Version 1.0. This Privacy Policy explains how Euro Intermed Solutions S.R.L. processes personal data in connection with the palletclearance.com website, its forms, communication channels and associated services. This notice is provided in accordance with Articles 13–14 of Regulation (EU) 2016/679 (GDPR).
1. Who we are
The data controller is EURO INTERMED SOLUTIONS S.R.L., with its registered office in Brașov, Romania, VAT/Tax ID (CUI) 39132147, registered with the Trade Register under no. J8/735/2018, e-mail: contact@euro-intermed.com, telephone: 0765934455, hereinafter referred to as the “Controller”, “we” or “us”.
For any data-protection requests, you can contact us at contact@euro-intermed.com.
2. Who this Policy applies to
This Policy applies to individuals whose data we process in a B2B context, including: persons who request quotes or submit enquiries through the website, chat or other channels; representatives, directors, employees or contact persons of customer, supplier or partner companies; contact persons associated with commercial leads; website users; and persons whose data is obtained indirectly from public sources, from partners, from counterparties or from company-verification providers.
Although the website is intended for B2B purposes, certain professional data — such as a name, job title, professional e-mail address or business phone number — constitutes personal data where it identifies or makes identifiable a natural person.
3. What data we process
Depending on how you interact with us, we may process the following categories of data:
- identification and contact data, such as first name, last name, job title, company, professional e-mail address, business phone number;
- company and commercial-relationship data, such as company name, tax/VAT ID, tax status data, field of activity, information about representatives or directors, where relevant to verifying a commercial relationship;
- enquiry, quote or lead data, such as the commercial interest expressed, product or service category, quantities, locations, deadlines, and the content of documents, images or messages sent;
- the content of conversations and interactions, including messages sent via form, web chat, e-mail, WhatsApp or other channels used in dealing with us;
- internally generated commercial-qualification data, such as lead status, commercial priority or internal interest/compatibility scores;
- technical and usage data, such as IP address, session identifiers, access records, security and consent logs, browser type, device data and interaction with the website;
- data needed for legal compliance, such as billing information, supporting documents and records required for tax, accounting or the defence of our rights.
We do not aim to process special categories of data, unless these are provided incidentally or there is a distinct and necessary legal basis for processing. If a given flow were to involve special-category data or national identification numbers, it will be subject to additional safeguards and, where applicable, a specific information notice.
4. Sources of the data
We may obtain data either directly from you or indirectly, from other sources.
Where data is obtained directly, it generally comes from forms, user accounts, quote requests, conversations, sign-ups, e-mails, chat, WhatsApp, calls or other direct interactions with us.
Where data is obtained indirectly, it may come from: the company you represent or on whose behalf you act; customers, partners, suppliers or counterparties who provide us with contact details in the context of a commercial opportunity; public or publicly accessible sources, including commercial registers, tax sources or company databases; third-party company-verification and commercial-data enrichment providers; professional platforms or communication channels used in a business environment, to the extent permitted by law.
Where data is not obtained directly from the data subject, we provide the information required by Article 14 GDPR within a reasonable period — at the latest within one month of obtaining the data, or upon first contact with the data subject if this occurs earlier, or at the latest upon the first disclosure to another recipient if such disclosure takes place earlier.
Where providing individual information to each data subject would prove impossible or would involve a disproportionate effort, or where it would seriously impair the achievement of the objectives of the processing (for example, in the context of certain fraud-prevention activities), we may rely on the exceptions permitted by applicable law, provided that we implement appropriate safeguards for the rights and freedoms of data subjects.
5. Purposes and legal bases of processing
We process data for one or more of the following purposes.
- For handling enquiries, qualifying requests and quotes, contacting the relevant person, managing the pre-contractual relationship and, where applicable, performing the contract, the legal basis is taking steps at the request of the data subject prior to entering into a contract, or performance of the contract, as the case may be.
- For creating and managing user accounts, website access, authentication, technical support, maintenance and operation of the service, the legal basis is performance of the contract or our legitimate interest in managing and securing the service.
- For verifying companies, validating the existence of a commercial partner, preventing fraud, performing commercial-compliance and creditworthiness checks, avoiding duplication and protecting our economic interests, the legal basis is legitimate interest, and where the law requires certain checks or retention, the basis may also be a legal obligation.
- For operational communications — such as confirmations, responses to requests, notices regarding the account, security, the contractual relationship or the status of an enquiry — the legal basis is performance of the contract or our legitimate interest in managing the professional relationship.
- For improving services, internal analytics, measuring commercial performance, organising leads and non-exclusively automated internal scoring, the legal basis is our legitimate interest in making services and commercial processes more efficient, while respecting the rights and freedoms of data subjects.
- For complying with legal obligations — including tax, accounting, archiving, the defence of rights in court, cooperation with authorities and security — the legal basis is a legal obligation or legitimate interest, as applicable.
