Commitment and purpose
DISTRIBUCION DE CLASE MUNDIAL, S.L. trading as B2B Mobiles Europe treats the protection of personal data as a core business responsibility. It is part of how we design commercial processes, select service providers, manage records, handle devices and maintain trust with buyers, suppliers, staff and institutional partners.
This GDPR Data Protection Policy describes the organisational framework used to meet our responsibilities under Regulation (EU) 2016/679, the General Data Protection Regulation, Spain's Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights, and other data-protection requirements that apply to a particular activity.
The policy supports the GDPR accountability principle by stating the standards expected across our operation. It complements, but does not replace, transaction-specific contracts, processor instructions, internal procedures, retention schedules, incident records or the public Privacy and Cookie Policies.
Organisation and data-protection contact
B2B Mobiles Europe is the trading name and website of DISTRIBUCION DE CLASE MUNDIAL, S.L., a company incorporated and registered in Spain. The company is responsible for implementing this policy within the activities it controls.
The email address below is the designated contact for privacy governance, rights and due-diligence enquiries. We do not describe it as a Data Protection Officer address and do not claim an ICO or AEPD registration reference that has not been supplied and verified.
- Company Registration Number: 6080019513784.
- EU VAT Number: ESB56672850.
- Registered address: Carrer Creu Coberta, 77, Sants-Montjuic, 08014 Barcelona, Spain.
- Data-protection contact: [email protected].
- Telephone and WhatsApp: +34 662 90 94 48.
- Website: b2bmobiles.eu.
Scope
This policy applies to personal data processed through the B2B Mobiles Europe website and business operation, whether held electronically, in a structured manual record or by an approved service provider on our behalf.
Everyone working for or on behalf of the company is expected to follow the controls relevant to their role and raise a concern promptly. Contracts and instructions may impose additional requirements for a particular client, service or category of information.
- Directors, employees, temporary personnel, contractors, consultants and authorised agents.
- Trade buyers, applicants and the individual representatives who act for them.
- Suppliers, potential suppliers, manufacturers, sellers and their representatives.
- Website visitors, subscribers and individuals who submit enquiries, applications or requests.
- Individuals whose data may be present on devices received through an agreed corporate or institutional service.
- Processors, sub-processors and professional advisers handling personal data for a defined B2B Mobiles Europe purpose.
Legal framework and supervision
The company's principal framework is the EU GDPR and Spain's Organic Law 3/2018. Because the company is established in Spain, the Spanish Data Protection Agency, the AEPD, is normally the competent or lead supervisory authority for processing connected with that establishment.
The UK GDPR and Data Protection Act 2018 may also apply to a particular activity where the legal territorial tests are met, such as relevant offering of goods or services to individuals in the United Kingdom or monitoring their behaviour there. In that situation, the Information Commissioner's Office may have a role within its jurisdiction.
We do not state that the company is registered with the ICO because no confirmed registration reference has been provided. If a registration or representative obligation becomes applicable, it is assessed and managed under the relevant law rather than presumed from the fact that the company trades with UK businesses.
Controller and processor roles
DISTRIBUCION DE CLASE MUNDIAL, S.L. acts as controller where it decides why and how personal data is used for its own website, workforce, trade relationships, quotations, accounts, orders, supplier management, marketing choices, fraud prevention, logistics, warranty administration and legal compliance.
The company may act as a processor where a corporate, public-sector or other client instructs us to perform a defined service on personal data for which that client determines the purpose and essential means. Device intake and certified erasure services can create this relationship depending on the contract, custody model and instructions.
The role is assessed for each processing activity and documented where appropriate. A service label does not decide the legal role. If both parties independently determine different purposes, each may be a controller for its own processing. Where the parties jointly determine purposes and essential means, the responsibilities required for joint control are allocated transparently.
Data-protection principles
Every processing activity must be designed and operated consistently with the seven principles in Article 5 of the EU GDPR. Accountability requires us not only to follow these principles, but to be able to demonstrate how we do so.
- Lawfulness, fairness and transparency: identify a lawful basis, avoid unjustified effects and give individuals clear information about relevant processing.
- Purpose limitation: collect personal data for specified, explicit and legitimate purposes and do not reuse it incompatibly without a lawful route and appropriate notice.
- Data minimisation: request, access and retain only the information reasonably necessary for the defined purpose.
- Accuracy: take reasonable steps to keep material data accurate and current and correct or qualify inaccurate records without undue delay.
- Storage limitation: keep identifiable data only for the period justified by its purpose, legal obligation, security need or claim.
