1. ECOR PRO WORLDWIDE PRIVACY POLICY

    Effective date

    26 July 2026

    Applies worldwide

    Including the United Kingdom, the Republic of Ireland, the European Union, North America, Australia and other markets where applicable

    Websites

    www.ecor-pro.com, www.buildingdryer.co.uk, www.toyotomi.co.uk, and other websites, online shops or marketplaces operated or authorised by Ecor Pro

    Contact

    Data Lead — mail@ecorproducts.com

     

    This Privacy Policy explains how Ecor Pro collects, uses, discloses, stores and protects personal data. It also explains the rights available to individuals. It should be read with the applicable Terms and Conditions, Cookie Policy, warranty or repair terms, and any specific privacy notice provided when information is collected.

    1. Who we are and who controls your data

    “Ecor Pro”, “we”, “us” or “our” means Ecor Pro Limited, incorporated in England and Wales, and Ecor Pro B.V., incorporated in the Netherlands, each acting individually through the Ecor Pro brand. The entity that determines why and how personal data is used is the controller.

    • Ecor Pro Limited ordinarily controls personal data relating to sales and operations within the United Kingdom.
    • Ecor Pro B.V. ordinarily controls personal data relating to sales and operations in the Republic of Ireland, the European Union and other territories.
    • Either entity may control processing in another territory where required by fulfilment, stock location, taxation, regulatory or operational arrangements. The relevant quotation, order acknowledgement, invoice, checkout, website notice or other communication will identify the applicable entity where necessary.

    Each entity is responsible for its own processing. Where both entities jointly determine a particular processing activity, they will allocate their responsibilities as required by Applicable Data Protection Law. Individuals may contact the Data Lead regardless of which entity is the controller.

    Contact details

    Data Lead: mail@ecorproducts.com

    Ecor Pro Limited

    194 Whitley Road, Newcastle upon Tyne, NE26 2TA, United Kingdom

    Company number 04995589

    Ecor Pro B.V.

    Keizersgracht 572, 1017 EM Amsterdam, The Netherlands

    Company number NL007927034

    1. Scope of this Policy

    This Policy applies worldwide to personal data processed in connection with Ecor Pro’s products and services, irrespective of product, brand, order type, quantity, sales channel, fulfilment method or shipping route. It includes:

    • visits to and use of the websites and online shops listed above, accounts, forms, cookies and similar technologies;
    • retail and on-site sales where applicable, including customer collection and delivery to an address supplied by the customer or consumer;
    • trade, distributor, dealer, reseller, marketplace, wholesale, bulk and full-container orders;
    • Ecor Pro-branded, OEM, private-label, white-label, bespoke and customised products;
    • goods shipped from Ecor Pro stock or directly by a factory, supplier or fulfilment partner to a customer, consignee, importer or end user;
    • enquiries, quotations, orders, payment, delivery, customs and export documentation, product registration, marketing, technical support, warranty, returns, repairs, spare parts, complaints and legal or regulatory compliance; and
    • suppliers, contractors, job applicants, business contacts and visitors to Ecor Pro premises.

    This Policy does not govern independent distributors, retailers, marketplaces, OEM partners or other third parties that decide for themselves how to use personal data. Their own privacy notices apply to that processing.

    1. Data protection laws

    We process personal data under the laws that apply to the relevant controller, individual, activity and market. These may include the UK General Data Protection Regulation, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 in the United Kingdom; the EU General Data Protection Regulation and applicable Member State laws, including laws in the Republic of Ireland and the Netherlands; and privacy, electronic-marketing, consumer and data-security laws in North America, Australia and other countries where applicable.

    A reference to “Applicable Data Protection Law” means those mandatory laws as amended or replaced from time to time. This Policy does not state that every law applies to every transaction, nor that compliance with one jurisdiction confirms compliance with another. Where local law gives individuals additional rights or imposes stricter requirements, that law will prevail to the extent it applies.

    1. Personal data we collect

    The information collected depends on how an individual deals with us. We may collect the following categories:

    Category

    Examples

    Identity and contact

    Name, title, employer, job role, username, postal and delivery addresses, email, telephone number and signature.

