Privacy Policy — Alestra

Privacy Policy – Alestra (trade name of Selix bv)

Last updated: 7 July 2026

Language: NL · EN · FR · DE

1. Identity

Alestra is a trade name of Selix bv.

Selix bv
Heirbaan 13
2243 Zandhoven, Belgium
BE1038310269
E-mail: info@alestra.be

In this privacy policy, “Alestra”, “we”, “us” and “our” refer to Selix bv, trading under the name Alestra.

2. Scope

This privacy policy applies when you:

This privacy policy applies to all current and future applications and services offered by Selix bv under the Alestra brand.

3. Roles under the GDPR

Selix bv (trading as Alestra) develops and operates multiple software applications and services, including Shopify apps that support merchants with administrative, reporting and operational processes.

Depending on the specific application, functionality and configuration, Alestra may act as a processor and/or as a controller within the meaning of the GDPR.

3.1 When Alestra acts as a processor

For processing activities in which personal data of a merchant’s customers or users are processed on behalf of and according to the instructions of that merchant, Alestra acts as a processor. This includes, among others (but is not limited to):

In these cases the merchant is the controller and the processing is governed by a separate Data Processing Agreement (DPA).

3.2 When Alestra acts as a controller

For certain processing activities, Alestra independently determines the purpose and means and acts as a controller. This includes, among others (but is not limited to):

3.3 Who should a data subject contact?

4. What personal data do we process?

A. Data from Shopify (app)

Depending on the configuration and app functionality, we mainly process the data needed to produce the statutory daily sales register (dagontvangstenboek):

Shopify’s raw data stream may contain customer identifiers (such as name, address or VAT number). We minimise this data, use it only insofar as necessary to compile the daily sales register per VAT rate, and do not maintain a standalone customer profile. The generated register is an aggregated record of receipts per VAT rate per calendar day.

We do not process full payment card details or other sensitive payment information.

B. Merchant data (website, sales, support)

5. Sources of personal data

We receive personal data:

6. Purposes and legal bases

We process personal data only where there is a valid legal basis and always in accordance with applicable data protection legislation.

6.1 App service delivery (merchant is controller, Alestra is processor)

Purposes. Personal data are processed in order to provide, configure and operate our applications and services, including, depending on the specific application and chosen functionality, among others:

Legal basis (merchant). Processing takes place on the legal basis determined by the merchant, such as: performance of a contract with the data subject; compliance with a legal obligation; the legitimate interest of the merchant.

Alestra’s role. In this context Alestra acts as a processorand processes personal data solely on behalf of and according to the merchant’s instructions, as set out in the Data Processing Agreement (DPA).

6.2 Alestra’s own purposes (Alestra is controller)

Alestra also processes personal data for its own legitimate business purposes, including:

We do not use personal data for unsolicited marketing communications unless there is a valid legal basis or prior consent.

7. Retention periods

We apply retention periods that are as limited as possible:

8. Recipients and sharing of data

We share personal data only with parties necessary for our service delivery, such as:

These parties act as (sub)processors and are contractually bound by confidentiality and security.

An up-to-date list of subprocessors is available on request via info@alestra.be.

9. Transfers outside the EEA

If personal data are processed outside the European Economic Area, we do so only with appropriate safeguards, such as:

Where relevant, we provide additional information about the transfer mechanism on request.

10. Security

We take appropriate technical and organisational measures, including (non-exhaustively):

11. Cookies and similar technologies

Our applications and website use only functional cookies and similar technologies that are necessary for the correct operation and security of the services.

These cookies are used to, among other things, manage sessions, authenticate users and enable the technical operation of the application.

As these cookies are strictly necessary, no consent is required for them under applicable legislation on electronic communications and data protection.

We do not use marketing, tracking or analytics cookies without prior consent.

12. Automated decision-making

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, unless otherwise stated in specific documentation.

13. Your rights

Depending on the situation, you have the right to:

How to exercise them?

Send a request to info@alestra.be with sufficient information to verify your identity.

Important: for requests concerning shop end-customer data (orders/customer data), you should generally turn to the merchant (the store), as the merchant is the controller.

We respond within one month at the latest, unless the GDPR permits an extension.

14. Complaints (Belgium)

You may lodge a complaint with the supervisory authority:

Data Protection Authority (Gegevensbeschermingsautoriteit, GBA)
Drukpersstraat 35, 1000 Brussels, Belgium
www.gegevensbeschermingsautoriteit.be

15. Changes

We may amend this privacy policy. The most recent version is available via our website and/or in the app.

16. Contact

Questions or requests: info@alestra.be