⚙️
MetalCore
  • Home
  • Services
  • About
  • Compliance & Legal
  • Contact
← Back to Compliance Center

Legal Basis for Data Processing

📅 Effective Date: January 15, 2025 🔄 Last Updated: March 28, 2025 📄 Document Version: 2.4 🌍 Applicable Jurisdiction: EU GDPR / CCPA / Global Standards

1. Scope & Purpose

This document outlines the legal grounds under which MetalCore Manufacturing processes personal and enterprise data. As a precision manufacturing and engineering company operating across aerospace, automotive, medical, and industrial sectors, we handle sensitive technical, commercial, and personnel information.

Our data processing activities are strictly governed by the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and applicable industry-specific compliance frameworks (AS9100, ISO 13485, IATF 16949).

Note: This document applies to all data subjects, including customers, suppliers, employees, contractors, business partners, and regulatory auditors interacting with MetalCore Manufacturing facilities, digital platforms, and service channels. Any changes to legal bases will be communicated 30 days prior to implementation.

2. Legal Basis Classification

Under Article 6(1) of the GDPR and equivalent national laws, personal data may only be processed when one or more of the following conditions apply. MetalCore Manufacturing maps each processing activity to its corresponding legal basis:

  • Contractual Necessity (Art. 6(1)(b)): Processing required to fulfill manufacturing orders, supply agreements, or service contracts.
  • Legal Obligation (Art. 6(1)(c)): Processing mandated by statutory requirements (e.g., tax compliance, export controls, OSHA, REACH, RoHS).
  • Legitimate Interests (Art. 6(1)(f)): Processing necessary for quality control, supply chain optimization, fraud prevention, and business continuity, provided it does not override data subject rights.
  • Explicit Consent (Art. 6(1)(a)): Voluntary opt-in for marketing communications, webinar participation, or non-essential cookies.

3. Processing Activities & Data Categories

The following table details how specific data categories are processed, the associated legal basis, and retention periods:

Data Category Processing Purpose Legal Basis Retention
Customer & Supplier Master Data Order processing, invoicing, compliance audits Contract 7 years post-relationship
Engineering & CAD Files Manufacturing execution, prototyping, IP protection Contract Duration of NDA + 10 years
Quality Inspection Records Traceability, defect analysis, regulatory reporting Legal Legitimate Interest 15 years (medical/aerospace)
Employee & Contractor Data Payroll, access control, safety training, performance Contract Legal Employment period + 6 years
IoT & Machine Telemetry Predictive maintenance, production optimization Legitimate Interest 3 years (aggregated/anonymized)
Marketing & Event Data Newsletters, trade shows, product updates Consent Until withdrawal + 2 years

4. Data Subject Rights

Under applicable privacy legislation, data subjects retain the following enforceable rights. MetalCore Manufacturing commits to responding to valid requests within 30 calendar days:

🔍 Right of Access

Request a copy of all personal data we hold, including processing purposes and recipients.

✏️ Right to Rectification

Request correction of inaccurate or incomplete personal data without undue delay.

🗑️ Right to Erasure

Request deletion of data where legal basis no longer applies or processing is unlawful.

⛔ Right to Restriction

Limit processing while accuracy is verified or legal claims are assessed.

📦 Data Portability

Receive structured, machine-readable data for transfer to another controller.

🚫 Right to Object

Opt-out of processing based on legitimate interests or direct marketing at any time.

To exercise any right, submit a verified request to our Data Protection Officer via the contact channel below. Identity verification may be required to prevent unauthorized disclosure.

5. International Data Transfers

Due to our global supply chain and multinational clientele, personal data may be transferred outside the European Economic Area (EEA) and California. All cross-border transfers comply with:

  • EU Standard Contractual Clauses (SCCs) 2021/914
  • Adequacy decisions where applicable
  • California CCPA/CPRA cross-border disclosure requirements
  • ISO 27001 & SOC 2 Type II security controls

Transfers to manufacturing partners, quality laboratories, or cloud infrastructure providers are contractually bound to equivalent data protection standards. A full transfer impact assessment (TIA) is maintained on file.

6. Retention & Secure Disposal

Data is retained only for as long as necessary to fulfill the stated processing purposes, comply with statutory obligations, or resolve disputes. Upon expiration:

  • Digital records are securely purged using NIST 800-88 compliant wiping protocols
  • Physical documents are cross-cut shredded (DIN 66399 Level P-5)
  • Backups are overwritten according to lifecycle management policies
  • Anonymized datasets may be retained for historical quality benchmarking

7. Data Protection Officer & Contact

For inquiries regarding this legal basis, data subject requests, compliance audits, or vendor security assessments, contact our Data Protection Office:

🛡️ MetalCore DPO Office

Email: dpo@metalcore-mfg.com

Secure Portal: https://compliance.metalcore-mfg.com/data-requests

Mailing Address: Data Protection Officer, MetalCore Manufacturing, 4200 Industrial Blvd, Detroit, MI 48201, USA

Regulatory Authority: Michigan Attorney General's Consumer Protection Division / UK ICO (EU Representative)

All submissions are encrypted via TLS 1.3. Response SLA: 10 business days for acknowledgment, 30 days for resolution.

© 2025 MetalCore Manufacturing. All rights reserved.

Privacy Policy · Terms of Service · Compliance Center · Contact

ISO 9001:2015 | ISO 27001 | AS9100D | IATF 16949

Legal Basis Doc v2.4 | Last Verified: 2025-03-28