← HomeTerms of ServicePrivacy PolicyCookiesCompany details

Privacy Policy

Last updated: 29 July 2026

This policy explains how LEGAL NAME — TO BE COMPLETED handles personal data on zenwholesale.store, under the EU General Data Protection Regulation (GDPR) and Greek Law 4624/2019.

1. Controller

LEGAL NAME — TO BE COMPLETED, STREET ADDRESS — TO BE COMPLETED, POSTCODE — TO BE COMPLETED CITY — TO BE COMPLETED, Greece.
Data protection contact: CONTACT EMAIL — TO BE COMPLETED

We have not appointed a Data Protection Officer; we are not required to. Our core activity is wholesale distribution, not large-scale monitoring or processing of special categories of data.

2. What we collect

DataWhyLawful basis
Business name, VAT number, address, countryVerifying you are a genuine VAT-registered business; invoicing; VAT reportingContract; legal obligation
Contact name, email, phoneAccount administration and order correspondenceContract
Password (hashed with argon2id — never stored in readable form)AuthenticationContract
Two-factor secret (encrypted at rest), for administratorsProtecting administrative accessLegitimate interest — security
Order requests, offers, backorders and their historyFulfilling and evidencing transactionsContract; legal obligation
Security log: action, timestamp, actor, hashed IP addressDetecting abuse; tamper-evident record of who changed whatLegitimate interest — security and fraud prevention
Session cookie and interface preferencesKeeping you signed in; remembering your catalog layoutStrictly necessary — no consent required

We do not collect payment card data — no payment is taken through this site. We do not knowingly collect data about anyone under 18, and the Platform is not directed at consumers.

3. Where your data goes

We use a small number of processors, each bound by a data processing agreement:

  • Neon — database hosting, EU region (Frankfurt, Germany).
  • Netcup — application server hosting, Germany.
  • Resend — transactional email, where enabled.
  • Discord — internal notifications to our own staff channel. These contain business contact details of new applicants and order summaries.
  • Cloudflare — bot protection on the registration form, where enabled.

We also submit VAT numbers to the European Commission's VIES service to verify them. We do not sell personal data or share it for advertising.

Transfers outside the EEA

Our database and application servers are in the EU. Some processors (Resend, Discord, Cloudflare) are US-based and may process data outside the EEA under Standard Contractual Clauses and/or the EU–US Data Privacy Framework.

4. How long we keep it

  • Account and company records — for the life of the account, then up to 12 months.
  • Invoices, orders and accounting records — 10 years, as required by Greek tax law. This overrides deletion requests.
  • Security log — 24 months.
  • Rejected applications — 6 months, so we can recognise re-applications.

5. Your rights

Under the GDPR you may request:

  • access to your personal data, and a copy in a portable format;
  • rectification of inaccurate data;
  • erasure, where we have no overriding legal obligation to retain it;
  • restriction of, or objection to, processing based on legitimate interests;
  • withdrawal of consent, where processing relies on consent.

Email CONTACT EMAIL — TO BE COMPLETED. We respond within one month. There is no automated decision-making that produces legal effects: account approval is a human decision.

You may also complain to the Greek Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens — dpa.gr.

6. Security

Traffic is encrypted with HTTPS. Passwords are hashed with argon2id. Administrator access requires two-factor authentication. Wholesale prices are protected at both the application and database layers, so an unapproved account cannot read them even if application code is at fault. Administrative actions are written to a tamper-evident, hash-chained log. We will notify you and the supervisory authority of a qualifying personal data breach without undue delay.

7. Changes

We will post any changes here and update the date above. See also our Cookie Policy and Terms of Service.

Zen Wholesale · B2B only · VAT 0% on valid intra-EU supplies
TermsPrivacyCookiesCompany details