Data Protection & GDPR
Version 1.0 · Last updated: 21 July 2026
1. Controller and contact
ColdMatch Group is the controller of personal data processed via the platform for sourcing and marketing purposes. Privacy contact: privacy@coldmatchgroup.com. Where a supplier engages with a buyer following an introduction, that supplier acts as an independent controller for the personal data it processes to deliver the project.
2. Lawful bases
- Contract / pre-contract steps — to provide the sourcing service, host your account and respond to RFQs.
- Legitimate interests — to operate, secure and improve the platform, prevent fraud and misuse, and communicate about relevant services.
- Consent — for optional analytics/marketing cookies and certain marketing communications; may be withdrawn at any time.
- Legal obligation — for AML/CTF, sanctions, tax and accounting duties.
3. Categories of data
Contact and company data, RFQ content, financing assessment inputs, uploaded documents, usage and device data, and correspondence. We do not intentionally process special category data.
4. Recipients
Selected third-party suppliers, financing partners, logistics or insurance providers (only as required to prepare a quotation or fulfil a service), plus vetted subprocessors for hosting, authentication, email delivery, analytics, customer messaging and security.
5. International transfers
Personal data may be processed outside the EEA. Where required we rely on appropriate safeguards (Standard Contractual Clauses, adequacy decisions or equivalent).
6. Retention
We retain personal data only for as long as necessary for the purpose collected, to comply with legal obligations and to resolve disputes. Financing and AML records may be retained for the minimum period required by applicable law.
7. Data subject rights
Under GDPR you have the right to access, rectify, erase, restrict, port, object and (where processing is based on consent) withdraw consent. To exercise any of these rights, contact privacy@coldmatchgroup.com. You may lodge a complaint with your local supervisory authority.
8. Security
We implement appropriate technical and organisational measures, including encryption in transit, access controls, logging and least-privilege administration. See our Cyber Security & Responsible Disclosure policy.
9. Data breach
In the unlikely event of a personal data breach likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, affected data subjects, in line with GDPR Articles 33-34.
Related legal documents
- Terms of Service · v3.0
- Privacy Policy · v2.2
- Cookie Policy · v1.4
- General Disclaimer · v2.1
- Legal Notice · v1.3
- RFQ Terms · v1.0
- Buyer Terms · v1.0
- Supplier Terms · v1.0
Governing law: Republic of Cyprus · Exclusive jurisdiction: the competent courts of the Republic of Cyprus, without prejudice to any non-derogable rights available to users under mandatory local law. Contact: legal@coldmatchgroup.com.
