GDPR Statement
HomeGDPR Statement
1. Our Unwavering Commitment to Data Protection in a B2B Context
Vedra Chemicals (SC VEDRA SRL), a distinguished entity operating its digital presence viahttps://vedrachemicals.ro/ (our official corporate domain ), is unequivocally committed to upholding the most stringent standards of data protection and privacy. This commitment extends specifically to all professional personal data pertaining to individuals acting as representatives of our business contacts, partners, and clients. Our adherence to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, commonly known as the General Data Protection Regulation (GDPR), and the pertinent national implementing legislation in Romania, primarily Law No. 190/2018 on measures for the implementation of Regulation (EU) 2016/679, forms the bedrock of our data processing philosophy.
This comprehensive document meticulously outlines Vedra Chemicals’ proactive approach to GDPR compliance, detailing the robust measures, principles, and internal policies we rigorously apply to ensure that all professional personal data is handled with utmost lawfulness, security, and transparency. It is crucial to note that this statement is exclusively tailored for our business-to-business interactions and does not pertain to personal data collected from individual consumers for non-commercial purposes.
2. Understanding GDPR in a B2B Framework
The General Data Protection Regulation (GDPR) represents a landmark legislative act by the European Union, effective since May 25, 2018. Its primary objective is to fortify the fundamental right to privacy and the protection of personal data for individuals within the EU and EEA. In a B2B context, GDPR imposes significant obligations on organizations like Vedra Chemicals that collect, store, and process professional personal data of individuals who are representatives of EU-based entities, irrespective of Vedra Chemicals’ own geographical location.
Key tenets of GDPR particularly relevant to our B2B operations include:
•Expanded Territorial Scope: GDPR applies to the processing of personal data of data subjects residing in the Union, even if the processing entity is not established within the EU, provided it offers goods or services to, or monitors the behavior of, such data subjects.
•Enhanced Rights for Business Representatives: Individuals acting in a professional capacity are granted robust rights over their professional personal data, mirroring those of individual consumers.
•Accountability and Governance: Organizations are mandated to demonstrate and document their compliance with GDPR through various internal policies, records of processing activities, and data protection impact assessments.
•Strict Penalties for Non-Compliance: Significant administrative fines can be imposed for infringements, underscoring the critical importance of adherence.
3. Vedra Chemicals as a Data Controller in B2B Operations
SC VEDRA SRL functions as aData Controller for the professional personal data collected through our website and during the course of our business operations. This designation signifies that we determine the specific purposes and the means of processing such personal data. Our responsibilities as a Data Controller in the B2B sphere are extensive and include:
•Ensuring that all data processing activities are conducted lawfully, fairly, and with complete transparency towards the business representatives involved.
•Collecting professional personal data solely for specified, explicit, and legitimate business purposes, directly related to our chemical intermediation and logistics services.
•Implementing rigorous data minimization strategies, ensuring that the amount of data collected is strictly limited to what is necessary for the defined purposes.
•Maintaining the highest possible accuracy of professional personal data, with mechanisms in place for timely updates and corrections.
•Adhering to strict storage limitation principles, retaining data only for the period essential to fulfill the purposes for which it was collected, or as legally mandated.
•Implementing and continuously enhancing appropriate technical and organizational security measures to protect data integrity and confidentiality.
•Proactively respecting and facilitating the exercise of all data subjects’ rights by business representatives.
4. Our Comprehensive GDPR Compliance Framework
Vedra Chemicals has meticulously developed and implemented a robust framework to ensure ongoing and demonstrable GDPR compliance across all its B2B operations. This framework integrates various organizational and technical measures, reflecting our commitment to data protection:
4.1. Lawfulness, Fairness, and Transparency (GDPR Article 5(1)(a))
We process professional personal data based on clearly defined legal grounds, primarily the necessity for the performance of a contract (e.g., supply agreements, service contracts), our legitimate business interests (e.g., B2B marketing, website improvement, security), or, where appropriate and explicitly obtained, the consent of the business representative. Our Privacy Policy and this GDPR Compliance Statement serve as transparent disclosures, informing business representatives about how their data is collected, utilized, and protected.
