Privacy and Cookies Policy of the PALLEXA website
Version 1.3 · Effective from 5 August 2026
1. General information
This Privacy and Cookies Policy describes how personal data is processed in connection with the use of the website available at https://pallexa.pl and https://www.pallexa.pl (the “Website”), including:
- browsing the Website;
- sending enquiries via the contact form;
- contact by e-mail, phone, SMS or WhatsApp;
- conducting negotiations and concluding and performing contracts;
- verifying business partners, including via the VIES system;
- handling deliveries, settlements and complaints;
- the use of cookies and similar technologies.
The Website is intended primarily for businesses, their employees, associates and representatives. Data of all natural persons is protected under the GDPR, regardless of whether they act on their own behalf or represent a company.
2. Data controller
The controller of personal data is Bartosz Rogoziński, running a sole proprietorship registered in the Polish Central Register and Information on Economic Activity (CEIDG), tax ID (NIP) 7891790236, REGON 385525543, with the business and correspondence address: ul. Pola 1B, 62-300 Września, Poland, operating the Website under the PALLEXA brand (the “Controller”). PALLEXA and DBtrade are trading names of the Controller and do not constitute separate data controllers.
Contact for personal-data matters:
- e-mail: sales@pallexa.pl;
- phone: +48 784 748 370;
- by post: ul. Pola 1B, 62-300 Września, Poland.
The Controller has not appointed a data protection officer. In all privacy matters you can contact the Controller directly using the details above.
3. Scope and sources of data
3.1. Data provided directly
Depending on how you contact us, the Controller may process:
- first and last name;
- company name;
- the role of the person making contact and whether they act as a buyer or a supplier;
- e-mail address;
- phone number and the number used on WhatsApp;
- country;
- NIP or EU VAT number;
- type of business;
- product categories of interest and expected volume;
- type, quantity, location and availability frequency of goods;
- the content of correspondence and information shared in conversation;
- data contained in documents and attachments sent at later stages of cooperation;
- data concerning negotiations, orders, deliveries, payments, settlements and complaints;
- the chosen or requested contact channel;
- information on consents given, objections raised and consent withdrawals.
3.2. Data collected automatically
While the Website is used, the technical infrastructure may process data necessary to deliver the page and keep it secure, in particular:
- IP address;
- date and time of the request;
- requested URL;
- browser, operating system and device type;
- server response and error information;
- basic technical data related to security and abuse prevention.
The Controller does not store form contents or transmitted documents in logs.
3.3. Data obtained from other sources
The Controller may also obtain data:
- from the VIES system and relevant public registers;
- from CEIDG, KRS or other official business registers;
- from a person recommending a potential business partner;
- from an employer, associate or other representative of a business partner;
- from documents provided by a business partner during negotiations or contract performance.
If data was not obtained directly from the person concerned, the Controller provides the required processing information at the latest at first contact, or within another period resulting from art. 14 GDPR.
4. Purposes and legal bases of processing
| Purpose of processing | Categories of persons and data | Legal basis |
|---|---|---|
| Providing the Website, handling traffic and keeping it secure | Website users; technical data and logs | art. 6(1)(f) GDPR - legitimate interest in running a secure Website, detecting errors and preventing abuse |
| Measuring audiences and improving the Website with Google Analytics 4 | users who consented to analytics; page-view and technical data | art. 6(1)(a) GDPR - consent; storing and reading analytics cookies also on the basis of consent required by the Polish Electronic Communications Law |
| Receiving and handling an enquiry, preparing a reply or an offer | the person enquiring on their own behalf; form and correspondence data | art. 6(1)(b) GDPR - steps taken at the person's request prior to entering into a contract |
| Contact with an employee, representative or contact person of a business partner | representatives and staff of business partners | art. 6(1)(f) GDPR - legitimate interest in conducting B2B communication and cooperation |
| Conducting negotiations and concluding a contract | sole traders and representatives of business partners | art. 6(1)(b) or (f) GDPR, depending on the person's role |
| Verifying a business partner and EU VAT number, limiting business risk and fraud | entrepreneurs, representatives, registry and transaction data | art. 6(1)(f) GDPR; where verification is required by law - also art. 6(1)(c) GDPR |
| Fulfilling orders, purchases, sales, deliveries, logistics and settlements | contract parties, contact persons, transaction and delivery data | art. 6(1)(b), (c) or (f) GDPR, depending on the person and obligation |
| Issuing and storing accounting and tax documents | business partners and persons named in the documentation | art. 6(1)(c) GDPR - compliance with legal obligations |
| Handling complaints | complainants, business partners and their representatives | art. 6(1)(b), (c) or (f) GDPR |
| Direct marketing of the Controller's own services (e-mail, phone, SMS, WhatsApp) | persons who gave separate consent for the given channel | art. 6(1)(a) GDPR - consent; for electronic communication - also the provisions of the Polish Electronic Communications Law |
| Establishing, pursuing and defending claims | parties and participants of the specific case | art. 6(1)(f) GDPR - protecting the Controller's rights and defending against claims |
| Communicating by e-mail, phone, SMS or WhatsApp to the extent requested by the user | the person who initiated contact or chose the reply channel | art. 6(1)(b) or (f) GDPR; where required by the Electronic Communications Law - the user's prior request or consent |
| Documenting the exercise of rights, consents, objections and legal compliance | persons submitting requests or statements | art. 6(1)(c) and (f) GDPR |
4.1. Direct marketing
The Controller conducts direct marketing of its own services only towards persons who have given separate, voluntary consent - in the contact form or in later correspondence. Consents are collected separately for the e-mail channel and separately for the phone channel (calls, SMS, WhatsApp).
