top of page

Data Protection Policy Based On GDPR 

Data Protection Policy

This data protection policy outlines how Vestis Labs SARL collects, processes, and protects personal data in compliance with GDPR.

Who is the controller for the processing of your data?

VESTIS LABS SARL

9, Avenue des Hauts-Fourneaux

L - 4362 Esch-sur-Alzette

RCS : B254459

Email: info@vestislabs.com

Why do we process your personal data?

We collect your personal data to provide you with our services, to communicate with you, and to improve our services. We may also share your personal information with our partners who help us provide our services.

 

We process your personal data for the following purposes:

Prospecting

 

We may collect and use your personal information to identify potential customers and partners.

 

General survey: we may use your personal information to conduct surveys and research about our products and services.

Company development: we may use your personal information to develop new products and services, improve our existing products and services, and better understand our customers.

Legitimate interest: prospecting for business customers, development of economic activities

What personal data?

Classic identifiers (last name, first name, address, telephone), electronic identifiers, administrative data, sector data, function, language, currency, financial details, representative, content of the communications, business information.

How did we collect the data?

Data subject, official databases, commercial (public) databases, platform users, site visits, social networking platforms, newsletter sign ups, and personal contacts.

How long do we retain the data? 

Three (3) years after the last contact from the prospect.

With whom is the data shared?

We may share your personal information with our service providers.

Client management and operations

We may collect and use personal information for the following purposes:

Management of sales: We may user personal data to manage our sales activities, such as contacting Clients about products and services, and processing orders.

Execution of a contract: We may use personal data to execute contracts with Clients, such as providing products and services, and processing payments.

Legal obligation: We may use personal data to comply with legal obligations, such as tax laws and regulations.

Legitimate interest: execution of a contract, legal obligations

What personal data?

Classic identifiers (last name, first name, address, telephone), electronic identifiers, administrative data, sector data, function, language, currency, financial details, representative, content of the communications, business information.

How did we collect the data?

Data subject, official databases, commercial (public) databases, platform users, site visits, social networking platforms, newsletter sign ups, and personal contacts.

How long do we retain the data? 

Ten (10) years from the end of the contract.

With whom is the data shared?

We may share your personal information with our service providers and public administrations.

 

Social media network management

We may use personal data that we collect from you when you interact with our social media network for the following purposes:

Technical administration of accounts such as creation and publications.

Interactions, including public and private messaging, with subscribers/users and other platform users.

Usage statistics tracking and analysis.

Legitimate interest: account management, website operation, research and analytics, sales and marketing, network integrity and customer support.

What personal data?

Data visible by default on the platforms: first and last name or pseudonym, profile picture or avatar, presentation message, publications, content and messages exchanged, data made public by the users as part of their general settings on the platform concerned, platform usage data for the production of anonymous statistics.

How did we collect the data?

Platform users, site visits, social networking platforms, direct communications through social platforms.

How long do we retain the data? 

Five (5) years from the end of the business relationship, 5 additional years maximum when required by the supervisory authority.

 

With whom is the data shared?

We may share your personal information with our service providers and public administrations.

Supplier management

We may use personal data for the purpose of selction, order follow-up, accounting, administration, and quality control. 

Legitimate interest: execution of a contract, legal obligations.

What personal data?

Classic identifiers (last name, first name, address, telephone), electronic identifiers, administrative data, financial data, and content of the communications.

How did we collect the data?

Data subject, official databases, commercial (public) databases.

How long do we retain the data? 

Ten (10) years from the end of the contract.

 

With whom is the data shared?

Public administrations.

What are your rights and how do you exercise them?

Right to Access

You have the right to request access to your personal data that we maintain.  While we endeavor to provide you with a copy of this information, it is important to note that this may not be feasible for all categories of documents to safeguard the rights and liberties of other individuals.

Right to Rectification

If your personal data is inaccurate, you have the right to request the correction of inaccurate data.  If your data is incomplete, you have the right to have the data completed, including by means of providing supplementary information.

Right to Be Forgotten or Right to Erasure

You have the right to request the deletion of your personal data under specific circumstances, such as when the data is no longer necessary for the purposes for which it was collected.  However, under the circumstances where we are legally obliged to retain certain personal data, we are not able to comply with this request.

Right to Restriction of Processing

You can request the restriction of processing of their personal data under certain circumstances, such as to contest the accuracy of the data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and have the right to transfer the data in a safe and secure way, where technically feasible.  This right applies where the processing is based on your consent or on a contract to which you are party and the processing is carried out by automated means.  However, there are instances where we may not be able to comply with the request if the request is too complex or would require disproportionate effort.

Right to Object

You have the right to object to the processing of your personal data at any time, on grounds relating to your particular sitatuions.  If you object, we will no longer process your personal data unless we can demontsrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims. 

Right to Withdraw Consent

You have the right to withdraw your consent to the processing of your personal data at any time.  The withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.

Right to Lodge a Compaint

You have the right to lodge a complaint with a supervisory authority if you believe that your data protection rights have been infringed.  For your reference, the supervisory authority is;

 

CNPD

15, Boulevard du Jazz

L-4370 Belvaux

Tel: (+352) 26 10 60 -1

These rights are instituted to uphold the principles of data protection and ensure compliance with prevailing legal requirements. We are committed to facilitating the exercise of these rights while upholding the legal and ethical obligations that pertain to our data processing activities.

Exercising Your Rights

To exercise your rights under the GDPR, you can contact us at info@vestislabs.com

 

In the event of you contacting us to exercise your rights, we will respond within one month. This period may be extended by up to three months in exceptional circumstances, in which case we will inform you of the reason for the delay within one month of your request. Whether or not you will be able to exercise your rights will depend on the processing and the legal basis.

 

When exercisiong your rights, please ensure to clearly state which right you wish to exercise and how you would like to receive the information (e.g., by email, post, verbally, etc.). In some cases, we may need additional information to verify your identity and ensure that we are providing the information to the correct person.

bottom of page