Legal
Privacy policy
Last updated
This policy describes what personal data we process in connection with the ppwr24.pl website and the PPWR24 application at app.ppwr24.pl, for what purposes and on what legal basis, who we pass it to and how long we keep it.
Contents
1. Data controller
The controller of personal data is FEEGRID sp. z o.o., registered office in Lublin, ul. Kowalska 5/203, 20-115 Lublin, Poland, entered in the Polish National Court Register (KRS) under number 0001206934, tax identification number (NIP) 9462760804, REGON 543308312.
For any matter concerning personal data, write to kontakt@ppwr24.eu.
Personal data contained in the documents and data a customer enters into the application — for example, details of people named in supplier documents — is processed by FEEGRID on the customer's behalf, as a processor, under a data processing agreement. The customer is the controller of that data, and requests concerning it should be addressed to the customer.
2. What data we process
- Account data
- email address, first name, initials, password stored as a cryptographic hash, interface language, date of last login and role in the company.
- Company data
- name, address, tax identification number, BDO register number, company email and phone, name and position of the person who signs declarations.
- Order data
- company name, address, tax or EU VAT number, email address and, optionally, phone. Card details are entered directly with the payment operator.
- Documents uploaded by the user
- files from suppliers — statements, test reports, technical data sheets — together with the data read from them.
- Portfolio data
- packaging, components, materials, masses, suppliers and recipients entered by the user.
- Conversations with the assistant
- questions asked of the assistant in the application and its answers.
- Event log
- logins, including failed ones, with IP address; approvals of data read from documents; issuing of declarations; permission changes; exports and file operations.
- Website forms
- data from the contact form, the offer enquiry, the declaration check report and the order, together with a record of the statements and consents given in them.
Documents uploaded to the application concern packaging materials and as a rule contain no personal data other than contact details of supplier representatives. We do not ask for special categories of data and they should not be uploaded.
3. Purposes and legal bases
- Providing the service
- maintaining the account and the portfolio, reading data from documents, issuing documents — Art. 6(1)(b) GDPR, performance of a contract.
- Order and payment
- concluding the agreement, handling the order and payment — Art. 6(1)(b) GDPR.
- Accounting and invoices
- issuing and keeping accounting documents — Art. 6(1)(c) GDPR, legal obligation.
- Replying to your message and the contact you ask for
- contact form, offer enquiry, declaration check report — Art. 6(1)(b) GDPR for steps taken before entering into a contract, and otherwise Art. 6(1)(f) GDPR, the legitimate interest of replying to a message and keeping a record of the contact.
- Commercial information
- only if you tick a separate consent — Art. 6(1)(a) GDPR in conjunction with Art. 398 of the Polish Electronic Communications Law.
- Accountability
- keeping a record of the statements and consents given — Art. 6(1)(c) and (f) GDPR.
- Security
- event log, backups, limiting login attempts and form submissions — Art. 6(1)(f) GDPR.
- Legal claims
- establishing, pursuing and defending claims — Art. 6(1)(f) GDPR.
Providing data is voluntary but necessary to conclude the agreement and use the application. Without company data a declaration cannot be issued, because that data appears on the document itself. You can withdraw consent to commercial information at any time by writing to kontakt@ppwr24.eu; withdrawal does not affect the lawfulness of processing before it.
4. Where the data is processed
The application database, uploaded documents and backups are stored on the server that runs the application and the website.
To be completed[TO BE COMPLETED: the entity providing the server and the country in which the server is located]
The content of documents sent for automatic reading and the questions asked of the assistant are processed by the language model provider, OpenAI. This may involve processing outside the European Economic Area, including in the United States.
To be completed[TO BE COMPLETED: the basis for transfers outside the EEA under the agreement with the model provider (Art. 44–49 GDPR)]
The payment operator Stripe may process data outside the European Economic Area as described in its privacy policy.
