COMET / LEGAL
Privacy policy
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Comet Components UG (haftungsbeschränkt) i. G. Grunewaldstraße 38 10823 Berlin Germany
Represented by: Abdelali Sarhane Telephone: +49 176 46123174 Email: contact@cometcomponents.com
2. Scope and data we process
This privacy policy applies to cometcomponents.com, including its request-for-quotation (RFQ) function. Depending on how you use the site, we process in particular:
- technical access data, such as IP address, date and time, requested address, referrer, browser and device information, HTTP status and data volume;
- contact and company details, in particular company, name, business email address and an optional telephone number;
- enquiry and component data, in particular component name, drawing number and revision, material, hardness, annual quantity, reason for enquiry, operating conditions, required documentation, target date, message and NDA request;
- uploaded files and their file name, type, size and technical verification results;
- security data, in particular the result of an abuse check and a one-way hash identifier derived from the IP address to limit repeated requests.
Technical drawings may contain personal data, for example names in document metadata or title blocks. Please provide only data needed for the enquiry and do not submit special categories of personal data within the meaning of Article 9 GDPR.
3. Website delivery and server logs — Netlify
The website is delivered through Netlify, Inc. When you access the site, Netlify processes technically necessary connection and log data to deliver content, identify faults, maintain availability and defend against attacks.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, stable and efficient operation of the website and the prevention of abuse. Netlify processes data on our behalf to deliver the website; where Netlify processes data for its own purposes, Netlify’s own notices apply.
Further information: https://www.netlify.com/privacy/ https://www.netlify.com/gdpr-ccpa/
4. Contact and RFQ enquiries
When you contact us through the RFQ form, by email or by telephone, we process the information you provide to assess your enquiry, answer questions, evaluate technical and commercial feasibility, and prepare a quotation or business relationship.
The legal basis is Article 6(1)(b) GDPR where you are the prospective contracting party or request steps before entering into a contract. Where you act for a company, the legal basis is Article 6(1)(f) GDPR. Our legitimate interests are handling business enquiries and establishing, conducting and maintaining B2B relationships. Processing required by statutory record-keeping obligations is based on Article 6(1)(c) GDPR.
5. RFQ database and private file storage — Supabase
RFQ data and uploaded files are stored in a non-public database and private file storage provided by Supabase. The Supabase project is configured in the Central EU (Frankfurt) region. The browser uploads files directly to that private storage using time-limited, path-bound authorisation; files are not published at public URLs.
Supabase processes the data as a processor for the storage, security and technical operation of the RFQ system. Access is restricted to authorised persons and technically necessary service providers.
Further information: https://supabase.com/privacy https://supabase.com/docs/guides/platform/regions https://supabase.com/legal/customer-resources/data-processing-addendum
6. RFQ form protection — Cloudflare Turnstile
We use Cloudflare Turnstile, provided by Cloudflare, Inc., to protect the RFQ form from automated submissions and abuse. According to Cloudflare, Turnstile processes client-side signals such as the IP address, TLS fingerprint, user-agent, sitekey and associated origin, and generates a token whose validity is checked on the server.
The purpose is to identify and block bots and abusive requests. The legal basis is Article 6(1)(f) GDPR; our legitimate interests are protecting the form, our systems and submitted data. To the extent strictly necessary cookies or comparable technologies are used for this purpose, the access or storage is permitted under section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Cloudflare processes signals on our behalf to provide Turnstile and processes certain signals under its own responsibility to improve bot detection.
Further information: https://www.cloudflare.com/turnstile-privacy-policy/ https://www.cloudflare.com/cookie-policy/
7. Disclosure to suppliers and manufacturers
To handle a sourcing request, we may disclose the RFQ content and technical documents required for that purpose to carefully selected suppliers or manufacturers. Personal contact details are disclosed only where necessary for the specific enquiry.
The legal basis is Article 6(1)(b) GDPR where disclosure is necessary for pre-contractual steps requested by you, or Article 6(1)(f) GDPR for business contacts acting for a company. Our legitimate interest is the professional assessment and handling of the requested sourcing work.
If you require a confidentiality agreement or NDA before external disclosure, we will clarify the scope of confidentiality before the relevant documents are disclosed externally.
8. Email communication — Zoho Mail and Resend
Our general business email communication is provided through Zoho Mail. Sender and recipient addresses, timestamps, technical metadata, message content and any attachments sent by email are processed for this purpose.
For automated transactional emails from the RFQ function, we use Resend, a service provided by Plus Five Five, Inc. (“Resend”), as a processor. After an RFQ has been submitted successfully, Resend sends an acknowledgement to the business email address entered in the form and an internal RFQ notification to our designated mailbox. For this purpose, sender and recipient addresses, the RFQ reference, company, part name, submission time, subject and message content, and technical delivery and error data are processed. Technical files and drawings uploaded through the RFQ form remain in private Supabase storage; they are not attached to these automated emails or transferred to Resend for this purpose.
The purposes are to confirm receipt of the enquiry, initiate its internal handling, and identify delivery errors and abuse. The legal bases are those described under “Contact and RFQ enquiries”, in particular Article 6(1)(b) GDPR for steps before entering into a contract and Article 6(1)(f) GDPR for business contacts acting for a company. Our legitimate interests are the reliable acknowledgement and handling of RFQ enquiries and the secure operation of email delivery.
