Privacy Notice
Last updated: [15.02.2026]
This Privacy Notice explains how [Company / Site Name] (“we”, “us”, “our”) collects, uses, shares, and protects personal data when you interact with [Website URL] and our services (together, the “Services”). We are committed to complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and relevant national laws.
If you have questions, contact us at [
1) Who this Notice applies to
This Notice applies to personal data we process about:
-
website visitors
-
customers and prospective customers
-
suppliers and business partners
-
event and promotion participants
-
job applicants
-
anyone communicating with us (email, forms, phone, social media, etc.)
It covers processing done through any channel, including our website, apps (if any), social media pages, email, file transfer, and business tools.
Anonymous/aggregated data that does not identify you is not covered by this Notice.
2) Controller and contact details
Contact: [
3) What personal data we collect
The data we process depends on how you interact with us. We may collect:
A) Identity & contact details
-
name, title, company/organization
-
email, phone number
-
postal/shipping/billing address (where relevant)
B) Account and login data (if you create an account)
-
username, password (stored in hashed form where possible)
-
login/logoff timestamps and basic security logs
C) Order, customer, and support data
-
products/services requested or purchased
-
order history, instructions, service tickets, customer communications
-
business interests relevant to your request (where appropriate)
D) Payment and financial data (where relevant)
-
invoice data, payment terms, preferred payment method
-
bank account/IBAN or card details (typically handled by payment providers)
E) Website and device data (cookies/logs)
-
IP address, device identifiers, browser type, operating system
-
usage data (pages viewed, clicks, time spent, referral source)
-
advertising/measurement interactions (where enabled)
F) Recruitment data (if you apply for a job)
-
CV, education, qualifications, work history, skills
-
interview notes and communications (where permitted by law)
G) Data from other sources
We may receive business contact data from:
-
your employer or colleagues
-
public sources (e.g., business directories)
-
event partners/sponsors (where applicable)
-
service providers helping us run our Services
4) Why we use personal data and our legal bases
We only process personal data when we have a legal basis under the GDPR (and where applicable, national law). The main legal bases are:
4.1 Handling orders and fulfilling contracts
Purpose: process orders, deliver goods/services, provide support, manage invoicing and payments, and exercise contractual rights.
Data: identity/contact, order/customer info, payment/invoice info.
Legal basis:
-
Contract necessity (Art. 6(1)(b) GDPR)
-
Legal obligation (Art. 6(1)(c) GDPR) for accounting/tax records
-
Legitimate interests (Art. 6(1)(f) GDPR) for improving customer service, managing customer relationships, and business operations
4.2 Browsing our website, social media pages, or platforms (cookies & tracking)
Purpose: run the website, ensure security, understand usage, measure performance, and (where enabled) deliver personalized content/ads.
Data: device and usage data, IP address, cookie identifiers.
Legal basis:
-
Consent (Art. 6(1)(a) GDPR) where required (e.g., analytics/marketing cookies)
-
Legitimate interests (Art. 6(1)(f) GDPR) for essential security and basic site functionality (where permitted)
See Cookie Policy: [link to cookie policy] (includes cookie types, retention, and how to manage preferences).
4.3 Communication, marketing, promotions/events, and feedback
Purpose: respond to inquiries, send requested information, manage events/promotions, request feedback, and share relevant product/service updates.
Data: identity/contact details, communications, event participation data.
Legal basis:
-
Contract necessity (Art. 6(1)(b) GDPR) when communication relates to a contract or steps before a contract
-
Legitimate interests (Art. 6(1)(f) GDPR) for business communications and relationship management
-
Consent (Art. 6(1)(a) GDPR) where required for marketing or certain event activities
4.4 Legal obligations and compliance
Purpose: comply with legal duties (e.g., tax, accounting, trade/export compliance, anti-fraud, AML where applicable) and enforce our policies.
