Skip to main content
European wholesale mobile technology Barcelona · Girona · Europe+34 662 90 94 48
B2BMobiles
Europe
AboutWho we areOur visionWhy choose us
Wholesale overviewMobile phonesTabletsLaptopsSmart watchesAccessoriesGadgets
Services overviewBuy backSell devices — Buy Back enquiryStock sourcingBusiness consultancyDistribution
Stock ListOpen a trade accountGet a customised quoteBecome a supplierHow we workHow to orderHow we gradeMarginal VATWarranty and promise
FAQContact
Stock offersStock List >
AboutWho we areOur visionWhy choose usWholesaleWholesale overviewMobile phonesTabletsLaptopsSmart watchesAccessoriesGadgetsServicesServices overviewBuy backSell your devicesStock sourcingBusiness consultancyDistributionTradeStock ListOpen a trade accountGet a customised quoteBecome a supplierHow we workHow to orderHow we gradeMarginal VATWarranty and promiseStock offersContactFAQ
Home/GDPR Data

Organisational accountability across every data route

Data protection.
Built into the operation.

For buyers, suppliers, staff and institutional partners, responsible data handling must extend beyond a website notice. This policy sets out the governance, safeguards and accountable decisions applied across B2B Mobiles Europe.

Read the policy >Ask a governance question
Business professionals reviewing controlled governance records
EU GDPR governance in Spain
Accountability standard

A principle is only meaningful when the process can prove it.

Defined roles, proportionate records, controlled processors and a clear response route across the complete data lifecycle.

BarcelonaGironaEurope
EU governanceA Spain-established organisation accountable under EU GDPR
Privacy by designPurpose, necessity and risk considered before processing
Controlled accessPersonal data limited to authorised roles with a genuine need
Documented erasureAuditable Blancco-supported routes where the service requires them

Governance at a glance

A complete route through responsibility, risk and evidence.

Use the contents to move directly to a governance topic. The policy covers the people, systems, suppliers and device-processing activities that sit behind our public privacy commitments.

Last updated
8 August 2026
Responsible entity
DISTRIBUCION DE CLASE MUNDIAL, S.L.
Primary authority
Spanish Data Protection Agency, AEPD
Governance contact
[email protected]

Table of contents

22 numbered sections

Select a heading to move directly to that section.

  1. 1Commitment and purpose
  2. 2Organisation and data-protection contact
  3. 3Scope
  4. 4Legal framework and supervision
  5. 5Controller and processor roles
  6. 6Data-protection principles
  7. 7Categories of personal data
  8. 8Special-category and higher-risk data
  9. 9Lawful bases for processing
  10. 10Transparency and collection
  11. 11Privacy by design, records and risk assessment
  12. 12Technical and organisational security
  13. 13Device data, certified erasure and legitimacy
  14. 14Personal-data breaches
  15. 15Processors and third-party suppliers
  16. 16International data transfers
  17. 17Retention and secure disposal
  18. 18Individual data-protection rights
  19. 19Rights-request process
  20. 20Awareness, oversight and accountability
  21. 21Complaints and contact
  22. 22Policy review and changes

Accountability record

Governed in Spain. Built for serious due diligence.

This policy connects legal principles to operational controls across trade records, service providers, device data, security incidents and individual rights.

Ask a governance question >
Company number
6080019513784
EU VAT
ESB56672850
Version
8 August 2026
1

Commitment and purpose

DISTRIBUCION DE CLASE MUNDIAL, S.L. trading as B2B Mobiles Europe treats the protection of personal data as a core business responsibility. It is part of how we design commercial processes, select service providers, manage records, handle devices and maintain trust with buyers, suppliers, staff and institutional partners.

This GDPR Data Protection Policy describes the organisational framework used to meet our responsibilities under Regulation (EU) 2016/679, the General Data Protection Regulation, Spain's Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights, and other data-protection requirements that apply to a particular activity.

The policy supports the GDPR accountability principle by stating the standards expected across our operation. It complements, but does not replace, transaction-specific contracts, processor instructions, internal procedures, retention schedules, incident records or the public Privacy and Cookie Policies.

2

Organisation and data-protection contact

B2B Mobiles Europe is the trading name and website of DISTRIBUCION DE CLASE MUNDIAL, S.L., a company incorporated and registered in Spain. The company is responsible for implementing this policy within the activities it controls.

