1. Data controller
For European business contacts, the data controller is Leuchtturm Albenverlag GmbH & Co. KG, Am Spakenberg 45, 21502 Geesthacht, Germany. For North American business contacts, the data controller is Leuchtturm1917 US Distribution, 62 Tidewater Drive, Pawtucket, Rhode Island 02860, USA.
2. Categories of personal data
We process limited business-context personal data: name, work email, work phone, employer, job title and country. We do not collect special-category data. Free-text fields in the RFP intake form should be used only for specification content, not for personal data unrelated to the procurement enquiry.
3. Purposes & legal bases
Personal data is processed to respond to RFPs, to operate buyer codes, to maintain customer accounts, to despatch quotes and samples, and to support EDI / punchout integration. The legal bases under the EU General Data Protection Regulation are the performance of a contract (Article 6(1)(b)) and our legitimate business interest in administering a B2B catalog (Article 6(1)(f)).
4. Recipients
Personal data is shared internally with category managers, the audit desk, the despatch team and accounts receivable on a need-to-know basis. External recipients are limited to logistics partners, payment processors, the EDI gateway operator and certificate auditors. We do not sell personal data, nor do we share it with marketing aggregators.
5. International transfers
EU procurement data may be transferred to the United States distribution centre for accounts served from Pawtucket. Such transfers are governed by the Standard Contractual Clauses adopted by the European Commission, supplemented by the technical and organisational measures described in our intra-group data agreement.
6. Retention
Active buyer-code records are retained for the duration of the business relationship plus statutory archival periods (typically ten years under German commercial law). Closed RFPs that did not lead to a contract are retained for thirty-six months. Marketing-consent records are reviewed annually and purged if no longer current.
7. Your rights
Business contacts have the right to access, rectify, erase, restrict or object to the processing of their personal data, and the right to data portability where applicable. Requests should be sent to [email protected] and are answered within thirty calendar days.
8. Cookies & analytics
This site uses strictly necessary cookies to operate the Catalog Builder session and a small set of analytics cookies to measure the volume of catalog requests. Analytics cookies are configured with IP-address truncation and a thirteen-month retention horizon. Consent is collected on the first session and can be revised at any time from the footer.
9. Updates to this policy
This policy is reviewed at each catalog publication cycle. Material updates are flagged on the buyer-code login screen and in the procurement notes blog. The version date below is updated whenever a material change is made.
Current version: published 2026-Q1 cycle.