Our GDPR commitment
Vantrex Global OÜ processes personal data in accordance with the EU General Data Protection Regulation and applicable Estonian data-protection law. We apply the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.
Data governance
We identify the purpose and lawful basis for processing, limit access according to need, select service providers with regard to data protection, maintain appropriate records and review processing when services or systems change. Where processing could create a high risk to individuals, we will assess that risk before the processing begins.
Individual rights
Requests to access, correct, erase, restrict or transfer personal data, object to processing, or withdraw consent may be sent to privacy@vantrexglobal.xyz. We may verify identity and will respond within the period required by applicable law.
Not every right applies in every circumstance. If we cannot fulfil a request in whole or in part, we will explain the applicable reason unless the law prevents us from doing so.
Security and incidents
We use risk-based technical and organisational safeguards, including access controls, secure service providers, operational monitoring and incident-handling procedures. If a personal-data breach creates a legally reportable risk, we will notify the competent supervisory authority and affected individuals as required by law.
Processors and transfers
Providers that process personal data for us are expected to act under appropriate contractual and confidentiality obligations. Transfers outside the EEA use a lawful transfer mechanism where required, such as an adequacy decision or Standard Contractual Clauses, together with supplementary safeguards where appropriate.
Privacy responsibility
Privacy enquiries should be sent to privacy@vantrexglobal.xyz. We will appoint a formal Data Protection Officer if our processing activities make one legally necessary.