Privacy Policy
Last updated: July 9, 2026
[CAPSOIL LEGAL ENTITY NAME] (“Capsoil”, “we”, “us”) respects your privacy. This policy explains what personal data we collect through this website and our client onboarding and ordering processes, why we collect it, and the rights you have over it.
This website serves business customers only. The personal data we process is primarily the business contact information of people acting on behalf of a company — but it is still personal data, and we treat it accordingly.
1. Who we are
[CAPSOIL LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
Email: [PRIVACY EMAIL]
For visitors in the European Union: [IF REQUIRED — NAME AND CONTACT OF EU REPRESENTATIVE UNDER ART. 27 GDPR, OR REMOVE THIS PARAGRAPH].
2. What we collect
Client onboarding (Request Access form)
Company details — company name, country, brand names, legal entity name, business registration number / tax ID.
Contact details — primary contact name, title, email address, phone number; accounts payable contact name, email, and phone.
Addresses — billing and shipping addresses, receiving hours and delivery protocols.
Documents — reseller permits and tax forms (e.g. W-9) you choose to upload. These may contain personal data such as names and signatures.
Account and ordering
Account data — username, email address, password (stored hashed), and the approval status of your company account, including a log of approval decisions.
Order data — products ordered, quantities and formats (including sample requests), order history, invoices, and delivery details.
Payment data — processed by our payment provider [PAYMENT PROVIDER NAME]. We do not store full card numbers on our systems.
Communications
Messages you send through our contact and product inquiry forms, TDS/documentation requests, and email correspondence with our team.
Technical data
IP address, browser type, pages visited, and similar log data collected automatically by our hosting infrastructure for security and troubleshooting.
Cookies and similar technologies — see section 8.
3. Why we process it (legal bases)
Purpose Legal basis (GDPR)
Reviewing and approving client account requests; verifying business credentials Steps prior to entering a contract (Art. 6(1)(b)); legitimate interest in selling only to qualified businesses (Art. 6(1)(f))
Providing the gated catalog, processing orders, samples, delivery, and invoicing Performance of a contract (Art. 6(1)(b))
Tax, accounting, and export-control record keeping Legal obligation (Art. 6(1)(c))
Responding to inquiries and sending service communications (e.g. approval decisions, order updates) Legitimate interest / contract performance
Site security, fraud prevention, and access control Legitimate interest (Art. 6(1)(f))
Marketing communications to business contacts Legitimate interest, or consent where required by local law; you can opt out at any time
Non-essential cookies / analytics Consent (Art. 6(1)(a))
4. Who we share it with
We do not sell personal data. We share it only with service providers who process it on our behalf under contract, and with authorities where legally required:
Hosting — our website is hosted by [HOSTING PROVIDER, e.g. Cloudways / DigitalOcean, LOCATION OF SERVERS].
Payments — [PAYMENT PROVIDER NAME].
Shipping and logistics — carriers and freight forwarders, who receive delivery contact details.
Professional services — accountants, auditors, and legal advisers where necessary.
Email delivery — [EMAIL / TRANSACTIONAL MAIL PROVIDER].
5. International transfers
We operate internationally, and your data may be processed outside the country where you are located, including in [SERVER / COMPANY LOCATIONS]. Where data of EU/EEA or UK residents is transferred to countries without an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
6. How long we keep it
Client account and onboarding data — for the duration of the business relationship, plus [X] years after the account is closed or the request is rejected.
Order, invoice, and tax records — as required by applicable tax and commercial law (typically 7–10 years).
Inquiry messages — up to [X] years after the inquiry is resolved.
Uploaded documents (permits, tax forms) — for as long as needed to satisfy the verification or legal purpose they were collected for.
7. Your rights
Depending on where you are located, you may have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent at any time. EU/EEA residents also have the right to lodge a complaint with their local supervisory authority.
To exercise any of these rights, contact us at [PRIVACY EMAIL]. We will respond within the timelines required by applicable law.
8. Cookies
We use cookies that are strictly necessary for the site to function — including session cookies that keep you logged in to your client account and remember your cart. [IF ANALYTICS / MARKETING COOKIES ARE USED: We also use analytics cookies ([TOOL NAMES]) — these are set only with your consent, which you can give or withdraw via the cookie banner.]
9. Security
We apply appropriate technical and organizational measures to protect your data, including encrypted connections (HTTPS), hashed passwords, role-based access to client records, and restriction of the ordering environment to approved accounts. No system is completely secure; if a breach affecting your data occurs, we will notify you and the relevant authorities as required by law.
10. Children
This website is intended for business users and is not directed at children. We do not knowingly collect data from anyone under 16.
11. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of this page shows the current version. Material changes will be communicated to registered clients by email.
12. Contact
Questions about this policy or our data practices: [PRIVACY EMAIL] or write to us at [REGISTERED ADDRESS].