- Consent is voluntary - not giving it does not affect the handling of an enquiry or the terms of cooperation.
- The Controller documents the date consent was given and the version of this Policy in force at that moment.
- Consent can be withdrawn at any time - by e-mail to sales@pallexa.pl, by phone, or by replying to a received message; withdrawal is as easy as giving consent.
- Withdrawal does not affect the lawfulness of processing carried out before it.
- In addition, an absolute right to object to direct marketing applies (section 9).
5. Voluntariness and obligation to provide data
Providing data is, as a rule, voluntary. Not providing data marked as required may make it impossible to send an enquiry, prepare a reply, carry out verification, or conclude and perform a contract.
Data required by accounting, tax or customs regulations, or related to transaction settlement, may be mandatory. Not providing it may make it impossible to conclude or perform a given transaction.
The Controller applies the data-minimisation principle. At the first-enquiry stage, please do not send:
- special categories of data, e.g. data on health, beliefs or trade-union membership;
- data on convictions and offences;
- copies of identity documents;
- PESEL numbers;
- other data unrelated to the enquiry or transaction.
If such data is provided unnecessarily, the Controller may delete it or ask for a document limited in scope.
6. Data recipients
Data may be disclosed only to the extent necessary for a specific purpose:
- Vercel Inc. - provider of the Website's hosting, CDN, server functions and visitor statistics (Vercel Web Analytics, cookieless); the functions handling the form run in the Frankfurt (EU) region;
- Google Ireland Limited - provider of Google Analytics 4; after consent it processes page-view, device, browser, referrer and approximate-location data; enhanced measurement, Google Signals, ad personalisation and advertising storage are disabled;
- OVHcloud (OVH SAS, Roubaix, France) - provider of the domain, DNS and the e-mail mailbox through which form submissions are sent and received; mail is handled on infrastructure in the European Union;
- WhatsApp Ireland Limited and the relevant Meta group companies - if the user initiates contact via WhatsApp or asks for a reply through this channel; WhatsApp may act as a processor of contact data and as a separate controller of certain account, device and service-usage data;
- telecommunications providers - in the case of contact by phone or SMS;
- authorities maintaining official registers and the VIES system - for business-partner verification;
- banks, payment operators, accounting providers, carriers, warehouses, customs agencies, insurers and other participants in a transaction - if their involvement is necessary in a specific case;
- public authorities, courts and other authorised bodies - where disclosure is required by law;
- persons providing the Controller with legal or technical services - only if actually engaged and under an appropriate contract or duty of confidentiality.
Persons acting under the Controller's authority receive access only to the extent needed to perform their duties.
7. Transfers outside the European Economic Area
Due to the use of Vercel, Google Analytics and WhatsApp, data may be processed in the United States or in other countries outside the European Economic Area. Transfers take place:
- on the basis of a valid European Commission adequacy decision, in particular the EU-US Data Privacy Framework - where the given recipient holds an active certification covering the data;
- or on the basis of the European Commission's standard contractual clauses, together with a transfer assessment and, where needed, supplementary measures.
The data subject can obtain information about the safeguards applied by contacting the Controller.
