01
Governance
Merser Pumps should maintain clear responsibility for data protection, including who can access enquiries, quotes, uploaded files and reporting forms.
Access should be limited to relevant employees and trusted service providers.
Legal
This document explains the data protection framework behind the website and the day-to-day handling of personal data at Merser Pumps.
01
Merser Pumps should maintain clear responsibility for data protection, including who can access enquiries, quotes, uploaded files and reporting forms.
Access should be limited to relevant employees and trusted service providers.
02
The company asks for information that is relevant to the request. Contact forms and quote forms should avoid collecting information that has no practical purpose.
Visitors and reporters should not include unnecessary personal data or information about third parties unless it is relevant.
03
Merser Pumps relies on accurate technical and contact information to answer requests properly.
If information is incorrect, the sender can ask for correction by contacting info@merser.com.
04
Business enquiries, drawings, technical documents and whistleblower reports should be treated as confidential information.
Employees and service providers should handle data according to their role and the sensitivity of the material.
05
Data should not be kept longer than needed for the purpose, the customer relationship, legal obligations or documentation needs.
The final retention schedule should specify periods for contact enquiries, quotes, uploaded files, accounting records and whistleblower reports.
06
Service providers that process personal data on behalf of Merser Pumps should be covered by suitable data processing terms.
The final version should list or describe the categories of processors used for hosting, forms, storage, e-mail and other website operations.
07
Data protection should be considered when adding new website functions, new forms, integrations, storage locations or analytics tools.
Where risk is high, Merser Pumps should assess the impact before processing begins.
08
Suspected data incidents should be assessed promptly, contained where possible and documented internally.
If required by law, Merser Pumps must notify the supervisory authority and affected individuals within the applicable deadlines.
09
Requests from individuals should be registered, assessed and answered within the deadlines required by data protection law.
The company may reject or limit a request where the law allows it, for example where documentation must be retained.
10
People who handle enquiries, quotes, files and reports should understand confidentiality, secure communication and the importance of limiting access.
Practical routines are especially important in a company that handles technical drawings and spare part documentation.
11
The data protection framework should be reviewed when the website changes, when new suppliers are added, or when legislation changes.
A review date and approval owner should be added to the final document.
12
This is a structured draft for a professional company website.
Final legal wording, retention periods, processor names and internal responsibility must be confirmed before publication.