Privacy Notice
1. Introduction and what this Privacy Notice covers
This Privacy Notice has been drafted to comply with the data protection laws applicable in the European Union (the EU General Data Protection Regulation (GDPR)), the United Kingdom (the UK GDPR and the Data Protection Act 2018) and Switzerland (the Federal Act on Data Protection (FADP)).
This Privacy Notice explains how Vitol collects, uses, shares and protects personal data when you interact with us, and what rights you have in respect of that personal data. We are committed to protecting your privacy and processing your personal data in accordance with applicable data protection laws.
This Privacy Notice may be relevant for you in a range of situations, including (but not limited to) where you:
- visit or use our website at vitol.com or any other Vitol Group website that links to this notice;
- are, or represent, a prospective or existing counterparty, customer, supplier or business partner of Vitol (including as a director, officer, beneficial owner, authorised representative, agent or other associated individual of such an entity);
- register for or attend a Vitol-hosted event, or are nominated as a delegate by your employer;
- visit one of our offices, terminals or operated sites, or use our visitor Wi-Fi; or
- are otherwise in contact with us in a business context (for example as a journalist, regulator or professional adviser).
There may be other circumstances in which Vitol collects personal data where a separate privacy notice would apply. That privacy notice will govern the relevant processing.
2. Who we are
The terms “Vitol,” “Vitol Group”, “the Company,” or “the Group” may be used for convenience and refer to Vitol Netherlands Coöperatief U.A. and its direct and indirect subsidiaries and affiliates, each of which are separate and distinct legal entities. Further, the words “we,” “us,” “our,” and “ourselves” are used to refer generally to the companies of the Vitol Group.
The Vitol entity responsible for processing your personal data (the “controller”) depends on the relationship you have with us. The principal Vitol controllers and their lead supervisory authorities are:
| Controller | Registered office | Lead supervisory authority |
| Vitol Netherlands Coöperatief U.A. (ultimate controller) | Rotterdam, Netherlands | Autoriteit Persoonsgegevens (AP) |
| Vitol SA | Geneva, Switzerland | Swiss Federal Data Protection and Information Commissioner (FDPIC) |
| Vitol Services Ltd | London, United Kingdom | Information Commissioner’s Office (ICO) |
3. How to contact us
If you have any questions about this notice, wish to exercise your rights or want to raise a privacy concern, please contact us by e-mail via [email protected]. You can also reach us via post at: Vitol, Place des Bergues 3, P.O. Box 1384, 1211 Geneva 1, Switzerland.
4. When and how we collect personal data about you
The personal data we collect, and our reasons for collecting it, depend on how you interact with us. The principal interaction scenarios are set out below.
4.1. When you use our website
When you visit vitol.com we may collect limited technical data automatically (IP address, browser type and version, operating system, device identifiers, referrer URL, pages visited and timestamps), together with the cookies described in Section 7 and our separate Cookie Policy. When you choose to submit a contact or enquiry on the website, we may also collect the information you provide through that form.
4.2. When you use our visitor Wi-Fi service
If you connect to a Vitol office visitor Wi-Fi service, we (or your Vitol host) may collect your first and last name, business e-mail address and company name in order to create your Wi-Fi account, and while you use the service we record the MAC address and IP address assigned to your device and the visitor Wi-Fi username. We use this information to operate the Wi-Fi service securely and to investigate any misuse or cyber-security incidents.
4.3. When you are, or represent, a prospective or existing counterparty, customer, supplier or business partner
If you are, or represent, a prospective or existing counterparty, customer, supplier or other business partner of Vitol, we may collect personal data about you and (where applicable) about individuals associated with the organisation you represent, such as its directors, officers, beneficial owners and authorised representatives. This may include identification and contact details, professional information (such as job title and role), financial information, and identity verification documents.
If you do not provide this information, you, or the organisation you represent, may not be able to transact with us.
4.4. When you apply for a role with us, or are introduced to us
Where you apply for a role or other engagement with Vitol or are introduced to us by a recruitment agency or other intermediary, we may collect the information set out in our separate Fair Processing Notice for Job Applicants which is available to you. That notice prevails over this notice in respect of recruitment processing.
