Privacy Policy

Metal Hinges Manufacturing — How we handle your data

← Back to Dashboard
Last updated: April 2026 · Compliant with GDPR (EU 2016/679) and Malta Data Protection Act (Chapter 586)

1. Data Controller

Metal Hinges Manufacturing (FARRCO)
Siġġiewi, Malta
Email: [email protected]
Website: cnclaserquote.com

We are the data controller responsible for the personal data collected through this platform.

2. What Data We Collect

DataPurposeLegal Basis
Name, email, phoneAccount creation, order communication, login codesContract performance (Art. 6(1)(b))
Company name, VAT numberInvoicing, EU VAT zero-rating verificationLegal obligation (Art. 6(1)(c))
Address, city, postcode, countryDelivery, invoicing, VAT jurisdictionContract performance
DXF/DWG filesManufacturing, quoting, order historyContract performance
Order history, messagesService delivery, customer supportContract performance
IP address, login timestampsSecurity, fraud prevention, rate limitingLegitimate interest (Art. 6(1)(f))

3. How We Use Your Data

We use your personal data solely for:

We do not use your data for marketing, profiling, or automated decision-making. We do not sell, rent, or share your personal data with third parties for their marketing purposes.

4. Data Sharing

We may share your data with:

We do not transfer data outside the European Economic Area (EEA). All data is stored on servers located in Malta.

5. Data Retention

Data TypeRetention PeriodReason
Account details (name, email, phone)Duration of account + 1 yearService continuity
Order records, invoices7 years from order dateMaltese tax law requirement
DXF/DWG files2 years from last orderRe-ordering convenience
Messages2 yearsDispute resolution
Login codes15 minutes (auto-expire)Authentication only
Audit logs1 yearSecurity

6. Your Rights (GDPR Articles 15-22)

Under GDPR, you have the right to:

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

7. Cookies & Authentication

We use only strictly necessary cookies for:

We do not use analytics cookies, advertising cookies, or third-party tracking. No cookie consent banner is required for strictly necessary cookies under GDPR, but we inform you here for transparency.

8. Security

We protect your data through:

9. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Malta Information and Data Protection Commissioner (IDPC) within 72 hours and notify affected individuals without undue delay, as required by GDPR Articles 33-34.

10. Children

Our services are intended for business use and are not directed at individuals under 18 years of age. We do not knowingly collect data from minors.

11. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with:

Information and Data Protection Commissioner (IDPC)
Level 2, Airways House, High Street
Sliema SLM 1549, Malta
Website: idpc.org.mt

12. Changes to This Policy

We may update this policy from time to time. The current version will always be available at this page. Material changes will be communicated via email to registered users.