    Account and commercial

    Account profile, customer or supplier number, quotations, orders, invoices, credit terms, transaction history and correspondence.

    Payment and credit

    Payment status, billing information, limited payment-card or bank information, fraud indicators and credit-reference results. Payment providers may process full card details directly.

    Delivery and trade

    Delivery instructions, consignee, importer, end user, destination, shipping and tracking data, customs/export documents and sanctions-screening results.

    Product and service

    Product model and serial number, registration, installation or use information, warranty and repair history, photographs, diagnostic data, technical logs, fault descriptions, returns and spare-parts records.

    Website and device

    IP address, device and browser information, pages viewed, search and basket activity, referral source, identifiers and cookie or consent preferences.

    Communications

    Emails, web forms, reviews, complaints, survey responses, and call recordings where recording is used and lawful.

    Premises and security

    CCTV images, visitor records and access information where these systems are used.

    Recruitment and supplier

    Employment history, qualifications, references, right-to-work information, supplier contacts and payment details.

     

    We do not intentionally request special-category data, criminal-offence data or government identifiers unless they are necessary and lawful for a specific purpose. Please do not provide unnecessary sensitive information.

    1. How we obtain personal data

    We may obtain personal data directly from the individual; from the individual’s employer, customer, distributor, reseller, OEM partner, marketplace, payment provider, carrier, factory, supplier or service partner; from public registers and business sources; through websites, devices, cookies and analytics; or from authorities and fraud-prevention or credit-reference services where lawful.

    If a business contact gives us another person’s details, the business contact must be authorised to do so and should provide this Policy or otherwise ensure that person is informed as required by law.

    1. How and why we use personal data

    We use personal data only where there is a lawful basis. The bases below apply under UK and EU data-protection law; comparable grounds are used where other laws apply.

    Purpose

    Typical data and activities

    Lawful basis

    Enquiries, quotations and contracts

    Responding to requests; creating accounts; quotations; accepting and administering orders; on-site collection or delivery.

    Contract; steps before contract; legitimate interests

    Payment, credit and fraud

    Taking payment; managing credit; debt recovery; identity, fraud, sanctions and export-control checks.

    Contract; legal obligation; legitimate interests

    Worldwide fulfilment

    Manufacture, direct shipment, warehousing, delivery, tracking, customs, import/export and communications with consignees or importers.

    Contract; legal obligation; legitimate interests

    Products, warranty and repair

    Registration, technical support, warranty assessment, repairs, replacements, spare parts, recalls, safety notices and quality improvement.

    Contract; legal obligation; legitimate interests

    OEM and channel operations

    Administering OEM, private-label, distributor, reseller, retail and marketplace relationships, including allocated spare parts and claims.

    Contract; legitimate interests

    Customer service and records

    Handling correspondence, complaints, reviews, disputes, quality assurance and record keeping.

    Contract; legal obligation; legitimate interests

    Websites and security

    Operating accounts and baskets; essential cookies; system security; diagnostics; preventing misuse; measuring and improving performance.

    Contract; legal obligation; legitimate interests; consent where required

    Marketing

    Newsletters, product information, offers, exhibitions and audience measurement, subject to local direct-marketing and cookie rules.

    Consent; legitimate interests where permitted

    Business administration

    Suppliers, professional advice, insurance, audit, restructuring, business continuity and group administration.

    Contract; legal obligation; legitimate interests

    Premises and recruitment

    Site security, health and safety, visitor management and recruitment.

    Legal obligation; legitimate interests; contract

     

    Our legitimate interests include operating and improving the business; supplying safe products and effective support; protecting customers, systems and property; preventing fraud and non-payment; maintaining commercial relationships; enforcing legal rights; and communicating relevant products and services. We balance these interests against the individual’s rights and reasonable expectations.

    1. When information is required

    Some information is required by law or to enter into or perform a contract—for example identity, contact, delivery, payment, customs, warranty or compliance information. If required information is not provided, we may be unable to quote, accept an order, extend credit, deliver goods, process a return or warranty claim, complete a repair, or meet a legal obligation. We will explain material consequences where appropriate.

