KYC/AML Notice
We verify the identity and address of anyone requesting access to investor materials before those materials are disclosed.
Part of the verification is carried out by an external identity verification provider; the decision on access is taken by a person. Biometric comparison is performed only with your separate explicit consent, and a non-biometric alternative is available. This notice is informational: it explains how personal data is processed and does not replace the Privacy Policy or the non-disclosure agreement.
Basis for verification
This verification is our own access-control and fraud-prevention procedure, not the performance of a customer due diligence obligation imposed on us. As at the date of this edition the company does not fall within the categories of reporting entities listed in Romanian Law No. 129/2019. Should such an obligation become applicable to us, this notice will be updated.
Requirements of banks, payment providers and investment counterparties are a separate layer. Those parties apply their own procedures under their own responsibility; this notice neither describes nor replaces them.
Verification serves three purposes: to confirm that a person is who they claim to be; to prevent fraud and improper access to confidential materials; and to retain evidence of the decision taken, for the establishment, exercise or defence of legal claims.
Controller and contact
- Controller
- MICRO DIGITAL ELECTRONICS CORP S.R.L., brand VENDOR.Energy™
- Address
- Splaiul Unirii nr.16, etajul 10, cam 6/2
- Tax identification number
- 50047468
- Data protection contact
- info@vendor.energy — subject line [PRIVACY]
No data protection officer has been appointed: the processing does not meet the conditions of Article 37 GDPR. Enquiries are handled by the contact above.
Data, purposes and legal bases
Only the data needed for verification is processed:
- Identity data — name, date of birth, nationality, type of document, its number, issuing authority and validity, and the image of the document.
- Address data — residential address and the document evidencing it.
- Contact data — email address and, where given, telephone number.
- Biometric data — only where consent is given, see Biometric verification.
- Verification metadata — time, IP address, outcome and review markers.
| Legal basis | What it covers |
|---|---|
| Article 6(1)(f) GDPR — legitimate interest | verification of identity and address in order to protect confidential materials, prevent fraud and control access; the balancing assessment is available on request |
| Article 6(1)(a) together with Article 9(2)(a) GDPR — consent and explicit consent | biometric comparison for the purpose of unique identification, where it is used |
Under this notice we do not collect source-of-funds declarations, politically exposed person or sanctions screening data, beneficial ownership records, or data relating to criminal convictions within the meaning of Article 10 GDPR.
Providing the data is a condition of access, not a statutory or contractual obligation. You may decline to provide it; in that case access is not granted, and there are no other adverse consequences.
Biometric verification
Where special technical means capable of allowing or confirming the unique identification of a person are used to compare a facial image with the photograph in the document, or to check liveness, that processing is treated as processing of biometric data for the purpose of unique identification. It is carried out only where your prior, explicit and separately given consent is present. Consent may be withdrawn at any time; withdrawal does not affect the lawfulness of processing carried out before it.
If you decline, a non-biometric check with human review is available. Where that check does not allow identity to be confirmed to a reasonable degree, access is not granted. Declining biometric verification has no other consequences in itself.
Automated checks and the human decision
The identity verification provider applies automated methods to assess the authenticity of the document and, in biometric verification, the correspondence between images. It returns an assessment result, not a decision.
The decision on access is taken by a member of staff, who considers that result alongside other information. The processing is therefore not a decision based solely on automated processing within the meaning of Article 22(1) GDPR. An explanation of the result is available on request at info@vendor.energy.
Recipients and transfers outside the EEA
- Internal personnel — on a need-to-know basis.
- Identity verification provider — receives the data to the extent needed to carry out the verification; its role under the GDPR and the applicable processing terms are determined by the actual allocation of purposes and means of processing.
- External legal advisers — where necessary, under professional secrecy.
- Competent authorities — upon a valid lawful request and within its limits.
Details of the current identity verification provider are available on request.
Where a recipient processes data outside the European Economic Area, the transfer is permitted only where safeguards under Chapter V GDPR are in place: an adequacy decision, standard contractual clauses, or an applicable derogation. A copy of the safeguards in force is available on request.
Retention
| Scenario | Period |
|---|---|
| Access not granted, or the relationship is not pursued | up to 1 year from the date of the decision |
| Pre-contractual discussions or the relationship continue | up to 3 years after they end, where retention is necessary for the establishment, exercise or defence of possible legal claims; the period is set having regard to the general three-year limitation period under Article 2517 of the Romanian Civil Code |
| Dispute, investigation or requirement of law | for as long as necessary for the establishment, exercise or defence of legal claims, or to comply with a retention obligation |
Biometric data, where created, is kept no longer than the period needed to carry out the specific verification and to complete its result technically, after which it is deleted unless further retention is required by applicable law. The specific period, or the criteria by which it is set, is communicated before biometric data is obtained.
Your rights
Subject to the conditions and exceptions of the GDPR, you have the rights of access (Article 15), rectification (16), erasure (17), restriction of processing (18), portability (20), objection to processing based on legitimate interest (21), withdrawal of consent (7(3)), and to lodge a complaint with a supervisory authority (77). The right to erasure is limited in particular where the data is necessary for the establishment, exercise or defence of legal claims.
Requests are sent to info@vendor.energy; we respond within the time limits of Article 12(3) GDPR.
- Supervisory authority
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Address
- B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336 Bucharest, Romania
- Website
- https://www.dataprotection.ro/
A complaint may also be lodged with the supervisory authority of your habitual residence or place of work in the European Union.
Authenticity of requests
- The verification procedure is never accompanied by a demand for payment. Access to investor materials is not charged for.
- Requests for data originate only from addresses on the domain . Requests arriving by any other route are not part of the procedure.
- A letterhead, logo, seal, signature image, copy of an identity document or patent material does not in itself establish either the authenticity of a request or the authority of the person making it. Materials produced, altered, reproduced or used without permission confer no authority.
- Where a request raises doubt, the recipient should verify it independently, using the contact details published on this site rather than those given in the request itself.
This notice is a transparency document under Article 13 GDPR. It does not create, modify or replace any contract, including the non-disclosure agreement, and does not replace the Privacy Policy. How access to investor materials is arranged is described on the Investor Room page.
