Política de Privacidade

Política de Privacidade | Frezite Group

Privacy Policy

Our Company is committed to safeguarding the privacy, confidentiality and security of personal data. This Privacy Notice explains how the company that is identified as the operator of this website collects, uses, stores, shares, transfers and otherwise processes personal data.
The processed personal data may vary depending on the nature of your relationship and interactions with our Company, the products, services, and features you use, your geographic location and the legal and regulatory requirements applicable in the relevant jurisdiction.
For more information on how Sandvik processes your personal data, please refer to the Sandvik Group Privacy Notice available here: Data privacy.


1. Who processes your personal data

The company that operates this website and determines the purposes for which and the manner in which your personal data is collected, used, disclosed, retained, or otherwise processed (“Data Controller”) is Frezite ("wer", "us"), Rua do Vau, nº 173, Bougado (São Martinho e Santiago), 4785 - 229 Trofa, Portugal;e-Mail: dpo@frezite.pt.
We have appointed a Data Protection Officer ("DPO"), who can be contacted at the following e-mail address: privacy@sandvik.com.


2. Scope

This Privacy Notice applies to visitors, customers, suppliers, distributors, business partners and users of our websites, customer portals, ecommerce solutions and digital services.


3. What are the personal data processed? What does processing mean? Who is the data subject?

Personal data: any information concerning a data subject that identifies or makes him/her identifiable. Through the website, we collect various personal data, including but not limited to: name, surname, e-mail address, telephone number, IP address.
Processing is any operation or set of operations, performed with or without the aid of automated processes, applied to personal data or sets of personal data, such as collection, recording, organization, structuring, storage, adaptation or modification, extraction, consultation, use, communication by transmission, dissemination or any other form of making available, comparison or interconnection, restriction, deletion or destruction.
Data subject or Individual is the identified or identifiable natural person. By way of example (not exhaustive), the interested party is the user who navigates on the platform and sends, through the platform, a request for information.


