GDPR Compliance — Sustalium

Hanya Inggris: Halaman ini hanya tersedia dalam bahasa Inggris. Untuk pertanyaan, hubungi kami dalam bahasa Inggris atau gunakan alat terjemahan.

Document Ref: GDPR-Pol-2026-V1.3 · Last updated: 31 August 2026

At Sustalium B.V., data privacy and security are foundational to our compliance intelligence platform. We are fully committed to complying with the General Data Protection Regulation (GDPR) and empowering our customers and their supply chain partners with control over their personal data.

Because we provide B2B services, we primarily process business-context personal data (such as work emails and roles). We do not process special category data (such as health or biometric data).

Our GDPR Commitments

  • Lawful Basis: We only process data when we have a valid legal basis (consent, contract, legitimate interest, or legal obligation).
  • Data Minimization: We collect only the data strictly necessary to generate compliance assets and verify supply chains.
  • Transparency: Our Privacy Policy clearly explains what data we collect, why we collect it, and our trusted EU-centric sub-processors.
  • Security by Design: We protect data using enterprise-grade Technical and Organizational Measures (TOMs), including encryption at rest and in transit, Multi-Factor Authentication (MFA), and tenant isolation.
  • Data Retention: We keep personal data only for as long as necessary. (Account data is deleted within 90 days of contract termination). See our Data Retention Policy.

Your Rights Under GDPR

As a data subject, you have the following rights regarding your personal data:

  • Right to Access: Request a copy of your personal data.
  • Right to Rectification: Correct any inaccurate or incomplete data.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data.

    Please note: To ensure global trade compliance and regulatory integrity, Sustalium must retain immutable, cryptographically-anchored compliance ledger records for a minimum of 10 years. In the event of an erasure request, personal data will be redacted/anonymized, but the underlying compliance anchor will be retained.

  • Right to Restriction: Limit how we process your data.
  • Right to Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to certain types of processing (such as direct marketing).
  • Right to Withdraw Consent: Withdraw your consent at any time, where processing is based on consent.

Exercising Your Rights

To submit a Data Subject Request (DSR) or to ask any questions about how we handle your data, please contact our Privacy Team directly at:

Email: privacy@sustalium.com

We will verify your identity and respond to all valid requests within 30 days, as required by the GDPR. If your request pertains to data where a Sustalium Customer is the Data Controller (e.g., you are a supplier to one of our customers), we will promptly forward your request to the relevant Customer and assist them in fulfilling it.

Supervisory Authority

If you believe we have not complied with data protection laws, you have the right to lodge a complaint with your local supervisory authority. As Sustalium B.V. is headquartered in The Hague, our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).