4.5. When you register for or attend a Vitol-hosted event
If you register for or attend an event that is hosted, sponsored or co-organised by Vitol, we may collect the information you provide on registration (including your name, employer, job title and contact details), and — where we organise your travel, accommodation or visas — your passport and visa details.
4.6. When you visit our offices, terminals or other premises
When you visit one of our offices, terminals or other premises, we may record your name, company name, time of arrival and departure and the name of your Vitol host in our visitor logs. For security reasons, our premises are monitored by CCTV in line with applicable signage.
4.7. When you are connected with a corporate transaction
Where Vitol is considering acquiring, investing in, divesting or financing a business, we may collect personal data about you if you are a director, shareholder, officer, employee or other associated individual of the target or counterparty in the corporate transaction. This will typically be collected from public registers, from professional advisers, from a data room or from the target itself.
4.8. When you are granted or hold a power of attorney
If a Vitol Group company grants a power of attorney to you, we will collect the identification, contact and authority information necessary to evidence and rely on that power of attorney.
5. What personal data we process, where we get it, and why
The table below sets out the categories of personal data we process, the purposes, the legal basis we rely on, and our rationale.
| Category | Examples | Purpose | Lawful basis | Rationale / Special category notes |
| Identification data | Name, employer, job title, nationality, date of birth; identity, residence and source-of-funds documents (KYC) | KYC/AML checks; verifying counterparty identity; onboarding | Legal obligation; Legitimate interest | Legal obligation: AML/KYC regulations require identity verification. Legitimate interest: verifying persons we transact with as part of our risk management function. |
| General business and compliance records | Business phone, e-mail, address, messaging IDs; relationship management records, accounting/tax data, insurance records, risk management files, | Managing commercial relationships; communicating with counterparties; executing transactions; record-keeping; accounting; tax; insurance; governance; dealing with claims | Contract; Legal obligation; Legitimate interest | Contract: to communicate with you and where you are personally a party to an agreement. Legal obligation: accounting, tax and other statutory obligations. Legitimate interest: managing relationships, good governance, insurance requirements and risk management. |
| Professional, ownership, financial and compliance data | Role, signing authority, qualifications and UBO information (KYC context), bank details, sanctions, PEP and adverse-media screening results; criminal conviction data (where lawful) | KYC onboarding and understanding counterparty governance; executing and settling transactions; credit/risk management; accounting and tax records; sanctions/AML/anti-bribery compliance; fraud prevention and crime detection | Contract; Legal obligation; Legitimate interest; Substantial public interest | Legal obligation: UBO identification required under AML directives; tax, accounting and regulatory record-keeping; sanctions, AML and anti-bribery laws mandate these checks. Contract: necessary to execute and settle trades. Legitimate interest: understanding authority structures of counterparties; credit and risk management. Substantial public interest: preventing financial crime. Special category note: criminal conviction data is processed only where lawful and subject to appropriate safeguards/additional conditions. |
| Communications data | Correspondence, e-mails, IMs; trade communication recordings | Regulatory trade recording; maintaining business records; resolving disputes | Legal obligation; Legitimate interest | Legal obligation: MiFID II, REMIT and Dodd-Frank mandate recording of trade communications. Legitimate interest: accurate records and dispute resolution. |
| Event, travel and visit data | Registration details, passport/visa data; dietary, accessibility or health requirements | Organising events and travel; accommodating your requirements; visa applications | Legitimate interest; Consent (explicit, for special category data) | Legitimate interest: organising events and travel logistics. Explicit consent: health/dietary info. Visa data may reveal race/ethnicity — processed your consent and at your request. |
| Website and device data | IP address, browser type/version, OS, device identifiers, pages visited, cookie identifiers | Website operation, security and performance monitoring; analytics (with consent) | Legitimate interest; Consent | Legitimate interest: strictly necessary cookies ensure website functions securely. Consent: analytics, functional and advertising cookies set only with prior consent. |
| Visitor and security data | Visitor-log entries, CCTV footage, Wi-Fi connection logs | Physical security of premises; IT network integrity; investigating incidents | Legitimate interest | Legitimate interest: ensuring security of premises, staff and visitors and integrity of IT network. |
| Corporate transaction data | Director, shareholder, officer, employee details of target/counterparty entities | Due diligence for acquisitions, investments, divestments, financings; reviewing key employee remuneration | Legitimate interest | Legitimate interest: making informed investment decisions and conducting thorough due diligence. |
