top of page

Privacy Policy

A Legal Disclaimer

This Privacy Notice has been drafted to comply with the data protection laws applicable in the European Union (the EU General Data Protection Regulation (GDPR)), the United Kingdom (the UK GDPR and the Data Protection Act 2018), Switzerland (the Federal Act on Data Protection (FADP)) and Singapore (Personal Data Protection Act 2012 (PDPA)).

This Privacy Notice explains how Brightway collects, uses, shares and protects personal data when you interact with us, and what rights you have in respect of that personal data. We are committed to protecting your privacy and processing your personal data in accordance with applicable data protection laws.
 

This Privacy Notice may be relevant for you in a range of situations, including (but not limited to) where you:
 

  • visit or use our website at vitol.com or any other Brightway Group website that links to this notice;

  • are, or represent, a prospective or existing counterparty, customer, supplier or business partner of Brightway (including as a director, officer, beneficial owner, authorised representative, agent or other associated individual of such an entity);

  • register for or attend a Brightway-hosted event, or are nominated as a delegate by your employer;

  • visit one of our offices, terminals or operated sites, or use our visitor Wi-Fi; or

  • are otherwise in contact with us in a business context (for example as a journalist, regulator or professional adviser).

 

There may be other circumstances in which Brightway collects personal data where a separate privacy notice would apply. That privacy notice will govern the relevant processing.

How We Keep Your Personal Data Secure

We take our security obligations seriously and have implemented appropriate technical and organisational measures to protect your personal data from unauthorised or unlawful processing and from accidental loss, destruction or damage. These measures include encryption in transit and at rest, role-based access controls, multi-factor authentication, vulnerability management, third party security due diligence, incident-response procedures, disaster recovery processes and regular staff training.

In the event of a personal data breach, we will assess the likely risk to your rights and freedoms and take appropriate steps to contain, investigate and remediate the incident. Where required by applicable law, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay, unless an applicable legal exception applies.

Changes to this Notice

We may update this notice from time to time. We will review it periodically and update it as required to reflect changes in our processing activities or in applicable law. The effective date at the top of this notice will be updated accordingly.

bottom of page