Resend processes transactional-email data according to the account settings, contractual terms, and retention or deletion criteria applicable to the service. Relevant criteria include providing and securing the email service, delivery and error analysis, preventing abuse, and complying with legal obligations. We therefore do not state a separate fixed provider retention period here.
Further information: https://www.zoho.com/privacy.html https://www.zoho.com/mail/gdpr.html https://resend.com/legal/privacy-policy https://resend.com/legal/dpa
9. Cookies, browser storage and audience measurement
We currently use no advertising or marketing trackers and no separate audience-measurement service, including Plausible Analytics. Browser storage is not used for advertising or profiling-based tracking.
Strictly necessary cookies or comparable storage may be used by security and delivery functions, particularly Cloudflare Turnstile. They are used only to provide the website and form functions expressly requested by the user in a secure manner.
10. Recipients
Personal data are made available only to recipients that need them for the purposes described above. These recipients include:
- internally authorised persons;
- Netlify for hosting, content delivery and technical website functions;
- Supabase for the database and private file storage;
- Cloudflare for Turnstile and abuse prevention;
- Zoho Mail for general email communication;
- Resend for automated RFQ acknowledgements and internal RFQ notifications;
- carefully selected suppliers or manufacturers where necessary to handle a specific sourcing request;
- legal, tax or other professional advisers where necessary;
- public authorities or courts where disclosure is required by law.
Where required, service providers are bound by data-processing agreements and appropriate safeguards.
11. International transfers
Primary database and file storage with Supabase takes place in Frankfurt. Some of the providers and subprocessors named above operate internationally; technical data, support data or other personal data may therefore also be processed outside the European Union or European Economic Area. Resend is provided by Plus Five Five, Inc., which is based in the United States; transactional-email data may therefore be processed in the United States and by international subprocessors.
A transfer to a third country takes place only in compliance with Articles 44 et seq. GDPR, in particular on the basis of an adequacy decision under Article 45 GDPR where applicable, or appropriate safeguards under Article 46 GDPR, especially the European Commission’s Standard Contractual Clauses and, where necessary, supplementary safeguards. The same applies where a supplier or manufacturer needed for a specific enquiry is located outside the EEA.
You may request information about the safeguards used by emailing contact@cometcomponents.com. Further information about the transfer mechanisms described by Resend is available at https://resend.com/legal/dpa.
12. Retention
We retain personal data only for as long as required for its purpose:
- files from incomplete upload sessions are marked for deletion after the upload authorisation expires and are removed by the scheduled cleanup process;
- enquiries, RFQ data and uploaded files are reviewed regularly and deleted when they are no longer needed to handle the enquiry, address reasonably expected follow-up questions or establish a business relationship. Relevant criteria include the processing status, the date of the last substantive contact and any documented further action;
- where an enquiry results in a contract, data are retained for the business relationship and subsequently to the extent required by statutory retention duties;
- where applicable, commercial and business correspondence is retained for six years, accounting vouchers for eight years, and certain books, inventories, opening balance sheets and annual financial statements for ten years. Statutory periods generally begin at the end of the relevant calendar year;
- content and delivery metadata for automated emails are processed by Resend according to the service’s account settings, contractual terms, and deletion cycles. Relevant criteria include delivery and error analysis, preventing and investigating abuse and security incidents, and legal obligations;
- technical log, security and abuse-prevention data are retained according to the settings and retention rules of the service providers used and for as long as required for site operation, attack detection, error analysis and security incidents;
- data are retained for longer only where required by law or needed to establish, exercise or defend legal claims.
Deletion from backups may occur later through the providers’ regular overwrite and deletion cycles.
13. Whether providing data is required
Fields marked as required are needed so that we can identify, assess and respond to your enquiry. Without this information, we may be unable to process the RFQ. All other information is voluntary. Please do not include personal data in technical files unless it is needed for the request.
14. Your rights and right to object
Subject to the statutory conditions, you have the right of access under Article 15 GDPR, rectification under Article 16 GDPR, erasure under Article 17 GDPR, restriction of processing under Article 18 GDPR and data portability under Article 20 GDPR.
Where processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation under Article 21 GDPR. We will then stop processing the relevant data unless we can demonstrate compelling legitimate grounds or the processing is needed to establish, exercise or defend legal claims.
Where processing is exceptionally based on your consent, you may withdraw that consent at any time with future effect. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. To exercise your rights, email contact@cometcomponents.com.
15. Right to complain
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for our establishment is:
Berlin Commissioner for Data Protection and Freedom of Information Alt-Moabit 59–61 10555 Berlin Germany Telephone: +49 30 13889-0 Email: mailbox@datenschutz-berlin.de https://www.datenschutz-berlin.de/
16. Automated decisions and data security
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Turnstile’s automated evaluation of technical signals is used only to identify abuse and is not such a decision within the meaning of Article 22 GDPR.
We apply appropriate technical and organisational measures to protect personal data. These include encrypted transmission, access-restricted systems and non-public file storage. Despite these measures, absolute security cannot be guaranteed for electronic data transmission.