4. What types of personal data do we use and why?

The following personal data belonging to users ("Personal Data" or "Data") is the subject of processing:
Category of Personal Data Purpose of Processing Legal Basis
Contact data (such as name, business address, email address, and phone number) Responding to inquiries and requests Legitimate interests
Managing customer and business relationships Legitimate interests; contract performance.
Sending product safety notices, recalls and compliance communications Compliance with legal obligations; legitimate interests.
Sending marketing communications and newsletters Consent
Identifying and managing business opportunities (lead management) Legitimate interests
Applicant and recruitment data (such as contact details, CV/resume information, qualifications, professional experience, employment history and application records). Processing and evaluating your application, assessing your qualifications and experience, presenting relevant career opportunities, and providing information, materials and invitations tailored to your professional profile. Performance of pre-contractual measures taken at the request of the data subject and the legitimate interests of the Controller in managing recruitment activities, assessing candidates' suitability for employment opportunities, and matching candidates with relevant positions.
Organizational data (such as your employer, business unit, department, job function or professional role) To process and fulfil your orders, including payment processing, delivery and customer support. Contract Performance.
To create, manage and maintain your user account and provide access to order history and personalized settings. Legitimate interests.
To communicate with you regarding your purchases, account status and customer service inquiries. Contract Performance; Legitimate interests.
To send marketing communications where you have provided your consent or where otherwise permitted by applicable law. Consent.
You may withdraw your consent at any time by clicking the “unsubscribe” link in any email which you receive from our organization.
To improve our website, products and services, including by analysing website usage, purchasing trends and customer interactions to enhance user experience, business operations and service quality. Legitimate interests.
Financial data (such as payment card information, payment details, bank account information and credit-related information) To process payments, manage refunds and rebates, assess creditworthiness where appropriate, prevent fraud, comply with anti-money laundering and other legal requirements, and support financial administration and accounting activities. Performance of a contract or pre-contractual measures; compliance with legal obligations, including anti-money laundering and accounting requirements; and legitimate interests in managing financial risk, preventing fraud and protecting the business.
Contract data (such as sales and purchase orders, delivery and return addresses, billing information, transaction records and other information collected in connection with customer or supplier contracts) To manage and fulfil orders, process deliveries and returns, administer contracts and service level agreements, provide warranty and after-sales services, manage invoicing and payments, handle claims and disputes, and comply with applicable legal and regulatory requirements. Performance of a contract or pre-contractual measures; compliance with legal obligations, including tax, accounting and regulatory requirements; and legitimate interests in managing customer and supplier relationships, enforcing contractual rights and defending legal claims.
Individual preferences (such as preferred language, country selection, saved settings and shopping preferences) To provide content and communications in your preferred language, personalize and improve your browsing and shopping experience, remember your preferences and settings, facilitate navigation on the website, and help you complete and manage purchases more efficiently. Legitimate interests, namely improving website usability, customer experience and the efficiency of our online services.
Marketing interaction data (such as referral source, campaign information, landing pages visited, forms submitted and materials downloaded from our website). To understand the products, services and content you are interested in, respond to your requests, provide information about relevant products and services, and manage marketing and business relationship activities as well as lead nurturing and marketing segmentation. Legitimate interests in developing business relationships and responding to requests for information; or consent where required by applicable law.
Subscription data (such as newsletter subscriptions, communication preferences and content interests) To provide newsletters and other subscribed content, manage your communication preferences, inform you about products, services, events and business updates that may be relevant to your interests, and measure engagement with our communications. Consent.
You may withdraw your consent at any time by clicking the “unsubscribe” link in any email which you receive from our organization.
Navigational data (such as IP address, cookie identifiers, session data, browser and device information, pages viewed and interactions with the website) To operate, maintain and secure our website; facilitate navigation and the use of website features; improve website performance, functionality and user experience; analyze website usage; provide customer support; process transactions; administer promotions, surveys and other website features; and personalize content and marketing communications, where permitted by applicable law and where required, based on your consent. Performance of a contract or pre-contractual measures, where necessary to provide requested services; legitimate interests in operating, securing and improving our website and services; and consent where required for cookies, analytics technologies or personalization activities.
Consent in case of personalization and marketing communications, where permitted by applicable law.
Providing AI assistant services To provide information, guidance, and support Legitimate interests.



5. AI Chatbots and AI Services

Where AI chatbots or generative AI tools are available on this website, we may process personal data necessary to provide and improve the service, including:
  • identification and contact information, such as your name, email address, company name, and account details where applicable;
  • account and customer relationship information associated with your use of our products and services;
  • \
  • information you provide during your interactions with the AI Assistant, including questions, requests, comments, feedback, and chat communications;
  • information relating to your orders, products, services, or support inquiries that is required to respond to your request;
  • technical and usage information, such as IP address, device information, browser type, session data, timestamps, and interaction logs;
  • information generated by the AI Assistant in response to your requests, including suggested answers, recommendations, and support information.
We process personal data through the AI Assistant for the following purposes: a) Providing the AI Assistant Service
  • responding to questions and requests;
  • providing information regarding products, services, orders, deliveries, returns, and customer support;
  • assisting users in navigating our websites, applications, and digital services;
  • improving the efficiency and accessibility of customer interactions.
b) Service Quality and Improvement
  • monitoring the performance, effectiveness, and reliability of the AI Assistant;
  • identifying and correcting errors, inaccuracies, or technical issues;
  • evaluating and improving user experience and service quality;
  • developing and enhancing AI-enabled functionalities.
c) Security, Compliance and Protection of Our services
  • protecting our systems, users, and business operations from misuse, fraud, unauthorized access, or other harmful activities;
  • investigating security incidents and ensuring compliance with applicable legal and internal requirements;
  • monitoring the appropriate use of AI services and preventing the generation of inappropriate or unlawful content.
Please note that the AI Assistant is designed to assist users by generating responses only based on patterns and information available to the system.
Unless otherwise stated at the time of collection, individual conversations, prompts, and customer-specific content are not used to train publicly available artificial intelligence models.
Information generated through interactions with the AI Assistant may be reviewed and analyzed in aggregated or limited form to evaluate service quality, improve functionality, and enhance the performance of our AI-enabled services, subject to appropriate privacy, security, and confidentiality safeguards.
Authorized personnel and approved service providers may review a limited number of interactions with the AI
Assistant for purposes such as:
  • quality assurance;
  • service improvement;
  • investigation of technical or security issues;
  • fraud prevention;
  • compliance with legal, regulatory, or contractual requirements.
The AI Assistant may be supported by third-party technology providers, including cloud service providers and artificial intelligence platform providers.
Where such providers process personal data on our behalf, they do so under contractual arrangements requiring appropriate confidentiality, security, and data protection measures.
The AI Assistant is intended to provide information, guidance, and support. At present, our AI-enabled services are not intended to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals without appropriate human involvement.


