Global Privacy Notice
Introduction
EM Topco Limited (Reg. No. 13855635), together with its subsidiaries, operates globally through a number of legal entities and trading brands in different jurisdictions (“Element”, “we”, “us”, or “our”). Element’s head office is located at 3rd Floor Davidson Building, 5 Southampton Street, London, United Kingdom.
Element is committed to complying with applicable data protection and privacy laws wherever we operate, and to handling personal data fairly, transparently, responsibly and securely.
This Privacy Notice explains how and why Element collects, uses, shares, and protects personal data about individuals who interact with us, including customers, prospective customers, business contacts, job applicants, site visitors, clinical research participants, and other individuals whose personal data we process in connection with our business activities (“you” or “your”).
Data controller
Each Element legal entity that provides services to you or otherwise determines the purposes and means of processing your personal data, acts as an independent data controller.
The relevant Element entity acting as your contracting party will typically be identified in your contract, engagement documentation, invoices, order forms, or other communications with us.
In some circumstances, multiple Element entities may be involved in the same processing activities and may act as independent controllers, joint controllers, or processors, depending on the nature of the processing.
Further information about the Element legal entities that may process personal data is available here: “Element Legal Entities Processing Personal Information”.
Contact us
If you have any questions or comments about this Privacy Notice, you can contact us using the details below:
|
|
privacy@element.com |
|
Post |
Data Privacy Manager, Element Materials Technology, 1 New Park Square, Airborne Place, Edinburgh Park, Edinburgh, UK, EH12 9GR |
|
Website | |
|
Telephone |
UK: +44 808 303 6606 Germany: +49 800 000 5137 Americas: +1 888 818 0395 Middle East: +971 800 353 6368 |
Data Protection Officer (Germany only)
If you are based in Germany and wish to contact our German Data Protection Officer, you can use the details below:
|
| |
|
Postal address |
Datenbeschützerin Regina Stoiber GmbH, Unterer Sand 9, 94209 Regen, Germany
|
|
Website |
Principles for processing
We are committed to processing personal data fairly, lawfully, and transparently, and in accordance with applicable data protection and privacy laws. Additional information about privacy rights and disclosures for California residents is set out in the California privacy section below. To support these commitments, we will:
- Collect and process personal data only for specified, explicit, and legitimate purposes, and not process it in a manner incompatible with those purposes;
- Process only personal data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed;
- Take reasonable steps to ensure that personal data is accurate, complete, and kept up to date where necessary; and
- Retain personal data only for as long as necessary for the purposes for which it was collected and processed, including to satisfy legal, regulatory, accounting, or reporting requirements and applicable limitation periods.
Purpose and legal basis for processing
We process personal data only where we have a lawful basis to do so under applicable data protection laws. Depending on the circumstances, these legal bases may include:
A) Performance of a contract
Processing necessary to enter into or perform a contract with you or your organisation.
B) Legitimate interests
Processing necessary for our legitimate business interests, including operating and improving our services, maintaining business relationships, managing access to our sites and facilities, ensuring security, preventing fraud, protecting our personnel, systems and assets and protecting legal rights, provided such interests are not overridden by your rights and freedoms.
C) Legal obligation
Processing necessary to comply with legal and regulatory obligations.
D) Consent
Where required by law, we rely on consent for certain processing activities, such as certain marketing communications or cookies. Where consent is used, it may be withdrawn at any time.
Categories of personal data we process
The table below explains the circumstances in which we may collect and use personal data, the categories of personal data involved, the purposes for which personal data is processed, and the legal bases that may apply under applicable data protection laws.
