Plyx
Features Tyre hotel AI assistant Workshop screen Pricing Contact Sign in

Privacy policy

Version 1.0 of 13 September 2026 — personal data for which Plyx is the controller.

This policy explains which personal data Plyx processes on its own behalf, for what purpose, on what legal basis, for how long and with which service providers, and how to exercise your rights. It applies to visitors of the plyx.be website, to people who contact Plyx and to the users of the accounts opened by customer garages.

1. Controller

The controller is Lorry Dupont, trading as CarveStudio, publisher of the Plyx brand — CBE / VAT BE 0643.672.796 — Avenue Baron Seutin 14, 1410 Waterloo, Belgium.

For any question about your data or to exercise your rights: contact@plyx.be.

2. What this policy covers, and what it does not

It covers the processing for which Plyx itself determines the purposes and means: the website contact form, user accounts and login security, subscription billing, support tickets, security and audit logs, website audience measurement, and cookies and local storage.

It does not cover the data that garages enter into Plyx about their own customers: identity and contact details, vehicles, appointments, quotes, repair orders, invoices, signatures, payments. For that data, the garage is the controller and Plyx acts as processor within the meaning of Article 28 of the GDPR, under the data processing agreement annexed to the contract concluded with the garage — not under this policy. The same applies to information a garage records about its own staff in the application.

Are you a customer of a garage that uses Plyx? Please contact that garage with any question about your data. If you write to Plyx, your request is passed on to the garage without delay.

3. Data processed, purposes and legal bases

3.1. Contact form

  • Data: name, e-mail address and message; company and phone number if you provide them; IP address of the sender.
  • Purposes: answering your request (demo, information, migration, pricing) and, where relevant, sending you an offer; the IP address is only used to limit abusive submissions.
  • Legal bases: pre-contractual steps taken at your request (Article 6(1)(b) GDPR); Plyx's legitimate interest in answering people who contact it and protecting the form against abuse (Article 6(1)(f)).
  • Retention: three years after the last exchange. If a contract is concluded, the relevant data becomes part of the contractual relationship (section 3.3).

3.2. User accounts and login security

  • Data: name, login (usually the e-mail address), role and language; password, stored only in hashed form; for each connected device, an access token stored in hashed form, the device name and the date of last activity; if you enable two-factor authentication, which is optional, an encrypted secret key and hashed recovery codes.
  • Purposes: giving access to the platform, authenticating users, protecting accounts against unauthorised access (limited login attempts, two-factor authentication), and allowing a forgotten password to be reset through a single-use, time-limited link.
  • Legal bases: Plyx's legitimate interest in providing the garage with the service it subscribed to and securing access to it (Article 6(1)(f) GDPR); performance of the contract where the user is personally Plyx's customer (Article 6(1)(b)).
  • Retention: for the duration of the garage's subscription. A device can be signed out at any time by revoking its token; disabling two-factor authentication erases the key and the codes. When the contract ends, accounts are deleted together with the garage's data within 30 days, and backup copies are purged within 60 days.

3.3. Subscription billing

  • Data: name, address, e-mail address and VAT number of the garage; plan and options subscribed; billable usage; invoices and payments. Where the garage is run by a natural person, this data relates directly to that person.
  • Purposes: issuing, sending and following up subscription and usage invoices; keeping the accounts. Invoices are issued in the Odoo online invoicing software.
  • Legal bases: performance of the contract (Article 6(1)(b) GDPR); legal accounting and tax obligations (Article 6(1)(c)).
  • Retention: ten years for invoices and accounting records, as required by Belgian law (in particular Article 60 of the VAT Code); other billing data for the duration of the contract.

3.4. Support tickets

  • Data: name and e-mail address of the author, garage concerned, type and subject of the ticket, messages exchanged, and technical context attached automatically (screen, application version, language, browser).
  • Purposes: handling reports, questions and suggestions; notifying the author of the reply, in the application and by e-mail; fixing and improving the platform.
  • Legal basis: Plyx's legitimate interest in providing the support set out in the contract concluded with the garage and in improving its service (Article 6(1)(f) GDPR).
  • Retention: for the duration of the garage's subscription; tickets are deleted together with the garage's data when the contract ends.

3.5. Security and audit logs

To protect the platform, detect outages and attacks and be able to trace sensitive operations, Plyx keeps the following logs:

  • Server technical logs (IP address, date and time, requested address, browser): kept 14 days.
  • Platform audit log (identifier of the person, action, garage concerned, date and time, IP address, browser): administrative actions, access by Plyx support to a garage's data, logins to the administration console, tickets, and account security events (enabling or disabling two-factor authentication, use of a recovery code). It contains no data about garages' customers and no secrets. Kept one year.
  • Technical history of synchronisations (device, record type, date) and of e-mails sent by the platform (recipient, subject, date, outcome): kept for the duration of the garage's subscription.
  • Legal basis: Plyx's legitimate interest in ensuring the security, availability and traceability of its platform, in line with its security obligation (Articles 6(1)(f) and 32 GDPR).

