Protecting Users' privacy is a fundamental commitment for Takion. This Privacy Policy describes how personal data is collected, used, retained and protected in connection with the Gunbix service, pursuant to Regulation (EU) 2016/679 (hereinafter the "GDPR") and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
The controller is:
TAKION SRL A private limited liability company incorporated under Belgian law Rue Mansart 39/A, 7534 Tournai (Belgium) Company number: 1014.464.305 Represented by Giannino Cuignet, managing director
Dedicated data protection contact: privacy@takion.be
Takion is not legally required to designate a Data Protection Officer (DPO) within the meaning of Article 37 GDPR, as its activity falls within none of the situations listed in that provision. The controller directly performs the function of point of contact for data protection matters and can be reached at privacy@takion.be. This assessment is reviewed annually, and whenever the processing operations change substantially. Should a DPO be designated, this will be announced on this page.
For one specific part of the Service, Takion is not the controller.
Where you are a member of a Club and that Club uses Gunbix to track the documents it requires of its members (membership fee, medical certificate, criminal record extract or certificate of good conduct, federation licence, sport shooting licence), it is the Club that is the controller. It decides which documents it requires, it examines them, and it draws the consequences. Takion is then only the processor within the meaning of Article 28 GDPR: it supplies the tool, it stores, it serves and it erases, on the Club's instructions.
What this means for you in practice:
A data processing agreement governs what Takion may do with that data on the Club's behalf. It can be consulted at https://gunbix.com/en/dpa.
For everything else (your account, your profile, your firearms, your sessions, your sign-in history), Takion remains the controller, and it is Takion that you should contact.
Two situations put your data into Gunbix without your having asked for anything. In both, it is the club that is the controller and Takion is only its processor, as in Article 1.1.
You have shot at a range as a visitor or as a one-day shooter. The club has a legal obligation to keep a register of every person who shoots there: this is Article 3, 4° of the Royal Decree of 13 July 2000 on the approval of shooting ranges, and that text requires the register to be retained for ten years. The club records your surname, your first name, the type and calibre of the firearm used, your exact arrival and departure times and the member who accompanied you. It also records your date of birth and your nationality, in order to verify that you are of age and to apply the rule limiting unlicensed practice to one visit per calendar year; those two items are erased automatically after twenty-four months, the register entry itself remaining in place. Nobody other than those responsible for the club sees them, except on inspection by the authority that approved it.
Your address, and why it is asked of only some people. The register itself does not require it: the Royal Decree of 16 October 2008 removed that particular from Article 3, 4°. It does however remain required on the day card, the document the club draws up for a person shooting without holding a sport shooter's licence or a possession authorisation: Article 5, third paragraph, 1° of the same decree requires it to bear "the name and address of the occasional shooter", and the club sends a copy to the governor of your province within seven days. Your address is therefore requested only if you shoot under that regime. If you come with your own licence, it is not.
Your club has migrated its membership file from earlier software. Your record - identity, contact details, membership number, federation number, history of your visits - was transferred into Gunbix by decision of your club. Three families of information were filtered out automatically before any recording and never enter: your national register number, any reference to a criminal record extract, any reference to a medical certificate. Nor is your photograph retained.
In both cases:
The categories of data processed in connection with the Service are as follows.
The Service creates, receives and retains no password. Authentication is carried out by means of a single-use code sent to the User's email address, valid for ten minutes and limited to five attempts, compared in constant time. Once verified, the Service issues a session token which the application presents on each request in the Authorization header; that token is never placed in a cookie. A session lasts thirty days at most, its expiry is absolute and is not extended by use, and it may be revoked from any of the User's devices with effect for all of them.
What the date of birth is used for. To verify the minimum age of access to the Service, set at sixteen (16), and to apply the legal restrictions specific to minors: inability to declare a personal firearms inventory, additional documents required in a minor candidate's licence file, absence of commercial communications.
Who sees it. The User themselves. The Club sees it only in the context of a licence file, and only if the User has given identity consent bounded to that file: a versioned consent, revocable at any time, limited to the fields it enumerates. Club staff may confirm the date of birth when they examine the identity card the User presents to them; neither the card nor its national register number enters the Service.
