ISO 9001:2015  ·  ISO 14001:2015  ·  RoHS  ·  REACH Compliant  ·  Samples ship within 48h

Legal

Privacy Policy

Effective date: January 15, 2025Last updated: March 1, 2026Version: 2.4

NanoConduct S.A. is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, store, and share information when you interact with our website, inquire about our products, or conduct business with us. Please read this policy carefully.

1. Data Controller

NanoConduct S.A. ("NanoConduct S.A.", "we", "us") is the data controller responsible for your personal information. We are incorporated under the laws of the Oriental Republic of Uruguay with registered address at Ruta 8, Km 17.500 — Parque Tecnológico del LATU, Montevideo, Uruguay CP 12500.

For privacy-related inquiries, contact our Data Protection Officer:

Email: privacy@nanoconduct.com

Postal: Attn: DPO, NanoConduct S.A., Ruta 8 Km 17.500, Montevideo, Uruguay

2. Information We Collect

We collect information you provide directly and information generated through your use of our services:

Contact & Commercial Data

Name, job title, company name, business email, phone number

Inquiry type, product interest, technical requirements

Quote requests, sample orders, and correspondence records

Technical Data

IP address, browser type and version, operating system

Pages visited, time on site, referral source (via server logs)

Cookie identifiers (see Section 7)

Transaction Data

Purchase history, invoice records, payment method (not card details — processed by third-party gateway)

Shipping addresses for sample deliveries

We do not collect special categories of personal data (health data, biometric data, etc.) through this website.

4. How We Use Your Information

Your information is used strictly for the following purposes:

Processing and fulfilling product inquiries, quotes, and orders

Sending technical documentation (TDS, SDS, COA) upon request

Customer account management and order tracking

Technical support and after-sales assistance

Compliance with export regulations and trade compliance (ECCN, EAR, REACH)

Product safety notifications and SDS updates as required by GHS/OSHA

Aggregate website analytics (anonymized — no individual profiling)

Direct marketing communications (only with explicit consent or existing customer relationship)

5. Data Sharing and Third Parties

We do not sell, rent, or trade your personal data. We share data only where necessary:

**Service Providers** (data processors under contract):

Cloud hosting: AWS (São Paulo region, Brazil)

CRM platform: Salesforce (with EU Standard Contractual Clauses)

Email delivery: SendGrid / Twilio

Payment processing: Stripe (PCI-DSS Level 1 certified)

Freight and logistics partners (for sample shipments only)

**Legal & Regulatory**:

Government authorities or courts where required by applicable law

Export control agencies for shipments classified under dual-use goods regulations

All third-party processors are bound by data processing agreements requiring equivalent protections.

6. Data Retention

We retain personal data for the minimum period necessary:

After retention periods expire, data is securely deleted or anonymized.

Data CategoryRetention Period
Inquiry / contact form data3 years from last contact
Customer order records10 years (accounting legal obligation, Uruguay Law 16.060)
Technical support tickets5 years
Website analytics (server logs)90 days (rolling)
Marketing consent recordsUntil withdrawal + 3 years
SDS request records30 years (GHS regulatory requirement)

7. Cookies and Tracking

We use a minimal set of cookies:

**Strictly Necessary** (no consent required):

Session cookie: Maintains form state across page navigation (expires: session)

CSRF token: Security protection for form submissions (expires: session)

**Analytics** (consent required):

We use privacy-respecting, self-hosted analytics. No Google Analytics, no Meta Pixel, no cross-site tracking.

You can configure cookie preferences at any time. Disabling strictly necessary cookies may affect form functionality.

8. Your Rights

Under applicable data protection law (Uruguay Law 18.331 — LPDP; GDPR for EEA contacts), you have the right to:

Access: Obtain a copy of the personal data we hold about you

Rectification: Correct inaccurate or incomplete information

Erasure: Request deletion of your data (subject to legal retention obligations)

Restriction: Limit how we process your data in certain circumstances

Portability: Receive your data in a structured, machine-readable format

Objection: Object to processing based on legitimate interests or for direct marketing

Withdraw consent: At any time, without penalty

To exercise these rights, email privacy@nanoconduct.com with subject line "Data Rights Request". We will respond within 30 days. Identity verification may be required.

9. Security Measures

We implement appropriate technical and organizational measures:

TLS 1.3 encryption for all data in transit

AES-256 encryption for data at rest

Role-based access control with principle of least privilege

Annual penetration testing and quarterly vulnerability scans

ISO 27001-aligned information security management practices

Employee data protection training (annual)

Incident response plan with 72-hour breach notification capability (per GDPR Art. 33)

No method of transmission over the Internet is 100% secure. We continuously improve our security posture.

10. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. We will notify existing customers of material changes via email at least 30 days before they take effect.

The "Last Updated" date at the top of this page indicates when the policy was most recently revised. Your continued use of our services after the effective date constitutes acceptance of the updated policy.

Questions or Concerns?

Contact our Data Protection Officer at privacy@nanoconduct.com or write to NanoConduct S.A., Attn: DPO, Ruta 8 Km 17.500, Montevideo CP 12500, Uruguay.

If you are located in the EEA and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.