- Integrity and confidentiality: use risk-appropriate technical and organisational measures against unauthorised or unlawful processing, accidental loss, destruction or damage.
- Accountability: assign responsibility, keep appropriate evidence, review risk and demonstrate compliance through proportionate records and controls.
Categories of personal data
The categories used depend on the relationship and service. We do not collect every category from every person. Corporate details relating only to a legal entity may fall outside the GDPR, while the name, direct contact details and activity of an identifiable person working for that entity remain personal data.
- Identity and business-contact data, including names, job titles, employers, business addresses, emails, telephone and WhatsApp numbers and authorised-contact details.
- Workforce and contractor data, including recruitment, identity, role, attendance, payment, performance, access, emergency-contact and legal employment records where applicable.
- Trade-account and due-diligence data, including authority, ownership or representative details, company identifiers, VAT information, trade references and verification outcomes.
- Transaction and commercial data, including enquiries, quotations, orders, invoices, payment references, bank details where needed for a payment or refund, stock requirements and trading history.
- Logistics and operational data, including delivery contacts, addresses, courier references, customs information, tracking, proof of delivery, warranty and RMA records.
- Device-related data, including IMEI or serial numbers, diagnostic results, CheckMend status, intake records and certified-erasure evidence where relevant.
- Communications data, including form submissions, emails, WhatsApp messages, call notes, instructions, complaints and correspondence history.
- Website and technical data, including IP address, browser, device, security logs and consent-based analytics identifiers if optional analytics is introduced.
- Marketing and preference data, including subscription, consent, objection and suppression records.
Special-category and higher-risk data
The ordinary wholesale operation does not normally require special-category personal data. If health, biometric, trade-union, religious, political or another protected category is required for a workforce, legal or exceptional purpose, both an Article 6 lawful basis and an Article 9 condition are identified before processing.
Criminal-offence data, national identity documents, financial credentials and large collections of device data receive additional consideration because of their potential impact. Collection is limited, access is restricted and an appropriate secure route is used where the information is genuinely necessary.
General website forms must not be used to send passwords, unrestricted identity documents, payment-card data or unrelated sensitive information. Where verification evidence is required, the individual is told what is needed and how it should be provided.
Lawful bases for processing
A lawful basis is selected for each purpose before processing begins. The same business record can support several distinct purposes, but each purpose must have its own valid basis and retention justification.
- Contract and requested pre-contract steps: quotations, trade applications, account opening, order processing, payment, delivery, warranties, supplier introductions and requested services involving an individual or sole trader.
- Legitimate interests: proportionate B2B relationship management, service improvement, system security, fraud prevention, counterparty due diligence, debt recovery and establishing or defending legal claims, after balancing those interests against individual rights.
- Legal obligation: accounting, VAT, tax, customs, employment, social-security and other records, sanctions or regulatory duties, and binding requests from courts or competent authorities.
- Consent: optional stock-list subscriptions, marketing communications where consent is the appropriate route, non-essential cookies and another purpose presented as a genuine choice.
- Vital interests or public-interest grounds: used only in the limited circumstances where the relevant legal tests are genuinely met.
Transparency and collection
Individuals receive concise, accessible information about the controller, purposes, lawful bases, recipients, transfers, retention and rights at the appropriate time. Our public Privacy Policy provides the principal external notice, while workforce, device-processing or contract-specific notices address processing that needs more tailored information.
Where data is obtained indirectly from a public register, employer, authorised colleague, trade reference, courier or verification source, the transparency duties for indirectly collected data are considered together with any lawful exception.
Required fields are limited to information needed to assess or provide the requested relationship. Optional information is identified where practical. A refusal to provide required information may prevent an application, quotation, transaction, delivery or compliance check from proceeding, and that consequence is explained where relevant.
Privacy by design, records and risk assessment
Data protection is considered when a new service, form, system, supplier, integration, data source or processing purpose is planned, not only after it is launched. Default settings should limit collection, access, visibility and retention to what the intended service needs.
We maintain proportionate records of processing activities where required, including the purpose, categories, recipients, transfers, retention and safeguards. Changes are reviewed so that public information, contracts and operational controls remain aligned with actual practice.
A data-protection impact assessment is carried out before processing that is likely to create a high risk to individuals, including where the scale, sensitivity, monitoring, new technology or vulnerable people involved makes a structured assessment necessary. Unresolved high risk is escalated and prior consultation with the competent authority is considered where Article 36 requires it.
Technical and organisational security
Security controls are selected according to the nature, scope, context and purpose of processing and the likelihood and severity of harm. No system can promise absolute security, but the organisation applies proportionate measures and reviews them as risks and operations change.