| Power of attorney data | Identification, contact and authority information | Evidencing and relying on powers of attorney granted by Vitol entities | Contract; Legal obligation; Legitimate interest | Contract: necessary to formalise the arrangement. Legal obligation: legal requirements around authority. Legitimate interest: facilitating authorised business operations. |
| Regulatory cooperation data | Data shared with courts, regulators and authorities | Responding to binding and non-binding requests from authorities | Legal obligation (binding); Legitimate interest (non-binding) | Legal obligation: compliance with binding requests. Legitimate interest: cooperating with proportionate non-binding requests. |
5.1. Where we get your personal data from
We may obtain personal data about you from the following sources:
- Directly from you — for example when you contact us, attend our events, apply for a role or communicate with us in the course of a commercial relationship;
- From your employer or the organisation you represent — for example when you are nominated as a counterparty contact, director, beneficial owner or authorised representative;
- From third-party service providers — including identity-verification, KYC, sanctions-screening, adverse-media, credit-reference and background-check providers, recruitment agencies, professional advisers, business introducers and event-management providers;
- From publicly available sources — including public registers, regulatory filings, court records, company registries, news media, professional networking sites such as LinkedIn, and sanctions and PEP lists;
- From counterparties or transaction parties — for example a target company or its advisers in the context of a corporate transaction; and
- Generated by us — including records of our meetings, correspondence, calls, transactions, screening outcomes and any internal analysis we carry out.
5.2. Anonymisation and aggregation
We may convert your personal data into statistical or aggregated form, or otherwise de-identify it, to better protect your privacy or so that you cannot be identified from it. We may then use the anonymised information for research and analysis, including the production of statistical reports, without further notice to you.
6. Automated decision-making
We may use automated tools to assist us. Where the outcome of such a tool could have legal or similarly significant effects on you, the result is always subject to meaningful human review before any decision is taken, and we do not make such decisions on a solely automated basis.
7. Cookies
Our website uses cookies to distinguish you from other users. Information about the cookies we use, their purposes, duration and recipients is set out in our Cookie Policy.
8. Marketing and event communications
From time to time, we may invite you to a Vitol event or send you other information that we consider may be of interest to you in your professional capacity. You may object to any such direct marketing at any time by contacting [email protected].
10. International transfers of your personal data
Vitol is a global business. Personal data that we collect from you in the EEA, the United Kingdom or Switzerland may be transferred to, stored at and processed in countries outside those territories, and may be processed by staff working for us or for one of our service providers outside those territories. We take all steps reasonably necessary to ensure that personal data is treated securely and in accordance with this notice.
We transfer personal data outside the EEA, the UK or Switzerland only where one of the following applies:
- The destination is the subject of an adequacy decision of the relevant authorities;
- The transfer is made subject to appropriate safeguards;
- Binding corporate rules approved by the competent supervisory authority are in place; or
- A specific derogation applies — used only on an exceptional, non-routine basis.
Where we rely on appropriate safeguards, we assess the level of protection in the destination country and put in place any additional measures needed to ensure your data remains adequately protected.
11. How we keep your personal data secure
We take our security obligations seriously and have implemented appropriate technical and organisational measures to protect your personal data from unauthorised or unlawful processing and from accidental loss, destruction or damage. These measures include encryption in transit and at rest, role-based access controls, multi-factor authentication, vulnerability management, third party security due diligence, incident-response procedures, disaster recovery processes and regular staff training.
In the event of a personal data breach, we will assess the likely risk to your rights and freedoms and take appropriate steps to contain, investigate and remediate the incident. Where required by applicable law, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay, unless an applicable legal exception applies.
12. How long we keep your personal data
We keep your personal data only for as long as is necessary for the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. When determining the appropriate retention period, we consider the nature, sensitivity and volume of the data, the purposes for which we process it, the potential risk of harm from unauthorised use or disclosure, applicable legal, regulatory, tax, accounting and reporting requirements, relevant contractual obligations, and any legitimate interest pursued by us or by a third party.
