Privacy Policy
Your privacy matters to us. Learn how we collect, use, and protect your personal data.
Table of Contents
01 Introduction
Welcome to SUAT Fuels (Sustainable Atlantic Fuels S.L.). We are committed to protecting and respecting your privacy in accordance with the General Data Protection Regulation (GDPR), Spanish data protection laws, and other applicable international privacy regulations.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website www.suatfuels.com, use our services, or engage with us through other channels. Please read this policy carefully to understand our views and practices regarding your personal data.
Important: By using our website or services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.
02 Data Controller
For the purposes of GDPR and applicable data protection laws, the data controller is:
Sustainable Atlantic Fuels S.L. (SUAT Fuels)
Registered Address: Calle Manzanares 4, 28005 Madrid, Spain
Email: info@suatfuels.com
Phone: +34 684 742
834
03 Data We Collect
We may collect, use, store, and transfer different kinds of personal data about you, grouped as follows:
| Data Category | Description |
|---|---|
| Identity Data | First name, last name, title, company name, job title |
| Contact Data | Billing address, delivery address, email address, telephone numbers |
| Financial Data | Bank account details, payment card details, billing information |
| Transaction Data | Details about payments, fuel orders, services purchased |
| Technical Data | IP address, browser type, operating system, device information |
| Usage Data | Information about how you use our website and services |
| Marketing Data | Your preferences for receiving marketing communications |
Special Categories of Data
We do not collect any Special Categories of Personal Data about you (including details about your race, ethnicity, religious beliefs, sexual orientation, political opinions, trade union membership, health, or genetic/biometric data).
04 How We Use Your Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
Service Delivery
- To provide aviation fuel supply services at airports worldwide
- To process and fulfill your fuel orders and service requests
- To manage your account and customer relationship
- To communicate with you about services, orders, and inquiries
Business Operations
- To process payments and manage financial transactions
- To comply with legal and regulatory obligations
- To prevent fraud and ensure payment security
- To maintain accurate business and financial records
Marketing and Communications
- To send you information about our services and industry updates (with your consent)
- To conduct market research and customer satisfaction surveys
- To improve our services based on customer feedback
Website and Technology
- To deliver and improve our website functionality
- To analyze website usage and optimize user experience
- To ensure network and information security
05 Legal Basis for Processing
Under GDPR, we must have a legal basis to process your personal data. We rely on the following legal grounds:
Contractual Necessity
Processing is necessary to perform our contract with you or to take steps at your request before entering into a contract (e.g., processing fuel orders, providing services).
Legal Obligation
Processing is necessary to comply with legal obligations, including tax laws, aviation regulations, financial reporting requirements, and anti-money laundering regulations.
Legitimate Interests
Processing is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests. Examples include:
- Fraud prevention and security measures
- Business operations and service improvements
- Network and information security
- Internal administration and reporting
Consent
For marketing communications and certain optional services, we will obtain your explicit consent. You have the right to withdraw consent at any time.
06 Data Sharing and Disclosure
We may share your personal data with the following categories of recipients:
Service Providers
- Payment processors: To process financial transactions securely
- IT service providers: For hosting, maintenance, and technical support
- Airport authorities: To facilitate fuel delivery services
- Logistics partners: For fuel supply chain management
Legal and Regulatory Bodies
- Tax authorities and government agencies as required by law
- Aviation regulatory bodies for compliance purposes
- Law enforcement when legally required or to prevent fraud
Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the successor entity, subject to continued compliance with this Privacy Policy.
Important: We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow service providers to use your personal data for their own purposes.
07 Data Security
We have implemented appropriate technical and organizational security measures to protect your personal data from unauthorized access, use, alteration, or disclosure:
Technical Measures
- SSL/TLS encryption for data transmission
- Encrypted storage of sensitive data
- Regular security updates and patch management
- Firewalls and intrusion detection systems
- Secure backup and disaster recovery procedures
Organizational Measures
- Access controls and authentication requirements
- Employee training on data protection
- Confidentiality agreements with staff and contractors
- Regular security audits and assessments
- Incident response and data breach procedures
Data Breach Notification: In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.
08 Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes for which it was collected, including for legal, accounting, or reporting requirements.
Retention Periods
- Customer account data: Duration of business relationship plus 7 years
- Transaction records: 10 years for tax and financial compliance
- Marketing data: Until consent is withdrawn or 3 years of inactivity
- Website analytics: 26 months
When we no longer need your personal data, we will securely delete or anonymize it in accordance with our data retention policy and legal obligations.
09 Your Rights Under GDPR
Under GDPR and applicable data protection laws, you have the following rights:
Right of Access
You have the right to request a copy of the personal data we hold about you.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure ("Right to be Forgotten")
You can request deletion of your personal data in certain circumstances.
Right to Restriction of Processing
You can request that we limit the processing of your personal data in certain situations.
Right to Data Portability
You can request to receive your personal data in a structured, commonly used format.
Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where processing is based on consent, you can withdraw it at any time.
Right to Lodge a Complaint
You have the right to lodge a complaint with the Spanish Data Protection Authority (AEPD) or your local supervisory authority if you believe your data protection rights have been violated.
Exercising Your Rights: To exercise any of these rights, please contact us at info@suatfuels.com. We will respond to your request within one month.
11 International Data Transfers
As we operate globally across 700+ airports, your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States and other jurisdictions.
Safeguards for International Transfers
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions recognizing equivalent data protection standards
- Binding Corporate Rules for intra-group transfers
- Your explicit consent where appropriate
We ensure that all international transfers comply with GDPR requirements and provide equivalent protection for your personal data.
12 Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
Data Protection Officer
Sustainable Atlantic Fuels S.L.
Calle Manzanares 4, 28005 Madrid, Spain
Changes to this Privacy Policy: We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on our website with a revised "Last Updated" date.