- For commercial communications and direct marketing through electronic channels, the legal basis and conditions differ depending on the channel and the context in which the data was collected. Commercial communications sent by e-mail or other means governed by the applicable special law on electronic communications will be carried out only under the conditions permitted by that law. Where required, we will request prior express consent. Where the legal conditions are met for promoting our own similar products or services to a customer whose e-mail address was obtained directly in the context of a commercial relationship, we may rely on this legal exception, offering a clear and free means of objecting both at the point of collection and in each subsequent message.
Where we use instant messaging channels (such as WhatsApp Business or similar services) for commercial communications, we will do so only in accordance with applicable data-protection and electronic-communications laws and with the contractual terms and acceptable-use policies of the relevant providers (including any requirements on consent, permitted content, frequency of messages, template approval and opt-out mechanisms). We will not use such channels for unsolicited bulk messaging or spam.
6. Legitimate interests pursued
Where processing is based on legitimate interest, our interests may include: efficient management of the website and of commercial relationships; fraud prevention and verification of the commercial reliability of partners; organising and prioritising commercial enquiries; the security of our systems, service continuity and the defence of our rights; and improving our products, services and commercial flows.
In each case where we rely on legitimate interest, we assess the impact on the data subject and apply measures for limitation, proportionality and data minimisation.
Where we rely on legitimate interest, you have the right to object, on grounds relating to your particular situation, to such processing at any time. In that case, we will no longer process your data for the relevant purpose, unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.
7. When providing data is necessary and what happens if you do not provide it
Some data is necessary in order to respond to your enquiry, to create your account, to send a quote, to connect the relevant parties or to perform the contract. If this data is not provided, we may be unable to process the request, open or maintain the account, provide the service or continue the commercial relationship.
Other data is optional. Its absence does not necessarily prevent a relationship with us, but it may limit service functionality, the accuracy of commercial qualification or the ability to personalise the interaction.
Where a particular set of data is required on the basis of a legal obligation, we will indicate this at the point of collection.
8. Who we disclose data to
We may disclose data, strictly to the extent necessary, to the following categories of recipients: providers of hosting, infrastructure, storage, IT support and maintenance; providers of transactional e-mail, ticketing, security, analytics and technical administration services; AI or assisted-processing service providers, where used in our workflows, within contractually and technically defined limits; company-verification and commercial-validation providers; legal, tax, accounting or audit advisers, under conditions of confidentiality; commercial partners or counterparties, where necessary to process a requested opportunity or transaction; and public authorities and institutions, where there is a legal obligation or a valid request.
Some recipients process data on our behalf as processors, on the basis of agreements compliant with Article 28 GDPR. Other recipients may act as independent controllers for their own purposes, as may be the case with certain platforms or communication channels. In such cases, their processing is also governed by their own policies.
9. International transfers
In principle, we seek to store and process data within the European Union or the European Economic Area.
If, for certain functionalities or providers (for example, cloud infrastructure, AI-based services or messaging services), data is transferred to or accessed from outside the EEA, the transfer is carried out only under the conditions of Chapter V of the GDPR, on the basis of an appropriate legal mechanism, such as an adequacy decision, standard contractual clauses or other appropriate safeguards, and, where necessary, with additional technical and organisational measures to ensure a level of protection essentially equivalent to that in the EU.
If we use providers that may involve international access to data, we will indicate in this policy the relevant categories of providers, the countries involved or the transfer mechanism used, to the extent applicable.
10. How long we keep data
We keep data only for as long as necessary for the purposes for which it was collected, for fulfilling legal obligations or for the defence of our rights.
- Leads with no conversion and no subsequent interaction are generally kept for a period of 24 months from the last relevant contact, after which they are deleted or anonymised.
- Data relating to active contractual relationships is kept for the duration of the commercial relationship and thereafter for the period necessary to meet legal obligations or defend our rights.
- Tax and accounting documents are kept for the periods required by applicable law.
- Conversation transcripts, support tickets and technical logs are kept for differentiated periods, proportionate to the purpose, security and the need for traceability.
- Records concerning consent, objection, unsubscription and marketing preferences may be kept for as long as necessary to demonstrate compliance and to respect the data subject’s choice not to be contacted.
Upon expiry of the applicable period, data is deleted, anonymised or restricted, as appropriate.
We periodically review the data we hold and either delete or anonymise it when it is no longer needed for the purposes described above, taking into account statutory limitation periods and our legitimate need to retain certain information for the establishment, exercise or defence of legal claims.
11. Profiling, scoring and automated decision-making
We may use internal mechanisms to organise and commercially score leads, for example to prioritise, route internally or make the commercial relationship more efficient.
In principle, these mechanisms are not used to make solely automated decisions that produce legal effects or similarly significantly affect the data subject, without human intervention.
Scoring is indicative in nature and may take into account information such as the type of enquiry, the completeness of the data, the company’s commercial profile, the history of interactions and relevance to the services offered. Any relevant commercial decision is subject to human validation.