|
In what context is your personal data collected? |
Categories of personal data |
Purposes of processing |
Legal basis |
|
Provision of products and services Information collected when you enquire about, purchase, access, or receive our products and services |
|
|
· Performance of a contract · Legitimate interests |
|
Billing, invoicing, and financial administration Information collected in connection with payments, invoicing, and financial management activities |
|
|
· Performance of a contract · Compliance with legal obligations |
|
Identity verification and compliance activities Information collected to verify identity, conduct due diligence, or comply with legal and regulatory obligations |
|
|
· Compliance with legal obligations · Legitimate interests |
|
Audits, inspections, testing, certification, and conformity assessment activities Information collected in the course of delivering professional and technical services |
|
|
· Performance of a contract · Compliance with legal obligations · Legitimate interests |
|
Website use, portals, and online services Information collected when you visit our websites, use online portals, or interact with digital services |
|
|
· Legitimate interests · Consent where required by law |
|
Marketing and business relationship management Information collected when you subscribe to communications, attend events, interact with us, or express interest in our services |
|
|
· Legitimate interests · Consent where required by law |
|
Security monitoring and business protection Information collected through security and monitoring measures implemented at our premises or communications systems |
|
|
· Legitimate interests · Compliance with legal obligations |
|
Recruitment and employment-related activities Information collected when you apply for a role or participate in recruitment processes |
|
|
· Legitimate interests · Performance of a contract · Compliance with legal obligations |
|
Legal, regulatory, and compliance matters Information collected or used in connection with disputes, investigations, legal proceedings, or regulatory requests
|
· Information relevant to investigations, disputes, legal claims, or regulatory requests · Criminal offence data where permitted by law
|
· To comply with legal and regulatory obligations · To respond to lawful requests · To protect legal rights · To establish, exercise, or defend legal claims
|
· Legitimate interests · Compliance with legal obligations
|
|
Visitor management at Element laboratories and sites Information collected when you visit our laboratories, offices, testing facilities, or other Element sites, including where identification checks are required for visitor management, site security, export control, sanctions, or regulatory purposes.
|
· Name and contact details · Employer or organisation · Visit details, including date, time, host, and site visited · Government-issued identification details and, where required, copies of identification documents · Nationality, citizenship, or residency information where required for export control checks · Visitor access or sign-in records |
· To manage visitor access to Element laboratories, offices, and sites · To protect the security of our sites, visitors, personnel, equipment, systems, and information · To verify an individual’s identity and nationality where required · To comply with applicable export controls, sanctions, security, and regulatory requirements · To maintain records needed for audits, investigations, or regulatory enquiries |
· Performance of a contract · Legitimate interests · Compliance with legal obligations
|
|
Clinical research participant recruitment and screening Information collected when you register interest in participating in a clinical research study, respond to study advertisements, complete screening questionnaires, or otherwise engage with our clinical research recruitment activities. |
|
|
For health information and other sensitive personal data, we will rely on an applicable lawful basis and condition for processing under applicable law, including where processing is necessary for scientific research activities, healthcare-related purposes, legal claims, or with your explicit consent where required. |
Sensitive or Special Categories of Personal Information
We do not ordinarily collect or process sensitive categories of personal information as part of most of our business activities.
However, in limited circumstances, we may receive or process sensitive personal information where necessary for the provision of services, compliance with legal or regulatory obligations, the establishment, exercise or defence of legal claims, or where otherwise permitted or required by applicable law. Depending on the applicable law and the context in which it is collected, this may include:
- Health data
- Biometric data
- Data revealing racial or ethnic origin
- Religious or philosophical beliefs
- Trade union membership
- Government-issued identifiers (such as passport or driver’s licence numbers)
- Precise geolocation data
- Account log-in credentials, where collected
Where required under applicable law, such information may constitute “special category personal data” under EU and UK data protection laws or “sensitive personal information” under California law. We will only process such information where a valid lawful basis and, where required, an applicable condition for processing special category personal data applies.
In connection with our clinical research participant recruitment activities, we may collect health and medical information provided by individuals who express an interest in participating in clinical research studies. Such information may be used for participant recruitment, eligibility assessment, study administration, participant safety, ethical review and oversight, compliance with applicable legal and regulatory requirements, and other purposes described in this Privacy Notice.
Criminal offence data
We may process information relating to criminal convictions or offences where this is necessary to comply with legal or regulatory obligations, or where required for screening, compliance, or security purposes.
