Privacy policy

Privacy Policy

European Made Goods

Last updated: 26 January 2026

1. Introduction

This Privacy Policy explains how European Made Goods (“EMG”, “we”, “us”, “our”) processes personal data in connection with the website www.europeanmadegoods.com and related services (the “Services”).

This Policy is drafted in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and applicable Luxembourg data-protection laws.

Certain features described in this Policy are optional, configurable, or subject to user choice and may not be active at launch.

This Privacy Policy is provided for transparency and information purposes and does not modify, replace, or limit any rights granted to individuals under applicable data-protection laws.

2. Data Controller

Data Controller
European Made Goods SARL-S (to be formed)
Legal form: SARL-S (or successor entity)
Registered office: 6A, Avenue des Hauts-Fourneaux, L-4362 Esch-sur-Alzette, Luxembourg
Email: privacy@europeanmadegoods.com

3. Scope of Application

This Policy applies to personal data processed in relation to:

  • Website visitors
  • Registered users and customers
  • Suppliers, manufacturers, and business partners
  • Individuals communicating with EMG

Third-party websites and services linked from the Services are governed by their own privacy policies.

4. Modular Service Architecture

4.1 Core Services (Always Active)

Processing strictly necessary to:

  • operate and secure the Website
  • create and manage user accounts
  • process transactions and payments
  • onboard and verify suppliers
  • prevent fraud and abuse
  • comply with legal and regulatory obligations

4.2 Optional and Configurable Features

Processing that may be enabled now or in the future, subject to configuration, user choice, or legal requirements, including:

  • marketing communications
  • personalisation and recommendations
  • enhanced analytics and measurement
  • supplier ranking, quality indicators, or trust signals
  • platform optimisation and controlled experimentation

Optional features are activated only where a valid legal basis applies, including consent where required.

5. Categories of Personal Data

Depending on interaction with the Services, EMG may process the following categories of personal data:

5.1 Website and Device Data

  • IP address
  • browser, device, and network information
  • usage and interaction data

5.2 Account and Transaction Data

  • name and contact details
  • billing and delivery information
  • account credentials
  • order and transaction records

5.3 Supplier and Partner Data

  • contact and company information
  • verification, compliance, and onboarding documentation

5.4 Communications

  • messages and correspondence sent to EMG

EMG does not intentionally process special categories of personal data under Article 9 GDPR.

6. Purposes of Processing and Legal Bases

Personal data is processed only for defined purposes under Article 6 GDPR:

Purpose

Legal Basis

Core platform operation

Contract (Art. 6(1)(b))

Payments, fulfilment, returns

Contract (Art. 6(1)(b))

Supplier onboarding and verification

Contract / Legitimate interest

Security, fraud prevention, abuse detection

Legitimate interest (Art. 6(1)(f))

Platform improvement and aggregated analytics

Legitimate interest

Optional personalisation and marketing

Consent (Art. 6(1)(a))

Legal and regulatory obligations

Legal obligation (Art. 6(1)(c))

Processing beyond core services is limited, modular, and may be disabled without affecting access to essential functionality where legally required.

7. Cookies and Similar Technologies

The Website uses cookies and similar technologies for:

  • essential technical functionality
  • security
  • performance and measurement
  • optional analytics and marketing

Non-essential cookies are used only where consent is provided. Further details are available in a separate Cookie Policy.

8. Processors and Data Recipients

Personal data may be shared with trusted third parties acting as processors, including:

  • hosting and infrastructure providers
  • e-commerce and marketplace platforms (e.g. Shopify)
  • payment service providers
  • analytics and communication tools
  • logistics and fulfilment partners

Processors act under contractual safeguards compliant with Article 28 GDPR.

9. Shopify Relationship

The Services are hosted on Shopify infrastructure.

  • EMG acts as Data Controller for marketplace operations.
  • Shopify acts as Data Processor for most processing activities.
  • For certain Shopify-provided enhanced features, Shopify may act as an independent data controller, subject to its own privacy documentation.

10. International Data Transfers

Personal data may be transferred outside the European Economic Area where required for service delivery or infrastructure operation.

Such transfers are safeguarded using:

  • European Commission adequacy decisions, or
  • Standard Contractual Clauses (SCCs)

EMG does not rely on uncontrolled international data transfers.

11. Global Users and Jurisdiction-Specific Rights

Where users are located outside the European Economic Area, EMG processes personal data in accordance with this Privacy Policy and applicable local data-protection laws, where required.

Depending on the user’s place of residence, additional rights or disclosures may apply. Where legally required, EMG will provide supplementary notices, mechanisms, or opt-out choices specific to those jurisdictions.

12. Data Retention

Personal data is retained only as long as necessary for the relevant purpose:

  • transaction and accounting data: statutory retention requirements
  • account data: duration of the account relationship
  • supplier data: duration of the commercial relationship and compliance needs
  • analytics data: aggregated or anonymised where feasible

Retention periods may vary based on legal and operational obligations.

13. Data Subject Rights

Individuals have the right to:

  • access their personal data
  • rectify inaccurate data
  • request erasure where applicable
  • restrict or object to processing
  • data portability
  • withdraw consent at any time

Requests may be submitted using the contact details in Section 2.

Individuals also have the right to lodge a complaint with the Commission Nationale pour la Protection des Données (CNPD) or another competent supervisory authority.

14. Security Measures

EMG implements appropriate technical and organisational measures to protect personal data, including access controls and secure infrastructure. No system can guarantee absolute security.

15. Children’s Data

The Services are not directed at children under 16 years of age. EMG does not knowingly collect personal data from children.

16. Automated Decision-Making and Profiling

EMG does not currently engage in automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR.

If such processing is introduced, appropriate safeguards and disclosures will be implemented.

17. Policy Updates

This Privacy Policy may be updated to reflect legal, technical, or operational changes. The “Last updated” date indicates the most recent revision.

18. Pre-Launch and Evolution Notice

The Services are in a pre-launch / evolving phase. Features, configurations, and processing activities may be introduced or modified over time. Material changes will be reflected in updated versions of this Policy and, where required, additional notices or consent mechanisms.