Client and Counterparty Privacy Policy
CLIENT AND COUNTERPARTY PRIVACY POLICY
Personal Data Processing Policy for Clients and Counterparties
INTRODUCTION
This Policy has been developed in accordance with the EU General Data Protection Regulation 2016/679 (GDPR) and other applicable data protection law.
Boilte considers the protection of data of its clients, partners, and website visitors as one of its highest priorities. We guarantee that the processing of personal data is carried out in full compliance with applicable data protection legislation and generally accepted international standards.
We understand that trust in us begins with respect for your privacy. This Policy explains what data we collect, why we do it, and how we protect it.
SECTION 1. PERSONAL DATA OPERATOR
1.1. Operator
Boilte LLC (hereinafter — the "Operator," "Boilte," "we," "us").
1.2. Contact Information
| Parameter | Value |
|---|---|
| info@boilte.com | |
| Website | www.boilte.com |
1.3. Data Protection Officer
We have appointed a person responsible for organizing the processing of personal data. You can contact them at: info@boilte.com (with the note "For the Data Protection Officer").
SECTION 2. PURPOSES AND LEGAL GROUNDS FOR PROCESSING PERSONAL DATA
Your personal data is processed for the following purposes:
| No. | Purpose of Processing | Data Categories | Legal Basis (GDPR) |
|---|---|---|---|
| 1 | Registration in the database (creating a counterparty account) | Representative's full name, position, contact details (phone, email), company name | GDPR Art. 6(1)(b) (performance of a contract) |
| 2 | Processing requests for consultation and/or information | Full name, phone, email, text of the request | GDPR Art. 6(1)(a) (consent), Art. 6(1)(b) (steps prior to entering a contract) |
| 3 | Conclusion and performance of the supply contract (including production, shipment, delivery) | Representative data (full name, position, contacts); individual entrepreneur or individual data (passport details, tax identification number, address, bank details) | GDPR Art. 6(1)(b) (performance of a contract) |
| 4 | Maintaining accounting and tax records, complying with legal requirements | Data necessary for issuing invoices, acts, reporting to tax authorities | GDPR Art. 6(1)(c) (legal obligation) |
| 5 | Providing after-sales service and warranty service | Data on orders, invoices, payments, shipments | GDPR Art. 6(1)(b) (performance of a contract) |
| 6 | Sending informational and promotional materials about products and events (marketing) | Contact details, preferences, interaction history | GDPR Art. 6(1)(a) (consent) |
| 7 | Protecting rights and legitimate interests in court, managing disputes, and debt collection | Contract-related data, correspondence, payment documents | GDPR Art. 6(1)(f) (legitimate interest) |
SECTION 3. CATEGORIES OF PERSONAL DATA PROCESSED
We process the following categories of personal data of clients and their representatives:
3.1. Data of a Legal Entity's Representative:
- Full name;
- Position;
- Contact details (phone number, email address);
- Signature sample (if applicable).
3.2. Data of an Individual Entrepreneur or Individual:
- Full name;
- Passport details (series, number, date of issue, issued by);
- Registration address and actual residence address;
- Tax identification number (if applicable);
- Contact details (phone number, email address);
- Bank details.
3.3. Data Necessary for Contract Performance:
- Information about orders, invoices, payments, shipments;
- Commercial correspondence;
- Certificates of work performed, waybills, invoices.
3.4. Data Voluntarily Provided for Marketing Purposes:
- Communication preferences;
- Newsletter subscriptions.
Important: Under no circumstances, unless expressly required for contract performance or provided by law, do we collect special categories of data (racial or ethnic origin, political opinions, religious beliefs, health information).
SECTION 4. METHODS OF COLLECTING PERSONAL DATA
Personal data of clients and their representatives is collected by the following methods:
4.1. Direct Provision by the Client:
- When filling out forms on the website;
- When sending requests via email;
- When signing contracts and additional agreements.
4.2. Obtaining Data During Contract Performance:
- During correspondence;
- When processing acts, invoices.
4.3. Obtaining Data from Public Sources:
- From public registers of legal entities and sole traders;
- From official websites of organizations (for counterparty verification).
4.4. Automated Collection of Technical Information:
- When visiting the website (cookies, IP address, website behavior data) — in accordance with the Cookie Policy.
SECTION 5. LEGAL GROUNDS FOR PROCESSING PERSONAL DATA
Processing of personal data is carried out on the following legal grounds:
| Legal Basis | Description |
|---|---|
| Contract | For the purposes of concluding and performing the supply contract |
| Consent to Processing | For purposes not related to contract performance (marketing, talent pool formation, if applicable) |
| Compliance with Legal Requirements | For accounting, tax purposes, document retention |
| Legitimate Interest of the Operator | For the purposes of protecting rights, managing disputes, and preventing fraud |
SECTION 6. TERMS OF PROCESSING AND STORAGE OF PERSONAL DATA
| Data Category / Purpose of Processing | Storage Period |
|---|---|
| Data related to contract performance (including accounting documents) | During the term of the contract and 5 years after its termination (statute of limitations and tax accounting requirements) |
| Data for marketing communications (subject to consent) | Until consent is withdrawn or communication ceases (maximum 3 years) |
| Data processed based on legitimate interest | For the period necessary to achieve the purpose, but not exceeding the statute of limitations period |
| Data processed based on consent (other purposes) | For the period specified in the consent, or until its withdrawal |
Upon expiration of the specified periods, personal data is subject to destruction, unless otherwise provided by applicable law.