- Role-based or need-to-know access so that personnel see only the information required for an authorised task.
- Appropriate account, authentication, device, network, communications, backup and recovery safeguards.
- Confidentiality expectations, controlled disclosure and clear handling procedures for commercial and workforce records.
- Supplier assessment and contractual controls where another organisation processes personal data for us.
- Data minimisation, retention controls and secure deletion or anonymisation when information is no longer required.
- Logging, monitoring, testing and review where proportionate to the system and risk.
- A documented route for reporting, containing, assessing and learning from security incidents.
Device data, certified erasure and legitimacy
Devices received through buy-back, fleet-clearance, insurance or other commercial routes may contain personal or confidential information. The supplying organisation must have authority and a lawful basis to transfer the devices and must disclose any required custody, preservation or erasure instructions before processing.
Where Blancco-supported certified erasure is included in the agreed service and technically supported by the device, the process can produce an auditable certificate or record linked to the relevant unit. A factory reset is not represented as equivalent certification. Failed or unsupported erasure outcomes are handled under the agreed exception process rather than being silently treated as successful.
CheckMend IMEI verification supports device legitimacy, identity and blacklist checks. It is an important stock-governance control, but it is not described as a substitute for GDPR security or certified data erasure.
Personal-data breaches
A personal-data breach is a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. Personnel and processors must escalate a suspected breach immediately so that containment and risk assessment can begin without delay.
For EU processing, a reportable breach is notified to the competent supervisory authority, normally the AEPD where our Spanish establishment is responsible, without undue delay and where feasible within 72 hours after awareness. Notification is not required where the breach is unlikely to result in a risk to individuals' rights and freedoms. Reasons for the decision are documented.
Where the breach is likely to result in a high risk, affected individuals are informed without undue delay unless a lawful exception applies. The communication explains the nature of the breach, likely consequences, measures taken and a contact route in clear language.
Every personal-data breach is recorded with the facts, effects, assessment and remedial action, whether or not it is notified. Where UK GDPR applies to the affected processing, any separate ICO duty is assessed under that framework rather than replacing the EU notification route.
Processors and third-party suppliers
Personal data is shared only for a defined lawful purpose and only to the extent reasonably necessary. Before appointing a processor, we consider its capability to provide sufficient guarantees for security and GDPR compliance. Appropriate Article 28 terms are put in place where the recipient acts as our processor.
Processors may act only on documented instructions unless law requires otherwise, must protect confidentiality and security, support applicable rights and breach duties, control sub-processing and return or delete data at the end of the service as the contract requires.
- Our six logistics partners: DHL Express for international and priority EU shipments, FedEx for global routes, UPS for European parcel and freight, GLS for our pan-European road network, Correos Express for Spanish domestic distribution and Royal Mail for UK buyers.
- Banks and payment providers for payment matching, transaction controls, refunds and required financial compliance.
- Website, hosting, cloud, email, communications, customer-management and IT providers supporting secure business systems.
- Diagnostic, device-verification and certified-erasure providers where their service is required for a transaction or programme.
- Accountants, auditors, insurers, lawyers and other professional advisers where the information is needed for their role.
- Courts, tax, customs, law-enforcement and regulatory authorities where disclosure is required or legally justified.
International data transfers
The company trades across the EEA, United Kingdom and other international markets. A transfer of personal data outside the EEA or UK takes place only where it is necessary for the purpose and an appropriate transfer route is available.
EEA transfers to the United Kingdom may rely on the European Commission's UK adequacy decision while it remains valid and applicable. UK transfers to the EEA may rely on the United Kingdom's adequacy regulations. An adequacy route generally avoids the need to add standard clauses to that transfer.
Where no adequacy decision applies, the transfer may use the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum as relevant, together with a transfer assessment and supplementary safeguards where required. A limited derogation is used only where the legal conditions are met.
Data minimisation, recipient diligence, access limitation, encryption or pseudonymisation where appropriate and contractual controls are considered as part of the transfer risk. Individuals may ask the privacy contact for information about the safeguard relevant to their data.
Retention and secure disposal
Personal data is kept only for as long as needed for the purpose, legal obligation, security requirement or claim. At the end of the justified period, records are securely deleted, anonymised or placed beyond ordinary use, subject to controlled backup cycles and legal holds.
- Commercial books, correspondence, invoices and supporting business records are normally retained for at least six years from the last relevant accounting entry under the Spanish Commercial Code, or longer where another tax, customs, employment, investigation or claims rule requires it.
- Active trade-account, buyer, supplier and partner records are kept through the relationship and then for the period needed for audit, tax, warranty, fraud prevention and legal claims.
