Legal
Privacy Notice
Last updated 3 September 2026
This Privacy Notice explains how TIMC collects, uses, shares and protects personal data when you visit timcontrols.com, request a quotation, contact us or work with us as a customer, supplier or business partner.
It covers the activities described below, including our dealings with businesses worldwide, and explains your privacy rights and how to contact us.
Who we are
TIMC is operated by TIMCONTROLS LLC, a company organised under the laws of Wyoming, United States.
We provide industrial, power generation and marine parts sourcing and supply services to businesses worldwide.
In this notice, “TIMC”, “we”, “us” and “our” refer to TIMCONTROLS LLC.
Responsibility for personal data
A data controller is the organisation that determines why and how personal data is used.
TIMCONTROLS LLC is the data controller for personal data collected through this Website, enquiries directed to us, and our customer, supplier and other business relationships.
This means that we determine why and how that personal data is used. We remain responsible for processing carried out on our behalf by service providers acting on our instructions.
For questions about our use of personal data or to exercise your privacy rights, email legal@timcontrols.com.
Scope and applicable laws
This notice applies to website visitors, people submitting enquiries or requests for quotations, representatives of customers and suppliers, and other individuals who communicate with us in connection with our business.
We process personal data in accordance with the privacy and data-protection laws applicable to our activities. These include applicable United States federal and state laws and the European Union General Data Protection Regulation where it applies.
Your rights depend on the relevant law and the circumstances in which your information is processed. Your nationality or location alone does not determine whether the GDPR applies. Nothing in this notice limits your statutory rights.
Personal data means information relating to an identified or identifiable individual. This includes professional contact information, such as a named employee’s business email address or telephone number. Company, equipment and transaction information is covered by this notice where it relates to an identifiable individual.
Our website and services are intended for business use and are not directed at children.
Personal data we collect
The information we collect depends on your interaction with us.
Contact and professional information
Your name, company, job title or role, business email address, telephone number, country, business address and communication preferences.
Enquiries and quotation requests
Information about your requirements, including manufacturers, part numbers, equipment or system models, serial numbers, quantities, preferred condition, urgency, required dates, target prices and messages.
Marine enquiries may also include vessel names, IMO numbers, delivery ports and associated contact details.
Documents and photographs
Personal data contained in parts lists, spreadsheets, drawings, photographs, correspondence and other files you provide. This may include names, signatures, contact details and information embedded in file metadata.
Business relationship and transaction information
Correspondence, quotations, purchase orders, contractual records, billing and delivery details, invoices, payment records and information relating to service enquiries, returns, warranty matters or complaints.
Verification and compliance information
Where necessary for a transaction, information used to confirm identity or authority to act, verify business details, prevent fraud or carry out applicable sanctions and trade-compliance checks.
Technical information
Information generated when you access the website, such as your IP address, browser and device information, pages requested, access times, referring pages and error or security events.
Preferences and privacy requests
Records of your communication preferences, consent where applicable, marketing objections and requests to exercise privacy rights.
Please provide only information relevant to your enquiry. Remove unnecessary personal details from attachments and photographs. Our ordinary quotation process does not require sensitive personal information such as health records, biometric data or identity-document copies.
If you provide another person’s details, please ensure that you are entitled to do so and make this notice available to them where appropriate.
How we obtain personal data
We collect personal data directly from you when you complete a form, send an email, speak with us, provide documents or otherwise communicate with us.
We may also receive relevant information from:
- Your employer, colleagues or authorised representatives.
- Customers, suppliers, manufacturers and other business contacts.
- Affiliated companies supporting the activities described in this notice.
- Publicly available company websites, professional directories, business registers and professional networking profiles.
- Official sources used for applicable business verification or compliance checks.
- Service providers supporting our website and business operations.
Where we obtain personal data from another source, we provide the privacy information required by applicable law. Under the GDPR, this is generally within one month of obtaining the information, or earlier if we first contact you or disclose the information to another recipient, unless a legal exception applies.
Why we use personal data
We use personal data for the purposes below. Where the EU or UK GDPR applies, we must also have an appropriate lawful basis.
Responding to enquiries and preparing quotations
We use contact details, requirement information and correspondence to understand your request, identify relevant parts, check availability and communicate supply options.
Our basis is our legitimate interest in responding to business enquiries. Where you are contracting with us personally, including as a sole trader, we may instead rely on taking necessary steps at your request before entering into a contract.
Sourcing parts and managing orders
We use relevant information to communicate with suppliers, obtain quotations, coordinate supply and delivery, administer orders and handle associated service or warranty matters.
For representatives of business customers and suppliers, our basis is our legitimate interest in managing and fulfilling those business relationships. Where you are personally a party to a contract, we rely on contractual necessity for processing needed to perform it.
Managing business relationships
We use professional contact details and correspondence to maintain accurate records, communicate about requirements and coordinate work with relevant business contacts.
Our basis is our legitimate interest in maintaining effective business communications and continuity of service.
Accounting and legal compliance
We use relevant contact and transaction information to maintain financial records and meet applicable tax, accounting and other legal requirements.
Our basis is compliance with a legal obligation where a specific requirement applies.
Security, fraud prevention and risk management
We use relevant technical, contact and transaction information to protect our website and systems, verify instructions and reduce the risk of fraud or unlawful transactions.
Our basis is our legitimate interest in protecting our business and the people we deal with, or compliance with a legal obligation where applicable.
Complaints and legal claims
We use relevant records to investigate complaints, resolve disputes, recover outstanding sums and establish, exercise or defend legal claims.
Our basis is our legitimate interest in resolving disputes and protecting legal rights, together with any applicable legal obligations.
Marketing and optional website technologies
The relevant purposes and lawful bases are explained below under ‘Business marketing’ and ‘Cookies and similar technologies’.
Where we rely on legitimate interests, we assess whether the processing is necessary and whether those interests are outweighed by your rights and interests. You may contact us for further information or to object.
If we intend to use personal data for a new purpose, we will assess whether that use is lawful and provide any additional information or obtain any consent required before proceeding.
Information you need to provide
Providing personal data is generally voluntary. However, without essential contact, transaction or legally required information, we may be unable to respond to your enquiry, provide a quotation or proceed with an order.
Optional information helps us assess your requirements more accurately.
Business marketing
If we send promotional communications, we do so only where permitted by applicable law. We obtain consent where required. Where the law permits relevant business marketing without consent, we may rely on our legitimate interest in promoting our products and services to appropriate professional contacts.
Submitting an enquiry or requesting a quotation does not, by itself, constitute consent to receive marketing.
You can object to direct marketing at any time by using the opt-out method provided in the communication or emailing legal@timcontrols.com.
If you opt out, we may retain a limited record of your contact details and preference to prevent further marketing. We may still send communications necessary to respond to your enquiries, administer existing orders or meet legal obligations.
International processing and transfers
We work with customers, suppliers, affiliated companies and service providers worldwide. Depending on how your enquiry or transaction is handled, personal data may be processed in the United States, the European Economic Area or other countries where relevant recipients operate.
This may include access by personnel of an affiliated company or by a service provider located abroad.
Countries have different data-protection laws. Where applicable law restricts an international transfer, we must satisfy its requirements before making that transfer. These requirements also apply to transfers between affiliated companies.
Our transfer arrangements
Depending on the arrangement, an appropriate mechanism may include an applicable adequacy decision or approved standard contractual clauses, together with additional safeguards where required.
We rely on the EU-US Data Privacy Framework only where the relevant recipient has a valid certification covering the transfer and that transfer mechanism remains legally available. Our incorporation in the United States does not itself establish certification.
You can contact legal@timcontrols.com to request information about transfers affecting your personal data and, where applicable, a copy of the relevant safeguards, subject to necessary redactions.
How long we keep personal data
We retain personal data for the period needed for the purpose for which it was collected, taking account of applicable legal requirements and the need to resolve outstanding matters.
Our retention period is 5 years from the date of receipt.