If a given flow were to involve a solely automated decision within the meaning of Article 22 GDPR, we will provide a separate, additional information notice, including the relevant logic, significance and consequences of the processing.
Where profiling is carried out on the basis of our legitimate interests or for direct marketing purposes, you have the right to object to such profiling at any time, as described in Section 12.
12. Your rights
Under the GDPR, you have the right of access to the data concerning you, the right to rectification, the right to erasure, the right to restriction of processing, the right to object, the right to data portability and, where processing is based on consent, the right to withdraw consent at any time, without affecting the lawfulness of processing carried out prior to the withdrawal.
If we process data for direct marketing purposes, you may object at any time to such processing, including profiling related to direct marketing. In that case, we will stop processing for that purpose. You also have the right to object, on grounds relating to your particular situation, to processing based on our legitimate interests, as described in Section 6.
To exercise your rights, you can contact us at contact@euro-intermed.com or at our registered office in Brașov, Romania. We will respond without undue delay and, in any case, within one month of receiving the request, with the possibility of extension under the conditions of the law.
You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), whose current contact details are available on its website. If you are located in the EU/EEA, you may also lodge a complaint with the supervisory authority in your country of residence, place of work or place of the alleged infringement.
13. Commercial communications and contact preferences
Strictly operational communications — those necessary to respond to a request, manage the account, perform the contract or ensure service security — are distinct from commercial communications.
With regard to direct marketing by e-mail or other electronic channels governed by the applicable special law, we will act only under the conditions permitted by law. Where consent is required, it will be requested separately, specifically, in an informed manner and in a way that is easy to withdraw. Where we rely on the legal exception for similar products or services, we will offer a clear, simple and free means of objecting both when the address is collected and in every subsequent message.
Every commercial message we send will include a valid and functional means of unsubscribing or objecting, as applicable.
Where we use instant messaging channels such as WhatsApp Business for commercial communications, we will only contact you if we have a valid legal basis to do so and in accordance with the applicable terms and policies of the relevant provider. We will not create groups or send bulk messages for promotional purposes without an appropriate legal basis and your prior agreement, and you will always be able to opt out of further messages through a simple and effective mechanism (for example, by using an unsubscribe link or by sending a clear opt-out message).
14. Cookies and similar technologies
The palletclearance.com website or its widget may use cookies and similar technologies.
In accordance with applicable electronic-communications laws, any storage of information or access to information already stored on your device (for example, through cookies or similar technologies) is allowed only if it is strictly necessary for transmitting a communication over an electronic-communications network or for providing a service explicitly requested by you, or if you have given your prior consent through the consent mechanism displayed on the website.
Analytics, measurement, personalisation or marketing cookies, as well as any storage of or access to information on the user’s device that is not strictly necessary, are used only on the basis of a valid choice expressed through the applicable consent mechanism.
Detailed information on the categories of cookies, their purposes, duration and management options can be found in the Cookie Policy and in the consent mechanism displayed on the website.
15. Data security
We apply appropriate technical and organisational measures to protect data, including measures relating to access control, separation of roles, logging, communications security, back-up, operational continuity and infrastructure protection.
Although we make reasonable efforts to protect data, no system can guarantee absolute security. In the event of an incident affecting you in a way that requires notification, we will act in accordance with the applicable legal obligations.
16. Changes to this Policy
We may update this Policy periodically to reflect legislative, technical or operational changes. The updated version and the date of the last revision will be published on the website.
If the changes are substantial, we will use an appropriate means of information, proportionate to the nature of the change and to our relationship with the data subjects.
Annex A — Short notice at the point of collection (data obtained directly)
We process the data you provide to us in order to review your enquiry or quote, to contact you and, where applicable, to manage the contractual or pre-contractual relationship. The controller is Euro Intermed Solutions S.R.L. The main legal bases are pre-contractual steps, performance of the contract and, where applicable, legitimate interest. We may use technical and company-verification providers. You have rights to access, rectification, erasure, objection and to lodge a complaint with the ANSPDCP. Full information is available in this policy.
Annex B — Short notice for contacts obtained indirectly (Article 14 GDPR)
We obtained your professional data from a source such as a public register, a partner, a counterparty, a company-verification provider, or the company you represent, in order to assess a commercial opportunity, validate the relevant professional relationship or manage a possible B2B contractual relationship. The data may include name, job title, company and professional contact details. The controller is Euro Intermed Solutions S.R.L. The main legal basis is our legitimate interest in managing B2B commercial relationships and preventing fraud or identification errors. If you do not wish us to continue using your data for commercial-contact purposes, you may object at any time by e-mail at contact@euro-intermed.com.
Where providing individual notice to each contact would be impossible or would involve a disproportionate effort, we may rely on the exceptions permitted by applicable law, provided that we implement appropriate safeguards for the rights and freedoms of the individuals concerned.