For how long. The date of birth follows the retention regime of the other profile data, set out in Article 8.
Takion neither processes nor stores payment card numbers directly. That data is processed exclusively by Stripe Payments Europe Limited, a PCI DSS Level 1 certified provider.
Position as at 30 August 2026. No Paid Offer is open: billing is disabled in the Service, no payment is collected and no payment data is processed. The elements above describe the processing as it will apply when the paid offerings open, which will be the subject of prior notice.
The Service contains no messaging between Users. The messaging that existed until 30 July 2026 was removed along with the infrastructure that carried it; no data from that processing remains, and no direct exchange feature between Users is offered.
The processing of this data is subject to the User's prior and revocable consent.
Two very different things hide behind the expression "email tracking". This Policy keeps them separate, because the law treats them separately.
What is measured: delivery. When the Service sends you an email, it retains the fact that it was handed over for delivery, the technical identifier assigned to it by the sending provider, and the outcome given to it by your provider's mail server: accepted, permanently rejected (address does not exist or mailbox closed), temporarily rejected, or reported as spam. That information is reported by mail servers, in the course of delivering the message. It does not say whether you opened the email, nor when, nor from which device, nor what you clicked on.
It serves three purposes and no others: knowing that a deadline reminder never arrived, ceasing to write to an address that no longer exists, and preserving the sending reputation on which the arrival of your sign-in codes in your inbox rather than your spam folder depends.
What is not measured: reading. The Service's emails currently contain no tracking pixel, no remote image and no link rewritten to count clicks. Takion does not know whether you open its messages, when, how many times, or from where.
If that were to change. A tracking pixel is not an innocuous statistic: it is a resource that your mail software fetches from a server at the moment you display the message, thereby signalling that you have read it. As such it falls under Article 5(3) of Directive 2002/58/EC (the "ePrivacy" Directive), transposed into Belgian law by Article 10/2 of the Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, on the same footing as a cookie. It therefore requires prior, freely given, specific, informed and revocable consent. The same applies to a link rewritten in order to measure clicks.
Three rules will apply, in this order, on the day such measurement is introduced:
The absence of consent to read tracking has no consequence for the Service: the same emails are sent, with the same content.
| Purpose | Legal basis | Categories of data concerned |
|---|---|---|
| Creation and management of the user account | Performance of the contract (Art. 6(1)(b) GDPR) | Identification, profile, connection |
| Verification of the minimum age of access to the Service (16) and application of the legal restrictions specific to minors | Performance of the contract + legal obligation (Art. 6(1)(b) and (c), Act of 8 June 2006) | Date of birth |
| Provision of the features of the Service | Performance of the contract | Profile, sporting practice, communication |
| Management of subscriptions and billing | Performance of the contract + legal obligation (Art. 6(1)(b) and (c)) | Account, payment |
| Accounting and tax retention | Legal obligation (Art. 6(1)(c), VAT Code, Companies Code) | Billing data |
| Security of the Service, prevention of fraud and abuse | Legitimate interests (Art. 6(1)(f)) | Connection, technical |
| Responding to support requests | Performance of the contract | Account, communications |
| Communication of information relating to the Service | Performance of the contract | Email address |
| Measurement of the delivery of emails sent by the Service (handover, acceptance, rejection, spam report) | Performance of the contract (Art. 6(1)(b)) for emails owed to a User under the Service; legitimate interests (Art. 6(1)(f)) for the message sent to an address without an account, the purpose being to avoid writing to an invalid address and to preserve the deliverability of sign-in codes | Email address, technical identifier of the message, delivery event and its timestamp |
| Measurement of the reading of emails (opens, clicks) - not implemented to date, see Article 2.8 | Consent (Art. 6(1)(a) GDPR, and Art. 5(3) of Directive 2002/58/EC as transposed by Art. 10/2 of the Act of 30 July 2018) | Not applicable to date |
| Sending marketing communications (adult accounts only) | Consent (Art. 6(1)(a)) | Email address, date of birth |
| Improvement of the Service through telemetry | Consent (Art. 6(1)(a)) | Telemetry |
| Moderation of illegal content | Legal obligation (Regulation (EU) 2022/2065) + legitimate interests | User content |
| Legal defence and establishment of rights | Legitimate interests (Art. 6(1)(f)) | All relevant categories |
| Tracking of documents required by a Club of its members (Takion as processor, see Art. 1.1) | Performance of the membership contract (Art. 6(1)(b)) and legal obligation of the Club (Art. 6(1)(c)); for the medical certificate, explicit consent (Art. 9(2)(a)) | Identification, documents, health (Art. 5.2) |
The legitimate interests pursued by Takion (security of the Service, prevention of abuse, defence of rights) have been the subject of a documented balancing exercise against the rights and freedoms of Users, which can be provided on request to privacy@takion.be.
