Privacy and data protection
How we handle personal data
This Privacy Policy explains how European-Standards.com collects, uses, shares and protects personal data when you browse the website, contact us, submit a standards or compliance project request, apply for a commercial partnership, or use links to independent external providers.
Purpose first
We collect information only for defined website, enquiry, matching, security and partnership purposes.
Controlled sharing
Project details are shared with independent providers only where the user requests or authorises that step.
No sale of personal data
We do not sell personal data or disclose it to unrelated parties for their independent mass-marketing purposes.
Who is responsible for your personal data?
Knowence, S.L., as the operator of European-Standards.com, is the data controller for the processing described in this Privacy Policy, unless a third-party service clearly identifies itself as a separate controller.
This email address may be used for privacy questions, data-subject requests and concerns about how information submitted through the website has been handled.
When this policy applies
This policy applies to personal data processed through:
- European-Standards.com and its public pages;
- general contact and correction requests;
- ISO, auditing, certification and compliance-support enquiries;
- laboratory testing, calibration and inspection requests;
- MDR, IVDR and medical-device consultancy requests;
- commercial partnership applications and related correspondence;
- website security, consent, analytics and performance tools; and
- commercial communications that you have requested or that are otherwise permitted by law.
It does not govern an independent website that you visit after leaving European-Standards.com. External standards catalogues, laboratories, consultants, certification bodies, payment providers and other third parties process data under their own privacy notices.
Personal data we may collect
Identity and business details
Name, role, company or organisation, business sector, company size, headquarters country, service countries, languages and website.
Contact details
Work email address and any telephone number or other contact detail that you voluntarily provide in a form or message.
Project and technical information
Relevant standards, products, services, test methods, intended use, project stage, locations, timing, budget range, deliverables and other information needed to understand a request.
Partnership information
Company type, areas of expertise, proposed partnership model, accreditation or certification evidence, public-register links, commercial objectives and supporting explanations.
Communications
Messages, attachments, follow-up correspondence, consent records, preferences and information needed to respond to or document a business relationship.
Technical and usage data
IP address, browser and device information, approximate location, referring page, pages viewed, timestamps, consent choices, security events and similar server or analytics data.
Do not send sensitive or unnecessary information
Initial forms are not intended for patient data, health records, passwords, payment-card details, full technical files, proprietary source code, criminal-record information or other highly confidential or special-category personal data. Use an agreed secure channel and, where appropriate, an NDA before sharing sensitive project material.
Please provide personal data relating to another person only when you are authorised to do so and have given that person any information required by applicable law.
Where the data comes from
We receive personal data:
- directly from you when you complete a form, email us or communicate with us;
- automatically from your browser, device, cookies, consent settings and server logs;
- from a colleague or representative who submits a request on behalf of an organisation;
- from selected independent providers when they update us about an enquiry or partnership; and
- from public company websites, accreditation databases, certification registers and other official sources when we verify provider claims or business information.
Where material personal data is obtained from another source, we will provide the information required by law unless an applicable exception applies.
Why we use personal data and our legal bases
| Purpose | Typical data | Legal basis |
|---|---|---|
| Operate, maintain and secure the website | Technical, device, log and security data | Legitimate interests in providing a secure and reliable service; legal obligations where applicable |
| Respond to questions, corrections and general contact | Identity, contact and message content | Steps requested before a possible contract and legitimate interests in responding to users |
| Review standards, testing, ISO, CE, MDR or IVDR project requests | Business, contact, project, timing and budget information | Steps requested before a possible contract; legitimate interests in operating the matching service |
| Share a project request with suitable independent providers | Contact and relevant project details | Your consent or the steps you expressly request to obtain quotations or professional support |
| Assess and manage commercial partnership applications | Company, representative, evidence and proposal information | Steps requested before a possible contract and legitimate interests in evaluating business partners |
| Measure website use and improve content | Cookie identifiers, pages viewed and interaction events | Consent where non-essential cookies or comparable technologies are used |
| Send requested updates or relevant business communications | Name, company, email and preferences | Consent or legitimate interests where permitted; you may object or unsubscribe at any time |
| Establish, exercise or defend legal claims and comply with law | Relevant records and communications | Legal obligations and legitimate interests |
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing already carried out lawfully before the withdrawal.
Project matching and independent providers
When you ask for ISO, certification, laboratory, CE-marking, MDR, IVDR or other professional support, European-Standards.com may review the information and identify one or more potentially suitable independent providers. We share only the information reasonably needed for the provider to understand and respond to the request.
- We do not guarantee that a provider will accept a project or issue a quotation.
- We do not make certification, accreditation, testing or regulatory decisions.
- Providers are responsible for verifying their own competence, scope, conflicts and availability.
- Once a provider receives an authorised enquiry, it may act as an independent data controller under its own privacy notice.
- You may ask us not to make a further introduction by emailing the privacy contact.
Commercial partnership applications
Partnership applications may be stored privately in the website’s administration system and sent to an authorised European-Standards.com business mailbox for review. We use the information to verify the applicant, assess relevance, request evidence, discuss a possible pilot or campaign and maintain a record of the decision.
Forms may use automated security checks, such as validation, duplicate detection, rate limiting or a hidden anti-spam field. These checks are intended to protect the website; they are not used to make a decision that produces legal or similarly significant effects. A legitimate applicant whose form is not accepted may contact us by email for manual review.