5. Who we pass data to
We pass data only to parties we need in order to provide the service:
- Language model provider
- OpenAI — automatic reading of data from uploaded documents (the document text or images of its pages) and the assistant's answers in the application (the question, the latest messages of the conversation and a summary of the portfolio without packaging or material names).
- Payment operator
- Stripe Payments Europe, Ltd. — payments and invoices for orders placed on the website. Stripe is a separate controller for the transaction data required by payment services law.
- Server provider
- maintaining the server that runs the application and the website, including backups.
- Message handling
- the tool that receives messages sent through the website forms, and the email provider.
To be completed[TO BE COMPLETED: names of the server provider, the message handling tool and the email provider, with the location of processing]
Data may be disclosed to public authorities only where required by law and to the extent of a request with a legal basis.
6. Documents and artificial intelligence models
FEEGRID does not use documents or data entered into the application to train or fine-tune artificial intelligence models. Documents are not shared with other customers.
The document content is processed automatically to read the number, date, material designation and concentration values. The result is a proposal: only values approved by the user enter the portfolio, each with a reference to its place in the source document, and the approval itself is recorded in the event log.
To be completed[TO BE COMPLETED: how long the model provider keeps the content it receives and the exclusion of its use for training — to be confirmed in the agreement with OpenAI]
7. How long we keep data
- Account, company and portfolio data, documents and assistant conversations
- for as long as the service is used and, after the agreement ends, until deleted at the customer's request. The application does not delete this data automatically.
- Issued declarations
- for as long as the company data is kept. An issued declaration cannot be changed or deleted in the application, because it is the record of a signed document. The declaration and technical documentation must be kept as required by the Regulation.
- Event log
- for as long as the data of the company it concerns is kept.
- Billing data and invoices
- 5 years from the end of the calendar year in which the tax payment deadline passed.
- Form messages and correspondence
- up to 24 months from the last message in the matter.
- Record of statements and consents
- for as long as the agreement or consent is in force and, after withdrawal or the end of the agreement, until the limitation period for claims expires.
- Backups
- up to 30 days.
8. Your rights
With regard to personal data for which we are the controller, you have the following rights:
- the right of access to your data and to obtain a copy;
- the right to rectify inaccurate data and complete incomplete data;
- the right to erasure, unless a legal obligation prevents it, for example keeping invoices;
- the right to restriction of processing;
- the right to data portability — the application lets you export portfolio data to CSV files and declarations to PDF files;
- the right to object to processing based on legitimate interest;
- the right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.
We handle requests without undue delay and in any case within one month of receipt. Requests can be sent to kontakt@ppwr24.eu.
10. Website forms
Contact form and offer enquiry: email address, company name, topic and message, and optionally name, phone, country, tax number, planned number of users and timeline. We use them to reply to the message, prepare an offer and keep a record of the contact.
Declaration check report: email address, optionally company name, the number of elements found and the list of missing ones. The declaration text is not sent — the check runs in the browser.
Order: invoice details and the statements given — on business status, acceptance of the terms and conclusion of the data processing agreement.
Each time a form is sent we record the wording of the statements and consents shown with it, whether they were ticked, their version, the date, the form and the email address they concern. The IP address is not part of this record — we process it only briefly, to limit the number of submissions from one source.
We do not add addresses from the forms to a mailing list. Commercial information is sent only to people who ticked a separate consent.
11. Security
- the connection to the website and the application is encrypted with TLS;
- passwords are stored only as cryptographic hashes, and the number of login attempts is limited;
- access to data in the application is granted by roles — read, edit, owner — separately for each company;
- only people who need it have access to the server;
- the event log records logins, data approvals and issued documents and cannot be changed from the application;
- we make backups of the database and uploaded documents;
- every issued document has a SHA-256 checksum, which makes it possible to show that it has not changed.
If a personal data breach is likely to result in a high risk to rights or freedoms, we will inform the people concerned and the supervisory authority within the time limits set by the GDPR.
12. Changes to this policy
We update this policy when the scope of processing, the list of processors or the law changes. The date of the last update is shown at the top of the document. Changes that matter to users of the application are announced by email.