The date of birth is requested at registration. It is mandatory, and it is what makes the following rule applicable: until now, age being collected nowhere, that rule could not be implemented.
The Service is open to persons aged sixteen (16) years or over. This threshold is a decision of Takion's, more protective than the legal minimum. In Belgium, the age at which a minor may consent alone to the processing of their data is thirteen (13): Article 8 GDPR sets sixteen as the default but allows Member States to go down to thirteen, and the Act of 30 July 2018 exercised that option. Takion applies sixteen in view of what the Service gives access to: practice regulated by firearms law, inventory, licence files.
An account whose declared date of birth corresponds to a person under the age of sixteen (16) cannot be created. If such an account already exists, or if the date is subsequently corrected, the account is suspended and then deleted together with the data attached to it, save where retention is legally required.
If the date is wrong. A User whose date of birth has been entered incorrectly may contest it and request its rectification at privacy@takion.be, providing any relevant evidence. The suspension is lifted if the rectification is established.
Accounts declared as minors (under eighteen). No communication of a commercial or promotional nature is sent to them, whatever the state of the consent recorded; only communications necessary for the operation of the Service reach them. Nor can these accounts declare a personal firearms inventory, the Act of 8 June 2006 rendering inadmissible an application for a possession authorisation made by a minor (Article 6 of the Terms of Use).
The fourteen or fifteen year old candidate in an Olympic discipline has no Gunbix account: their licence file is opened and held by their Club, which is the controller for it under the conditions of Article 1.1.
The legal representatives of minors between sixteen and eighteen may exercise the data subject's rights on the minor's behalf under the conditions of Belgian law.
Data concerning the User's possession of firearms (inventory, sessions) does not constitute "special categories of data" in the strict sense of Article 9 GDPR. Given however its contextual sensitivity (revealing a legally regulated activity, potential exposure in the event of a leak), it benefits from strengthened protective measures:
It is necessary to be precise about what encryption at rest covers and what it does not: it protects the hosting provider's storage media, not the content of the database as against the infrastructure that runs it. Takion implements no additional application-level encryption on the inventory: the serial number is stored as such in the database.
None of these elements is shared with a third party, save in the following cases:
A club may require its members to provide a medical certificate of fitness. Such a document is health data, and therefore falls under Article 9 GDPR, which prohibits such processing save by way of exception.
Who processes this data. The Club, as controller (see Article 1.1). Takion acts as processor.
On what basis. Article 9(2)(a) GDPR: your explicit consent. You choose either to lodge the certificate in the application or to present it physically at your club's counter. You may withdraw that consent at any time, without calling into question what has been done before; your club then remains free to require the document by another means, as it would do without Gunbix.
What is collected. The document itself (PDF, JPEG or PNG), its technical fingerprint, its type and size, and the date of lodging.
What is not retained, and this is the essential point. As soon as your club has taken its decision, whether favourable or unfavourable, the document is erased. All that remains is the administrative proof: that a document was seen or received, by whom, when, and until what date it is valid. No medical content is retained. There is in fact, within Gunbix, no field in which to enter a diagnosis, a contraindication or a doctor's name: that information has nowhere to go, and that is deliberate.
Who can read it, for as long as it exists. You, and the administrators of your club only. A club validator, who nevertheless handles the same validation queue, cannot open a medical certificate: the service refuses them access and does not even offer them a link. No other club, no other member.
