Skip to content
PALLEXA

Privacy and Cookies Policy of the PALLEXA website

Version 1.3 · Effective from 5 August 2026

1. General information

This Privacy and Cookies Policy describes how personal data is processed in connection with the use of the website available at https://pallexa.pl and https://www.pallexa.pl (the “Website”), including:

  • browsing the Website;
  • sending enquiries via the contact form;
  • contact by e-mail, phone, SMS or WhatsApp;
  • conducting negotiations and concluding and performing contracts;
  • verifying business partners, including via the VIES system;
  • handling deliveries, settlements and complaints;
  • the use of cookies and similar technologies.

The Website is intended primarily for businesses, their employees, associates and representatives. Data of all natural persons is protected under the GDPR, regardless of whether they act on their own behalf or represent a company.

2. Data controller

The controller of personal data is Bartosz Rogoziński, running a sole proprietorship registered in the Polish Central Register and Information on Economic Activity (CEIDG), tax ID (NIP) 7891790236, REGON 385525543, with the business and correspondence address: ul. Pola 1B, 62-300 Września, Poland, operating the Website under the PALLEXA brand (the “Controller”). PALLEXA and DBtrade are trading names of the Controller and do not constitute separate data controllers.

Contact for personal-data matters:

  • e-mail: sales@pallexa.pl;
  • phone: +48 784 748 370;
  • by post: ul. Pola 1B, 62-300 Września, Poland.

The Controller has not appointed a data protection officer. In all privacy matters you can contact the Controller directly using the details above.

3. Scope and sources of data

3.1. Data provided directly

Depending on how you contact us, the Controller may process:

  • first and last name;
  • company name;
  • the role of the person making contact and whether they act as a buyer or a supplier;
  • e-mail address;
  • phone number and the number used on WhatsApp;
  • country;
  • NIP or EU VAT number;
  • type of business;
  • product categories of interest and expected volume;
  • type, quantity, location and availability frequency of goods;
  • the content of correspondence and information shared in conversation;
  • data contained in documents and attachments sent at later stages of cooperation;
  • data concerning negotiations, orders, deliveries, payments, settlements and complaints;
  • the chosen or requested contact channel;
  • information on consents given, objections raised and consent withdrawals.

3.2. Data collected automatically

While the Website is used, the technical infrastructure may process data necessary to deliver the page and keep it secure, in particular:

  • IP address;
  • date and time of the request;
  • requested URL;
  • browser, operating system and device type;
  • server response and error information;
  • basic technical data related to security and abuse prevention.

The Controller does not store form contents or transmitted documents in logs.

3.3. Data obtained from other sources

The Controller may also obtain data:

  • from the VIES system and relevant public registers;
  • from CEIDG, KRS or other official business registers;
  • from a person recommending a potential business partner;
  • from an employer, associate or other representative of a business partner;
  • from documents provided by a business partner during negotiations or contract performance.

If data was not obtained directly from the person concerned, the Controller provides the required processing information at the latest at first contact, or within another period resulting from art. 14 GDPR.

4. Purposes and legal bases of processing

Purpose of processingCategories of persons and dataLegal basis
Providing the Website, handling traffic and keeping it secureWebsite users; technical data and logsart. 6(1)(f) GDPR - legitimate interest in running a secure Website, detecting errors and preventing abuse
Measuring audiences and improving the Website with Google Analytics 4users who consented to analytics; page-view and technical dataart. 6(1)(a) GDPR - consent; storing and reading analytics cookies also on the basis of consent required by the Polish Electronic Communications Law
Receiving and handling an enquiry, preparing a reply or an offerthe person enquiring on their own behalf; form and correspondence dataart. 6(1)(b) GDPR - steps taken at the person's request prior to entering into a contract
Contact with an employee, representative or contact person of a business partnerrepresentatives and staff of business partnersart. 6(1)(f) GDPR - legitimate interest in conducting B2B communication and cooperation
Conducting negotiations and concluding a contractsole traders and representatives of business partnersart. 6(1)(b) or (f) GDPR, depending on the person's role
Verifying a business partner and EU VAT number, limiting business risk and fraudentrepreneurs, representatives, registry and transaction dataart. 6(1)(f) GDPR; where verification is required by law - also art. 6(1)(c) GDPR
Fulfilling orders, purchases, sales, deliveries, logistics and settlementscontract parties, contact persons, transaction and delivery dataart. 6(1)(b), (c) or (f) GDPR, depending on the person and obligation
Issuing and storing accounting and tax documentsbusiness partners and persons named in the documentationart. 6(1)(c) GDPR - compliance with legal obligations
Handling complaintscomplainants, business partners and their representativesart. 6(1)(b), (c) or (f) GDPR
Direct marketing of the Controller's own services (e-mail, phone, SMS, WhatsApp)persons who gave separate consent for the given channelart. 6(1)(a) GDPR - consent; for electronic communication - also the provisions of the Polish Electronic Communications Law
Establishing, pursuing and defending claimsparties and participants of the specific caseart. 6(1)(f) GDPR - protecting the Controller's rights and defending against claims
Communicating by e-mail, phone, SMS or WhatsApp to the extent requested by the userthe person who initiated contact or chose the reply channelart. 6(1)(b) or (f) GDPR; where required by the Electronic Communications Law - the user's prior request or consent
Documenting the exercise of rights, consents, objections and legal compliancepersons submitting requests or statementsart. 6(1)(c) and (f) GDPR