The email address below is the designated contact for privacy governance, rights and due-diligence enquiries. We do not describe it as a Data Protection Officer address and do not claim an ICO or AEPD registration reference that has not been supplied and verified.

  • Company Registration Number: 6080019513784.
  • EU VAT Number: ESB56672850.
  • Registered address: Carrer Creu Coberta, 77, Sants-Montjuic, 08014 Barcelona, Spain.
  • Data-protection contact: [email protected].
  • Telephone and WhatsApp: +34 662 90 94 48.
  • Website: b2bmobiles.eu.
3

Scope

This policy applies to personal data processed through the B2B Mobiles Europe website and business operation, whether held electronically, in a structured manual record or by an approved service provider on our behalf.

Everyone working for or on behalf of the company is expected to follow the controls relevant to their role and raise a concern promptly. Contracts and instructions may impose additional requirements for a particular client, service or category of information.

  • Directors, employees, temporary personnel, contractors, consultants and authorised agents.
  • Trade buyers, applicants and the individual representatives who act for them.
  • Suppliers, potential suppliers, manufacturers, sellers and their representatives.
  • Website visitors, subscribers and individuals who submit enquiries, applications or requests.
  • Individuals whose data may be present on devices received through an agreed corporate or institutional service.
  • Processors, sub-processors and professional advisers handling personal data for a defined B2B Mobiles Europe purpose.
4

Legal framework and supervision

The company's principal framework is the EU GDPR and Spain's Organic Law 3/2018. Because the company is established in Spain, the Spanish Data Protection Agency, the AEPD, is normally the competent or lead supervisory authority for processing connected with that establishment.

The UK GDPR and Data Protection Act 2018 may also apply to a particular activity where the legal territorial tests are met, such as relevant offering of goods or services to individuals in the United Kingdom or monitoring their behaviour there. In that situation, the Information Commissioner's Office may have a role within its jurisdiction.

We do not state that the company is registered with the ICO because no confirmed registration reference has been provided. If a registration or representative obligation becomes applicable, it is assessed and managed under the relevant law rather than presumed from the fact that the company trades with UK businesses.

5

Controller and processor roles

DISTRIBUCION DE CLASE MUNDIAL, S.L. acts as controller where it decides why and how personal data is used for its own website, workforce, trade relationships, quotations, accounts, orders, supplier management, marketing choices, fraud prevention, logistics, warranty administration and legal compliance.

The company may act as a processor where a corporate, public-sector or other client instructs us to perform a defined service on personal data for which that client determines the purpose and essential means. Device intake and certified erasure services can create this relationship depending on the contract, custody model and instructions.

The role is assessed for each processing activity and documented where appropriate. A service label does not decide the legal role. If both parties independently determine different purposes, each may be a controller for its own processing. Where the parties jointly determine purposes and essential means, the responsibilities required for joint control are allocated transparently.

A client supplying devices remains responsible for having a lawful basis to transfer them and for giving lawful, complete instructions. B2B Mobiles Europe remains responsible for following documented processor duties where it acts on that client's behalf.
6

Data-protection principles

Every processing activity must be designed and operated consistently with the seven principles in Article 5 of the EU GDPR. Accountability requires us not only to follow these principles, but to be able to demonstrate how we do so.

  • Lawfulness, fairness and transparency: identify a lawful basis, avoid unjustified effects and give individuals clear information about relevant processing.
  • Purpose limitation: collect personal data for specified, explicit and legitimate purposes and do not reuse it incompatibly without a lawful route and appropriate notice.
  • Data minimisation: request, access and retain only the information reasonably necessary for the defined purpose.
  • Accuracy: take reasonable steps to keep material data accurate and current and correct or qualify inaccurate records without undue delay.
  • Storage limitation: keep identifiable data only for the period justified by its purpose, legal obligation, security need or claim.
  • Integrity and confidentiality: use risk-appropriate technical and organisational measures against unauthorised or unlawful processing, accidental loss, destruction or damage.
  • Accountability: assign responsibility, keep appropriate evidence, review risk and demonstrate compliance through proportionate records and controls.
7

Categories of personal data

The categories used depend on the relationship and service. We do not collect every category from every person. Corporate details relating only to a legal entity may fall outside the GDPR, while the name, direct contact details and activity of an identifiable person working for that entity remain personal data.

