Legal

Data Protection & GDPR

Version 1.0 · Last updated: 21 July 2026

This Data Protection statement summarises how ColdMatch Group complies with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and equivalent laws. It supplements the Privacy Policy.

1. Controller and contact

ColdMatch Group is the controller of personal data processed via the platform for sourcing and marketing purposes. Privacy contact: privacy@coldmatchgroup.com. Where a supplier engages with a buyer following an introduction, that supplier acts as an independent controller for the personal data it processes to deliver the project.

2. Lawful bases

  • Contract / pre-contract steps — to provide the sourcing service, host your account and respond to RFQs.
  • Legitimate interests — to operate, secure and improve the platform, prevent fraud and misuse, and communicate about relevant services.
  • Consent — for optional analytics/marketing cookies and certain marketing communications; may be withdrawn at any time.
  • Legal obligation — for AML/CTF, sanctions, tax and accounting duties.

3. Categories of data

Contact and company data, RFQ content, financing assessment inputs, uploaded documents, usage and device data, and correspondence. We do not intentionally process special category data.

4. Recipients

Selected third-party suppliers, financing partners, logistics or insurance providers (only as required to prepare a quotation or fulfil a service), plus vetted subprocessors for hosting, authentication, email delivery, analytics, customer messaging and security.

5. International transfers

Personal data may be processed outside the EEA. Where required we rely on appropriate safeguards (Standard Contractual Clauses, adequacy decisions or equivalent).

6. Retention

We retain personal data only for as long as necessary for the purpose collected, to comply with legal obligations and to resolve disputes. Financing and AML records may be retained for the minimum period required by applicable law.

7. Data subject rights

Under GDPR you have the right to access, rectify, erase, restrict, port, object and (where processing is based on consent) withdraw consent. To exercise any of these rights, contact privacy@coldmatchgroup.com. You may lodge a complaint with your local supervisory authority.

8. Security

We implement appropriate technical and organisational measures, including encryption in transit, access controls, logging and least-privilege administration. See our Cyber Security & Responsible Disclosure policy.

9. Data breach

In the unlikely event of a personal data breach likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, affected data subjects, in line with GDPR Articles 33-34.


Related legal documents

Governing law: Republic of Cyprus · Exclusive jurisdiction: the competent courts of the Republic of Cyprus, without prejudice to any non-derogable rights available to users under mandatory local law. Contact: legal@coldmatchgroup.com.

Get QuotesFind the Best Solution