How we obtain information
We collect personal data in a variety of ways, including:
- Directly from you, including when you enquire about or purchase products or services, request support, attend events, use our websites or portals, provide feedback, or apply for a role
- Through your use of our websites, portals, and online services, including information collected through forms, cookies, server logs, and other automated technologies
- Through business relationships where your organisation engages with us and you act in a professional capacity
- From third parties, including service providers, industry, trade, or regulatory bodies
- From publicly available sources, including professional networking platforms, company websites, press publications, public registers, and search engines
- Through our client portals and online reporting platforms, including where you access test results, certificates, or other service-related documentation, or submit information in connection with sample submissions or service requests
- Directly from visitors to our laboratories, offices, testing facilities, and other sites, including through visitor registration processes, visitor logs, identity verification procedures, access control systems, and export control or regulatory compliance checks.
- Directly from individuals who express an interest in participating in clinical research studies, including through study enrolment forms, participant screening questionnaires, study websites, advertisements, referrals, and communications with our research teams. We may also receive information from research sponsors, investigators, healthcare professionals, or other parties involved in the administration of clinical research studies where permitted by applicable law.
Failure to provide personal data
Where personal data is required to enter into or perform a contract, or to comply with legal obligations, failure to provide such data may prevent or delay us from providing products or services to you or your organisation.
Who personal data is shared with
We may share personal data where necessary to carry out business activities, provide products and services, operate systems, or comply with legal and regulatory obligations.
Personal data may be shared with:
A) Companies within our group
We may share personal data within our group where necessary for internal administrative purposes, service delivery, customer management, marketing activities, or to maintain consistent service standards.
Depending on the context, these companies may act as independent controllers, joint controllers, or processors acting on our behalf.
B) Service providers and business partners
We may share personal data with third-party service providers and business partners who support our operations, including IT and hosting providers, customer support services, email distribution services, digital advertising and marketing platforms (such as search and display advertising tools used for audience targeting, ad relevance, and marketing suppression), professional advisers, payment processors, and subcontractors.
Where such parties act as processors on our behalf, they are required to implement appropriate technical and organisational measures and process personal data only in accordance with our instructions. In some cases, third-party platforms may process personal data as independent controllers in accordance with their own privacy policies. Where relevant, details of such third-party platforms are set out in our Cookies Policy.
C) Debt recovery and legal service providers
Where necessary, we may share personal data with debt recovery agencies, solicitors, and other professional advisers for debt recovery, dispute resolution, or enforcement of contractual rights.
D) Regulatory authorities and other third parties
We may disclose personal data to courts, law enforcement authorities, regulators, government bodies, accreditation and certification bodies, and other competent agencies where required or permitted by applicable law. This may include disclosures needed to comply with legal obligations, respond to lawful requests, protect our rights, or support the assessment, granting, or maintenance of accreditations and certifications.
We may also share personal data with research sponsors, ethics committees, regulatory authorities, healthcare professionals, laboratories, monitors, auditors, and other parties involved in the oversight, administration, or conduct of clinical research studies, where necessary and permitted by applicable law. Where required for export control, sanctions, security, regulatory, or similar legal purposes, we may share visitor identity information, including copies of identification documents where relevant, with government authorities, regulators, or other competent agencies.
E) Corporate transactions
We may share personal data in connection with mergers, acquisitions, restructurings, joint ventures, or asset sales.
International transfers of personal data
As a global organisation, we may transfer personal data internationally in connection with our operations and service delivery.
We may transfer personal data to group companies and third-party service providers in countries outside the jurisdiction in which it was originally collected, where appropriate safeguards are in place to ensure personal data is protected in accordance with applicable data protection laws.
We will only transfer personal data where one or more of the following applies:
A) The destination country or recipient has been recognised as providing an adequate level of data protection under applicable law (including, where relevant, under UK adequacy regulations or EU Commission adequacy decisions)
B) Appropriate safeguards have been implemented, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission, for transfers subject to EU GDPR
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, for transfers subject to UK GDPR
- Binding Corporate Rules (BCRs), or other legally approved transfer mechanisms
C) The transfer is otherwise permitted under applicable data protection law, for example where necessary for contract performance, legal compliance, or where valid consent has been obtained
Where required, we apply additional technical, organisational, and contractual measures to protect personal data during international transfers.