4.1. Direct marketing

The Controller conducts direct marketing of its own services only towards persons who have given separate, voluntary consent - in the contact form or in later correspondence. Consents are collected separately for the e-mail channel and separately for the phone channel (calls, SMS, WhatsApp).

  • Consent is voluntary - not giving it does not affect the handling of an enquiry or the terms of cooperation.
  • The Controller documents the date consent was given and the version of this Policy in force at that moment.
  • Consent can be withdrawn at any time - by e-mail to sales@pallexa.pl, by phone, or by replying to a received message; withdrawal is as easy as giving consent.
  • Withdrawal does not affect the lawfulness of processing carried out before it.
  • In addition, an absolute right to object to direct marketing applies (section 9).

5. Voluntariness and obligation to provide data

Providing data is, as a rule, voluntary. Not providing data marked as required may make it impossible to send an enquiry, prepare a reply, carry out verification, or conclude and perform a contract.

Data required by accounting, tax or customs regulations, or related to transaction settlement, may be mandatory. Not providing it may make it impossible to conclude or perform a given transaction.

The Controller applies the data-minimisation principle. At the first-enquiry stage, please do not send:

  • special categories of data, e.g. data on health, beliefs or trade-union membership;
  • data on convictions and offences;
  • copies of identity documents;
  • PESEL numbers;
  • other data unrelated to the enquiry or transaction.

If such data is provided unnecessarily, the Controller may delete it or ask for a document limited in scope.

6. Data recipients

Data may be disclosed only to the extent necessary for a specific purpose:

  • Vercel Inc. - provider of the Website's hosting, CDN, server functions and visitor statistics (Vercel Web Analytics, cookieless); the functions handling the form run in the Frankfurt (EU) region;
  • Google Ireland Limited - provider of Google Analytics 4; after consent it processes page-view, device, browser, referrer and approximate-location data; enhanced measurement, Google Signals, ad personalisation and advertising storage are disabled;
  • OVHcloud (OVH SAS, Roubaix, France) - provider of the domain, DNS and the e-mail mailbox through which form submissions are sent and received; mail is handled on infrastructure in the European Union;
  • WhatsApp Ireland Limited and the relevant Meta group companies - if the user initiates contact via WhatsApp or asks for a reply through this channel; WhatsApp may act as a processor of contact data and as a separate controller of certain account, device and service-usage data;
  • telecommunications providers - in the case of contact by phone or SMS;
  • authorities maintaining official registers and the VIES system - for business-partner verification;
  • banks, payment operators, accounting providers, carriers, warehouses, customs agencies, insurers and other participants in a transaction - if their involvement is necessary in a specific case;
  • public authorities, courts and other authorised bodies - where disclosure is required by law;
  • persons providing the Controller with legal or technical services - only if actually engaged and under an appropriate contract or duty of confidentiality.

Persons acting under the Controller's authority receive access only to the extent needed to perform their duties.

7. Transfers outside the European Economic Area

Due to the use of Vercel, Google Analytics and WhatsApp, data may be processed in the United States or in other countries outside the European Economic Area. Transfers take place:

  • on the basis of a valid European Commission adequacy decision, in particular the EU-US Data Privacy Framework - where the given recipient holds an active certification covering the data;
  • or on the basis of the European Commission's standard contractual clauses, together with a transfer assessment and, where needed, supplementary measures.

The data subject can obtain information about the safeguards applied by contacting the Controller.

8. Retention periods

Data / processRetention period
spam and rejected submissionscontent not stored; technical trace up to 14 days
enquiry with no further reply from the userup to 6 months from the Controller's last message
enquiry with a substantive conversation but no transactionup to 12 months from the last contact
active negotiationsfor the duration of negotiations and up to 12 months after their closure, unless limited evidence material is needed
VIES result without a transactionwith the enquiry, no longer than 12 months
contracts, orders, deliveries, settlements and accounting documentationfor the duration of performance, then for the period required by accounting and tax law, as a rule 5 years under the rules applicable to the given document
data needed to pursue or defend claimsuntil the applicable limitation period expires; for business-related claims this is often 3 years, subject to special periods
data processed on the basis of marketing consentuntil consent is withdrawn or an effective objection is raised
complaintsfor the duration of handling, then for the liability period and the applicable claims period
ordinary e-mail, SMS and WhatsApp correspondenceaccording to the period applicable to the matter it concerns
an ordinary WhatsApp chat after a matter is closed90 days; relevant messages are moved to the case file beforehand
attachments unrelated to a transactionwith the enquiry; unnecessary copies up to 30 days after assessment
website and API logs14 days, without form contents
data concerning a specific security incidentfor the duration of the investigation and no longer than needed for claims or demonstrating compliance
Google Analytics 4 cookies (_ga and _ga_<identifier>)up to 90 days from the last visit; withdrawing consent causes the Website to attempt their deletion
Google Analytics 4 event data2 months under the property setting; aggregate reports without identifiers may be retained longer
backups30-day cycle; full deletion within 90 days at the latest
data-subject requests3 years from closing the case
breach register and compliance documentation5 years

