Who? | Categories of personal data | Purposes of processing | Legal basis | Retention periods |
Customers and their employees | First and last name, gender, address, phone number, e-mail address, job title, and place of work. | To carry out ordinary customer relationship i.e.: administration of payments, general communication, management of day-to-day operations in accordance with legitimate and fair business practice (incl. planning, execution. and management of the cooperation; statistics, analyses). | Performance of a contract (Article 6 (1) (b) GDPR). | 6 years from end of financial year after the last purchase of our products or services. (Customer Statements are held for 2 years from end of financial year after the last purchase of our products or services). |
To provide general customer service and support (including follow-up surveys). | Legitimate interests in ensuring customer satisfaction and improving our products and services (Article 6 (1) (f) GDPR). |
To gain customer insights and knowledge of how our products and services are used (e.g., by sending satisfaction surveys or market surveys). |
To prevent fraud. | Legitimate interests in protecting interests of the company (Article 6 (1) (f) GDPR). |
To establish, defend or assert legal claims. |
Prospective Customers and their employees | First and last name, gender, address, phone number, e-mail address, title, and place of work. | To create business leads. | Legitimate interests in promoting ROCKWOOL and selling our products and services (Article 6 (1) (f) GDPR). | 5 years from obtained or your last interaction. |
For statistical purposes. | Legitimate interests in measuring effectiveness of our activities (Article 6 (1) (f) GDPR). |
To pursue business leads. | Taking steps prior to entering into a contract (Article 6 (1) (b) GDPR). |
Suppliers and their employees | First and last name, company phone number, e-mail address, title, and place of work | To carry out ordinary supplier relationship, i.e. administration of payments, general communication, management of day-to-day operations in accordance with legitimate and fair business practice (incl. planning, execution, and management of the cooperation, performing credit ratings, as well as carry out statistics, and analyses). | Performance of a contract (Article 6 (1) (b) GDPR) – if you are self-employed, legitimate interest in performing the contract concluded with your employer (Article 6 (1) (f) GDPR). | 6 years from the end of the financial year to which the data relate if the data is considered accounting material. (Supplier statement are only held for the current year in which they relate) 6 years from obtained for non-accounting materials if there was no activity with the supplier. |
To source and locate suppliers. | Legitimate interest in fulfilling business needs and conducting regular business activities (Article 6 (1) (f) GDPR). |
Visitors to physical locations | First and last name, phone number, e-mail address, place of work, license plate, if applicable, date and time of your visit. | To ensure the safety of our physical locations and to prevent and solve crime in our physical locations. | Legitimate interest in ensuring safety on premises and to protect employees, visitors and property (Article 6 (1) (f) GDPR) and in accordance with HMRC rules and regulations. | 4 years from registration |
CCTV recordings (photos and videos) of your activity at our physical locations. | Legitimate interest in ensuring safety on premises/physical locations and if necessary, protecting ROCKWOOL’s interests in criminal offence cases (Article 6 (1) (f) GDPR) and Information Commissioner’s CCTV Code of Conduct | 30 days from the day of the visit or as long as necessary in relation to an ongoing case. |
Receiver of e-mail and/or SMS - direct marketing. | First and last name, gender (salutation), job title, place of work, e-mail address and/or phone number. | To distribute marketing communication based on collected information and consent given. | Legitimate interest in providing interested parties with direct marketing consent based on valid e-communication consent (Article 6 (1) (f) GDPR) and where relevant, the Privacy and Electronic Communications Regulations 2003 | Until the marketing consent has been withdrawn. A copy of the marketing consent will be stored 2 years after withdrawal for evidentiary purposes. |
Users of contact forms | First and last name, email address, phone number, what your inquiry is about, date of your inquiry. | To communicate with you to market, promote and sell ROCKWOOL products and services, as well as to provide support. | If your inquiry concerns a (potential) formation of contract, the legal basis will be taking steps necessary to enter into an agreement or execute an existing one (Article 6 (1) (b) GDPR). If your inquiry does not concern a contract, the legal basis will be our legitimate interest in handling your inquiry, communication with you, marketing, promoting, and developing our products and services (Article 6 (1) (f) GDPR). | 2 years after obtained or from your last interaction if your personal data has not been used in connection with a purchase of our products or services. |
Account users | First and last name, e-mail address, username, digital footprints, password as well/and as your profile activity. | To deliver our services on the/our websites or apps to you. | Performance of a contract for the provision of electronic services (Article 6 (1) (b) GDPR). | Until closing of the account. |
To manage created user accounts; for statistical and analytical purposes. | Legitimate interest in conducting statistics and analyses for the purpose of improving the user experience (Article 6 (1) (f) GDPR). | Until closing of the account. |
Visitors of social media profiles | Information available on your profile, including your name, gender, civil status, workplace, interests, image, and your city; whether you “like” or have applied other reactions to our profile; comments you leave on our posts; content your shared with ROCKWOOL with intention of interacting; that you have visited our profile; IP address. | To improve our products and services, including our social media profiles and pages; for statistical and analytical purposes; to communicate with you if you engage with our content (comments, reviews, messages); to reshare content shared with us. * platform providers may process your personal data for their own purposes – please keep in mind this is outside of our control | Legitimate interests in being able to communicate with and direct marketing communication to you on our social media profiles, as well as our legitimate interest in improving our products and services (Article 6 (1) (f) GDPR). | Retention periods are set out by social media platform providers and can be found in their privacy policies: Meta (Instagram, Facebook) Google (YouTube) LinkedIn X (formerly Twitter) |