    1. Websites, cookies and similar technologies

    Our websites may use strictly necessary cookies to operate accounts, shopping baskets, checkout, security and user preferences. With consent where required, we may also use analytics, functionality and advertising technologies to understand site use and improve or promote our products. Individuals can use the website’s cookie controls and browser settings to manage non-essential technologies.

    A separate Cookie Policy or consent interface should identify the technologies, providers, purposes and lifetimes actually used on each site. Refusing non-essential cookies will not prevent essential website functions, although some optional features may be reduced. Third-party websites and marketplaces have their own privacy and cookie practices.

    1. Marketing

    We may send product news, offers and business communications where the recipient has consented or where Applicable Data Protection Law permits us to rely on legitimate interests or an existing-customer relationship. Rules differ between the United Kingdom, the Republic of Ireland, the European Union, North America, Australia and other markets; we will obtain consent where required.

    Marketing can be stopped at any time by using an unsubscribe link or contacting the Data Lead. Opting out does not stop service messages about an order, account, warranty, repair, safety issue or legal obligation. We may retain minimal suppression information to respect the opt-out.

    1. Sharing personal data

    We disclose personal data only where reasonably necessary and lawful. Recipients may include:

    • Ecor Pro Limited, Ecor Pro B.V. and personnel who need the information for their work;
    • payment processors, banks, credit-reference, identity-verification, fraud-prevention and debt-recovery providers;
    • carriers, freight forwarders, warehouses, customs brokers, postal operators, insurers, importers, consignees and delivery partners;
    • factories, manufacturers, suppliers, OEM partners, distributors, resellers, marketplaces and repair or service centres where necessary to fulfil an order or resolve a product issue;
    • IT, hosting, cloud, communications, CRM, analytics, cookie-management, marketing and cybersecurity providers;
    • accountants, auditors, lawyers, insurers, consultants and other professional advisers;
    • regulators, tax, customs, law-enforcement, courts and public authorities where disclosure is required or lawful; and
    • a buyer, seller, investor, lender or adviser in connection with a proposed or completed corporate transaction, subject to appropriate protections.

    Service providers acting for us must process personal data under appropriate instructions, confidentiality and security obligations. Independent recipients use data under their own legal responsibilities. We do not sell personal data for money. If a local law treats certain advertising disclosures as a “sale” or “sharing”, any applicable notice and opt-out rights will be provided.

    1. International transfers

    Ecor Pro sells and fulfils orders worldwide. Personal data may therefore be transferred to or accessed from the United Kingdom, the Republic of Ireland, the European Union, North America, Australia, China and other countries involved in an enquiry, order, direct factory shipment, delivery, technical support, warranty, repair or service.

    Where UK or EEA personal data is transferred to a country not recognised as providing adequate protection, we use an approved transfer mechanism where required, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, together with transfer-risk assessments and supplementary measures where appropriate. Other lawful safeguards, derogations or local transfer mechanisms may be used when applicable. Contact the Data Lead for information about the relevant safeguard, subject to lawful confidentiality restrictions.

    1. Retention

    We keep personal data only for as long as reasonably necessary for the stated purpose, including contract performance, product safety and traceability, warranty or repair support, accounting and tax, dispute resolution, fraud prevention and legal claims. We consider the nature and sensitivity of the data, the risk of harm, product life, mandatory limitation and record-keeping periods, and whether the purpose can be achieved with less data.

    Record

    Standard period or criterion

    Enquiries and unsuccessful quotations

    Normally 24 months after the last meaningful contact.

    Orders, invoices, payments, delivery, customs and tax

    Normally 7 years after the relevant financial year or transaction, or longer where legally required.

    Product registration, warranty, repair, safety and traceability

    For the applicable warranty/service period and normally 7 years after closure; longer where reasonably necessary for product safety, recall, liability or legal claims.

    Supplier and business records

    Normally 7 years after the relationship or transaction ends.

    Marketing records

    Until opt-out or no longer needed; contact data is normally reviewed after 24 months of inactivity. Minimal suppression data may be kept longer.

    Website and security logs

    Normally up to 12 months unless needed for an investigation, security or legal claim.

    CCTV, where used

    Normally up to 60 days unless an incident requires longer retention.