Data held in the Plyx database is also contained in its encrypted backup copies, which are kept thirty days.

3.6. Website audience measurement

The plyx.be website measures its traffic with Matomo, installed on Plyx's own servers: no data is passed on to third parties. Measurement works without cookies or persistent identifiers, and the IP address is anonymised (truncated) before being recorded. The data collected (pages viewed, date and time, referring site, device type, operating system, browser and language) is used only to produce traffic statistics.

  • Legal basis: Plyx's legitimate interest in knowing how its website is used in order to improve it (Article 6(1)(f) GDPR).
  • Retention: 25 months for visit data; aggregated statistics, which no longer identify anyone, are kept indefinitely.

3.7. Cookies and local storage

The plyx.be website sets no cookies. If you choose a language, that choice is saved in your browser's local storage.

The Plyx application uses no advertising or audience measurement cookies. It keeps on each device only what is strictly necessary for it to work: the device's login token, display and language preferences, drafts not yet saved, a copy of the garage's data for working offline, and the application files. The workshop screen uses a single technical cookie, which keeps its access until the end of the day.

These items are strictly necessary for the service you use: they do not require your consent. You can erase them at any time in your browser settings; changes made offline and not yet synchronised would then be lost.

4. Recipients and processors

Plyx does not sell or rent any personal data and does not use it for any advertising purpose. Data is only accessible to the people who need it for the purposes described above, and to the following service providers, which act on Plyx's instructions as processors:

ProviderServiceLocation
OVH SAS (OVHcloud), 2 rue Kellermann, 59100 Roubaix, FranceHosting: production server, standby server, encrypted backup copies, contact@plyx.be mailboxEuropean Union: France (production, Gravelines) and Germany (standby, Limburg)
Brevo (Sendinblue SAS), FranceSending the platform's e-mailsEuropean Union
Mailjet SAS, FranceSending e-mails (backup service)European Union
Odoo SA, BelgiumOnline invoicing software (subscription invoices)Europe; backup copies in Europe and Canada
AnthropicArtificial intelligence features: only the content needed for the requested feature is transmittedUnited States — standard contractual clauses; not used to train its models; deleted within 30 days

Plyx may also disclose data where required by law, in particular to judicial or tax authorities, and to the professionals bound by professional secrecy who assist it (accountant, legal adviser).

5. Transfers outside the European Union

Plyx's servers and their backup copies are located in the European Union. Where a provider processes data outside the European Economic Area, the transfer relies on an adequacy decision of the European Commission or on appropriate safeguards within the meaning of Article 46 GDPR, such as standard contractual clauses. This applies to Anthropic, established in the United States (standard contractual clauses), and to Odoo's backup copies, which may be replicated in Canada (adequacy decision).

6. Security

Plyx protects data with appropriate technical and organisational measures: encryption of all exchanges (HTTPS), a database encrypted on disk, backup copies encrypted before leaving the server, passwords and tokens stored only in hashed form, optional two-factor authentication, limited login attempts, data partitioned per garage, server access by SSH key only, and an audit log. Details are set out in the service commitment.

In the event of a data breach that poses a risk to your rights, Plyx notifies the Data Protection Authority within 72 hours and informs you where required by law.

7. Your rights

You may at any time request access to your data, its rectification or erasure, or the restriction of its processing, and receive in a structured format the data you provided to us under a contract (portability). You may also object, on grounds relating to your particular situation, to processing based on Plyx's legitimate interest.

To exercise these rights, write to contact@plyx.be. Plyx replies within one month, which may be extended by two months for a complex request; you will then be informed. If there is reasonable doubt about your identity, additional information may be requested.

Some data cannot be erased while a legal obligation requires it to be kept, such as invoices. Plyx makes no decision based solely on automated processing that would produce legal effects concerning you.

8. Complaints

If you believe your data is not processed in accordance with the regulations, you may lodge a complaint with the Belgian Data Protection Authority: Rue de la Presse 35, 1000 Brussels — contact@apd-gba.be — www.dataprotectionauthority.be. You may also write to Plyx first, which will look for a solution with you.

9. Changes

This policy is updated when a processing activity or a provider changes. The current version is published on this page with its date; customer garages are informed of significant changes.

Plyx
© 2026 Plyx — Logiciel de gestion d'atelier · Home · Contact · Terms & conditions · Service commitment · Privacy policy · Customer area