- Workforce records follow the relevant Spanish employment, social-security, tax, health and safety and limitation periods, with categories separated where their legal periods differ.
- Warranty, RMA, delivery, IMEI, CheckMend and erasure records are retained with the related transaction or programme for the applicable commercial, evidential and legal period.
- Routine enquiries and unsuccessful applications are normally retained for up to two years after the last meaningful contact unless a shorter period is appropriate or a documented fraud, complaint or compliance reason requires longer.
- Marketing consent is kept until withdrawal or inactivity. A minimal suppression record may remain so an unsubscribe or objection continues to be respected.
- Cookie and analytics information follows the current Cookie Policy and the configured provider period. Optional analytics is not currently active on the website.
Individual data-protection rights
Subject to the conditions and exemptions in applicable law, individuals can exercise the following rights. A right may be limited where information must be retained for a legal obligation, another person's rights or a legal claim, but every valid request receives a reasoned response.
- Access: confirmation of processing, a copy of qualifying personal data and the required information about how it is used.
- Rectification: correction of inaccurate data and completion of information that is materially incomplete.
- Erasure: deletion where a statutory ground applies and no overriding lawful reason requires retention.
- Restriction: limitation of processing in the circumstances defined by law.
- Portability: qualifying data supplied by the individual in a structured, commonly used and machine-readable format, with direct transmission where technically feasible.
- Objection: objection to processing based on legitimate interests because of the individual's situation and an absolute objection to direct marketing.
- Withdraw consent: withdrawal at any time where consent is the basis, without affecting processing lawfully completed before withdrawal.
- Automated decisions: protection from a qualifying decision based solely on automated processing that produces legal or similarly significant effects, subject to the legal exceptions and safeguards.
- Complaint: referral to the competent supervisory authority where the individual believes processing is unlawful.
Rights-request process
A request may be sent to [email protected] with the subject Data Protection Request or submitted through the form below. The requester should provide their name, business relationship, the contact details previously used and the right or records concerned. This helps us locate the correct information without collecting unnecessary data.
We respond without undue delay and normally within one month after receiving a valid request. Where a request is complex or several requests are received, the period may be extended by up to two further months as the GDPR permits. The requester is informed of the extension and reasons within the first month.
Limited evidence may be requested where reasonably necessary to verify identity, authority or the data concerned. Identity documents should not be sent through the general form unless we first request them and provide an appropriate route. Rights are normally free, but a manifestly unfounded or excessive request may be refused or subject to a reasonable fee where the law permits, with reasons and complaint information provided.
Awareness, oversight and accountability
Relevant personnel and agents receive data-protection expectations appropriate to their responsibilities. Access to personal data carries a duty of confidentiality, secure handling, accurate record keeping and immediate escalation of a suspected incident or rights request.
The company maintains proportionate evidence of compliance, which may include processing records, privacy notices, lawful-basis assessments, retention decisions, processor contracts, transfer safeguards, incident records, rights-request logs, erasure certificates, risk assessments and review actions.
Processor and supplier diligence is performed before and during higher-risk relationships. Material changes to a provider, system, purpose or data flow trigger a review of instructions, contracts, security, transfers and transparency information.
Responsibility is assigned internally and concerns are escalated to the privacy contact or management according to their seriousness. Where specialist legal, security or forensic advice is needed, an appropriate professional is engaged.
Complaints and contact
An individual, client or due-diligence team may raise a data-protection question through [email protected], WhatsApp at +34 662 90 94 48, or in writing to DISTRIBUCION DE CLASE MUNDIAL, S.L., Carrer Creu Coberta, 77, Sants-Montjuic, 08014 Barcelona, Spain.
For EU processing connected with our Spanish establishment, a complaint may be made to the Spanish Data Protection Agency, AEPD. An individual may also have the right to complain to the authority in the EEA country of habitual residence, place of work or alleged infringement.
Where UK GDPR applies to the relevant processing, a UK complaint may be raised with the Information Commissioner’s Office. We encourage the individual to contact us first so that the concern can be investigated and, where appropriate, resolved promptly.
Policy review and changes
This policy is reviewed periodically and when a material change occurs in law, processing, systems, services, risk, suppliers or organisational responsibility. The last-updated date identifies the current published version.
A policy update does not itself provide a lawful basis for a new incompatible purpose. Where a change affects the information individuals must receive, the relevant notice is updated and any required consent or contractual step is obtained before the new processing begins.
This public policy demonstrates the governance framework and commitments applied by the organisation. It is not a certification, independent audit report or substitute for transaction-specific security, processor or due-diligence documentation.