For how long. The document exists only between lodging and decision. If your club never decides, the document is erased at the latest ninety (90) days after lodging. The proof of validation, for its part, is retained for the duration of your membership of the club, and then for twelve (12) months.
A club may need to verify your good standing, by means of a criminal record extract or a certificate of good conduct. This is data relating to criminal convictions, governed by Article 10 GDPR, whose regime is the strictest in the Regulation.
Gunbix has chosen never to hold these documents.
The lodging of a criminal record extract is refused by the service itself. This is not a technical limitation nor a setting: it is a deliberate refusal, written into the code, that nobody can disable, neither your club nor Takion. Such a document can therefore at no time be found on our servers.
What exists instead. You present the original to your club. An officer looks at it, returns it to you, and ticks "original seen and received" in Gunbix. That attestation carries three items of information: who made it, when, and until what date it is valid. It does not say what the extract contained, nor whether it bore any entry at all.
Why this choice. A platform that gathered the criminal record extracts of the members of many clubs would in effect constitute a register of convictions. Article 10 reserves that kind of register to public authorities. Rather than attempting to contain that risk, we removed it.
For how long. The attestation follows the same period as the other proofs of validation: for the duration of your membership of the club, and then twelve (12) months. There is no document to erase, since there never was one.
If your club otherwise keeps paper originals in its own archives, that does not concern Gunbix: that processing belongs entirely to the club, which must answer for it.
For the purposes of the Service, the data is accessible only to:
No data is sold, rented or exchanged with third parties for commercial purposes.
The Service is hosted on Cloudflare infrastructure (Workers, D1, R2). The storage of files uploaded by Users (R2 bucket) is created in the European Union jurisdiction.
Certain technical operations (support, aggregated telemetry, content distribution via CDN) may involve occasional transfers to servers located outside the European Economic Area, in particular in the United States.
These transfers are governed by the following safeguards:
A copy of these safeguards may be obtained on request to privacy@takion.be.
| Category | Retention period |
|---|---|
| Active account | For the whole duration of registration with the Service |
| Closed account (erasure) | Erasure on receipt of the request, at the latest within 30 days, save where retention is legally required (see Article 9) |
| Accounting and tax data | 7 years from the close of the financial year (VAT Code, Art. 60 §4) |
| Acknowledgement of a payment event transmitted by Stripe | 8 years, aligned with the period of the accounting record it accompanies (7 years from the close of the financial year, which may end almost a year after the event). The entry carries no amount, no customer and no User identifier |
| Security and connection logs | 12 months maximum |
| Email delivery event (handover, acceptance, rejection, spam report) | 12 months, like the other sending logs |
| Address removed from sending after a permanent rejection or a spam report | Retained as a fingerprint for as long as the address is associated with an account, so as not to write again to a mailbox that rejects |
| Unsubscription from a non-essential email | Never erased, at no point, and this is a measure taken in your favour rather than an oversight: erasing an objection because it had become "stale" would amount to automatically re-subscribing a person who had objected, which Article XII.13 of the Code of Economic Law prohibits. Only the data subject withdraws their unsubscription, from their account settings or the link provided on the confirmation page |
| Attendance recorded in a Club's register | 10 years, a period imposed by the Royal Decree of 13 July 2000, Art. 3, 4°, which covers each individual shooter and each shooting instructor. Detached from the account when the account is deleted (see Article 9), the period continuing to run from the attendance itself |
| Shooting session not validated by a Club, active account | For the whole life of the account. It is the User's shooting log, which no Club has entered in its register: draft, session never submitted, session awaiting decision or refused. It is erased with the account, and not before |
| Shooting session validated by a Club, active account | Likewise for the whole life of the account. The Royal Decree of 13 July 2000 requires the Club to retain for ten years; it does not require it to destroy after that period. Ten years is a floor for the Club, never a ceiling for the shooter, and validation by a Club does not take the session away from the person who shot it |
| Shooting session validated by a Club, after deletion of the account | 10 years from the date of the session, and never from the deletion of the account: running the period from erasure would mean that exercising that right lengthened retention. The session is detached from the account and the pseudonym frozen at the time of submission remains (see Article 9) |
