Privacy Policy
Last updated
This policy explains what personal data we collect when you use our website or contact us, why we process it, who we share it with, how long we keep it, and how you can exercise your rights.
1. General information
This Privacy Policy applies to our website, our contact and quotation forms, and the commercial relationships that follow from them. We process personal data under Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and other applicable European data-protection and electronic-communications rules.
Where a topic is covered in more detail elsewhere, we link to that document. See our Cookie Policy for tracking technologies and our Data Protection Notice for the short-form notice presented at the point of collection.
2. Data controller
Stronx ("we", "us") is the data controller for the personal data described in this document. You can reach our privacy team at info@example.com.
Please use the contact details above for privacy enquiries and requests. If a data protection officer or representative is appointed and required to be identified under applicable law, the relevant contact details will be added to this policy.
3. What information we collect
We collect only the data we need for the purpose it was given to us.
- Identity and contact data — full name, email address, telephone number, and the country you tell us you are writing from.
- Project data — the content of your message, the building type you are interested in, site location, intended use, and any drawings or specifications you choose to send us.
- Commercial data — quotation history, order and delivery records, invoicing details, and correspondence relating to a project.
- Technical data — IP address, browser and device type, operating system, referring page, and pages viewed. This is collected through server logs and, where you consent, analytics cookies.
- Marketing data — your consent status for commercial electronic messages and your interaction with those messages.
We do not ask for special categories of personal data (such as health, biometric, or belief data) and we ask that you do not include them in your messages.
4. Why we process your data
- Responding to enquiries and preparing quotations for prefab buildings and structures.
- Managing contracts, production planning, delivery, installation, and after-sales support.
- Meeting accounting, tax, customs, and other statutory obligations.
- Operating, securing, and improving our website and measuring how it is used.
- Sending campaigns, newsletters, and product announcements where you have given separate consent.
- Establishing, exercising, or defending legal claims.
5. Legal bases for processing
Each processing activity has a legal basis under Article 6 GDPR. The basis depends on why the data is needed and may change if the context changes.
| Processing activity | GDPR basis |
|---|---|
| Answering your enquiry and preparing a quotation | Steps taken at your request prior to entering a contract — Art. 6(1)(b) |
| Performing a supply, delivery, or installation contract | Performance of a contract — Art. 6(1)(b) |
| Invoicing, bookkeeping, and statutory record keeping | Compliance with a legal obligation — Art. 6(1)(c) |
| Website security, fraud prevention, and service improvement | Our legitimate interests — Art. 6(1)(f) |
| Analytics and marketing cookies, commercial electronic messages | Your consent — Art. 6(1)(a), together with applicable ePrivacy rules |
| Pursuing or defending legal claims | Our legitimate interests — Art. 6(1)(f) |
6. How we collect your data
- Forms on this website, including the contact and quotation forms.
- Email, telephone, and messaging applications you use to reach us.
- Trade fairs, dealer meetings, and other business events.
- Cookies and similar technologies, subject to your consent.
- Publicly available sources such as company registries, for business contacts.
7. Service providers we use
We work with a limited number of processors who act only on our documented instructions under a contract meeting Article 28 GDPR.
- Hosting and content delivery for this website.
- Email and office productivity services used to handle your correspondence.
- Web analytics, activated only after you accept analytics cookies.
- Accounting, logistics, and installation partners engaged for a specific project.
The providers used for a particular enquiry or project may change according to location and scope. You may ask us for further information about the relevant provider categories and safeguards. We do not sell personal data or allow service providers to use it for their own unrelated advertising.
9. International transfers
If personal data is transferred from the European Economic Area to a country or recipient without an applicable adequacy decision, we use a permitted Chapter V GDPR transfer mechanism after assessing the transfer. Depending on the circumstances, this may include the European Commission Standard Contractual Clauses and appropriate supplementary measures. You may ask us for information about the safeguard relevant to your data.
11. How we protect your data
We use technical and organisational measures selected according to the nature of the data, the processing context, and the risk to individuals, in line with Article 32 GDPR.
- TLS encryption for all traffic to and from this website.
- A restrictive Content Security Policy and modern security response headers.
- Role-based access control and the principle of least privilege for internal systems.
- Backup and recovery controls appropriate to the relevant system.
- Confidentiality undertakings and data protection training for staff with access.
If a personal data breach occurs, we assess it promptly and make notifications to regulators and affected individuals when and within the period required by the law that applies. The GDPR 72-hour supervisory-authority rule applies only where the GDPR and its notification threshold apply.
12. How long we keep your data
We keep personal data only for as long as the purpose requires, plus any statutory limitation period.
| Data category | Retention period |
|---|---|
| Enquiry and quotation records that do not lead to a contract | Up to 2 years from the last substantive contact, unless a longer period is needed for a claim or legal obligation |
| Contract, delivery, and warranty records | For the contract term and the applicable statutory limitation or record-keeping period |
| Invoices and statutory accounting records | For the period required by applicable tax and commercial-record legislation |
| Marketing consent records | While consent is active and for the legally required evidence period after withdrawal |
| Website server logs | Normally up to 12 months, unless security or legal needs require longer |
| Cookie consent records | 12 months, or until you change your choice |
At the end of the applicable period, data is deleted, destroyed, or anonymised.
13. Commercial electronic messages
We send campaigns, newsletters, and product announcements only to people who have opted in. Consent is separate from any contract, it is never a condition of receiving a quotation, and you can withdraw it at any time through the unsubscribe link in every message or by writing to us. The full terms are set out in our Electronic Communications Consent.
14. Your rights
Under Articles 15 to 22 GDPR, you may have the following rights, subject to their statutory conditions and exceptions.
- Access — obtain confirmation of whether we process your data and receive a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — request deletion where we no longer have a lawful reason to keep the data.
- Restriction — ask us to limit processing while a request or objection is assessed.
- Portability — receive the data you provided in a structured, machine-readable format and have it transmitted to another controller.
- Objection — object to processing based on our legitimate interests, and object at any time to direct marketing.
- Withdrawal of consent — withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Automated decisions — not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions.
Write to info@example.com to exercise any of these rights. We normally respond within one month, subject to the extensions permitted by GDPR. You may also complain to the competent data-protection supervisory authority in the EEA country where you live, work, or believe an infringement occurred.
15. Changes to this policy
We update this policy when our processing activities, service providers, or the applicable law change. The date at the top of this page always reflects the current version. Where a change materially affects you, we give notice before it takes effect.
16. Contact us
For any question about this policy or about how we handle your personal data, contact us at info@example.com, or use our contact form.











