6. Your personal data flows

Your personal data may be accessed or shared, on a need-to-know basis and solely for the purposes described above, with the following categories of recipients:
A. Sandvik Personnel
Your personal data may be processed by duly authorized Sandvik personnel who require access to such data in connection with their job responsibilities and who are subject to confidentiality obligations and appropriate training regarding the protection of personal data.
Access to personal data is limited to personnel whose duties require such access and who are authorized to process personal data under the authority of the Data Controller.
B. Third Parties
Your personal data may also be shared with the following categories of third parties acting on behalf of Sandvik:
  1. External Advisors: Professional advisers and consultants providing legal, compliance, auditing, technical or other advisory services;
  2. Providers: Service providers supporting information technology, hosting, maintenance, business administration, data management and other operational activities;
  3. Other companies within the Sandvik Group for administrative, operational, compliance, security and business management purposes.



7. Personal Data Transfers outside EU or UK

As a global organization, we may transfer and process personal data within the Sandvik Group and with trusted service providers, business partners, and other recipients located in countries outside the country in which the data was originally collected, including countries outside the European Economic Area (EEA) or the United Kingdom.
Where required by applicable law, we implement appropriate safeguards to protect personal data transferred internationally. Such safeguards may include adequacy decisions issued by competent authorities, Standard Contractual Clauses approved by relevant regulators, Binding Corporate Rules, intra-group data transfer agreements, or other legally recognized transfer mechanisms.
In addition, we may implement supplementary technical, organizational, and contractual measures designed to ensure that personal data remains protected and is processed in accordance with applicable privacy and data protection laws.
Further information regarding applicable transfer safeguards may be requested by contacting us through the channels indicated in this Privacy Notice.


8. Data disclosure

Your personal data will not be publicly disclosed except in limited circumstances, including where:
  • disclosure is required by applicable law or a competent authority;
  • disclosure is necessary to establish, exercise or defend legal claims;
  • you have provided your prior consent, where required by applicable law.
  • disclosure may also occur in connection with mergers, acquisitions, corporate reorganizations or the sale of assets.
For example, subject to your prior consent where required, Sandvik may publish your name, photographs or video recordings on its websites, social media channels or other communication materials in connection with corporate communications, promotional activities, events or other business-related purposes.

9. Social media sites

When interacting with our social media pages, personal data may be processed both by the relevant social media platform and by us. Further information is available in the privacy notices of the relevant social media providers.


10. Encryption of Communications

To help protect the security of information transmitted through our websites, we may use industry-standard encryption technologies, such as Secure Sockets Layer (SSL) or Transport Layer Security (TLS), where appropriate.
Where such technologies are implemented, the connection may be identified by the presence of the "https://" prefix in the browser address bar and/or a padlock icon displayed by the browser.
The use of these measures is intended to help protect information transmitted between users and our systems against unauthorized access, use, or disclosure.


11. Security

We take the security of personal data seriously and maintain administrative, technical, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
These measures may include, where appropriate, access controls, authentication mechanisms, encryption technologies, network security controls, monitoring and logging activities, secure development practices, employee awareness and training programs, and business continuity and incident response processes.
We also seek to ensure that service providers and third parties processing personal data on our behalf implement appropriate security measures consistent with applicable legal, regulatory, and contractual requirements.
While we strive to use industry-recognized safeguards and continuously improve our security practices, no method of electronic transmission, storage, or processing can be guaranteed to be completely secure. Accordingly, we cannot guarantee absolute security of personal data.
Users are encouraged to help protect their information by maintaining the confidentiality of their account credentials, using strong passwords, and promptly notifying us of any suspected unauthorized access or security incident involving interactions with our websites, products, or services.