| Expired sign-in session | 30 days after its expiry; 90 days after its revocation, so that fraudulent access can be investigated |
| Single-use sign-in code | Erased as soon as it expires, with no retention period |
| Rate-limiting counter, which protects the Service against abuse | Erased at the end of its own counting window, that is from one hour to one day depending on the ceiling concerned |
| Membership fee call and payment recorded by a Club | 7 years from the close of the financial year, an accounting record of the association |
| Club audit log, decision concerning a person | 5 years (exclusion, change of role or status, refusal of affiliation, decision on a document). References to the person are set to null as soon as the account is deleted |
| Club audit log, record of routine operation | 12 months (sign-in, sign-out, evening close, registration of a guest, lodging of a session) |
| Invitation to join a Club, as a member or as staff | 365 days from whatever brought it to an end: its revocation, its acceptance, or its expiry if it went unanswered (failing a recorded expiry, its last modification). The invited email address then disappears, whether or not its holder has a Gunbix account, and sooner if they delete their account: in that case the entry remains in the Club's log without an address, until its term (see Article 9) |
| Entry in a Club's range register, as visitor or one-day shooter | 10 years, a period imposed by the Royal Decree of 13 July 2000, Art. 3, 4° (see Article 1.2) |
| Date of birth and nationality in the range register | 24 months, then erasure of those two fields, the register entry remaining |
| Address recorded on a day card | 10 years, like the register entry it accompanies, then erased with it (see Article 1.2) |
| Member record migrated from earlier software | For the duration of membership of the Club, then 12 months, subject to the attendance records attached to it (see Article 1.2) |
| Source line of a membership file import | 90 days after the last import, then erasure |
| Platform administration audit log | Retained, including after deletion of the account, as evidence of the operation |
| Targets and session scores | For as long as the User keeps the corresponding session |
| Proof of validation of a document requested by a Club | For the duration of membership of the Club, then 12 months |
| Document lodged for a Club, ordinary kinds | 90 days after the Club's decision; 365 days if the Club never decides |
| Medical certificate lodged for a Club | Erased as soon as the Club decides; at the latest 90 days after lodging if the Club never decides |
| Criminal record extract | No retention: lodging is refused by the Service (see Article 5.3) |
| Telemetry data | 13 months maximum, aggregation thereafter |
| Data necessary for legal defence | The applicable limitation period (5 years as a general rule) |
At the end of the periods indicated, the data is erased, anonymised or archived on a restricted basis in accordance with legal requirements.
In accordance with Articles 15 to 22 GDPR, the User has the following rights:
No automated decision producing legal effects or significantly affecting the User is implemented by the Service.
The User exercises their rights:
Takion replies within one month of receipt of the request. That period may be extended by two months in the event of complexity or a high volume of requests, with prior notice to the User.
Reminder of Article 1.1: for documents required by a Club, the controller is the Club. A request concerning those documents should be addressed to the Club first.
Deletion of the account erases the profile, the firearms inventory, personal shooting sessions, targets and photographs lodged (including those of a session validated by a Club), quiz attempts, sign-in history, the personal activity log, support requests, Club memberships and documents lodged with a Club. It also erases the email address carried by invitations a Club sent to that address: those that went unanswered or were revoked disappear entirely, while the one that was accepted remains in the Club's log stripped of the address, as a dated record of a recruitment that took place, no longer designating anyone. An irreversible fingerprint of the email address is retained in order to prevent the same account being recreated; it does not allow the address to be recovered.
Four categories of information deliberately survive deletion. It is right to be informed of them.
Attendance recorded in a Club's register. An attendance record is a document of the Club before it is data of the member: the Club needs it in order to keep its register, issue its attendance certificates and answer to the administration. The attendance entry therefore remains, but detached from the account: the link to the User is erased. Legal basis: legal obligation on the Club (Article 6(1)(c) GDPR), the Royal Decree of 13 July 2000 requiring every approved range to keep that register and to retain it for ten years. The certificate the member may derive from it falls, for its part, under performance of the membership contract (Article 6(1)(b)).
