PRIVACY POLICY OF THE SERVICE

DEFINITIONS  

Data Controller – Aldrich International, a company registered in the United Arab Emirates, Dubai, and located at 1514, Grosvenor Business Tower, TECOM, Dubai, UAE.

Personal Data – information about a natural person who is identified or identifiable by one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity, including device IP address, location data, online identifiers, and information collected via cookies and/or similar technologies.

Policy – this Privacy Policy.

GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of personal data and on the free movement of such data, and repealing Directive 95/46/EC.

UAE PDPL – Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.

Service – the website operated by the Data Controller at https://www.aldrich.me

User – any natural person visiting the Website or using one or more services or functionalities described in this Policy.

DATA PROCESSING IN CONNECTION WITH THE USE OF THE WEBSITE  

In connection with the User’s use of the Website, the Data Controller collects personal data to the extent necessary to provide services offered and to ensure the proper functioning, security, and improvement of the Website, as well as information relating to User activity on the Website.

Detailed rules and purposes of processing Personal Data collected during use of the Website are described below.

System logs containing technical activity data are also collected and processed for security, operational, and administrative purposes.

PURPOSES AND LEGAL BASIS FOR DATA PROCESSING ON THE WEBSITE  

USING THE SERVICE  

Personal data of all persons using the Website (including IP address, device identifiers, and information collected via cookies or similar technologies) are processed by the Data Controller:

  • to provide electronic services and make Website content available to Users – the legal basis is necessity for performance of a contract (Article 6(1)(b) GDPR);
  • for analytical and statistical purposes – the legal basis is the legitimate interest of the Data Controller (Article 6(1)(f) GDPR), consisting of improving Website functionality and services;
  • for security, fraud prevention, and protection of rights – the legal basis is legitimate interest (Article 6(1)(f) GDPR / UAE PDPL equivalent).

The User’s activity on the Website, including personal data, is recorded in system logs. These logs are used for:

  • service provision,
  • technical administration,
  • system security and monitoring,
  • analytical and statistical evaluation.

The legal basis is the legitimate interest of the Data Controller (Article 6(1)(f) GDPR).

Users may only publish personal data of third parties where such publication is lawful and does not infringe personal rights.

CONTACT FORMS  

The Data Controller provides electronic contact forms for communication.

Use of the form requires providing personal data necessary to identify the sender and respond to the inquiry. Mandatory fields are required to process the request. Optional data may be provided voluntarily.

Personal data is processed:

  • to identify the sender and handle inquiries – legal basis is performance of a contract or pre-contractual steps (Article 6(1)(b) GDPR);
  • for optional data – legal basis is consent (Article 6(1)(a) GDPR);
  • for analytical and statistical purposes – legal basis is legitimate interest (Article 6(1)(f) GDPR).

NEWSLETTER  

The Data Controller provides a newsletter service to Users who provide their email address.

Providing data is required to receive the newsletter.

Personal data is processed:

  • to provide newsletter services – legal basis is consent (Article 6(1)(a) GDPR / UAE PDPL);
  • for marketing content within newsletter communications – legal basis is consent and/or legitimate interest where permitted by law;
  • for analytical and statistical purposes – legitimate interest (Article 6(1)(f) GDPR);
  • for legal protection purposes – legitimate interest (Article 6(1)(f) GDPR).

Consent may be withdrawn at any time.

DIRECT MARKETING  

The User’s personal data may be used to deliver marketing communications via email, SMS, telephone, or similar channels only where the User has provided consent.

Consent may be withdrawn at any time.

The Data Controller may also, in limited cases, use postal marketing. Users have the right to object to such processing.

SOCIAL MEDIA  

The Data Controller processes personal data of Users visiting its social media profiles (YouTube, LinkedIn) for communication, marketing, and brand promotion purposes.

The legal basis is legitimate interest (Article 6(1)(f) GDPR), consisting of promoting the Data Controller’s services and activities.