  • Identity and business-contact data, including names, job titles, employers, business addresses, emails, telephone and WhatsApp numbers and authorised-contact details.
  • Workforce and contractor data, including recruitment, identity, role, attendance, payment, performance, access, emergency-contact and legal employment records where applicable.
  • Trade-account and due-diligence data, including authority, ownership or representative details, company identifiers, VAT information, trade references and verification outcomes.
  • Transaction and commercial data, including enquiries, quotations, orders, invoices, payment references, bank details where needed for a payment or refund, stock requirements and trading history.
  • Logistics and operational data, including delivery contacts, addresses, courier references, customs information, tracking, proof of delivery, warranty and RMA records.
  • Device-related data, including IMEI or serial numbers, diagnostic results, CheckMend status, intake records and certified-erasure evidence where relevant.
  • Communications data, including form submissions, emails, WhatsApp messages, call notes, instructions, complaints and correspondence history.
  • Website and technical data, including IP address, browser, device, security logs and consent-based analytics identifiers if optional analytics is introduced.
  • Marketing and preference data, including subscription, consent, objection and suppression records.
8

Special-category and higher-risk data

The ordinary wholesale operation does not normally require special-category personal data. If health, biometric, trade-union, religious, political or another protected category is required for a workforce, legal or exceptional purpose, both an Article 6 lawful basis and an Article 9 condition are identified before processing.

Criminal-offence data, national identity documents, financial credentials and large collections of device data receive additional consideration because of their potential impact. Collection is limited, access is restricted and an appropriate secure route is used where the information is genuinely necessary.

General website forms must not be used to send passwords, unrestricted identity documents, payment-card data or unrelated sensitive information. Where verification evidence is required, the individual is told what is needed and how it should be provided.

9

Lawful bases for processing

A lawful basis is selected for each purpose before processing begins. The same business record can support several distinct purposes, but each purpose must have its own valid basis and retention justification.

  • Contract and requested pre-contract steps: quotations, trade applications, account opening, order processing, payment, delivery, warranties, supplier introductions and requested services involving an individual or sole trader.
  • Legitimate interests: proportionate B2B relationship management, service improvement, system security, fraud prevention, counterparty due diligence, debt recovery and establishing or defending legal claims, after balancing those interests against individual rights.
  • Legal obligation: accounting, VAT, tax, customs, employment, social-security and other records, sanctions or regulatory duties, and binding requests from courts or competent authorities.
  • Consent: optional stock-list subscriptions, marketing communications where consent is the appropriate route, non-essential cookies and another purpose presented as a genuine choice.
  • Vital interests or public-interest grounds: used only in the limited circumstances where the relevant legal tests are genuinely met.
Consent is not used where a person has no real choice or where processing is required for a contract or legal obligation. Withdrawing consent does not affect earlier lawful processing or processing supported by a different valid basis.
10

Transparency and collection

Individuals receive concise, accessible information about the controller, purposes, lawful bases, recipients, transfers, retention and rights at the appropriate time. Our public Privacy Policy provides the principal external notice, while workforce, device-processing or contract-specific notices address processing that needs more tailored information.

Where data is obtained indirectly from a public register, employer, authorised colleague, trade reference, courier or verification source, the transparency duties for indirectly collected data are considered together with any lawful exception.

Required fields are limited to information needed to assess or provide the requested relationship. Optional information is identified where practical. A refusal to provide required information may prevent an application, quotation, transaction, delivery or compliance check from proceeding, and that consequence is explained where relevant.

11

Privacy by design, records and risk assessment

Data protection is considered when a new service, form, system, supplier, integration, data source or processing purpose is planned, not only after it is launched. Default settings should limit collection, access, visibility and retention to what the intended service needs.

We maintain proportionate records of processing activities where required, including the purpose, categories, recipients, transfers, retention and safeguards. Changes are reviewed so that public information, contracts and operational controls remain aligned with actual practice.

A data-protection impact assessment is carried out before processing that is likely to create a high risk to individuals, including where the scale, sensitivity, monitoring, new technology or vulnerable people involved makes a structured assessment necessary. Unresolved high risk is escalated and prior consultation with the competent authority is considered where Article 36 requires it.