12. Retention

We retain personal data for as long as necessary to fulfill the purposes described in this Privacy Notice, to provide our products and services, to comply with legal, regulatory, tax, accounting, and reporting requirements, to resolve disputes, to protect our rights and interests, and to establish, exercise, or defend legal claims.
Retention periods are determined based on the type of data, the purpose of processing, legal requirements and applicable records retention schedules.
When personal data is no longer required, we will securely delete, anonymize, or otherwise dispose of it in accordance with our records retention policies and applicable laws.
In some cases, personal data may be retained for longer periods where necessary for legitimate business purposes, including analytics, research, security monitoring, audit activities, fraud prevention, business continuity, or historical and statistical purposes. Appropriate technical and organizational safeguards will be implemented to protect personal data throughout such retention periods.


13. Cookies

You can find all relevant information regarding the processing of personal data in connection with cookies in our Cookie Policy: Cookies Policy | Frezite Group.


14. Your Privacy Rights

Where applicable, as a data subject, the user is granted the following rights over the Personal Data collected and processed by the Data Controller for the purposes set out in this Privacy Notice:
  • Access your personal data: you have the right at any time, to obtain confirmation as to whether your personal data are being processed and ask for clarification about the information included in this privacy notice;
  • Correct inaccurate data: you can request the rectification (integration or updating) or correction of your data if not accurate;
  • Request erasure (“right to be forgotten”): you can ask the erasure; if the consent is withdrawn or you oppose for legitimate reason to their treatment; if the personal data have been unlawfully processed, that is in case of a legal obligation of deletion;
  • Restrict the processing: you may request to process your data solely for the period necessary for the rectification; in case of unlawful processing and excluding any other data processing; in case the data we have kept can be useful for you to exercise your rights in court of law and, finally, if you oppose to the data processing and there is a review of the prevalence of our legitimate reasons to yours;
  • Object to the processing: you can at any time object to the processing of your data, unless there are compelling and legitimate reasons for us to proceed with the data processing which override yours (for example, for our exercise or defense of legal claims);
  • Withdraw your consent at any time: you can withdraw your consent at any time by notifying the Data Controller. The withdrawal will not affect the lawfulness of the processing carried out before you have withdrawn the consent.
  • Data portability: where the processing is based on your consent or on a contract and is carried out by automated means, you have the right to receive the personal data that you have provided to us in a structured, commonly used and machine-readable format and, where technically feasible, to have those data transmitted directly to another controller without hindrance.
  • Right not to be subject to automated decision-making: you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on you.
You may have the right to lodge a complaint with a competent privacy, data protection, consumer protection, or other regulatory authority in the jurisdiction where you reside, work, or where an alleged violation of applicable privacy laws has occurred.
For individuals located in the European Economic Area (EEA), information on the relevant supervisory authorities is available at the European Data Privacy Boards website: https://edpb.europa.eu/about-edpb/about-edpb/members_en.
For individuals located in United Kingdom, the relevant supervisory authority is the Information Commissioner's Office.
We encourage individuals to contact us first so that we may attempt to resolve any privacy-related concern promptly and effectively.
To exercise your privacy rights or submit a privacy-related inquiry, please contact us using the details provided below:
  • Applicants
  • Customers, suppliers, intermediaries and others
  • Employee
  • Former Employee



15. Contact us

Privacy-related questions or requests may be submitted by contacting the Data Controller at: privacy@sandvik.com.


16. Changes to this Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our business practices, technologies, legal requirements, or other relevant developments. When we make changes, we will revise the "Last Updated" date at the beginning or end of this Privacy Notice. We encourage you to review this Privacy Notice periodically to stay informed about how we collect, use and protect your personal data.
-->