DPA) within 72 hours and to inform you as soon as possible.

Article 9: Your Rights and How to Exercise Them

The GDPR grants you fundamental inalienable rights over your personal data (Art. 15 to 22):

  • Right of Access: Obtain confirmation that your data is being processed and obtain a copy.
  • Right of Rectification: Demand the correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request the deletion of your data, unless a compelling legal reason obliges us to keep it (e.g., invoices).
  • Right to Restriction of Processing: Freeze the use of your data during the resolution of a dispute.
  • Right to Portability: Receive your data in a structured and machine-readable format to transmit it to another provider.
  • Right to Object: Object at any time to processing based on our legitimate interest, particularly for commercial solicitations.

How to Exercise: You can exercise all these rights by sending a clear request to hello@massiv.digital or by post to the registered office (Rue Hautmont 40, 4990 Lierneux). In accordance with the law, a response will be provided within a maximum of 30 days. In case of reasonable doubt about the identity of the requester, proof of identity may be required.

Article 10: Cookie Management

The use of trackers and cookies (analytical, marketing, or functional) is the subject of separate documentation, in accordance with the ePrivacy Directive. We notably use the massiv-lang cookie to remember your language preference. We invite you to consult our Cookie Management Policy to set your preferences.

Article 11: Recourse to the Supervisory Authority

If you believe, after contacting us, that your rights are not being respected or that Seventh Trade SRL's processing system does not comply with data protection rules, you have the right to lodge a complaint with the competent Belgian supervisory authority:

  • Data Protection Authority (DPA)
  • Rue de la Presse 35, 1000 Brussels, Belgium
  • Tel: +32 (0)2 274 48 00
  • Email: contact@apd-gba.be
  • www.dataprotectionauthority.be