After the applicable period, data is deleted or anonymised, unless further storage is required by law, a public authority, or a genuine need to secure claims.

9. Rights of data subjects

Within the limits set by the GDPR, the data subject has:

  • the right of access to data and to obtain a copy;
  • the right to rectification;
  • the right to erasure;
  • the right to restriction of processing;
  • the right to data portability - where processing is automated and based on consent or a contract;
  • the right to object to processing based on art. 6(1)(f) GDPR, on grounds relating to the person's particular situation;
  • an absolute right to object to direct marketing and related profiling;
  • the right to withdraw consent at any time, where consent is the basis; withdrawal does not affect earlier processing;
  • the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).

Requests can be sent to the Controller's e-mail or postal address given in section 2. The Controller responds without undue delay, as a rule within one month. In cases provided for by the GDPR, this period may be extended by a further two months. The Controller may ask for additional information necessary to confirm the identity of the person making the request.

Complaints can be addressed to: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl.

10. Automated decisions and profiling

The Controller does not make decisions about users based solely on automated processing that would produce legal effects or similarly significantly affect them. The Controller does not profile Website users or automatically score enquiries.

11. Contact via WhatsApp, phone and SMS

WhatsApp Business is used as a channel for handling an enquiry or cooperation when the user initiates the conversation or explicitly chooses WhatsApp as the expected reply channel, and additionally - for marketing purposes - only towards persons who gave separate consent for the phone channel (section 4.1).

Merely providing a phone number is not treated as consent to contact through every possible channel. The user may at any time ask to change the contact channel or end the WhatsApp conversation. Data relevant to a contract, delivery, settlement or complaint may be moved from the messenger to the case documentation.

Please do not send identity documents, special-category data or other information not necessary for cooperation via WhatsApp.

12. Security

The Controller applies technical and organisational measures appropriate to the nature of the data and the risk, in particular encrypted HTTPS connections, encoding of form data when generating notifications, no storage of form contents in logs, and restricting data access to authorised persons.

No method of transmitting or storing data guarantees absolute security. The Controller regularly assesses the adequacy of the safeguards applied and updates them as the Website and the risk evolve.

13. Cookies and similar technologies

Without analytics consent, the Website does not use technical, analytics or advertising cookies. It stores only the necessary “pallexa:consent” record in the device's localStorage to remember acceptance, rejection or a custom privacy choice. The record contains the mechanism and consent-notice versions, selected categories, decision type and save date; it contains no user identifier or form data. It remains on the device until site data is deleted or the notice version changes and requires a new decision. The language version follows solely from the URL (/pl, /en, /de, /fr), not from a cookie.

After consent to the analytics category, the Website activates Vercel Web Analytics - a visitor-statistics tool that works without cookies and without identifiers capable of tracking a user across sites. Only aggregate data is collected (page views, page URL, country, device type and referrer), with no profiling and no linking to form data. The tool is not loaded after rejection.

Under the same consent, the Website activates Google Analytics 4 (Google Ireland Limited). It sends page-view data (page path and title), date and time, device and browser type, referrer and approximate location. Google may process the IP address briefly to derive approximate location, but it is not logged or stored in Google Analytics. The tool uses first-party _ga and _ga_<identifier> cookies for up to 90 days. Enhanced measurement, Google Signals, ad personalisation and all advertising storage are disabled; the Website sends no user identifier or form data. The banner makes accepting and rejecting analytics equally easy. The decision can be changed or withdrawn through the “Privacy settings” link in the footer; withdrawal blocks further measurement and removes GA cookies accessible to the Website. The Website does not use Google Tag Manager, Meta Pixel, Hotjar or similar advertising tools.

15. Children's data

The Website is intended for businesses and is not directed at children. The Controller does not knowingly collect children's data through the form. If the Controller finds that a child's data was provided without a basis and is not needed to fulfil a legal obligation, it will take steps to delete it.

16. Changes to this Policy

The Policy may be updated in the event of:

  • a change of the Controller or contact details;
  • changes to the Website's features;
  • introduction of new providers, cookies, analytics or marketing;
  • changes in the sales, purchasing, logistics or contracting process;
  • changes in law or in supervisory authorities' practice.

The current version will be published on the Website together with its update date. If a change materially affects how already-collected data is processed, the Controller will additionally inform the relevant persons where required.