Privacy policy
Last updated: September 2026
1. Who we are
Frixxion ("we", "us") provides messaging infrastructure and a CPaaS platform. Our registered office is Minderbroedersstraat 6, 8700 Sint-Truiden, Belgium. This policy explains what personal data we process, on what legal basis, and what rights you have under the General Data Protection Regulation (EU) 2016/679 (GDPR). It applies to our website and services. For privacy questions, contact privacy@frixxion.com.
2. Controller and processor roles
We act as controller for data about our website visitors, prospects, customer contacts and job applicants. When our customers send messages through our platform, they are the controller of their end-user data and we act as their processor under a data processing agreement (Art. 28 GDPR). End users should direct requests to the business that messaged them; we will forward or assist as instructed.
3. Data we process
Contact and account details you provide (name, business email, phone, company, role); message traffic data required to deliver and bill traffic (sender and recipient number, timestamps, routing, delivery status, and message content for the period needed to deliver it); technical data such as IP address, device and browser information and logs; and billing data. We collect only what is necessary for the purposes below.
4. Purposes and legal bases
Delivering and routing messages and providing the platform: performance of a contract (Art. 6(1)(b)). Security, fraud and abuse prevention, service improvement and direct business communication with existing customers: our legitimate interests (Art. 6(1)(f)), balanced against your rights. Invoicing, accounting, and lawful requests from authorities or regulators: legal obligation (Art. 6(1)(c)). Marketing email to prospects: consent (Art. 6(1)(a)), which you can withdraw at any time without affecting processing carried out before withdrawal. This website sets no non-essential cookies at all, so there is nothing here we ask you to consent to; if that ever changes we will ask first, on the same basis (see section 11). We do not sell personal data.
5. End-user consent and opt-out
Customers sending messages through Frixxion are responsible for having a valid legal basis and, where required, prior consent from their recipients. Our platform provides tools to capture, record and honour consent, and to process opt-out and STOP requests across every channel.
6. Recipients and sub-processors
We share data with mobile network operators and messaging aggregators to the extent needed to deliver your traffic, with channel providers such as WhatsApp, Viber and RCS operators, and with vetted suppliers for hosting, monitoring, support and payment processing. Each sub-processor is bound by a written agreement with confidentiality and security obligations. A current list of sub-processors is available on request and changes are notified in advance to platform customers.
7. International transfers
Our platform is hosted entirely within the European Economic Area, in data centres in Ireland, Germany, Austria and Finland. Message delivery is global by nature, so traffic data may be transmitted to operators outside the EEA to reach the destination network. Where we transfer personal data outside the EEA, we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses together with any additional safeguards the transfer requires. A copy of the relevant safeguards is available on request.
8. Retention and erasure
We keep personal data only as long as necessary for the purpose it was collected for. Message content is retained for the period configured by the customer and deleted afterwards; traffic and billing records are kept for the statutory accounting period (seven years in Belgium); account data is deleted after the contract ends, subject to legal retention duties. The platform supports content and identity erasure so personal data can be deleted on request.
9. Job applicants
When you apply for a role, through the form on this site or as an open application, we process the details you give us: your first and last name and your email address, and — only if you choose to provide them — your phone number, location, earliest start date, a link to a portfolio or profile, and whatever you write in the motivation field. If you attach a CV we store the file itself. We also record which role you applied for and the moment you gave consent. Our legal basis is that consent (Art. 6(1)(a)), given by the checkbox on the form; you can withdraw it at any time by emailing privacy@frixxion.com, and withdrawal does not affect processing carried out beforehand. Applications are read only by the Frixxion staff involved in hiring: access is restricted by role in the system we use to publish this site, a CV is never published at a public or guessable address, and downloading one requires both a short-lived signed link and that permission. We do not send applications to anyone outside Frixxion, we do not use them for marketing or profiling, and no automated decision is made about you — a person reads every application. We keep an application and its CV for twelve months from the day you submit it, after which the record and the file are both deleted automatically. Ask us sooner at privacy@frixxion.com and we will delete them, or send you a copy of what we hold, within one month (see section 13). We check submissions for automated abuse, which uses your IP address at the moment you submit but does not store it with your application. Please do not include special categories of data — health, religion, political opinions, trade union membership — in your CV or your motivation: we do not ask for them and do not need them.
10. Security
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), including encryption in transit, access control on a need-to-know basis, network segregation, logging and regular testing. In the event of a personal data breach we notify the competent supervisory authority within 72 hours where required, and affected customers without undue delay.
11. Cookies
We use two cookies and no others, both strictly necessary to run the site. One protects our contact and application forms against cross-site request forgery (.AspNetCore.Antiforgery); it is set only when you open one of those forms, and your browser discards it when you close it. The other keeps Frixxion staff signed in to the system we use to publish this site (FrixxionWebsite2026.CmsAuth), and is never set for ordinary visitors. Both are exempt from the consent requirement in Article 5(3) of the ePrivacy Directive, because the site cannot do what you asked of it without them — which is why we do not ask you to accept cookies. We set no analytics, advertising or tracking cookies, we embed no third-party content, and we store nothing else on your device. Nothing about your visit is shared with anyone for advertising or measurement. If we ever introduce a non-essential cookie we will ask for your consent before setting it.
12. Automated decision-making
We do not carry out automated decision-making producing legal or similarly significant effects on individuals. Automated filtering is used for spam and fraud detection on traffic, and is reviewed by our team.
13. Your rights
You have the right to access your personal data, to have it rectified or erased, to restrict or object to processing (including profiling and direct marketing), to data portability, and to withdraw consent at any time. Write to privacy@frixxion.com and we will respond within one month, extendable by two months for complex requests. You may also lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels) or with the supervisory authority of your country of residence.
14. Changes to this policy
We update this policy when our processing changes. The date above shows the current version, and material changes are communicated to customers before they take effect. Questions? Email privacy@frixxion.com.