Business meeting

Privacy Policy

Business meeting

Privacy Policy

Business meeting

Privacy Policy

Privacy Policy

Effective Date: 18 June 2026

This Privacy Policy applies to all customers, suppliers, business partners, employees, and visitors to the Symbiochem Europe website and services. It describes how Symbiochem Europe (“we”, “us”, or “our”) collects, uses, stores, and protects your personal data in accordance with the EU General Data Protection Regulation (“GDPR”) and the UK General Data Protection Regulation (“UK GDPR”), as applicable.

This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it. We encourage you to read it in full before using our website or services.

1. Who We Are

Symbiochem Europe is a chemical and pharmaceutical supplier operating across multiple EU and UK jurisdictions. We act as the data controller for the personal data described in this policy, meaning we decide why and how it is processed. Our data protection contact details are set out in Section 13 (Contact Us).

2. Information We Collect

We may collect and process the following categories of personal data:

•       Name, job title, and employer or organisation

•       Business and personal contact details (email address, phone number, postal address)

•       Order, account, and transaction information

•       Regulatory and compliance documentation where required by law (for example, export-control or chemical-safety records)

•       Technical data collected via cookies and analytics tools when you visit our website (for example, IP address, browser type, and pages visited)

Where we collect personal data from a source other than you directly (for example, a business partner or public register), we will, where required by Article 14 GDPR, inform you of the source and categories of data concerned.

In most cases, providing personal data is necessary to enter into or perform a contract with us, or to comply with a legal or regulatory obligation. Where this is the case, and you choose not to provide the requested data, we may be unable to process your order, respond to your enquiry, or perform our contract with you.

3. How and Why We Use Your Information, and Our Legal Basis

We only process personal data where we have a lawful basis to do so under Article 6 GDPR. Our main purposes and the corresponding legal basis for each are set out below:

•       Processing orders, enquiries, and managing customer and supplier relationships — necessary for the performance of a contract with you, or to take steps at your request before entering into one.

•       Complying with legal, regulatory, and export-control requirements — necessary to comply with a legal obligation to which we are subject.

•       Communicating with you about products, services, and business matters — based on our legitimate interest in maintaining business relationships, or on your consent where the law requires it (for example, certain marketing communications, which you may withdraw at any time — see Section 9).

•       Maintaining the security and functionality of our website — necessary for our legitimate interest in operating a secure and reliable website.

•       Conducting internal analysis and improving our services — based on our legitimate interest in understanding and improving how our business operates, or on your consent where analytics cookies require it (see Section 7).

Where we rely on legitimate interests, we have considered that this processing is proportionate and does not override your rights and freedoms. You can ask us for more information about this assessment using the contact details in Section 13.

4. Automated Decision-Making


5. Sharing of Information

We do not sell or rent your personal data to third parties. We may share it with the following categories of recipients, where necessary to deliver our services or to comply with the law:

•       Logistics and delivery partners

•       IT, hosting, and software service providers

•       Professional advisers (for example, auditors, lawyers, and insurers)

•       Regulatory bodies and public authorities, where required by law

All third parties that process personal data on our behalf are required, by contract, to handle it securely and in line with their GDPR / UK GDPR obligations, and only on our documented instructions.

6. International Transfers


•       an adequacy decision by the European Commission or UK Government confirming the destination country provides an adequate level of protection; or

•       Standard Contractual Clauses (or, for UK transfers, the International Data Transfer Agreement / UK Addendum) approved by the relevant authorities, together with any supplementary measures needed to protect your data.

You can request more information about these safeguards, including how to obtain a copy, using the contact details in Section 13.



7. Cookies


•       Technical cookies — strictly necessary to deliver the website or a service you requested (for example, session, security, and load-balancing cookies). These do not require consent.

•       Analytics cookies — used to produce aggregated statistics about site usage. Where these are configured to mask or truncate identifying data (for example, masking part of the IP address) and the provider does not combine the data with other information it holds, they are treated like technical cookies and do not require consent; otherwise, consent is required.

•       Profiling and marketing cookies — used to remember your preferences or build a profile of your interests for more relevant communications. These always require your prior, freely given, specific, and informed consent.


8. Data Retention

We keep personal data only for as long as necessary to fulfil the purposes described in this policy, including to satisfy any legal, accounting, or reporting requirements. The criteria we use to set retention periods include the length of our ongoing relationship with you, our legal and regulatory obligations, and any applicable limitation periods for legal claims. Suggested retention periods, based on common practice for Italian/EU suppliers in the chemical and pharmaceutical sector, are:

•       Customer and supplier account / transaction records: 10 years from the end of the business relationship or invoice date

•       Regulatory and compliance documentation (e.g., pharmacovigilance / authorisation records): for the duration of the relevant product or marketing authorisation, plus 10 years after it lapses or is withdrawn

•       Website analytics data: 12–26 months from collection

•       Marketing contact preferences: until you withdraw consent or unsubscribe, after which we keep a minimal record of that choice (e.g., your email address and opt-out date) to demonstrate compliance with your request, as required by the accountability principle in Article 5(2) GDPR.

Once data is no longer required, we securely delete or anonymise it.

9. Your Rights

Subject to certain conditions and exemptions under the GDPR and UK GDPR, you have the following rights in relation to your personal data:

•       Right of access — to obtain a copy of the data we hold about you

•       Right to rectification — to request correction of inaccurate or incomplete data

•       Right to erasure — to request deletion of your data in certain circumstances

•       Right to restrict processing — to limit how we use your data

•       Right to data portability — to receive your data in a structured, commonly used, machine-readable format

•       Right to object — to object to processing based on our legitimate interests or for direct marketing purposes

•       Right to withdraw consent — where we rely on your consent (for example, for certain cookies or marketing communications), you may withdraw it at any time, free of charge, without affecting the lawfulness of processing carried out before your withdrawal

•       Right to lodge a complaint — with your national data protection authority (see Section 13 for details)

To exercise any of these rights, please contact us using the details in Section 13. We will normally respond within one month, as required by law.

10. Data Protection Officer and EU Representative

Under Article 37 GDPR, appointing a Data Protection Officer (DPO) is mandatory where an organisation's core activities involve regular and systematic monitoring of individuals on a large scale, or large-scale processing of special-category data (for example, health data). For a chemical/pharmaceutical supplier, this assessment typically turns on whether activities such as pharmacovigilance, clinical-data handling, or large-scale customer monitoring are a core part of the business, rather than an incidental one.


11. Security and Personal Data Breaches

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. In the event of a personal data breach, we will assess the risk it poses and, where required by law, notify the relevant supervisory authority within 72 hours and inform any affected individuals without undue delay.

12. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in the law. Where changes are significant, we will take reasonable steps to bring them to your attention (for example, via a notice on our website or by email). The “Effective Date” at the top of this policy shows when it was last revised, and we encourage you to review it periodically.

13. Contact Us

For any privacy-related queries, requests, or complaints, please contact: info@symbiochem.eu