Skip to content

Privacy policy

Privacy and data protection

This policy explains what personal data TrueBell General Trading processes, the lawful bases we rely on, how long we keep records, where data may be transferred and the rights available to you.

Document
Privacy policy
Version
1.0
Effective
2 September 2026
Last updated
2 September 2026

Scope of this policy

This policy applies to personal data processed through this website, through enquiries and quotations, and through the supply, servicing and payment of hardware orders. It applies to visitors, enquirers, customer staff and supplier contacts.

Where the EU or UK General Data Protection Regulation applies to a given processing activity, this policy is written to meet its transparency requirements. Where other data protection laws apply to you, we apply the standard in this policy as a minimum and the stricter local requirement where one exists.

Controller and contact

TrueBell General Trading is the controller for the personal data described here. We determine why and how it is processed, except where we act on written instructions from a customer, in which case we act as a processor for that customer.

All privacy enquiries, including rights requests, should be sent to info@truebell.io. We do not require a specific form of words; a plain email is enough.

Personal data we process

  • Identity and contact data: name, job title, organisation, email address and postal or delivery address.
  • Enquiry and order data: specifications, quantities, quotations, purchase orders, delivery instructions, service tickets and correspondence.
  • Payment data: invoice reference, amount, currency, settlement confirmation, bank reference or, where crypto settlement is used, the transaction and wallet identifier. We do not store full card numbers; card details are handled by the payment provider.
  • Technical data: IP address, user agent and request time held briefly in server logs for security and reliability, plus aggregated page counts from Vercel Web Analytics (cookieless) only where you have allowed analytics.
  • Compliance data: sanctions, export control and anti-money-laundering checks on counterparties where an order requires them.

Purposes and lawful bases

We process personal data only where a lawful basis under Article 6 of the GDPR, or its equivalent in your jurisdiction, applies.

Processing activities and the basis relied on
PurposeLawful basis
Responding to enquiries and issuing quotationsSteps taken at your request prior to entering a contract (Art. 6(1)(b))
Fulfilling, delivering and supporting an orderPerformance of a contract (Art. 6(1)(b))
Invoicing, payment reconciliation and accounting recordsLegal obligation (Art. 6(1)(c)) and legitimate interests in being paid (Art. 6(1)(f))
Sanctions, export control and anti-money-laundering checksLegal obligation (Art. 6(1)(c))
Site security, fraud prevention and abuse detectionLegitimate interests in protecting our systems (Art. 6(1)(f))
Optional preference and analytics cookiesConsent (Art. 6(1)(a)), withdrawable at any time

Where we rely on legitimate interests we have assessed that our interest is not overridden by your rights and freedoms, and you may object as described below.

Special category data and children

We do not seek special category data as defined in Article 9 of the GDPR, and we ask that none is sent to us in enquiries. Where it reaches us unsolicited, it is deleted once identified.

This site and our services are directed at organisations, not children. We do not knowingly process the personal data of anyone under 16. If you believe we hold such data, write to us and we will delete it.

Where the data comes from

Most personal data comes directly from you or from a colleague acting for your organisation. Some comes from third parties in the course of an order, for example a distributor confirming a delivery contact, a carrier confirming receipt, a bank confirming a settlement, or a public sanctions list consulted for a compliance check.

Recipients and processors

We disclose personal data only where it is needed for the purposes above, and we place written terms on processors requiring confidentiality, security and processing on our instructions only, in line with Article 28 of the GDPR.

  • Manufacturers, distributors and repair partners, limited to what an order or warranty claim requires.
  • Freight forwarders, carriers and customs agents for delivery and clearance.
  • Banks, card processors and the operator of the wallet used for settlement.
  • IT, hosting and email providers that operate the systems we use.
  • Auditors, insurers and professional advisers under duties of confidence.
  • Public authorities where disclosure is required by law or by a valid legal request.

We do not sell personal data, do not share it for advertising, and do not use it for profiling or advertising-based targeting.

International transfers

We supply across several regions, so personal data may be transferred to, or accessed from, a country other than the one in which it was collected, including by our suppliers, carriers and service providers.

Where personal data protected by the EU or UK GDPR is transferred outside those territories, we rely on one of the following safeguards under Chapter V:

  • An adequacy decision covering the receiving country.
  • Standard Contractual Clauses adopted by the European Commission, together with the UK International Data Transfer Addendum where the UK GDPR applies, supported by a transfer risk assessment.
  • A derogation under Article 49 where a transfer is occasional and necessary to perform a contract with you, for example passing a delivery contact to a carrier in the destination country.

A copy of the relevant safeguard, with commercial terms redacted, is available on request from info@truebell.io.

Retention periods

We keep personal data only as long as it is needed for the purpose it was collected for, or as long as a legal or accounting rule requires. At the end of a period, records are deleted or anonymised.

Standard retention schedule
RecordPeriod
Enquiries that do not become orders24 months from last contact
Order, quotation and delivery records7 years from completion of the order
Invoices, payment and accounting recordsThe period required by applicable tax and accounting law, normally 7 years
Warranty and service historyDuration of warranty plus 2 years
Server and security logs90 days, on a rolling basis
Cookie consent record12 months, then you are asked again

Security and personal data breaches

We apply technical and organisational measures appropriate to the risk, as required by Article 32: access limited to those who need it, individually held accounts, multi-factor authentication on administrative systems, encryption in transit, controlled backups and supplier due diligence.

If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and we will inform affected people directly where the risk is high.

Your rights

Subject to the conditions in the applicable law, you have the following rights over your personal data.

  • Access: a copy of the personal data we hold about you and the information in this policy (Art. 15).
  • Rectification: correction of inaccurate or incomplete data (Art. 16).
  • Erasure: deletion where we no longer need the data and no legal duty requires us to keep it (Art. 17).
  • Restriction: a pause on processing while an accuracy or objection issue is resolved (Art. 18).
  • Portability: data you provided to us, in a structured, commonly used, machine-readable format (Art. 20).
  • Objection: to processing based on legitimate interests, including any direct marketing, which we stop on request (Art. 21).
  • Withdrawal of consent: at any time, without affecting processing carried out before withdrawal (Art. 7(3)).

How to make a request

Write to info@truebell.io describing what you want. We respond within one month of receipt and may extend by up to two further months for complex requests, telling you if we do. We may ask for enough information to confirm your identity. Requests are free unless they are manifestly unfounded or excessive.

Automated decisions

We do not make decisions producing legal or similarly significant effects about you by automated means alone, and we do not carry out automated profiling.

Complaints

Raise a concern with us first and we will try to resolve it. You also have the right to lodge a complaint with the data protection supervisory authority in the country where you live, work, or where you believe an infringement occurred (Art. 77).

Whether you have to provide data

Providing contact and order details is not a statutory requirement, but it is necessary to quote, supply and invoice. If it is not provided we cannot process an enquiry or fulfil an order. Compliance checks required by law cannot be waived.

Cookies

Cookies and similar technologies, the categories used, their purpose and how to change your choice are set out in the cookie policy. Optional cookies are set only after consent and can be withdrawn at any time from the footer.

Changes to this policy

We review this policy periodically and when our processing changes. The version number and effective date at the top of the page record each revision. Where a change is material we will make it plain on the site before it takes effect.

Questions

Need something clarified?

Write to us and we will answer in plain terms, including any request about the information we hold.

Contact usSend a specification and quantities