Data protection and website transparency
WooveBeer Privacy Policy
This policy explains how LIMITED LIABILITY COMPANY WOOVE collects, uses, shares, protects and retains personal data when individuals visit WooveBeer, submit a B2B quotation request or communicate with us.
Privacy at a glance
How We Handle Website and Enquiry Data
Business enquiries
We use submitted information to assess and respond to wholesale, product, logistics and quotation requests.
No consumer data sales
We do not sell personal data. Access is limited to authorised recipients and providers needed for stated purposes.
Consent controls
Where consent is required, non-essential website technologies are controlled through the cookie-consent interface.
Your rights
Applicable law may give you rights over your personal data, including access, correction, deletion and objection.
01
Who Is Responsible for Your Personal Data?
The controller for the processing described in this policy is LIMITED LIABILITY COMPANY WOOVE. WooveBeer is the trading identity used for the company’s B2B wholesale website and commercial enquiry process.
Zakhysnykiv Ukrainy Square
Kharkiv, Kharkiv Region, 61001
Ukraine
Important distinction: Rögelein GmbH, Turbinenstraße 17, 70499 Weilimdorf, Germany is stated as a European fulfilment location. It is not the registered office of LIMITED LIABILITY COMPANY WOOVE and is not identified by this policy as the data controller or as an EU/UK data-protection representative.
Corporate and operational information is available on our Company page.
02
Scope of This Privacy Policy
This policy applies when personal data is processed through or in connection with:
- the website at woovebeer.com;
- the wholesale quotation form and the contact page;
- business email, telephone or messaging communications initiated through the website;
- company, buyer and destination checks performed to assess a B2B enquiry;
- website security, server logs, consent records and permitted analytics.
This policy protects information relating to identifiable individuals. A company name or registration number may not be personal data by itself, but the name, email address, telephone number or activity of a company representative can be personal data. The policy therefore also applies to individuals acting for business buyers, suppliers and professional partners.
03
Personal Data We May Collect
Identity and contact data
Name, job or purchasing role, company name, business email address, telephone or WhatsApp number and company website.
Business-verification data
Company registration, VAT or EORI number, business type and information available from public company or trade sources.
Quotation and logistics data
Requested brands, formats, quantities, estimated order volume, destination, city, postcode, delivery preferences and requested timing.
Communication data
Messages, attachments, quotation discussions, enquiries, corrections, complaints and records of our responses.
Technical and security data
IP address, date and time, requested URL, browser and device information, referrer, diagnostic events and suspected-spam indicators.
Consent and preference data
Cookie choices, consent status and associated technical records needed to remember or demonstrate those choices.
Please do not submit unnecessary sensitive information. The website forms are not intended for passwords, payment-card data, health data, biometric data, private identity documents or other special-category personal data. Payment instructions are not collected through the public quotation form.
04
Why We Use Personal Data and Our Legal Bases
The legal basis depends on the purpose and the law that applies. Where the EU GDPR or UK GDPR applies, the principal purposes and bases are described below. Under Ukrainian law, processing is also carried out in accordance with applicable grounds and data-protection obligations.
| Purpose | Data commonly used | Legal basis where applicable |
|---|---|---|
| Respond to an enquiry or prepare a requested quotation | Contact, company, product, volume and destination information | Steps requested before a possible contract; legitimate interests in managing B2B enquiries |
| Verify the business buyer and assess fraud, sanctions or commercial risk | Business identity, registration information, contact information and relevant public records | Legitimate interests; compliance with legal obligations where applicable |
| Manage quotations, orders, delivery coordination and commercial records | Enquiry, contract, order, contact, delivery and communication data | Contractual necessity; legal obligations; legitimate interests in record keeping and claims |
| Protect the website, forms and communications | IP address, logs, diagnostics and suspected-abuse information | Legitimate interests in security, service integrity, fraud prevention and troubleshooting |
| Remember consent choices and provide requested website functions | Consent status, preferences and essential technical identifiers | Legal obligations; legitimate interests; necessity to provide a requested function |
| Use non-essential analytics or marketing technologies | Consent status, online identifiers, device and usage information | Consent where consent is required |
When we rely on legitimate interests, we assess whether the processing is necessary and whether an individual’s rights and interests override that purpose. Consent can be withdrawn for future processing at any time, but this does not affect processing already carried out lawfully before withdrawal.
05
Quotation Forms, Email and Messaging
Website forms
Our quotation and contact forms are intended for registered business enquiries. Required fields are identified on the form. The submitted data is transmitted to authorised recipients through the website and email systems used to review and answer the request. Technical information, including the submitter’s IP address, may be included for security, audit and anti-abuse purposes.
Submitting a form does not reserve stock, create a purchase contract or authorise unrelated marketing. Information is used for the enquiry, associated commercial steps and closely related record-keeping purposes described here.
Email content and addressing information are processed by our mailbox and email-delivery providers. Email is not an inherently confidential transmission method. Do not send payment credentials or unnecessary sensitive documents until the recipient and requested transmission method have been verified.
WhatsApp and external messaging
If you choose a WhatsApp or similar third-party messaging link, the external provider processes information under its own terms and privacy notice. Opening or using that service may disclose identifiers, device information and communication data to the provider. Use of an external messaging service is optional; email remains available at sales@woovebeer.com.
06
Cookies, Consent and Analytics
Cookies and similar technologies can store or read information on a device. The website’s consent interface groups technologies into categories such as functional, preferences, statistics and marketing. The active categories, purposes and available choices are shown in that interface.
- Strictly necessary or functional technologies support security, form operation, consent storage and requested website functions.