8. Retention periods
| Data / process | Retention period |
|---|---|
| spam and rejected submissions | content not stored; technical trace up to 14 days |
| enquiry with no further reply from the user | up to 6 months from the Controller's last message |
| enquiry with a substantive conversation but no transaction | up to 12 months from the last contact |
| active negotiations | for the duration of negotiations and up to 12 months after their closure, unless limited evidence material is needed |
| VIES result without a transaction | with the enquiry, no longer than 12 months |
| contracts, orders, deliveries, settlements and accounting documentation | for the duration of performance, then for the period required by accounting and tax law, as a rule 5 years under the rules applicable to the given document |
| data needed to pursue or defend claims | until the applicable limitation period expires; for business-related claims this is often 3 years, subject to special periods |
| data processed on the basis of marketing consent | until consent is withdrawn or an effective objection is raised |
| complaints | for the duration of handling, then for the liability period and the applicable claims period |
| ordinary e-mail, SMS and WhatsApp correspondence | according to the period applicable to the matter it concerns |
| an ordinary WhatsApp chat after a matter is closed | 90 days; relevant messages are moved to the case file beforehand |
| attachments unrelated to a transaction | with the enquiry; unnecessary copies up to 30 days after assessment |
| website and API logs | 14 days, without form contents |
| data concerning a specific security incident | for the duration of the investigation and no longer than needed for claims or demonstrating compliance |
| Google Analytics 4 cookies (_ga and _ga_<identifier>) | up to 90 days from the last visit; withdrawing consent causes the Website to attempt their deletion |
| Google Analytics 4 event data | 2 months under the property setting; aggregate reports without identifiers may be retained longer |
| backups | 30-day cycle; full deletion within 90 days at the latest |
| data-subject requests | 3 years from closing the case |
| breach register and compliance documentation | 5 years |
After the applicable period, data is deleted or anonymised, unless further storage is required by law, a public authority, or a genuine need to secure claims.
9. Rights of data subjects
Within the limits set by the GDPR, the data subject has:
- the right of access to data and to obtain a copy;
- the right to rectification;
- the right to erasure;
- the right to restriction of processing;
- the right to data portability - where processing is automated and based on consent or a contract;
- the right to object to processing based on art. 6(1)(f) GDPR, on grounds relating to the person's particular situation;
- an absolute right to object to direct marketing and related profiling;
- the right to withdraw consent at any time, where consent is the basis; withdrawal does not affect earlier processing;
- the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).
Requests can be sent to the Controller's e-mail or postal address given in section 2. The Controller responds without undue delay, as a rule within one month. In cases provided for by the GDPR, this period may be extended by a further two months. The Controller may ask for additional information necessary to confirm the identity of the person making the request.
Complaints can be addressed to: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl.
10. Automated decisions and profiling
The Controller does not make decisions about users based solely on automated processing that would produce legal effects or similarly significantly affect them. The Controller does not profile Website users or automatically score enquiries.
11. Contact via WhatsApp, phone and SMS
WhatsApp Business is used as a channel for handling an enquiry or cooperation when the user initiates the conversation or explicitly chooses WhatsApp as the expected reply channel, and additionally - for marketing purposes - only towards persons who gave separate consent for the phone channel (section 4.1).
Merely providing a phone number is not treated as consent to contact through every possible channel. The user may at any time ask to change the contact channel or end the WhatsApp conversation. Data relevant to a contract, delivery, settlement or complaint may be moved from the messenger to the case documentation.
Please do not send identity documents, special-category data or other information not necessary for cooperation via WhatsApp.
12. Security
The Controller applies technical and organisational measures appropriate to the nature of the data and the risk, in particular encrypted HTTPS connections, encoding of form data when generating notifications, no storage of form contents in logs, and restricting data access to authorised persons.
No method of transmitting or storing data guarantees absolute security. The Controller regularly assesses the adequacy of the safeguards applied and updates them as the Website and the risk evolve.
14. External links
The Website may contain links to third-party sites or services, in particular WhatsApp. Once you move to an external service, processing is also governed by the rules set by its operator. The Controller recommends reading the relevant privacy policy before providing data. Placing an ordinary link does not mean that the external party automatically receives data from the PALLEXA form.
15. Children's data
The Website is intended for businesses and is not directed at children. The Controller does not knowingly collect children's data through the form. If the Controller finds that a child's data was provided without a basis and is not needed to fulfil a legal obligation, it will take steps to delete it.
16. Changes to this Policy
The Policy may be updated in the event of:
- a change of the Controller or contact details;
- changes to the Website's features;
- introduction of new providers, cookies, analytics or marketing;
- changes in the sales, purchasing, logistics or contracting process;
- changes in law or in supervisory authorities' practice.
The current version will be published on the Website together with its update date. If a change materially affects how already-collected data is processed, the Controller will additionally inform the relevant persons where required.