4.2. Purpose Limitation (GDPR Article 5(1)(b))
Professional personal data is collected exclusively for specific, explicit, and legitimate business purposes directly related to our core activities of chemical intermediation, supply, and logistics. These purposes include, but are not limited to, managing client accounts, processing orders, facilitating deliveries, communicating about business opportunities, and fulfilling regulatory requirements. We strictly prohibit any further processing of data in a manner incompatible with these initial, clearly articulated purposes.
4.3. Data Minimization (GDPR Article 5(1)(c))
Our data collection practices are designed to be lean and efficient. We ensure that the professional personal data we gather is strictly adequate, relevant, and limited to what is absolutely necessary to achieve the specified business purposes. This principle guides our data input forms, database structures, and information exchange protocols, actively avoiding the collection of superfluous or irrelevant information.
4.4. Accuracy (GDPR Article 5(1)(d))
Vedra Chemicals takes all commercially reasonable steps to ensure that professional personal data is accurate, complete, and, where necessary, kept up to date. We encourage business representatives to inform us of any changes to their professional contact details. Mechanisms are in place to promptly erase or rectify any inaccurate data, taking into account the specific business purposes for which it is processed.
4.5. Storage Limitation (GDPR Article 5(1)(e))
Professional personal data is retained in a form that permits the identification of data subjects (business representatives) for no longer than is strictly necessary to fulfill the business purposes for which it was collected, or as mandated by applicable legal and regulatory obligations (e.g., tax laws, commercial record-keeping). Once the retention period expires, data is securely deleted, anonymized, or archived in a manner that prevents re-identification.
4.6. Integrity and Confidentiality (GDPR Article 5(1)(f))
We process professional personal data with a steadfast commitment to ensuring its appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage. This is achieved through a comprehensive suite of robust technical and organizational measures, which are regularly reviewed and updated:
•Access Controls: Implementation of stringent, role-based access control policies ensures that only authorized personnel, whose job functions necessitate access, can view or process professional personal data. Multi-factor authentication and strong password policies are enforced.
•Data Encryption: Utilization of industry-standard encryption protocols (e.g., SSL/TLS) for all data transmitted over our website and secure communication channels. Where feasible and appropriate, data at rest within our systems is also encrypted.
•Network Security: Deployment of firewalls, intrusion detection/prevention systems, and secure network configurations to protect our IT infrastructure from external threats.
•Regular Security Audits and Vulnerability Assessments: Conducting periodic internal and external security audits, penetration testing, and vulnerability assessments of our IT systems and data processing environments to proactively identify and mitigate potential weaknesses.
•Employee Training and Awareness: Mandatory and ongoing data protection and cybersecurity training for all employees, fostering a strong culture of privacy awareness and ensuring that staff are fully cognizant of their responsibilities under GDPR, particularly in a B2B context.
•Data Processing Agreements (DPAs): Establishing legally binding Data Processing Agreements with all third-party processors (e.g., cloud service providers, IT support) that obligate them to adhere to GDPR standards, implement appropriate security measures, and process data strictly according to our instructions.
•Physical Security: Implementing robust physical security measures to protect our premises and data storage facilities from unauthorized access, including restricted access and surveillance.
•Backup and Disaster Recovery: Maintaining comprehensive data backup and disaster recovery plans to ensure business continuity and data availability in the event of unforeseen incidents.
While Vedra Chemicals employs commercially reasonable and industry-standard security measures, it is important to acknowledge that no method of transmission over the Internet or method of electronic storage can guarantee absolute security. Therefore, while we strive to protect your professional personal data, we cannot guarantee its absolute security. Any transmission of data to our website is undertaken at your own risk. Upon receipt of your information, we commit to employing strict procedures and robust security features to endeavor to prevent unauthorized access.
5. Data Subject Rights for Business Representatives (GDPR Articles 12-22)
Under the General Data Protection Regulation (GDPR), individuals acting as business representatives are endowed with a comprehensive set of rights concerning their professional personal data. Vedra Chemicals is fully committed to respecting and facilitating the exercise of these rights:
•Right to Information (Articles 13 & 14): You have the right to be informed about the collection and use of your professional personal data, including the purposes of processing, the categories of data concerned, and the recipients of the data.
•Right of Access (Article 15): You have the right to obtain confirmation from us as to whether or not professional personal data concerning you is being processed, and, where that is the case, to request access to that personal data and receive specific information regarding the processing activities.
•Right to Rectification (Article 16): You have the right to request that Vedra Chemicals rectify any professional personal information you believe is inaccurate or incomplete without undue delay.
•Right to Erasure (‘Right to be Forgotten’) (Article 17): You have the right to request the erasure of your professional personal data under certain specific conditions, for instance, if the data is no longer necessary for the business purposes for which it was collected, or if you withdraw consent and there is no other legal ground for processing.
•Right to Restriction of Processing (Article 18): You have the right to request that Vedra Chemicals restrict the processing of your professional personal data under certain conditions, such as when you contest the accuracy of the data, or the processing is unlawful.
•Right to Data Portability (Article 20): You have the right to receive your professional personal data, which you have provided to us, in a structured, commonly used, and machine-readable format, and to transmit that data to another data controller without hindrance from us, where technically feasible.
•Right to Object (Article 21): You have the right to object to our processing of your professional personal data, under certain conditions, particularly when the processing is based on legitimate interests (including profiling) or for direct B2B marketing purposes. If you object to direct marketing, we will cease processing your data for that purpose.
•Right to Withdraw Consent (Article 7): Where our processing of your professional personal data is based on your explicit consent, you have the right to withdraw that consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
•Right to Lodge a Complaint (Article 77): You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement, if you believe that the processing of your professional personal data infringes GDPR.
To exercise any of these rights, please submit your request in writing tooffice@vedrachemicals.ro. We commit to responding to your request within one calendar month of receipt. This period may be extended by two further months where necessary, taking into account the complexity and number of the requests, in which case we will inform you of any such extension within one month of receipt of the request, together with the reasons for the delay.
6. Data Protection Officer (DPO) / Designated Contact Person
For any questions, concerns, or requests pertaining to our GDPR compliance, the processing of your professional personal data, or the exercise of your data protection rights, please do not hesitate to contact our designated Data Protection Contact:
Data Protection Contact:
•Email: office@vedrachemicals.ro
•Telephone: +40 350 408 098
7. Lodging a Complaint with the Supervisory Authority
If you, as a data subject, have concerns regarding our data processing practices or believe that your data protection rights have been violated, you possess the right to lodge a formal complaint with the competent supervisory authority in Romania:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
•Address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, code 010336, Bucharest, Romania
•Phone: +40.318.059.211 / +40.318.059.212
•Email: anspdcp@dataprotection.ro
•Website: https://www.dataprotection.ro/
8. Data Breach Notification Procedures
In the unlikely and unfortunate event of a personal data breach, Vedra Chemicals has established rigorous internal procedures to promptly assess the risk to individuals’ rights and freedoms. Where such a breach is likely to result in a high risk to these rights and freedoms, we commit to notifying the National Supervisory Authority for Personal Data Processing (ANSPDCP) without undue delay and, where feasible, not later than 72 hours after having become aware of it. Furthermore, affected data subjects will be notified without undue delay, in accordance with GDPR Articles 33 and 34. Our procedures include internal reporting, investigation, containment, and remediation steps.
9. Review and Updates to This GDPR Compliance Statement
This GDPR Compliance Statement, alongside our Privacy Policy and Cookie Policy, is subject to regular and comprehensive review and updates. This ensures our ongoing compliance with evolving data protection laws, regulatory guidance, and best practices. Any significant revisions will be communicated by posting the updated statement on this page and by revising the “Last Updated” date. We strongly advise all business representatives to review this statement periodically to remain informed about how Vedra Chemicals is protecting professional personal data.
