Data Protection & Data Processing Information
Overview of processing activities relevant to business relationships, counterparties, and professional contacts.
Last updated: May 2026
1. Scope
This information applies to personal data processed in the context of:
- Sourcing, trading, logistics, and advisory services;
- Know-your-counterparty, compliance, sanctions screening, and audit trails;
- Finance, invoicing, credit assessment, and collections;
- Professional communication with contacts at customer, supplier, partner, or public bodies.
2. Roles under GDPR
Depending on the scenario, Nordely Materials may act as controller or processor. Where we process personal data on documented instructions of another party (e.g. as a service provider), the agreement defines roles and obligations.
3. Categories of personal data
Examples include: names, business contact details, job titles, communication logs, bank/payment-related identifiers where necessary for transactions, compliance documentation (e.g. excerpts from registers), and — where strictly required — identification data relating to individuals acting on behalf of legal entities.
4. Purposes
- Initiating and performing contracts;
- Regulatory compliance (trade, tax, anti-money laundering where applicable);
- Risk management, insurance, and dispute resolution;
- Recording commercial correspondence and operational decisions.
5. Legal bases
Processing may rely on contract performance, legal obligation, legitimate interests (balanced against data subjects’ rights), or consent where specifically obtained. Special categories of data are processed only where a permissive ground exists.
6. Processors & international transfers
We may engage providers for IT, hosting, communication, banking, logistics platforms, or compliance tools. Transfers outside the EU/EEA use appropriate safeguards when required.
7. Retention
Retention follows statutory commercial and tax retention rules, limitation periods, and operational necessity. Data no longer needed is deleted or anonymized according to internal policies.
8. Data subjects’ rights & inquiries
Rights under applicable law (access, correction, erasure, restriction, objection, portability, complaint to a supervisory authority) may be exercised as described in our Privacy Policy.
For dedicated compliance contacts (if designated), add them here in line with your governance structure.