12

Technical and organisational security

Security controls are selected according to the nature, scope, context and purpose of processing and the likelihood and severity of harm. No system can promise absolute security, but the organisation applies proportionate measures and reviews them as risks and operations change.

  • Role-based or need-to-know access so that personnel see only the information required for an authorised task.
  • Appropriate account, authentication, device, network, communications, backup and recovery safeguards.
  • Confidentiality expectations, controlled disclosure and clear handling procedures for commercial and workforce records.
  • Supplier assessment and contractual controls where another organisation processes personal data for us.
  • Data minimisation, retention controls and secure deletion or anonymisation when information is no longer required.
  • Logging, monitoring, testing and review where proportionate to the system and risk.
  • A documented route for reporting, containing, assessing and learning from security incidents.
13

Device data, certified erasure and legitimacy

Devices received through buy-back, fleet-clearance, insurance or other commercial routes may contain personal or confidential information. The supplying organisation must have authority and a lawful basis to transfer the devices and must disclose any required custody, preservation or erasure instructions before processing.

Where Blancco-supported certified erasure is included in the agreed service and technically supported by the device, the process can produce an auditable certificate or record linked to the relevant unit. A factory reset is not represented as equivalent certification. Failed or unsupported erasure outcomes are handled under the agreed exception process rather than being silently treated as successful.

CheckMend IMEI verification supports device legitimacy, identity and blacklist checks. It is an important stock-governance control, but it is not described as a substitute for GDPR security or certified data erasure.

The controller and processor allocation, chain of custody, scope of erasure, evidence supplied and treatment of exceptions should be agreed for each institutional device programme.
14

Personal-data breaches

A personal-data breach is a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. Personnel and processors must escalate a suspected breach immediately so that containment and risk assessment can begin without delay.

For EU processing, a reportable breach is notified to the competent supervisory authority, normally the AEPD where our Spanish establishment is responsible, without undue delay and where feasible within 72 hours after awareness. Notification is not required where the breach is unlikely to result in a risk to individuals' rights and freedoms. Reasons for the decision are documented.

Where the breach is likely to result in a high risk, affected individuals are informed without undue delay unless a lawful exception applies. The communication explains the nature of the breach, likely consequences, measures taken and a contact route in clear language.

Every personal-data breach is recorded with the facts, effects, assessment and remedial action, whether or not it is notified. Where UK GDPR applies to the affected processing, any separate ICO duty is assessed under that framework rather than replacing the EU notification route.

15

Processors and third-party suppliers

Personal data is shared only for a defined lawful purpose and only to the extent reasonably necessary. Before appointing a processor, we consider its capability to provide sufficient guarantees for security and GDPR compliance. Appropriate Article 28 terms are put in place where the recipient acts as our processor.

Processors may act only on documented instructions unless law requires otherwise, must protect confidentiality and security, support applicable rights and breach duties, control sub-processing and return or delete data at the end of the service as the contract requires.

  • Our six logistics partners: DHL Express for international and priority EU shipments, FedEx for global routes, UPS for European parcel and freight, GLS for our pan-European road network, Correos Express for Spanish domestic distribution and Royal Mail for UK buyers.
  • Banks and payment providers for payment matching, transaction controls, refunds and required financial compliance.
  • Website, hosting, cloud, email, communications, customer-management and IT providers supporting secure business systems.
  • Diagnostic, device-verification and certified-erasure providers where their service is required for a transaction or programme.
  • Accountants, auditors, insurers, lawyers and other professional advisers where the information is needed for their role.
  • Courts, tax, customs, law-enforcement and regulatory authorities where disclosure is required or legally justified.
We do not sell personal data and do not disclose it to unrelated third parties for their own marketing. Some recipients, including couriers, banks and authorities, may act as independent controllers for their regulated purposes.
16

International data transfers

The company trades across the EEA, United Kingdom and other international markets. A transfer of personal data outside the EEA or UK takes place only where it is necessary for the purpose and an appropriate transfer route is available.

EEA transfers to the United Kingdom may rely on the European Commission's UK adequacy decision while it remains valid and applicable. UK transfers to the EEA may rely on the United Kingdom's adequacy regulations. An adequacy route generally avoids the need to add standard clauses to that transfer.