At the end of the applicable retention period we securely delete, destroy or anonymise your personal data. Where data has been anonymised so that it can no longer be associated with you, we may continue to use the anonymised information without further notice to you.
13. Your rights
Subject to the conditions and limitations of applicable data protection law, you have the following rights in respect of the personal data we hold about you. Please note that your ability to exercise these rights may be limited in circumstances where we are obliged to retain certain data.
| Your right | What it means in practice |
| Right to be informed | To know who is processing your data, for what purposes, on what basis, with whom it is shared and for how long it is retained — this notice is designed to give you that information. |
| Right of access | To obtain confirmation that we are processing your data and to receive a copy of the data we hold about you. Where compliance with your request would adversely affect the rights and freedoms of others (for example the privacy of our staff, counterparties or third parties), we may redact or withhold the relevant information. |
| Right to rectification | To require us to correct inaccurate personal data or complete incomplete personal data. |
| Right to erasure (“right to be forgotten”) | To require us to delete your personal data in defined circumstances (for example where the data is no longer necessary; consent is withdrawn and no other basis applies; or the data was unlawfully processed). We will not be able to erase your personal data where we need to retain it to comply with a legal, regulatory, tax or accounting obligation (for example our AML, sanctions, MiFID II, REMIT or Dodd-Frank record-keeping obligations), to exercise or defend legal claims, or where another exception applies. |
| Right to restrict processing | To require us to limit the way we use your data in defined circumstances (for example pending verification of a rectification request, or the outcome of an objection). |
| Right to data portability | To receive the personal data that you have provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller. This right applies only where (i) our processing is based on your consent or on the performance of a contract to which you are a party, and (ii) the processing is carried out by automated means. It does not apply to data we have derived or inferred about you, nor to paper records. |
| Right to object | To object on grounds relating to your particular situation to processing based on legitimate interests. Where the processing is for direct marketing, the right to object is absolute. |
| Right not to be subject to automated decision-making | Not to be subject to a decision based solely on automated processing — including profiling — which produces legal or similarly significant effects on you, except where one of the legal exceptions applies and appropriate safeguards are in place. |
| Right to withdraw consent | Where processing is based on consent, you may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal. |
| Right to lodge a complaint | To complain to a competent supervisory authority — see Section 18. |
We will respond to any request without undue delay and in any event within one month of receipt, extendable by a further two months for complex or numerous requests (in which case we will inform you of the extension within one month). We do not generally charge a fee, save where requests are manifestly unfounded or excessive.
To exercise your rights, please contact [email protected]. We may ask you for additional information to confirm your identity before responding. If any of the personal data you have provided to us changes, or you believe something we hold about you is incorrect, please let us know without delay.
To help us deal with your request as quickly as possible, please tell us as clearly as you can which personal data your request relates to (for example by reference to a date range, a specific Vitol entity or a specific business interaction). Where you wish to update or correct personal data we hold about you, please first check whether the relevant information can be updated directly (for example through any account or registration portal you may have with us).
14. Right to lodge a complaint
We would appreciate the opportunity to address your concerns before you approach a regulator, and encourage you to contact us at [email protected] in the first instance. However, you have the right to lodge a complaint at any time with the competent supervisory authority. These include:
- For individuals in the EEA: the data protection authority of your habitual residence, place of work or the place of the alleged infringement. The lead supervisory authority for the Vitol Group is Autoriteit Persoonsgegevens (AP) — autoriteitpersoonsgegevens.nl;
- For individuals in the United Kingdom: the Information Commissioner’s Office (ICO) — ico.org.uk;
- For individuals in Switzerland: the Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch.
15. Children
Our website and services are not directed to, or intended for use by, children under the age of 16, or such lower age as Member State law permits (e.g. 13 in the United Kingdom). If you believe we have inadvertently collected personal data of a child, please contact [email protected] and we will take appropriate steps.
16. Changes to this notice
We may update this notice from time to time. We will review it periodically and update it as required to reflect changes in our processing activities or in applicable law. The effective date at the top of this notice will be updated accordingly.
17. Contact
If you would like more information about anything in this notice, or to discuss any concern with us, please contact us at [email protected].
Last Updated: 7 July 2026