How we protect personal data
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.
These measures are designed based on the nature of the data, associated risks, and applicable legal requirements, and are reviewed and updated where appropriate.
Access to personal data is restricted to authorised personnel who require access for their role and who are subject to confidentiality obligations.
We also maintain security policies covering access control, system security, and internal governance.
While we apply appropriate safeguards, no system is completely secure and we cannot guarantee absolute security.
How long we retain personal data
We retain personal data only for as long as necessary for the purposes for which it was collected, including to provide services, manage relationships, and comply with legal obligations.
Retention periods are determined based on legal, regulatory, contractual, and business requirements. In determining appropriate retention periods, we consider the nature and sensitivity of the personal data, the purposes for which it is processed, applicable legal and regulatory requirements, and relevant limitation periods.
Where statutory or regulatory retention periods apply, we retain personal data for the required duration.
We may retain personal data for longer where necessary to comply with legal obligations or to establish, exercise, or defend legal claims.
Cookies and online tracking
We use cookies and similar technologies to operate our websites, improve functionality and performance, analyse usage, and support security.
This may involve processing personal data such as IP addresses, browser information, and browsing behaviour.
Where required by law, we obtain consent for the use of non-essential cookies. Further information about the cookies we use and how to manage your preferences is available in our Cookies Policy. Please note that disabling certain cookies may affect website functionality.
Marketing communications
You may opt out of receiving marketing communications at any time by using the unsubscribe link in our marketing emails or by contacting tactical.marketing@element.com.
Data subject rights
Depending on your location and subject to applicable legal limitations, you may have the following rights in relation to your personal data:
- Right of access – to obtain confirmation of whether personal data is processed and to receive a copy of that data
- Right to rectification – to request correction of inaccurate or incomplete personal data
- Right to erasure – to request deletion of personal data where legally applicable
- Right to restriction of processing – to request limitation of processing in certain circumstances
- Right to object – to object to processing where it is based on legitimate interests or where otherwise permitted by law
- Right to data portability – to receive personal data you have provided in a structured, commonly used, machine-readable format and/or request its transfer where technically feasible
- Right to withdraw consent – where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal
These rights may be subject to legal or regulatory limitations depending on the jurisdiction in which you are located. For clarity, we do not carry out automated decision-making or profiling that produces legal or similarly significant effects on individuals.
How to exercise your rights
To exercise your rights, contact us using the details provided above. We may need to verify your identity before responding. In some cases, legal exemptions may apply. We will respond within the timeframe required by applicable law. Where permitted by law, this period may be extended if your request is complex or if we receive multiple requests, in which case we will notify you.
California residents
If you are a California resident, this section applies to you in addition to the rest of this Privacy Notice.
The categories of personal information we collect, the sources from which we collect it, the purposes for which we use it, and the categories of third parties to whom we disclose it are described in the sections above.
Some of the personal information we collect may be considered “sensitive personal information” under California privacy law, including government-issued identifiers, account log-in credentials, health information, biometric information, precise location information, and information revealing racial or ethnic origin, religious or philosophical beliefs, or trade union membership, where applicable.
We do not sell personal information. We do not use or disclose sensitive personal information for purposes other than those permitted under California privacy law.
California residents may have additional rights under California privacy law, including the right to know what personal information we collect, use, disclose, sell, or share, where applicable; the right to access, correct, delete, or receive a copy of personal information; the right to limit certain uses or disclosures of sensitive personal information; and the right not to be discriminated against for exercising their privacy rights. To exercise these rights, please contact us using the details in the “Contact us” section and mark your request “California privacy rights request”. We may need to verify your identity before responding.
Complaints and supervisory authorities
We are committed to resolving any concerns you may have about how your personal data is handled.
If you have any concerns, you can contact us using the details above or submit a data protection complaint via our complaints form. We will review your complaint and respond to you.
You also have the right to lodge a complaint with a relevant data protection supervisory authority in your jurisdiction.
Privacy notice updates
We may update this Privacy Notice from time to time. Updates will be published on our website and take effect upon publication.
Last updated: 04/09/2026
