Privacy notice · Regulation (EU) 2016/679
What we process, why, and for how long.
Controller: ISO EU, UAB, TODO: registered office address, Lithuania. Data Protection Officer: Data Protection Officer — dpo@isoeu.com.
Legal bases and purposes
- Contract execution (Art. 6(1)(b)) — processing of client contact and organisational data necessary to deliver audit and certification services under contract.
- Legal obligation (Art. 6(1)(c)) — retention of audit documentation required by ISO/IEC certification body requirements and accreditation regulations.
- Public interest / official authority (Art. 6(1)(e)) — operation of the public certificate verification directory, which reflects current certification status.
- Legitimate interests (Art. 6(1)(f)) — handling of complaints and appeals, safeguarding the integrity of certification decisions.
- Consent (Art. 6(1)(a)) — any optional measurement technology, only after explicit opt-in via the cookie preference centre. No such technology is deployed on this site today.
Retention schedules
- Client certification and audit documentation: 10 years (certification cycle record requirement).
- Complaint files, including evidence: 5 years after closure.
- Appeal files and board decisions: 5 years after the decision.
- Verification directory query logs: 12 months, kept in aggregate form only.
- Evidence files
- Complaint and appeal uploads are stored encrypted at rest, outside any publicly indexable directory, and are accessible only to the personnel handling the case.
- Verification directory
- Search queries are not linked to identified visitors beyond what is strictly required for aggregate statistics.
Your rights
You have the right of access, rectification, erasure, restriction, portability and objection under Chapter III of the Regulation. You may also lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) at any time.
How a data subject request is handled
-
You write to the Data Protection Officer
Send your request to dpo@isoeu.com, stating which right you are exercising. A template is not required — plain language is enough.
-
Identity is verified proportionately
We ask only for the information needed to confirm that the request comes from the data subject or an authorised representative. Copies of identity documents are requested only where genuinely necessary and are deleted after the check.
-
Response within one month
We respond without undue delay and at the latest within one month of receipt (Art. 12(3)). For complex or numerous requests the period may be extended by two further months, with the reasons for the delay communicated within the first month.
-
No fee, in principle
Requests are handled free of charge (Art. 12(5)). Where a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline to act, and we will document the reasons.
-
Escalation remains open
If you are not satisfied with our response, you may complain to the Lithuanian State Data Protection Inspectorate and seek a judicial remedy. Requests concerning certification decisions may additionally be raised through the complaints portal.
Cookie notice
- Essential — security, session administration and storage of your cookie choice. These are strictly necessary and set without consent.
- Analytics — none are loaded on this site. Should any be deployed, they will remain inactive until you opt in through the preference centre, and the change will be recorded here.
- Marketing / profiling — not used, not loaded, not planned.
No third-party resource is loaded from this website: no external fonts, no CDN scripts, no embedded maps or media. Requests stay between your browser and ISO EU LLC.
You can change your choice at any time by clearing the cookie_consent cookie in your browser, which reopens the preference centre on your next visit.