Where no adequacy decision applies, the transfer may use the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum as relevant, together with a transfer assessment and supplementary safeguards where required. A limited derogation is used only where the legal conditions are met.

Data minimisation, recipient diligence, access limitation, encryption or pseudonymisation where appropriate and contractual controls are considered as part of the transfer risk. Individuals may ask the privacy contact for information about the safeguard relevant to their data.

17

Retention and secure disposal

Personal data is kept only for as long as needed for the purpose, legal obligation, security requirement or claim. At the end of the justified period, records are securely deleted, anonymised or placed beyond ordinary use, subject to controlled backup cycles and legal holds.

  • Commercial books, correspondence, invoices and supporting business records are normally retained for at least six years from the last relevant accounting entry under the Spanish Commercial Code, or longer where another tax, customs, employment, investigation or claims rule requires it.
  • Active trade-account, buyer, supplier and partner records are kept through the relationship and then for the period needed for audit, tax, warranty, fraud prevention and legal claims.
  • Workforce records follow the relevant Spanish employment, social-security, tax, health and safety and limitation periods, with categories separated where their legal periods differ.
  • Warranty, RMA, delivery, IMEI, CheckMend and erasure records are retained with the related transaction or programme for the applicable commercial, evidential and legal period.
  • Routine enquiries and unsuccessful applications are normally retained for up to two years after the last meaningful contact unless a shorter period is appropriate or a documented fraud, complaint or compliance reason requires longer.
  • Marketing consent is kept until withdrawal or inactivity. A minimal suppression record may remain so an unsubscribe or objection continues to be respected.
  • Cookie and analytics information follows the current Cookie Policy and the configured provider period. Optional analytics is not currently active on the website.
A blanket seven-year period is not applied to every record. Retention is assigned by category under the Spanish and, where genuinely applicable, UK legal framework.
18

Individual data-protection rights

Subject to the conditions and exemptions in applicable law, individuals can exercise the following rights. A right may be limited where information must be retained for a legal obligation, another person's rights or a legal claim, but every valid request receives a reasoned response.

  • Access: confirmation of processing, a copy of qualifying personal data and the required information about how it is used.
  • Rectification: correction of inaccurate data and completion of information that is materially incomplete.
  • Erasure: deletion where a statutory ground applies and no overriding lawful reason requires retention.
  • Restriction: limitation of processing in the circumstances defined by law.
  • Portability: qualifying data supplied by the individual in a structured, commonly used and machine-readable format, with direct transmission where technically feasible.
  • Objection: objection to processing based on legitimate interests because of the individual's situation and an absolute objection to direct marketing.
  • Withdraw consent: withdrawal at any time where consent is the basis, without affecting processing lawfully completed before withdrawal.
  • Automated decisions: protection from a qualifying decision based solely on automated processing that produces legal or similarly significant effects, subject to the legal exceptions and safeguards.
  • Complaint: referral to the competent supervisory authority where the individual believes processing is unlawful.
19

Rights-request process

A request may be sent to [email protected] with the subject Data Protection Request or submitted through the form below. The requester should provide their name, business relationship, the contact details previously used and the right or records concerned. This helps us locate the correct information without collecting unnecessary data.

We respond without undue delay and normally within one month after receiving a valid request. Where a request is complex or several requests are received, the period may be extended by up to two further months as the GDPR permits. The requester is informed of the extension and reasons within the first month.

Limited evidence may be requested where reasonably necessary to verify identity, authority or the data concerned. Identity documents should not be sent through the general form unless we first request them and provide an appropriate route. Rights are normally free, but a manifestly unfounded or excessive request may be refused or subject to a reasonable fee where the law permits, with reasons and complaint information provided.

20

Awareness, oversight and accountability

Relevant personnel and agents receive data-protection expectations appropriate to their responsibilities. Access to personal data carries a duty of confidentiality, secure handling, accurate record keeping and immediate escalation of a suspected incident or rights request.

The company maintains proportionate evidence of compliance, which may include processing records, privacy notices, lawful-basis assessments, retention decisions, processor contracts, transfer safeguards, incident records, rights-request logs, erasure certificates, risk assessments and review actions.

