Privacy notice
Effective 22 July 2026 · version 1.1
Controller
SolarCoach & Fuels GmbH is responsible for personal data processed through the direct-supply website and SC & F Marketplace. Privacy enquiries and rights requests can be initiated through the secure contact route.
Data processed
Depending on the relationship, records may include customer and business contacts, delivery location and site conditions, organization and beneficial-ownership evidence, authority and role, applications, enquiries, quotations, offers, approvals, orders, delivery and invoice records, messages, documents, device and authentication events, IP addresses, support cases and screening outcomes.
Purposes and legal bases
SCF processes data for supply enquiries, pre-contractual steps and contracts, delivery planning, legal obligations, marketplace membership decisions, access control, fraud and sanctions risk, transaction execution, disputes and the legitimate operation and protection of both services. Consent is used only where it is freely given and appropriate.
Recipients and transfers
Access is limited to authorized SCF personnel, the member organization, necessary counterparties within a transaction and contracted infrastructure or verification providers. Production policy restricts hosting and primary processing to the EU/EEA. A third-country transfer requires an applicable transfer mechanism and documented assessment.
Retention
Periods follow the record category, contract, security purpose and applicable law. Encrypted raw login IP values are retained for 30 days and pseudonymous security events for 365 days. Accounting and transaction records follow statutory periods. A documented legal hold pauses deletion only for records within its scope.
Your rights
Subject to the GDPR and applicable limits, a person may request access, correction, deletion, restriction or portability, object to processing and complain to the competent authority. SCF must verify identity proportionately and record the response deadline and decision.
Security and authentication logs
SCF is designed around organization-scoped authorization, encryption, restricted administration, monitoring and tested recovery. Authentication events include source-IP evidence to investigate abuse and protect accounts. Raw IP access requires a defined investigation purpose and is itself logged.
