Privacy Policy

Last Updated: 2025/05/16

EU Regulus GmbH (“we,” “us,” or “our”) acts as an EU Responsible Person (RP) under Regulation (EU) 2023/988 (GPSR). This Privacy Policy explains how we collect, use, and protect the personal data of our clients (“Party A”) and their end-users in compliance with the EU General Data Protection Regulation (GDPR).

1. Data We Collect

We may process the following data:

  • From Party A (Manufacturer):
  • Company name, address, registration details, contact details (name, email address, phone number).
  • Product categories, Product technical documentation (e.g., CE certificates, test reports).
  • Information about how you use our website, including IP address, browser type and access time.
  • EU market sales records (as required by GPSR).
  • From End-Users (via Party A):
  • Product-related incident reports (e.g., safety complaints).
  • Contact details only if directly provided for recalls or investigations.

2. Purpose of Processing

We use data strictly for:

  • Fulfilling our obligations as an EU RP under GPSR (e.g., communicating with EU authorities).
  • Process registration, contracts, and payment for your selected services plan.
  • Respond to your inquiries and provide support.
  • Assisting with product recalls or safety investigations at extra cost.
  • Maintaining records as mandated by GPSR (10-year retention).

3. Legal Basis

  • Contractual Necessity: Processing is required to perform our RP services under the signed agreement.
  • Legal Obligation: Compliance with GPSR and EU product safety laws.
  • Legitimate Interest: Responding to regulatory requests or safety incidents.

4. Data Sharing & Transfers

  • With EU Authorities: Only when legally required (e.g., product safety audits).
  • Third-Party Service Providers: Secure cloud storage, payment processors, email platforms or legal advisors (under strict GDPR-compliant agreements).
  • Our internal compliance and legal team.
  • No Cross-Border Transfers: Data remains within the EU/EEA unless otherwise agreed.

5. Data Retention

  • Party A’s Documents: 10 years (as per GPSR and our contract).
  • End-User Data: Deleted after resolving safety inquiries or recall actions.

6. Your Rights

Under GDPR, you may:

  • Request access, update or deletion of your data (where applicable).
  • Withdraw consent (if processing is consent-based).

7. Security Measures

We implement:

  • Encryption for digital files.
  • Access controls to limit internal data exposure.
  • Regular audits of data handling practices.[QL1] 

8. Contact Us

For GDPR requests or questions:
Email: service@eu-regulus.com

9. Cookies and Website Tracking

We may use cookies and analytics tools to enhance your browsing experience. You can control or disable cookies through your browser settings.[QL2] 

10. Policy Updates

We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised effective date.