Standards catalogue searches and external websites
The standards search may send the reference, title or keyword you enter to an independent external catalogue provider. After you leave European-Standards.com, that provider controls its own catalogue, accounts, availability information, licensing, purchasing process and related personal-data processing.
Search interactions may also generate limited website analytics events when analytics consent is active. Do not enter names, email addresses, confidential project details or other personal data into the catalogue search field.
Other pages may link to official registers, standards bodies, laboratories, consultants, certification bodies, social networks, payment services or embedded external content. Review the relevant third party’s privacy information before providing personal data.
Cookies, consent and analytics
The website may use strictly necessary cookies or similar technologies for security, form operation, consent storage and core functionality. Non-essential analytics, personalisation or embedded third-party tools should be activated in accordance with the consent choices available on the website.
You can review or change available cookie choices through the website’s consent controls and find further information in the Cookie Policy. Browser settings can also delete or block cookies, although some website functions may then work differently.
Who may receive personal data?
Depending on the service used, recipients may include:
- website hosting, security, backup and technical-support providers;
- email, SMTP, form, database and customer-communication providers;
- cookie-consent, analytics and performance providers where enabled;
- selected independent laboratories, consultants, auditors, certification bodies or other providers when you request or authorise an introduction;
- an external standards catalogue or document-access provider when you use its search or purchasing route;
- payment, invoicing or accounting providers where a commercial transaction is agreed;
- professional advisers, insurers, auditors and prospective transaction advisers under appropriate confidentiality duties; and
- courts, regulators, law-enforcement bodies or public authorities where disclosure is required or permitted by law.
Service providers acting on our instructions are expected to process personal data only for agreed purposes and with appropriate safeguards. We do not sell personal data.
International data transfers
Some service providers or potential project partners may be located outside the European Economic Area. Where personal data is transferred internationally, we use an available lawful transfer mechanism and appropriate safeguards, such as an adequacy decision, approved standard contractual clauses or another mechanism recognised by applicable data protection law.
You may contact us for further information about the safeguards relevant to a particular transfer.
How long we keep personal data
We keep personal data only for as long as reasonably needed for the relevant purpose, legal duties, dispute management and security. The following are general retention periods and may be shortened or extended where the circumstances or law require it.
| Record | Typical retention approach |
|---|---|
| General contact and correction requests | Up to 24 months after the last meaningful interaction, unless a longer period is justified |
| Project-matching requests | Up to 24 months after closure or the last interaction; introduced providers apply their own retention rules |
| Unsuccessful partnership applications | Normally up to 24 months so that we can document the review and avoid repeated verification |
| Active commercial relationships | For the relationship and any additional period required for contracts, accounting, claims or legal obligations |
| Security and server logs | Normally up to 12 months, unless an incident or legal requirement justifies longer retention |
| Consent and objection records | For as long as needed to demonstrate the relevant choice and respect future objections |
| Cookie and analytics data | According to the applicable tool settings and the Cookie Policy |
Data may be anonymised so that it no longer identifies an individual. Anonymous information may be retained for research, statistics and service improvement.
Security
We use organisational and technical measures intended to protect personal data against accidental loss, unauthorised access, alteration and disclosure. Measures may include access controls, authenticated administration, encryption in transit, backups, updates, security monitoring and restricted access to submitted applications.
No online service can guarantee absolute security. Please do not use a public form to send information that requires a dedicated secure transfer method.
Your data-protection rights
Subject to the conditions in applicable law, you may have the right to:
Access
Ask whether we process your personal data and obtain a copy and related information.
Rectification
Correct inaccurate data and complete information that is materially incomplete.
Erasure
Request deletion where the data is no longer needed or another legal condition applies.
Restriction
Ask us to limit processing in specified circumstances.
Portability
Receive eligible data in a structured, commonly used, machine-readable format.
Object
Object to direct marketing and, in certain cases, processing based on legitimate interests.
Withdraw consent
Withdraw consent at any time where consent is the legal basis.
Complain
Lodge a complaint with the competent data-protection supervisory authority.
Send a request to info@european-standards.com. State the right you wish to exercise and provide enough information for us to locate the relevant record. We may request proportionate proof of identity before disclosing or changing personal data.
We normally respond within one month, subject to the extensions and exceptions allowed by law. Requests are generally free of charge, although the law permits a reasonable fee or refusal where a request is manifestly unfounded or excessive.
You may also complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority, particularly in the country where you live or work. Visit the AEPD website.
Automated decisions and profiling
We do not use personal data to make solely automated decisions that produce legal or similarly significant effects. Automated tools may be used for spam prevention, duplicate detection, security, routing support and aggregate analytics. Material provider-matching and partnership decisions are subject to human review.
Children
European-Standards.com is intended for business, technical, academic and professional audiences and is not directed to children. We do not knowingly request personal data from children through our commercial or project-enquiry forms. Contact us if you believe a child has submitted personal data inappropriately.
Changes to this Privacy Policy
We may update this policy when the website, forms, providers, commercial model or legal requirements change. The revised version will be published on this page with an updated date. Where a change is material and appropriate, we may also provide an additional notice.
Privacy contact
Questions or a data request?
Contact us by email and include the page, form or interaction concerned so we can locate the relevant information efficiently.
