Privacy Policy
PRIVACY AND COOKIE POLICY
Fluff Bedding
Last updated: May 31, 2026
1. Identity of the data controller
Fluff Bedding (hereinafter "Fluff Bedding", "we", "us" or "our") respects your privacy and processes personal data in accordance with the European General Data Protection Regulation (GDPR) and applicable Belgian privacy legislation.
Data Controller
Company name: Fluff Bedding
Address: Driekerkenstraat 75
Postal code and city: 8501 Bissegem (Please note: no visiting address)
Company number: BE0780889293
Email: hello@fluffbedding.be
2. What personal data do we collect?
Depending on your interaction with our website or services, we may process the following personal data:
Identification data
- First and last name
- Company name
- Billing and shipping address
- Email address
- Phone number
Financial data
- Billing information
- Payment status
- Transaction data
Note: Fluff Bedding never stores full credit card details. Payments are processed via certified payment providers.
Website data
- IP address
- Browser data
- Device data
- Cookie identifiers
- Browsing behaviour on our website
Communication data
- Contact form submissions
- Email traffic
- Customer service requests
- Social media messages
Marketing data
- Newsletter subscriptions
- Marketing preferences
- Newsletter open and click behaviour
3. Purposes of processing
We process personal data solely for legitimate purposes.
Performance of agreements
For:
- Order processing
- Product delivery
- Customer service
- Warranty handling
- Return processing
Legal basis: performance of the agreement.
Legal obligations
For:
- Accounting
- Invoicing
- Tax obligations
- Fraud prevention
Legal basis: legal obligation.
Direct marketing
For:
- Newsletters
- Promotions
- Product updates
- Personalised offers
Legal basis: consent or legitimate interest in accordance with applicable legislation.
You can always unsubscribe via the unsubscribe link in each newsletter.
Website analysis and optimisation
For:
- Website usage analysis
- Performance measurement
- Improving user experience
Legal basis: consent for analytical cookies.
4. Retention periods
We do not retain personal data longer than necessary.
| Data type | Retention period |
|---|---|
| Customer data | Up to 10 years after last purchase |
| Invoices | 10 years |
| Contact requests | 2 years |
| Newsletter data | Until unsubscribe |
| Cookie data | Maximum 13 months |
If legal obligations require a longer retention period, these will be complied with.
5. Recipients of personal data
Your data may be shared with carefully selected service providers.
Examples:
- Hosting providers
- Payment providers
- Accounting software
- Shipping companies
- Email marketing platforms
- IT service providers
These parties only receive the data necessary for their services.
6. International data transfer
If personal data is processed outside the European Economic Area (EEA), this will only occur:
- to countries with an adequate level of protection;
- or via approved standard contractual clauses of the European Commission.
7. Security
We take appropriate technical and organisational measures, including:
- SSL/TLS encryption
- Access control
- Strong password protection
- Regular software updates
- Backups
- Limited access to personal data
8. Your rights
You have the following rights:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object
- Right to withdraw consent
Requests can be addressed to:
[Insert email address]
We will respond to requests within one month.
9. Complaints
If you are not satisfied with the processing of your personal data, you can file a complaint with:
Data Protection Authority
Drukpersstraat 35
1000 Brussels
Belgium
COOKIE POLICY
What are cookies?
Cookies are small text files stored on your device when you visit our website.
Which cookies do we use?
Essential cookies
These are necessary for:
- Shopping cart functionality
- Security
- Website operation
These cookies do not require consent.
Functional cookies
These remember:
- Language settings
- User preferences
- Login status
Analytical cookies
These help us understand:
- Visitor behaviour
- Page performance
- Website improvements
Example:
- Google Analytics (if used)
Marketing cookies
These may be used for:
- Personalised advertisements
- Remarketing
- Social media integrations
Examples:
- Meta Pixel
- Google Ads
- TikTok Pixel
These cookies are only placed with your consent.
Cookie management
Upon your first visit, you will receive a cookie banner where you can manage your preferences.
You can change or withdraw your consent at any time.
NEWSLETTER POLICY
When you subscribe to our newsletter:
- we ask for explicit consent;
- we record the date, time, and source of subscription;
- we store your email address as long as you remain subscribed.
You can unsubscribe at any time via the unsubscribe link at the bottom of each newsletter.
After unsubscribing, your data will be deleted or anonymised, unless a statutory retention obligation applies.
PROCESSOR AGREEMENT (TEMPLATE)
This agreement is between Fluff Bedding ("Controller") and any external service provider ("Processor").
Subject Matter
The Processor shall process personal data solely on behalf of Fluff Bedding.
Processor's Obligations
The Processor:
- processes personal data only according to written instructions;
- ensures confidentiality;
- takes appropriate security measures;
- reports data breaches without undue delay;
- does not engage sub-processors without consent;
- supports Fluff Bedding with GDPR obligations.
Security
The Processor shall take appropriate technical and organisational measures to protect personal data against:
- loss;
- unauthorised access;
- destruction;
- alteration.
Termination of Agreement
Upon termination of services, the Processor shall:
- delete all personal data; or
- return it to Fluff Bedding,
unless legal obligations stipulate otherwise.
DATA BREACH PROCEDURE
In case of a suspected data breach:
- Register incident.
- Conduct risk analysis.
- If required, notify the Data Protection Authority within 72 hours.
- Inform data subjects if there is a high risk.
- Take corrective measures.
- Document incident.