Legal basis:
-
Legal obligation (Art. 6(1)(c) GDPR)
-
Legitimate interests (Art. 6(1)(f) GDPR) where non-EU legal compliance or internal compliance efforts apply and are lawful
4.5 Recruitment and job applications
Purpose: review applications, conduct interviews, select candidates, and (if hired) manage pre-employment steps.
Legal basis:
-
Contract necessity (Art. 6(1)(b) GDPR) (steps prior to entering an employment contract)
-
Legitimate interests (Art. 6(1)(f) GDPR) to defend against claims and operate fair recruitment
-
Consent (Art. 6(1)(a) GDPR) where you agree to remain in our talent pool
If you apply via a third-party careers portal, their privacy information may also apply.
5) Children’s privacy
Our Services are intended for [B2B / general audience — choose one] and are not directed to children. We do not knowingly collect personal data from children under 16 (or the relevant age in your country). If you believe a child provided data to us, contact [
6) Who we share personal data with
We do not sell personal data. We may share it as follows:
6.1 Service providers (processors)
We use trusted vendors to provide services on our behalf under data-processing agreements and appropriate security measures, such as:
-
IT and cloud hosting providers
-
website/app analytics and consent management providers
-
customer support and CRM tools
-
marketing agencies and email delivery services
-
payment service providers
-
logistics and shipping partners
-
professional advisors supporting our operations (where acting as processors)
6.2 Third parties (independent controllers)
We may share personal data where necessary for:
-
compliance with law, regulation, or legal process
-
prevention of fraud or security incidents
-
protection of our rights and the rights of others
-
business transactions (merger, acquisition, sale of assets)
Recipients may include:
-
public authorities, regulators, law enforcement
-
courts and legal counsel
-
auditors and accountants
-
banks, insurers, credit reference agencies (where relevant)
-
business partners involved in fulfilling your request/order (e.g., manufacturers or resellers), where appropriate
6.3 Social media platforms
If you interact with us through social media or link your account, the platform may process personal data under its own terms. Please review the platform’s privacy policies.
7) International transfers (outside the EEA)
If we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
-
an EU adequacy decision, or
-
EU Standard Contractual Clauses (SCCs), and/or
-
Binding Corporate Rules (BCRs) (where applicable)
You can request information about applicable safeguards by contacting [
8) How long we keep personal data (retention)
We keep personal data no longer than necessary for the purposes described above, unless longer retention is required by law or needed to establish, exercise, or defend legal claims.
Typical examples (adjust to your business/law):
-
customer/order records: for the duration of the relationship and as required by law
-
invoices/accounting records: often 6–10 years depending on jurisdiction
-
website analytics: for the period defined in the Cookie Policy
-
marketing contacts: until you opt out (or we no longer have a lawful basis)
-
job applicants: commonly up to 6 months after rejection (to manage claims), or up to [12–24] months if you consent to remain in a talent pool
9) Security of personal data
We use technical and organizational measures designed to protect personal data, such as:
-
access controls and authentication
-
network security and monitoring
-
encryption and/or pseudonymization where appropriate
-
secure development and vendor due diligence
-
regular review of security measures
No system can be guaranteed 100% secure. If you have a security concern, contact [
10) Your marketing preferences
Where we send marketing communications, you can opt out at any time by:
-
clicking the unsubscribe link in emails
-
updating preferences in your account (if available)
-
contacting us at [
This email address is being protected from spambots. You need JavaScript enabled to view it. ]
Opting out of marketing does not stop essential service communications (e.g., order confirmations, billing, security notices).
11) Your rights (GDPR)
Depending on your location and the laws that apply, you may have the right to:
-
Access your personal data
-
Rectify inaccurate data
-
Erase your data (where applicable)
-
Object to processing (including direct marketing)
-
Restrict processing in certain cases
-
Withdraw consent where processing is based on consent
-
Data portability (receive or transfer your data)
-
Lodge a complaint with your local Data Protection Authority
To exercise your rights, contact [
12) Changes to this Privacy Notice
We may update this Notice from time to time. The “Last updated” date shows when it was most recently revised. If changes are material, we may provide additional notice (e.g., on the website or by email where appropriate).