Skip to content
PPWR24

Legal

Privacy policy

Last updated

This policy describes what personal data we process in connection with the ppwr24.pl website and the PPWR24 application at app.ppwr24.pl, for what purposes and on what legal basis, who we pass it to and how long we keep it.

Contents
  1. 1. Data controller
  2. 2. What data we process
  3. 3. Purposes and legal bases
  4. 4. Where the data is processed
  5. 5. Who we pass data to
  6. 6. Documents and artificial intelligence models
  7. 7. How long we keep data
  8. 8. Your rights
  9. 9. Cookies and browser storage
  10. 10. Website forms
  11. 11. Security
  12. 12. Changes to this policy

1. Data controller

The controller of personal data is FEEGRID sp. z o.o., registered office in Lublin, ul. Kowalska 5/203, 20-115 Lublin, Poland, entered in the Polish National Court Register (KRS) under number 0001206934, tax identification number (NIP) 9462760804, REGON 543308312.

For any matter concerning personal data, write to kontakt@ppwr24.eu.

Personal data contained in the documents and data a customer enters into the application — for example, details of people named in supplier documents — is processed by FEEGRID on the customer's behalf, as a processor, under a data processing agreement. The customer is the controller of that data, and requests concerning it should be addressed to the customer.

2. What data we process

Account data
email address, first name, initials, password stored as a cryptographic hash, interface language, date of last login and role in the company.
Company data
name, address, tax identification number, BDO register number, company email and phone, name and position of the person who signs declarations.
Order data
company name, address, tax or EU VAT number, email address and, optionally, phone. Card details are entered directly with the payment operator.
Documents uploaded by the user
files from suppliers — statements, test reports, technical data sheets — together with the data read from them.
Portfolio data
packaging, components, materials, masses, suppliers and recipients entered by the user.
Conversations with the assistant
questions asked of the assistant in the application and its answers.
Event log
logins, including failed ones, with IP address; approvals of data read from documents; issuing of declarations; permission changes; exports and file operations.
Website forms
data from the contact form, the offer enquiry, the declaration check report and the order, together with a record of the statements and consents given in them.

Documents uploaded to the application concern packaging materials and as a rule contain no personal data other than contact details of supplier representatives. We do not ask for special categories of data and they should not be uploaded.

3. Purposes and legal bases

Providing the service
maintaining the account and the portfolio, reading data from documents, issuing documents — Art. 6(1)(b) GDPR, performance of a contract.
Order and payment
concluding the agreement, handling the order and payment — Art. 6(1)(b) GDPR.
Accounting and invoices
issuing and keeping accounting documents — Art. 6(1)(c) GDPR, legal obligation.
Replying to your message and the contact you ask for
contact form, offer enquiry, declaration check report — Art. 6(1)(b) GDPR for steps taken before entering into a contract, and otherwise Art. 6(1)(f) GDPR, the legitimate interest of replying to a message and keeping a record of the contact.
Commercial information
only if you tick a separate consent — Art. 6(1)(a) GDPR in conjunction with Art. 398 of the Polish Electronic Communications Law.
Accountability
keeping a record of the statements and consents given — Art. 6(1)(c) and (f) GDPR.
Security
event log, backups, limiting login attempts and form submissions — Art. 6(1)(f) GDPR.
Legal claims
establishing, pursuing and defending claims — Art. 6(1)(f) GDPR.

Providing data is voluntary but necessary to conclude the agreement and use the application. Without company data a declaration cannot be issued, because that data appears on the document itself. You can withdraw consent to commercial information at any time by writing to kontakt@ppwr24.eu; withdrawal does not affect the lawfulness of processing before it.

4. Where the data is processed

The application database, uploaded documents and backups are stored on the server that runs the application and the website.

To be completed[TO BE COMPLETED: the entity providing the server and the country in which the server is located]

The content of documents sent for automatic reading and the questions asked of the assistant are processed by the language model provider, OpenAI. This may involve processing outside the European Economic Area, including in the United States.

To be completed[TO BE COMPLETED: the basis for transfers outside the EEA under the agreement with the model provider (Art. 44–49 GDPR)]

The payment operator Stripe may process data outside the European Economic Area as described in its privacy policy.

5. Who we pass data to

We pass data only to parties we need in order to provide the service:

Language model provider
OpenAI — automatic reading of data from uploaded documents (the document text or images of its pages) and the assistant's answers in the application (the question, the latest messages of the conversation and a summary of the portfolio without packaging or material names).
Payment operator
Stripe Payments Europe, Ltd. — payments and invoices for orders placed on the website. Stripe is a separate controller for the transaction data required by payment services law.
Server provider
maintaining the server that runs the application and the website, including backups.
Message handling
the tool that receives messages sent through the website forms, and the email provider.