    Call recordings, where used and lawful

    Only for the notified business purpose and approved internal period; the actual practice must be confirmed before publication.

    Recruitment

    Normally 6 months after the process ends, or longer with consent for a talent pool or where law requires.

     

    Records may be kept longer where a complaint, investigation, litigation hold, recall, unpaid account or legal duty applies, or may be anonymised so they no longer identify an individual.

    1. Warranty, repair and returned products

    Warranty, repair, return and spare-parts processing may require customer, distributor, reseller, retailer, OEM partner, product, serial-number, purchase, delivery, fault, diagnostic, image and communications data. Ecor Pro may share relevant information with the responsible Seller, manufacturer, OEM partner, repair centre, carrier, insurer or technical supplier.

    Before returning a connected or data-capable product, the customer should back up and remove personal data, passwords, accounts, removable media and confidential content where reasonably possible, and reset the product if appropriate. Ecor Pro may access, copy, preserve or erase device data only as reasonably necessary to diagnose, repair, test, investigate or meet legal obligations. Ecor Pro is not responsible for data the customer leaves on a returned product except to the extent liability cannot lawfully be excluded.

    For OEM or private-label products, the OEM partner or customer may be an independent controller for its distributors, retailers and end users. Ecor Pro will normally process warranty information only for the contractual OEM customer and only to the extent agreed, including administration of agreed spare-parts arrangements.

    1. Automated decisions, fraud checks and credit

    We may use automated tools to flag potentially fraudulent, sanctioned or high-risk orders and may obtain credit information for business-account decisions. A flag may lead to manual review, a request for information, refusal of credit or a requirement for advance payment. We do not intend to make solely automated decisions that produce legal or similarly significant effects unless permitted by law and accompanied by required safeguards. Where applicable, individuals may request human review, express their view and challenge a decision.

    1. Security

    We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, authentication, encryption where appropriate, backups, logging, supplier review, confidentiality duties, staff awareness, incident procedures and physical security. No internet or storage system is completely secure; individuals should protect account credentials and notify us promptly of suspected misuse.

    1. Individual rights

    Depending on the country and circumstances, individuals may have rights to:

    • be informed about processing and obtain access to personal data;
    • correct inaccurate or incomplete data;
    • request deletion or restriction of processing;
    • object to processing based on legitimate interests and object at any time to direct marketing;
    • receive certain data in a portable format and have it transmitted where applicable;
    • withdraw consent at any time, without affecting earlier lawful processing;
    • request safeguards relating to solely automated significant decisions; and
    • complain to a competent privacy or data-protection authority.

    To exercise a right, contact the Data Lead and describe the request. We may verify identity and authority, and may ask for clarification. We normally respond within the period required by Applicable Data Protection Law. Rights are not absolute: exemptions may apply, and a reasonable fee or refusal may be permitted for manifestly unfounded or excessive requests.

    1. Complaints and supervisory authorities

    Please contact the Data Lead first so we can investigate. Individuals may also complain to the authority in the country where they live or work, or where an alleged infringement occurred. Relevant authorities include the Information Commissioner’s Office for the United Kingdom, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) for the Netherlands, and the Data Protection Commission for the Republic of Ireland. Contact details are available on each authority’s official website.

    1. Children

    Our websites, products and services are not directed to children, and we do not knowingly collect personal data from children for marketing or account creation. If a child’s data is provided in connection with a product-safety, warranty or customer-service matter, we will use only what is necessary and lawful. A parent or guardian who believes a child has provided data should contact the Data Lead.

    1. Changes to this Policy

    We may update this Policy to reflect legal, regulatory, operational, technology or business changes. The current version will be published on the applicable websites with its effective date. Where required, we will provide additional notice or obtain consent before materially changing how existing personal data is used.

    1. Contacting us

    Questions, requests and complaints about this Policy or our use of personal data should be sent to:

    • Data Lead: mail@ecorproducts.com
    • Ecor Pro Limited: 194 Whitley Road, Newcastle upon Tyne, NE26 2TA, United Kingdom
    • Ecor Pro B.V.: Keizersgracht 572, 1017 EM Amsterdam, The Netherlands

    Please do not send product returns to these addresses unless Ecor Pro has issued return instructions or an RMA.