Membership fee calls and payments recorded by a Club. These are accounting records of the association, to be retained for seven (7) years from the close of the financial year. The link to the account is erased, but the member's label, frozen at the time of the call, remains: without it, the Club's accounts would become unreadable. Gunbix merely records these fees and never collects them. Legal basis: legal obligation (Article 6(1)(c) GDPR, Article 60 §4 of the VAT Code).
Shooting sessions validated by a Club. A session that a Club has examined and validated is a document of its register: it feeds its reports and its certificates. It remains, detached from the account (the link to the User is erased), with only the information frozen at the time of submission: the shooter's pseudonym, the firearm label, the name of the Club, the label of the firing point, the discipline, the date of the session and the locked score. Neither the targets, nor the photographs, nor the list of firearms used in the session remain. A personal session, never submitted, awaiting decision or refused, is by contrast erased: no Club entered it in its register. Legal basis: legitimate interests of the Club (Article 6(1)(f) GDPR).
Audit logs. A Club's audit log retains the decisions taken by its staff; references to the person are set to null, so that the decision remains without naming anyone. The platform administration audit log, for its part, retains the action and its target, including the deletion of the account itself: it is the only evidence of it, and it therefore cannot disappear with it. Legal basis: legitimate interests, establishment and defence of rights (Article 6(1)(f) GDPR).
None of this information includes the firearms inventory, which is erased without exception.
A particular case: files imported by a Club. Where a Club imports its membership file from its former software, the imported entries are not attached to a Gunbix account: deleting an account therefore does not reach them. Their erasure is a matter for the Club, as controller, and is carried out following a request sent to privacy@takion.be, which handles it manually.
A User who considers that the processing of their data infringes the GDPR or Belgian law may lodge a complaint with the competent supervisory authority:
Data Protection Authority (DPA) Rue de la Presse 35, 1000 Brussels Telephone: +32 (0)2 274 48 00 Website: dataprotectionauthority.be
A User residing in another Member State may also apply to the competent supervisory authority of their place of residence, in accordance with Article 77 GDPR.
Takion implements technical and organisational measures appropriate to the risks. The list below describes only measures actually in place as at the date of this version.
Technical measures
Organisational measures
In the event of a data breach presenting a risk to the rights and freedoms of data subjects, Takion notifies the incident to the Data Protection Authority within seventy-two (72) hours of becoming aware of it, in accordance with Article 33 GDPR. Affected Users are informed without undue delay where the incident presents a high risk, under the conditions of Article 34 GDPR.
The data processed is principally collected directly from the User on registration, in their personal space, and in the course of using the Service.
Certain data may be obtained indirectly:
For any data collected indirectly, the information required by Article 14 GDPR is owed. For a User's data, it is provided by this page. For the two cases in Article 1.2, where the person has no account and will not come to read this page of their own accord, it falls to the Club, which is the controller: Takion provides it with the texts to display at the sign-in desk and to send to imported members (https://gunbix.com/en/third-party-information).
The use of cookies and equivalent technologies on gunbix.com is described in the Cookie Policy. The mobile application and the web application use no third-party cookies for advertising purposes.
Pixels and remote images placed in an email fall under the same Article 5(3) of the ePrivacy Directive as cookies, and therefore under the same prior consent regime. The Service's emails contain none: see Article 2.8.
Takion may amend this Privacy Policy in order to adapt it to changes in the Service, in the legal framework or in industry standards.
Substantial amendments are brought to Users' attention at least thirty (30) days before they enter into force, by notification within the application and by email to the address associated with the account. Users are invited to read the new provisions and, where appropriate, to confirm their consent for new processing operations requiring it.
Each language version of this Policy binds the User who accepted it. In the event of a difference of interpretation between versions, the French version serves as the reference, without this giving rise, for the User, to any obligation that does not appear in the version they accepted.
For any question relating to this Policy or to the exercise of rights:
TAKION SRL Rue Mansart 39/A 7534 Tournai Belgium