To be completed[TO BE COMPLETED: names of the server provider, the message handling tool and the email provider, with the location of processing]

Data may be disclosed to public authorities only where required by law and to the extent of a request with a legal basis.

6. Documents and artificial intelligence models

FEEGRID does not use documents or data entered into the application to train or fine-tune artificial intelligence models. Documents are not shared with other customers.

The document content is processed automatically to read the number, date, material designation and concentration values. The result is a proposal: only values approved by the user enter the portfolio, each with a reference to its place in the source document, and the approval itself is recorded in the event log.

To be completed[TO BE COMPLETED: how long the model provider keeps the content it receives and the exclusion of its use for training — to be confirmed in the agreement with OpenAI]

7. How long we keep data

Account, company and portfolio data, documents and assistant conversations
for as long as the service is used and, after the agreement ends, until deleted at the customer's request. The application does not delete this data automatically.
Issued declarations
for as long as the company data is kept. An issued declaration cannot be changed or deleted in the application, because it is the record of a signed document. The declaration and technical documentation must be kept as required by the Regulation.
Event log
for as long as the data of the company it concerns is kept.
Billing data and invoices
5 years from the end of the calendar year in which the tax payment deadline passed.
Form messages and correspondence
up to 24 months from the last message in the matter.
Record of statements and consents
for as long as the agreement or consent is in force and, after withdrawal or the end of the agreement, until the limitation period for claims expires.
Backups
up to 30 days.

8. Your rights

With regard to personal data for which we are the controller, you have the following rights:

  • the right of access to your data and to obtain a copy;
  • the right to rectify inaccurate data and complete incomplete data;
  • the right to erasure, unless a legal obligation prevents it, for example keeping invoices;
  • the right to restriction of processing;
  • the right to data portability — the application lets you export portfolio data to CSV files and declarations to PDF files;
  • the right to object to processing based on legitimate interest;
  • the right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
  • the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.

We handle requests without undue delay and in any case within one month of receipt. Requests can be sent to kontakt@ppwr24.eu.

9. Cookies and browser storage

We use only cookies that are necessary for the website and the application to work. We do not run behavioural analytics, use advertising pixels or profile visitors. For that reason the website shows no consent banner — there is no consent to ask for.

Website language cookie (NEXT_LOCALE)
remembers the chosen language version; expires when the browser is closed.
Application session cookie (ppwr24_sesja)
keeps you logged in; valid for up to two weeks or until you log out.
Application security cookie (ppwr24_csrf)
protects against requests sent from other websites; valid for up to a year.
Application browser storage
recent search phrases and whether the sidebar is collapsed; this data does not leave the browser.

Payment takes place on the site of the payment operator Stripe, which uses its own cookies. When a scanned declaration is checked, the tool on the website may download a text recognition module from an external CDN server, which then sees the browser's IP address; the document content is not sent.

Cookies can be deleted in the browser settings. Deleting the session cookie logs you out of the application.

10. Website forms

Contact form and offer enquiry: email address, company name, topic and message, and optionally name, phone, country, tax number, planned number of users and timeline. We use them to reply to the message, prepare an offer and keep a record of the contact.

Declaration check report: email address, optionally company name, the number of elements found and the list of missing ones. The declaration text is not sent — the check runs in the browser.

Order: invoice details and the statements given — on business status, acceptance of the terms and conclusion of the data processing agreement.

Each time a form is sent we record the wording of the statements and consents shown with it, whether they were ticked, their version, the date, the form and the email address they concern. The IP address is not part of this record — we process it only briefly, to limit the number of submissions from one source.

We do not add addresses from the forms to a mailing list. Commercial information is sent only to people who ticked a separate consent.

11. Security

  • the connection to the website and the application is encrypted with TLS;
  • passwords are stored only as cryptographic hashes, and the number of login attempts is limited;
  • access to data in the application is granted by roles — read, edit, owner — separately for each company;
  • only people who need it have access to the server;
  • the event log records logins, data approvals and issued documents and cannot be changed from the application;
  • we make backups of the database and uploaded documents;
  • every issued document has a SHA-256 checksum, which makes it possible to show that it has not changed.

If a personal data breach is likely to result in a high risk to rights or freedoms, we will inform the people concerned and the supervisory authority within the time limits set by the GDPR.

12. Changes to this policy

We update this policy when the scope of processing, the list of processors or the law changes. The date of the last update is shown at the top of the document. Changes that matter to users of the application are announced by email.