01. Data Controller Identification & Corporate Governance
This Privacy Policy outlines the operational principles and technological standards by which M Ali Zeirbani Trading Ltd (operating commercially under the trademark and trade name Lord of BMW) collects, processes, stores, and safeguards the personal data and automotive technical identifiers of visitors, registered clients, and commercial partners.
M Ali Zeirbani Trading Ltd is a private limited liability company incorporated under the laws of the Republic of Cyprus with Department of Registrar of Companies Registration Number HE429180, maintaining its registered commercial headquarters and primary parts fulfillment operations in Nicosia, Cyprus. For all data processing activities initiated via this website, associated subdomain properties, mobile interfaces, and digital commerce endpoints, M Ali Zeirbani Trading Ltd acts as the statutory Data Controller as defined under Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation or "GDPR").
Our commitment to transparent and privacy-centric data governance applies universally across all user interactions, whether you are browsing our online BMW catalog, submitting a chassis compatibility query, creating an account, or completing an order for replacement parts.
02. Taxonomy of Collected Personal Information
Depending on the nature of your interaction with our catalog and customer service systems, we collect and process several distinct categories of personal and technical data:
- Personal Contact & Identification Data: Full legal name, business entity name, commercial tax registration and VAT identification numbers (for B2B transactions), primary contact telephone numbers, and electronic mail addresses.
- Billing & Physical Freight Delivery Data: Precise street addresses, postal/zip codes, city, regional province, country of destination, and specific courier delivery instructions or gate codes.
- Automotive Vehicle Identifiers & Technical Fitment Logs: 17-character Vehicle Identification Numbers (VIN), chassis codes (e.g., E30, E36, E46, E90, F30, F80, G20, G80), manufacturing model year, engine variant designations (e.g., N54, N55, S55, B58, S58), transmission codes, pre-LCI or LCI facelift identifiers, and customer-uploaded diagnostic error logs.
- Transaction & Payment Settlement Data: Order identification numbers, purchased SKU catalogs, invoice amounts, currency selections, payment gateway transaction reference tokens, payment timestamps, and masked card identifiers (last 4 digits). We never store raw credit card numbers or CVV security codes on our infrastructure.
- Technical Telemetry & Network Data: Internet Protocol (IP) addresses, browser user-agent strings, operating system versions, device screen resolutions, geographic location estimated at country/city level, referrer URLs, session interaction timestamps, and server request latency metrics.
03. Processing Purposes & Legal Justifications
We process your personal information exclusively for clearly defined, lawful operational purposes, backed by valid legal grounds under Article 6 of the GDPR:
Order Fulfillment & Contract Performance (Art. 6(1)(b) GDPR): Processing your identity, payment reference tokens, and shipping coordinates is strictly necessary to assemble, package, insure, dispatch, and track your parts consignment, as well as to communicate real-time delivery status updates and handle potential return requests.
Automotive Fitment & Precision Validation (Art. 6(1)(b) GDPR): Cross-referencing your supplied VIN or vehicle specifications against official BMW parts catalog databases (ETK) and technical service bulletins to guarantee 100% mechanical compatibility prior to shipping high-value components.
Statutory Compliance & Fiscal Reporting (Art. 6(1)(c) GDPR): Fulfilling our mandatory corporate obligations under Cyprus fiscal law, European VAT reverse-charge mechanisms, customs export declarations, and consumer protection regulations regarding warranty logging.
Fraud Prevention & Network Cybersecurity (Art. 6(1)(f) GDPR): Analyzing telemetry and transactional patterns to prevent unauthorized card use, defend our web infrastructure against distributed denial-of-service (DDoS) attacks, and maintain catalog database integrity under our legitimate commercial interests.
04. Protection of Automotive Diagnostic & Fitment Records
Automotive specifications and VIN logs submitted via our compatibility checker or customer support tickets receive specialized technical protection. We understand that chassis details represent proprietary technical data for vehicle owners and independent performance tuning garages.
Vehicle fitment data is linked solely to your individual customer order ledger for the purpose of ensuring correct part dispatch and honoring manufacturer warranty terms. We never monetize, aggregate, or license customer VIN records to commercial telemetry aggregators, automotive insurance data brokers, or third-party vehicle history reporting platforms.
05. Third-Party Service Providers & Sub-processors
To execute smooth international e-commerce operations, Lord of BMW collaborates with trusted enterprise sub-processors under rigorous Data Processing Agreements:
- Payment Gateways (Stripe, PayPal): All credit/debit card transactions are processed through tokenized, PCI-DSS Level 1 compliant payment channels. Direct card numbers are transmitted through encrypted SSL/TLS channels directly to the processor's secure vault without traversing or residing on our local servers.