Business contact records are reviewed for continuing relevance. Marketing opt-out records are kept for as long as necessary to respect the preference recorded.
Information relevant to an unresolved complaint, investigation or legal claim may be retained until the matter is resolved and any applicable legal retention period has expired.
When retention is no longer justified, we delete the information or anonymise it. Copies in backups are removed through the applicable backup-retention cycle and remain protected until deletion.
How we protect personal data
We use technical and organisational measures appropriate to the nature of the information and the risks involved. These measures are intended to protect personal data against unauthorised access, misuse, accidental loss, alteration or disclosure.
Access is limited to people and service providers who need the information for their work and are subject to appropriate confidentiality obligations.
No method of internet transmission or electronic storage is completely secure. Please avoid sending unnecessary sensitive information through enquiry forms or ordinary email.
Your privacy rights
Your rights depend on the applicable law, the information involved and the circumstances of the processing.
Rights under the GDPR
Where the EU or UK GDPR applies, you may have the right to:
- Access your personal data and obtain information about how it is used.
- Correct inaccurate or incomplete personal data.
- Request deletion in circumstances provided by law.
- Restrict processing in specified circumstances.
- Object to processing based on legitimate interests, on grounds relating to your particular situation.
- Object to direct marketing at any time.
- Receive and transfer your data where the right to data portability applies.
- Withdraw consent at any time where processing relies on consent.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
An objection to direct marketing is absolute: we will stop using your personal data for that purpose. For other processing based on legitimate interests, we may continue only where the law permits, including where compelling legitimate grounds override your interests or the information is needed for legal claims.
We normally respond to GDPR rights requests within one month. If a permitted extension is necessary because of the complexity or number of requests, we will explain this within the initial month.
Rights under United States privacy laws
Depending on your state of residence and whether the relevant law applies, you may have rights to:
- Confirm whether we process your personal information and request access to it.
- Request correction or deletion of personal information.
- Obtain a portable copy of personal information.
- Opt out of the sale of personal information, certain sharing for advertising, targeted advertising or certain forms of profiling.
- Limit specified uses or disclosures of sensitive personal information.
- Appeal a decision concerning a privacy request.
- Exercise applicable privacy rights without unlawful discrimination.
Some state privacy laws exclude information processed in a business or employment context. We assess requests under the law applicable to the information and processing concerned.
Where permitted by law, you may use an authorised agent. We may require evidence of the agent’s authority and any verification permitted by applicable law.
If an appeal right applies, you may appeal our decision by replying to our response or emailing legal@timcontrols.com with the subject ‘Privacy request appeal’. We will respond within the applicable legal deadline and explain any further complaint options.
How to exercise your rights
Email legal@timcontrols.com and describe your request.
Where verification is required, we will request only information reasonably necessary to verify your identity or authority. We will not require identity verification for opt-out requests where applicable law prohibits it.
Requests are normally handled without charge. If a lawful exception permits a charge or refusal, we will explain the reason. Where we cannot fulfil a request, we will explain our decision and any available review or complaint rights.
Automated decisions
We do not make decisions about you based solely on automated processing, including profiling, that produce legal or similarly significant effects.
Questions and complaints
If you have concerns about our handling of personal data, contact legal@timcontrols.com.
Where applicable law provides a right to complain, you may contact the competent data-protection or privacy authority. You do not need to contact us before doing so.
Where the GDPR applies, you may complain to a competent supervisory authority, including the authority in the country of your habitual residence, place of work or the alleged infringement. Contact details are available in the European Data Protection Board’s directory of supervisory authorities.
Where UK data-protection law applies, you may complain to the Information Commissioner’s Office.
In the United States, relevant complaint routes may include your state attorney general or the applicable state privacy regulator. Elsewhere, you may contact the competent authority under the law applicable to your complaint.
Changes to this notice
We may update this notice to reflect changes in our operations, services or legal obligations. The current version will be published on this page with an updated revision date.
Where required, we will bring material changes to your attention and provide information before using your personal data for a new purpose. If a change requires your consent, we will request it separately.