SECTION 7. PROCEDURE FOR DESTRUCTION OF PERSONAL DATA
Destruction of personal data is carried out by a commission appointed by order of the head of Boilte, with the drawing up of a corresponding destruction act. Destruction is carried out in a manner that excludes the possibility of further restoration or use of personal data.
Destruction Methods:
- Mechanical destruction (shredding) of paper media;
- Erasing (overwriting) of electronic media;
- Chemical destruction (for specific media).
SECTION 8. LIST OF ACTIONS WITH PERSONAL DATA
We carry out the following actions with clients' personal data:
- Collection;
- Recording;
- Systematization;
- Accumulation;
- Storage;
- Clarification (updating, changing);
- Extraction;
- Use;
- Transfer (distribution, provision, access);
- Depersonalization;
- Blocking;
- Deletion;
- Destruction.
Processing is carried out both with and without the use of automation tools. To ensure information security, we use modern information protection tools, including antivirus software, firewalls, and access control systems.
SECTION 9. TRANSFER OF PERSONAL DATA TO THIRD PARTIES
9.1. Transfer Without Separate Consent (by operation of law or contract):
| Categories of Recipients | Purposes of Transfer |
|---|---|
| Transport companies and logistics services | Delivery of products to the Client |
| Banks and payment systems | Processing payments, refunds |
| Customs authorities, government authorities (if necessary) | Compliance with legal requirements (including customs clearance) |
| External consultants (auditors, lawyers) | Protection of rights, advisory support |
| IT service providers (hosting, cloud services) | Ensuring the operation of information systems |
9.2. Cross-Border Transfer:
We carry out cross-border transfer of clients' personal data only:
- to countries that provide adequate protection of the rights of personal data subjects (in accordance with the EC decision on third countries or based on relevant contractual guarantees, including the EU Standard Contractual Clauses);
- with the express consent of the data subject for such transfer;
- for the performance of a contract involving the data subject.
SECTION 10. RIGHTS OF PERSONAL DATA SUBJECTS
10.1. Rights in accordance with the GDPR:
- The right of access (Art. 15);
- The right to rectification (Art. 16);
- The right to erasure (right to be forgotten) (Art. 17);
- The right to restriction of processing (Art. 18);
- The right to data portability (Art. 20);
- The right to object to processing (Art. 21);
- The right not to be subject to a decision based solely on automated processing (Art. 22).
10.2. Procedure for Exercising Rights:
To exercise their rights, the data subject can send a request to info@boilte.com. The request must contain:
- Full name of the data subject;
- Information confirming the subject's involvement in relations with the Operator (contract number, contact details);
- The essence of the request;
- The method of sending the response.
We undertake to review the request within 30 (thirty) days, with the possibility of extending this period by no more than 30 days, notifying the data subject.
SECTION 11. OBJECTION TO PROCESSING (FOR MARKETING)
The data subject has the right to object at any time to the processing of their personal data for direct marketing purposes (including profiling) by sending a request to info@boilte.com. In this case, we will stop processing the data for the specified purposes.
Unsubscribe: Every marketing email contains an "Unsubscribe" link. You can opt out with one click.
SECTION 12. RIGHT TO LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY
Each data subject has the right to lodge a complaint with the competent data protection supervisory authority:
- For EU countries: the national Data Protection Authority at the place of residence or work.
- For EU countries: The relevant national Data Protection Authority at the place of residence or work.
SECTION 13. CONTACT INFORMATION
For any questions related to the processing of personal data, as well as to exercise your rights, you can contact:
| Contact | Information |
|---|---|
| info@boilte.com | |
| For the Data Protection Officer | info@boilte.com (with the note "For the Data Protection Officer") |
SECTION 14. COOKIE PROCESSING
Our website uses cookies and similar tracking technologies. Detailed information about the types of cookies, the purposes of their use, and how to manage them is contained in our Cookie Policy, available on the website.
SECTION 15. FINAL PROVISIONS
15.1. Entry into Force
This Policy comes into force from the moment of its approval and is valid indefinitely until replaced by a new version.
15.2. Current Version
The current version of the Policy is always available on the website www.boilte.com.
15.3. Amendments
We have the right to make changes to this Policy. The new version of the Policy comes into force from the moment it is posted on the website, unless otherwise provided by the new version.
15.4. Notification of Changes
We will notify users of material changes to the Policy by posting a notice on the website or by email (for subscribers).
Approved by:
CEO of Boilte
