This Policy aims to ensure compliance with all GDPR and all Applicable Data Protection Laws. Applicable Data Protection Laws set out the following principles with which any party handling Personal Data must comply. All Personal Data must be:
Applicable Data Protection Laws set out the following rights applicable to Data Subjects (please refer to the parts of this policy indicated for further details):
Applicable Data Protection Laws seek to ensure that Personal Data is processed lawfully, fairly, and transparently, without adversely affecting the rights of the Data Subject. Applicable Data Protection Laws state that processing of Personal Data will be lawful if at least one of the following applies:
ComponentSource collects and processes the Personal Data set out in Section 20 of this Policy. This includes:
The Company only collects, processes, and holds Personal Data for the specific purposes set out in Section 20 of this Policy (or for other purposes expressly permitted by the Applicable Data Protection Laws).
Data Subjects will be kept informed of the purpose or purposes for which ComponentSource uses their Personal Data. Please refer to Section 12 for more information on keeping Data Subjects informed.
ComponentSource will only collect and process Personal Data for and to the extent necessary for the specific purpose or purposes of which Data Subjects have been informed (or will be informed) as under Section 5, above, and as set out in Section 20, below.
ComponentSource will ensure that all Personal Data collected, held, and processed is kept secure and protected against unauthorised or unlawful processing and against accidental loss, destruction, or damage. Further details of the technical and organisational measures which should be taken are provided in Sections 20 to 26 of this Policy.
The Company’s Data Protection Manager ("DPM") can be contacted at dpm@componentsource.com.
The DPM will be responsible for overseeing the implementation of this Policy and for monitoring compliance with this Policy, the Company’s other data protection-related policies, and with all Applicable Data Protection Laws. ComponentSource will keep internal records of all Personal Data collection, holding, and processing, which will incorporate the following information:
ComponentSource will carry out Data Protection Impact Assessments for any and all new projects and/or new uses of Personal Data.
Data Protection Impact Assessments will be overseen by the Data Protection Manager and will address the following:
The following personal data is collected, held, and processed by ComponentSource (for details of data retention, please refer to the Company’s Data Retention Policy):
| Data Reference | Type of Data | Purpose of Data |
|---|---|---|
| Customer | Name | Quote creation, order processing, authentication & software delivery |
| Customer | Organisation name and type | Customer registration, quote creation, order processing, authentication & software delivery |
| Customer | Address (including street, county/state, zip or post code, country) | Quote creation, order processing, authentication & software delivery, paper catalogue delivery, promotional item delivery (coffee mug) |
| Customer | Email Address | Customer registration, quote creation, order processing, authentication & software delivery, Product news, customer email newsletter delivery, customer communications |
| Customer | Telephone number | Quote creation, order processing & software delivery, customer communications |
| Data Reference | Type of Data | Purpose of Data |
|---|---|---|
| Customer | IP address | Quote creation, order processing, authentication, payment processing & software delivery |
| Customer | Bank Account Numbers, Sort Code, Account Name | Order processing and payment processing |
| Customer | Credit/Debit Card Number, Card Holder Name, Expiry Date and CV2 number (CV2 is only used per transaction and never stored) | Order processing, payment processing, authentication and verification |
| End User Licensee | Name (if different from Customer) | Quote creation, order processing, authentication & software delivery |
| End User Licensee | Organisation name and type | Licensee registration with Publisher, quote creation, order processing, authentication & software delivery |
| End User Licensee | Address (including street, county/state, zip or post code, country) | Quote creation, order processing, authentication & software delivery |
| End User Licensee | Email address | Quote creation, order processing, authentication, & software delivery, licensee communications |
| End User Licensee | Telephone number | Quote creation, order processing & software delivery, licensee communications |
| End User Licensee | IP address | Quote creation, order processing, authentication, payment processing & software delivery |
| Publisher | Name, Address, Email Address, Telephone number, Bank Account Details | Order processing, payment processing and software delivery |
| Supplier | Name, Address, Email Address, Telephone number, Bank Account Details | Order processing, payment processing and delivery |
| Shareholder | Name, Address, Email Address, Telephone number, Bank Account Details | Shareholder communications, company returns and registers, plus payment processing |
| Employee/ Director/ Contractor | Name, Address, Email Address, Telephone number, National Insurance number, Tax Codes, Bank Account Details and all other information required in connection with the operation and administration of their employment contracts | Data usage in the individual Privacy Notice Schedules to their Employment Contracts or Contracts of Engagement |
When any Personal Data is to be erased or otherwise disposed of for any reason (including where copies have been made and are no longer needed), it should be securely deleted and disposed of. For further information on the deletion and disposal of personal data, please refer to the Company’s Data Retention Policy.
ComponentSource will ensure that the following measures are taken with respect to the use of Personal Data:
ComponentSource will ensure that the following measures are taken with respect to IT and information security:
ComponentSource will ensure that the following measures are taken with respect to the collection, holding, and processing of Personal Data:
The effective date of this Policy is 1st November 2025.
CSDPP 10/2025