- Preference technologies remember selected settings where enabled.
- Statistics technologies help measure website use where enabled and lawfully permitted.
- Marketing technologies are used only if configured and permitted by the visitor’s applicable consent choice.
Where consent is required, non-essential technologies should not be activated before consent. You can accept, reject or change optional categories through the Manage Consent control displayed on the website. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
Browser settings may also block or delete cookies, although disabling necessary technologies may affect form or website functionality. Consent and cookie configurations can change when services are added, removed or updated; this policy and the consent scan must therefore be reviewed after material website changes.
07
Who May Receive Personal Data?
We do not sell personal data. Access or disclosure may occur only where relevant to a stated purpose, including to:
- authorised sales, administration, compliance and technical personnel;
- website hosting, security, backup, email-delivery and mailbox providers;
- consent-management, analytics or anti-spam providers that are lawfully enabled;
- fulfilment, logistics or commercial partners when needed to assess or perform a requested transaction;
- professional advisers, auditors, insurers and payment or banking providers involved in an authorised transaction;
- courts, regulators, law-enforcement authorities or other recipients where disclosure is required or legally permitted.
Providers are given only the information reasonably required for their function. Their role may be that of a processor acting on instructions or, for certain independent services, a separate controller under their own privacy notice.
08
Ukraine, the EEA, the UK and International Processing
The controller is established in Ukraine and serves business enquiries that may originate in the European Economic Area, the United Kingdom and other markets. Personal data submitted through the website may therefore be accessed or processed in Ukraine and in countries where relevant service providers or commercial recipients operate.
Where EU or UK international-transfer rules apply, an appropriate transfer mechanism or permitted derogation must be used. Depending on the circumstances, safeguards may include an adequacy decision, approved standard contractual clauses, contractual and technical supplementary measures, or another mechanism recognised by applicable law. Information about the safeguard relevant to a particular transfer can be requested using the privacy contact below.
The European Commission explains that special safeguards are required for transfers outside the EEA. See its official international-transfer guidance.
09
How Long We Keep Personal Data
We keep personal data only for as long as reasonably necessary for the purpose collected and for applicable legal, accounting, security, dispute and record-keeping requirements. The criteria used include:
- whether an enquiry is active, concluded or reasonably expected to continue;
- whether a quotation led to a contract, order, payment, shipment, complaint or legal claim;
- statutory periods that apply to commercial, accounting, customs, tax or transaction records;
- the period needed to investigate security events, prevent abuse or demonstrate consent;
- the retention settings and legal role of an applicable service provider.
When information is no longer required, it is deleted, anonymised or placed beyond routine use, subject to backup cycles and legal preservation duties. You may ask about the criterion applied to your information by contacting us.
10
Security and Data Minimisation
We apply technical and organisational measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected according to the nature of the data, processing context and risk and include HTTPS transport encryption, role-based access, software maintenance, authentication, backups, logging and provider controls where appropriate.
No internet service can guarantee absolute security. If you believe personal data submitted through the website has been exposed, altered or misused, contact us promptly at sales@woovebeer.com.
11
Your Data-Protection Rights
Depending on your location, the processing and the applicable legal basis, you may have rights to:
- receive information about how your personal data is processed;
- request access to personal data concerning you;
- correct inaccurate or incomplete information;
- request deletion where the legal conditions are met;
- restrict certain processing;
- receive eligible data in a portable format;
- object to processing based on legitimate interests;
- withdraw consent for future processing where consent is the basis;
- not be subject to a decision based solely on automated processing where it produces legal or similarly significant effects.
Your right to object
Where we rely on legitimate interests, you may object to the processing based on your particular situation. We will stop the relevant processing unless there are compelling legitimate grounds that override your interests, rights and freedoms or the processing is needed for legal claims. You may object to direct marketing at any time.
Rights are not absolute and may be limited by applicable exemptions, the rights of other people or legal record-keeping duties. We may request information needed to verify identity and authority before acting on a request. Where the GDPR or UK GDPR applies, we normally respond within one month; a lawful extension may apply to complex or numerous requests.
The European Data Protection Board’s rights guidance provides further information.
12
Automated Decisions and Anti-Spam Checks
We do not use information in the wholesale quotation form to make a decision based solely on automated processing that produces legal or similarly significant effects. Website security or anti-spam tools may automatically flag or block suspected abuse. If a legitimate enquiry appears not to have been delivered, contact us by email so it can be reviewed.
13
Minors
WooveBeer is a business-to-business website concerning age-restricted products. It is not directed to children or intended to collect personal data from minors. If you believe a minor has submitted personal data, contact us so the information can be assessed and deleted where appropriate.
14
Questions and Complaints
Please contact us first if you have a concern so we can investigate it. This does not remove any right to complain to a competent supervisory authority.
- Ukraine: information about the personal-data function of the Ukrainian Parliament Commissioner for Human Rights is available from the Commissioner’s official website.
- European Economic Area: the EDPB provides a list of national data-protection authorities.
- United Kingdom: information about privacy rights and complaints is available from the Information Commissioner’s Office.
15
How to Contact Us About Privacy
Use the subject line Privacy Request and provide enough information for us to identify the relevant communication or record. Do not email a passport, password or payment information unless a secure method has first been agreed.
Office 15, Building 7/8
Zakhysnykiv Ukrainy Square
Kharkiv, Kharkiv Region, 61001
Ukraine
16
Changes to This Policy
This policy may be updated when website services, processing purposes, recipients, legal requirements or company operations change. The current version and effective date will be published on this page. Material changes will be communicated through an appropriate website notice or direct message where required.
Official references