SOCIAL MEDIA PLUGINS  

The Website uses plugins from social media platforms (LinkedIn, YouTube).

When such plugins are activated, the User’s browser may transmit data to the respective social media platform, even if the User does not have an account.

The Data Controller does not control the scope or purpose of data collected by these platforms.

Users are encouraged to review:

  • LinkedIn Privacy Policy
  • YouTube Privacy Policy

Where required, plugins are activated only after user consent.

COOKIES AND SIMILAR TECHNOLOGY  

Cookies are small text files installed on the User’s device when browsing the Website. They are used to improve functionality, usability, and analytics.

“SERVICE” COOKIES  

The Data Controller uses service cookies to:

  • ensure proper Website operation,
  • improve user experience,
  • maintain security.

These include:

  • session cookies,
  • authentication cookies,
  • security cookies,
  • interface customization cookies.

ANALYTICAL AND MARKETING TOOLS USED BY THE DATA CONTROLLER’S PARTNERS  

The Data Controller uses third-party analytical and marketing tools.

GOOGLE ANALYTICS AND LEADFEEDER  

Google Analytics cookies are used to analyze Website usage, generate reports, and improve services. Google does not identify Users personally.

Leadfeeder uses IP-based analytics to determine business-related Website visits. Only business IP data is used; non-business IPs are excluded. The _lfa cookie is stored for up to 2 years.

COOKIES SETTINGS MANAGEMENT  

Cookies requiring consent are only used after the User has provided consent.

Consent may be withdrawn at any time via browser settings or privacy tools.

Users can manage cookies through:

Internet Explorer: https://support.microsoft.com/en-en/help/17442/windows-internet-explorer-delete-manage-cookies
Mozilla Firefox: https://support.mozilla.org/en/kb/ciasteczka
Google Chrome: https://support.google.com/chrome/bin/answer.py?hl=en&answer=95647
Opera: https://help.opera.com/Windows/12.10/en/cookies.html
Safari: https://support.apple.com/kb/PH5042?locale=en-GB

RETENTION OF PERSONAL DATA  

Personal data is retained only for as long as necessary for the purposes for which it was collected.

Retention periods include:

  • service duration or contract period,
  • until consent is withdrawn,
  • until objection is raised where processing is based on legitimate interest.

Data may be retained longer where necessary to:

  • establish or defend legal claims,
  • comply with legal obligations.

After retention periods, data is securely deleted or anonymized.

USER’S RIGHTS  

Users have the right to:

  • access their personal data,
  • rectify inaccurate data,
  • request deletion,
  • restrict processing,
  • object to processing,
  • data portability,
  • withdraw consent at any time,
  • lodge a complaint with a supervisory authority.

Users may object to processing for marketing purposes at any time.

DATA RECIPIENTS  

Personal data may be shared with:

  • IT service providers,
  • hosting providers,
  • accounting and administrative providers,
  • payment processors,
  • courier services,
  • marketing service providers,
  • affiliated entities.

Data may also be disclosed to authorities where legally required.

Personal data is not sold to third parties.

TRANSFER OF DATA OUTSIDE EEA  

Personal data may be transferred outside the EEA, including to the UAE and other jurisdictions.

Such transfers are safeguarded using:

  • European Commission adequacy decisions,
  • Standard Contractual Clauses (SCCs),
  • other lawful transfer mechanisms.

Users are informed where such transfers occur.

SECURITY OF PERSONAL DATA  

The Data Controller applies appropriate technical and organizational measures, including:

  • access control systems,
  • encryption where applicable,
  • monitoring and logging systems,
  • secure infrastructure,
  • confidentiality obligations for personnel.

CONTACT DETAILS  

Contact with the Data Controller is possible via:
Email: support@aldrich.ae
Address: Aldrich International, Dubai, United Arab Emirates

For data protection matters, Users may contact the same address.

PRIVACY POLICY AMENDMENTS  

This Policy is reviewed regularly and may be updated from time to time.

The latest version is always available on the Website and includes the effective date stated above