Legal · GDPR disclosure

Data Processing Notice

MICRO DIGITAL ELECTRONICS CORP S.R.L. is the controller of personal data within the meaning of Article 4(7) GDPR for data processed through the VENDOR.Energy™ website and related communication channels.

Effective from 19 August 2026

What this notice is

This notice sets out the processing environment: who processes personal data on the Company’s instructions, who acts independently, and how transfers outside the European Economic Area are governed. It is an informational disclosure intended for review by counterparties and supervisory authorities. It is not a contract and does not replace the Privacy Policy, which remains the primary source of information for data subjects.

01. Our role

In relation to personal data collected through the website, the Company determines the purposes and means of processing and acts as a controller. The Company does not provide data processing services to third parties and does not act as a processor on the instructions of external controllers.

This notice is not a data processing agreement under Article 28 GDPR: it is a unilateral disclosure. Should the Company take on the role of a processor, a separate Article 28 agreement is concluded with the relevant controller and operates independently of this notice.

02. Processors acting on our instructions

Service providers that process personal data on the Company’s instructions are engaged on data processing terms that meet the requirements of Article 28 GDPR: subject matter and duration of processing, categories of data, confidentiality, security measures, engagement of sub-processors, assistance with data subject rights, incident notification, and return or deletion of data at the end of the service.

Processing environment as at the date of this notice
ProviderServiceLocationRole
Hetzner Online GmbHwebsite hostingGermany (EU)processor
Google Ireland Limitedweb analytics, only where valid consent is in placeIreland (EU)processor for data processed on the Company’s instructions

The role of the analytics provider depends on the configuration of the service: individual data-sharing features, where enabled, result in the provider acting as an independent controller in respect of the data concerned.

This list reflects the configuration as at the date of this notice. A provider is added to the list once processing actually begins, not once software is purchased or installed.

The categories of data, the purposes of processing and the retention periods are set out in the Privacy Policy.

03. Independent recipients

Where a visitor independently turns to a third-party service that determines the purposes and means of the relevant processing independently of the Company, that provider acts as an independent controller in respect of that processing. This may apply, in particular, to a payment service where such a service is used. Information about processing by that provider is set out in its own privacy policy.

In individual cases, a provider used by the Company may also act as an independent controller in respect of certain processing operations, where this follows from the nature of the service, its settings or the applicable terms.

This rule applies equally to providers of identification and verification services where, in respect of individual operations, they independently determine the purposes and means of processing.

04. Transfers outside the EEA

The website infrastructure is located within the European Economic Area.

Where personal data are transferred to a recipient outside the EEA, the Company relies on a transfer mechanism provided for in Chapter V GDPR and applicable to the recipient and to the transfer concerned. For recipients in the United States this may include the European Commission adequacy decision on the EU–US Data Privacy Framework in respect of organisations participating in it, or the standard contractual clauses where applicable.

If the transfer mechanism relied upon ceases to apply, the transfer continues only where another ground under Chapter V GDPR is available, or it is discontinued.

The description of transfers and of the safeguards applied is set out in the Privacy Policy.

05. Data protection enquiries

Questions about the data protection measures applied and about international transfers may be sent to info@vendor.energy.

The Company may provide further information to the extent it considers reasonable, having regard to legal requirements, confidentiality, information security, trade secrets and contractual restrictions.

Requests by data subjects to exercise their rights under the GDPR are handled in the manner set out in the Privacy Policy.

  • Privacy Policy — data subject rights, legal bases, purposes, categories of data, retention periods, supervisory authority.
  • Legal Notice — identification of the Company, commercial register, EUID.
  • Terms of Service — terms governing use of the website.
  • Cookie Policy — storage technologies on the device and the consent mechanism.

07. Governing law, language and changes

This notice is governed by the law of Romania and by directly applicable European Union law. In the event of a discrepancy between this notice and the Privacy Policy, the Privacy Policy prevails for information addressed to data subjects.

This notice is published in English, Romanian, German, Chinese (Simplified) and French. In the event of a material discrepancy between language versions, the English version prevails for the purposes of interpretation, without prejudice to mandatory rules requiring a particular language version to prevail.

This notice is updated as necessary where the processing described here, or the requirements applicable to it, change materially. The date shown at the top of this notice indicates the current version.

This notice is issued by MICRO DIGITAL ELECTRONICS CORP S.R.L. as an informational disclosure and is not a data processing agreement within the meaning of Article 28 GDPR.