- International Courier Networks (DHL Express, FedEx, Cyprus Post, DPD): Essential delivery coordinates and contact telephone numbers are transmitted to authorized transport carriers solely to execute physical transit, international airfreight logistics, and customs clearance formalities.
- Cloud Hosting & Content Acceleration: High-security server infrastructure and Redis caching clusters hosted within certified European Union data centers governed by strict ISO/IEC 27001 and GDPR compliance frameworks.
06. Cross-Border Transfers & International Safeguards
As an international distributor shipping to customers globally, personal information may occasionally be transferred to or accessed by technical infrastructure or courier hubs located outside the European Economic Area (EEA).
Whenever cross-border data transfers occur to jurisdictions lacking an adequacy decision by the European Commission, M Ali Zeirbani Trading Ltd enforces standard contractual clauses (SCCs) adopted by the European Commission under Article 46(2)(c) of the GDPR, coupled with supplementary technical safeguards such as end-to-end payload encryption to ensure that your personal information receives a level of protection fully equivalent to that guaranteed within the European Union.
07. Cryptographic Security Protocols & Infrastructure Defense
Lord of BMW deploys advanced technical and organizational measures to defend customer data against unauthorized interception, destruction, loss, or modification:
- Transport Layer Security (TLS 1.3): All network traffic across our catalog, user accounts, and checkout flow is encrypted using TLS 1.3 cryptographic suites with strict HSTS (HTTP Strict Transport Security) enforcement.
- Role-Based Access Control (RBAC): Administrative access to order records, customer addresses, and diagnostic files is strictly limited to authorized technical personnel who require access to fulfill specific fulfillment duties.
- Hardened Database & Server Environments: Dedicated database isolation, automated security patch cycles, automated penetration testing, and continuous intrusion detection systems (IDS) operating 24/7.
08. Cookie Architecture & Local Storage Directives
Our digital platform uses cookies and localized browser storage mechanisms to provide essential e-commerce capabilities:
| Cookie Classification | Functionality & Purpose | Lifecycle Duration |
|---|---|---|
| Strictly Necessary | Maintains cart items, user login session, and CSRF security nonces | Session / 48 Hours |
| Functional & UI | Remembers currency selection, theme settings, and filter drawer states | 30 Days |
| Performance & Analytics | Aggregated anonymous telemetry to optimize page load speeds and search latency | 90 Days |
You can configure your browser settings to decline or delete non-essential cookies. However, disabling strictly necessary cookies will impair essential checkout and cart operations.
09. Diagnostic File Uploads & Tuning Calibration Data Governance
Customers utilizing our bespoke performance upgrade consultation or requesting technical guidance for engine software flashes (e.g., Bootmod3, MHD, xHP Flashtool) may voluntarily transmit diagnostic log files, OBD2 readouts (CSV/Datalog format), dyno power charts, and vehicle ECU identification dumps to our engineering team.
All customer-uploaded automotive engineering files are stored within air-gapped, encrypted cloud storage partitions accessible exclusively by senior BMW technical calibration staff. Diagnostic files are utilized strictly for the technical assessment of component suitability, engine health verification, and warranty analysis. These proprietary performance files are never shared with automotive manufacturers for warranty invalidation purposes, nor are they distributed to third-party telemetry data aggregators. Customers may request the permanent cryptographic erasure of their uploaded vehicle calibration files at any time upon completion of their technical service inquiry.
10. Children's Privacy & Age of Digital Consent
The commercial products and technical services distributed by M Ali Zeirbani Trading Ltd are directed exclusively at licensed drivers, certified automotive mechanics, and individuals who have reached the legal age of majority (at least 18 years of age in the Republic of Cyprus and the vast majority of international jurisdictions).
We do not knowingly solicit, collect, or process personal data relating to minors under the age of 16 without verifiable parental consent. If we become aware that personal data belonging to an individual under the statutory age of consent has been collected through our portal without verified parental authorization, we will immediately execute protocols to purge such data permanently from our database infrastructure. Parents or legal guardians who suspect that a minor has provided personal details to our service may contact our Data Protection Officer for immediate removal.
11. Your Legal Rights & Opt-Out Directives
Under European data protection legislation, you maintain comprehensive statutory rights regarding your personal records. You may at any time request access to your stored records, demand correction of outdated vehicle or contact info, request account erasure (subject to statutory tax retention rules), or withdraw consent for marketing broadcasts.
All data subject inquiries and rights requests are fulfilled without administrative charges within 30 calendar days upon identity verification.
12. Contact Our Privacy Team & Regulatory Recourse
If you have questions regarding this Privacy Policy or wish to exercise your data protection rights, please contact our dedicated privacy officers:
You also have the right to lodge a formal complaint with the supervisory authority:
