Skip to content
Enveon
Contact

Privacy policy

This document describes how we process personal data when you use enveon.com and the contact channels described below.

Version 1.0Last updated:

1. Who we are

The controller of personal data processed through enveon.com is ENVN Distribution Limited, registration number HE479783, a company registered in Cyprus with its registered office at Troodous 4, Office No. 4, Industrial Area, 7100 Aradippou, Cyprus. It operates under the Enveon brand.

Our correspondence address is Korte Lijnbaanssteeg 1, Suite 4517, 1012 SL Amsterdam, Netherlands.

We have not appointed a Data Protection Officer. For privacy questions, see section 8.

2. What data we collect and why

We collect only the data we need. This site has no user accounts, sells nothing directly, and takes no job applications.

2.1 The contact form

When you use the contact form, we collect the topic you choose, your name, your company if you give one, your email address, your phone number if you give one, and the content of your message. We use them to answer you, and for nothing else. We do not add you to a mailing list.

Two topics ask for a few more details, because a report cannot be followed up without them:

  • A problem with a product: the product name, the batch number printed on the package, and where you bought it.
  • A suspected counterfeit: the link to the listing, or the name of the shop or seller, and where you saw it.

Give us only what the fields ask for. Please do not send us health information, and do not describe a medical condition: we have no need of it, we cannot advise on one, and it belongs to a special category of data under Art. 9 GDPR that we do not set out to process.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in answering the message you chose to send us, and yours in getting an answer. Where your message is about stocking our brands, Art. 6(1)(b) GDPR also applies, because the correspondence is a step taken at your request before a possible contract.

Where your message concerns a problem with a product or a suspected counterfeit, we also process it under Art. 6(1)(c) GDPR, because product safety and market surveillance obligations require us to record and follow up such reports.

You may object to processing under Art. 6(1)(f) at any time, under Art. 21 GDPR. In practice that means we stop handling your enquiry and delete it, unless one of the obligations above requires us to keep it.

2.2 Analytics and cookies

With your consent, we use Google Tag Manager, which may load further tags according to our container configuration. Google Consent Mode v2 defaults are set before any tag loads, so nothing measures you before you have answered our cookie banner.

Legal basis: Art. 6(1)(a) GDPR — your consent, given through the cookie banner. See the cookies policy for the detail.

3. How long we keep your data

Data Retention
Contact form: general and wholesale enquiries Up to 24 months from your message, or longer where a business relationship continues
Contact form: product problems and counterfeit reports, with the product, batch and purchase details given Up to 10 years, as product safety and traceability obligations require
Analytics and cookie data As each tool's retention settings and your consent choices define

After the retention period, data is deleted or anonymised.

4. Who we share your data with

We do not sell personal data. We share it only where it is needed to run the website, answer you, or comply with the law:

  • Mailgun Technologies, Inc., which delivers the messages our contact form sends, acting as our processor. We use its EU region, so messages are processed on infrastructure in the European Union.
  • Our hosting provider, which runs the website's infrastructure, acting as our processor.
  • Google Ireland Limited, for Google Tag Manager and any tags loaded through it, where you have consented.
  • Regulators and authorities, where the law or a valid legal request requires it. A counterfeit or product safety report may be passed to the competent authorities.

A processor may handle your data only on our instructions, under a data processing agreement, unless the law requires otherwise.

5. International data transfers

Some providers are based outside the European Economic Area, including in the United States. Where we transfer personal data to a country without an EU adequacy decision, we rely on the Standard Contractual Clauses approved by the European Commission under Art. 46(2)(c) GDPR.

Mailgun is a United States company. We use its EU region, so message content is processed within the European Union, and the Standard Contractual Clauses cover any transfer that nonetheless occurs.

You may ask us for more information about a transfer by writing to [email protected].

6. Your rights

Under the GDPR you have the right to:

  • Access — ask what data we hold and receive a copy
  • Rectification — ask us to correct data that is wrong or incomplete
  • Erasure — ask us to delete your data, in the cases the GDPR provides for
  • Restriction — ask us to limit how we process your data, in certain situations
  • Data portability — receive your data in a structured, machine-readable format, where it applies
  • Object — object to processing based on a legitimate interest
  • Withdraw consent — at any time, without affecting processing carried out before the withdrawal
  • Lodge a complaint — with a supervisory authority

To exercise a right, write to us using the details in section 8. We answer within 30 days.

Our registered office is in Cyprus, so the lead supervisory authority is the Office of the Commissioner for Personal Data Protection of Cyprus, at dataprotection.gov.cy. You may also complain to the authority of the country you live or work in.

7. Changes to this policy

We may update this policy, for example when the law or our practices change. The version and the date at the top of this page change with it. For a significant change, we will make a reasonable effort to tell you, for example through a notice on the website.

8. Contact us

Questions about this policy, requests to exercise a right, or concerns about how we handle data:

We answer within 30 days.