Processor and supplier diligence is performed before and during higher-risk relationships. Material changes to a provider, system, purpose or data flow trigger a review of instructions, contracts, security, transfers and transparency information.

Responsibility is assigned internally and concerns are escalated to the privacy contact or management according to their seriousness. Where specialist legal, security or forensic advice is needed, an appropriate professional is engaged.

21

Complaints and contact

An individual, client or due-diligence team may raise a data-protection question through [email protected], WhatsApp at +34 662 90 94 48, or in writing to DISTRIBUCION DE CLASE MUNDIAL, S.L., Carrer Creu Coberta, 77, Sants-Montjuic, 08014 Barcelona, Spain.

For EU processing connected with our Spanish establishment, a complaint may be made to the Spanish Data Protection Agency, AEPD. An individual may also have the right to complain to the authority in the EEA country of habitual residence, place of work or alleged infringement.

Where UK GDPR applies to the relevant processing, a UK complaint may be raised with the Information Commissioner’s Office. We encourage the individual to contact us first so that the concern can be investigated and, where appropriate, resolved promptly.

22

Policy review and changes

This policy is reviewed periodically and when a material change occurs in law, processing, systems, services, risk, suppliers or organisational responsibility. The last-updated date identifies the current published version.

A policy update does not itself provide a lawful basis for a new incompatible purpose. Where a change affects the information individuals must receive, the relevant notice is updated and any required consent or contractual step is obtained before the new processing begins.

This public policy demonstrates the governance framework and commitments applied by the organisation. It is not a certification, independent audit report or substitute for transaction-specific security, processor or due-diligence documentation.

End of GDPR Data Protection PolicyLast updated 8 August 2026Return to contents >

Data protection and due diligence

Ask a governance question or exercise a data right.

Use this route for an individual request, supplier assessment, processor question, security questionnaire, transfer query or concern about a specific processing activity. We collect only the information needed to identify and assess the enquiry.

Choose the right routeRights, due diligence and processor questions stay distinct
Give relevant contextA known account or programme reference helps investigation
Receive a documented answerWe will explain the applicable role, control or next step
Prefer WhatsApp? +34 662 90 94 48 >
Direct to the B2B Mobiles Europe teamGDPR Data Protection Enquiry from [Name] — B2B Mobiles Europe Website

Do not send passports, identity cards, passwords, payment data or sensitive evidence through this form. If verification or supporting documentation is necessary, we will request it separately through an appropriate route.

Rights requests are normally answered within one month. Due-diligence questions are routed to the relevant operational or governance contact.
B2BMobiles
Europe

Wholesale mobile technology, supplied with clarity.

B2B Mobiles Europe is a Spain-registered wholesale technology partner supplying Mobile Phones, Tablets, Laptops, Smart Watches, Accessories and Gadgets across Europe, Africa and the Middle East, with verified grading, compliant documentation, reliable logistics and genuine after-sale support.

Company

About usWho we areOur visionWhy choose usFAQContact us

Wholesale

Product linesMobile phonesTabletsLaptopsSmart watchesAccessoriesGadgetsStock List

Trading

How to orderHow we gradeMarginal VATWarranty and promise

Work With Us

Open a trade accountGet a customised quoteBecome a supplierSell your devicesHow we work

Our Services

Services overviewBuy backStock sourcingBusiness consultancyDistribution

Stock offers

iPhone 15 Pro EU MixGalaxy S24 Ultra Volume LotMacBook Pro Trade BatchDell Latitude Corporate ReleaseHP EliteBook 840 Fleet Batch

Contact

Email[email protected]
Phone+34 662 90 94 48
WhatsAppOpen WhatsApp
Business hoursMon to Fri 9AM to 7PM
Sat 10AM to 5PM
Trading and operationsCarrer de Santa Eugenia, 42
17005 Girona, Spain
Scan for WhatsAppOpen our trade conversation
www.b2bmobiles.eu is the trading website of DISTRIBUCION DE CLASE MUNDIAL, S.L. incorporated and registered in Spain. Company Registration No. 6080019513784. EU VAT No. ESB56672850.
© 2026 DISTRIBUCION DE CLASE MUNDIAL, S.L.
PrivacyCookiesTermsGDPR
EU VAT ESB56672850Back to top >
Designed & Developed By World Business Software Solutions