Excellent PRO
Excellent PRO

Personal Data Protection

Privacy Policy

Version 1.3 · effective from 23 September 2026 · excellentpro.app

This Privacy Policy sets out the rules for processing the personal data of users of the excellentpro.app platform in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the GDPR) and the Personal Data Protection Act of 10 May 2018.

§ I

Data Controller

  1. The Controller of your personal data is Gurgul Investment sp. z o.o., with its registered office at ul. Polna 3, 44-285 Kobyla, NIP: 6392018818, REGON: 384767161, KRS: 0000812023, entered in the register of entrepreneurs kept by the District Court in Gliwice, Commercial Division of the National Court Register (KRS).
  2. Contact with the Controller on matters relating to personal data protection:
  3. The Controller has not appointed a Data Protection Officer (DPO), as the processing does not require such an appointment under Article 37 of the GDPR. All enquiries addressed to the Controller are handled directly.
  4. The Controller takes care to keep personal data secure and processes it in accordance with the applicable law, applying appropriate technical and organisational measures.
§ II

Definitions

GDPR
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (the General Data Protection Regulation).
Personal data
Any information relating to an identified or identifiable natural person (e.g. first name, surname, email, a natural person's NIP, IP address).
Processing
Operations performed on personal data: collection, recording, storage, modification, disclosure, erasure.
Controller
Gurgul Investment sp. z o.o. - the entity that determines the purposes and means of processing the data.
Processor
An entity that processes personal data on behalf of the Controller (e.g. a hosting provider, an email service provider).
Customer / User
A natural person conducting business activity, or a person representing an entrepreneur, who uses the Platform.
Platform
The B2B service available at excellentpro.app, conducting wholesale sales to professional entities.
§ III

Purposes of data processing

  1. Performance of the sales contract concluded via the Platform and the handling of orders (acceptance, fulfilment, delivery).
  2. Setting up and maintaining the Customer Account on the Platform, including verification of entrepreneur status.
  3. Issuing invoices and keeping accounting records in accordance with accounting and tax regulations.
  4. Handling complaints and returns.
  5. Communication with Customers: transactional notifications (order confirmations, statuses, account activation) and responses to enquiries from the contact form.
  6. Sending a product availability notification at the Customer's request, after confirmation of the email address (legal basis: Article 6(1)(b) of the GDPR - steps taken at the request of the data subject prior to entering into a contract).
  7. Fulfilment of the legal obligations incumbent on the Controller (e.g. those arising from tax regulations, AML and the DSA).
  8. Ensuring the security of the Platform: detecting abuse and protection against attacks (rate limiting by IP address, log monitoring).
  9. Pursuing claims or defending against claims (the legitimate interest of the Controller).
  10. Commercial support of Customers: assigning price groups, assessing the course of cooperation and contacting Customers on the basis of purchasing-activity summaries (order frequency and value) - details in § X.
  11. Maintaining and developing the Platform: visit statistics (with consent) and traffic measurement that stores nothing on the User's device.
§ IV

Legal bases for processing

  1. Article 6(1)(b) of the GDPR - performance of the contract or taking steps prior to entering into a contract (registration, orders, delivery, complaints).
  2. Article 6(1)(c) of the GDPR - compliance with a legal obligation (issuing invoices, accounting records, tax reporting, AML obligations, obligations arising from the DSA).
  3. Article 6(1)(f) of the GDPR - the legitimate interest of the Controller:
    • ensuring the security of the Platform (detecting and blocking abuse)
    • pursuing claims or defending against claims
    • keeping internal technical statistics, including traffic measurement that stores nothing on the User’s device (Cloudflare Web Analytics) - without profiling
    • commercial support of Customers: purchasing-activity summaries of companies (order frequency and value) reviewed by the Controller's staff (§ X(5))
  4. Article 6(1)(a) of the GDPR - the consent of the data subject - solely in respect of analytics cookies (visit statistics). Consent is voluntary, given in the banner, and you may withdraw it at any time via the "Cookie settings" link in the footer. The Controller carries out no marketing activities towards Users and no profiling within the meaning of Article 22 of the GDPR.
§ V

Scope of the data processed

  1. Data provided during account registration:
    • company name, NIP (REGON - optional, added later in the Account settings)
    • business address (street, postcode, city)
    • email address (business)
    • contact telephone number
    • the first name and surname of the person representing the Customer
    • preferred language of communication and price display currency (settlements are made in PLN)
  2. Technical data collected automatically:
    • the device's IP address
    • the date and time of connection
    • session identifier (cookie)
    • browser type and operating system (User-Agent)
    • pages visited on the Platform (server logs)
  3. Data related to orders:
    • order number and date
    • list of ordered products (SKU codes, quantities, prices)
    • order value (net, gross, VAT)
    • delivery address (if different from the registered office)
    • order notes
  4. Invoice data (in addition to the registration data): payment method, payment status, accounting document numbers.
  5. Data related to the use of the Account: current cart contents, saved purchase sets (saved carts) with the name you gave them, order status history, date of last login and login counter (for security and Account support), whether 2FA is enabled.
  6. Data of persons signed up for a product availability notification (without an account): email address, product code, language, confirmation and dispatch dates.
  7. The Controller does not collect so-called special categories of personal data (Article 9 of the GDPR): data concerning health, ethnic origin, sexual orientation, political opinions, religious beliefs, etc.
§ VI

Data recipients

  1. Personal data may be disclosed to the following categories of recipients (on the basis of processing entrustment agreements in accordance with Article 28 of the GDPR):
    • Studio Kozubek Łukasz Kozubek - provider and operator of the Platform's IT system: maintenance, development, technical support and database administration (Poland). The operator is a processor within the meaning of Article 28 of the GDPR and uses the infrastructure providers listed below as sub-processors, with the Controller's authorisation.
    • Cloudflare, Inc. - provider of hosting infrastructure and CDN (USA, EC adequacy decision + Standard Contractual Clauses)
    • Supabase Inc. - provider of database and authentication services (USA, EC adequacy decision + SCC)
    • Resend, Inc. - provider of the transactional email sending service (USA, SCC)
    • Zoho Corporation - provider of email mailboxes (India, SCC)
    • Anthropic PBC - provider of the AI model for the Excellent PRO AI assistant, for reading photographs of an order list (the import-order-from-photo feature) and for translating product content in the Controller's panel (only product descriptions are sent for translation, no Customer data) (USA, SCC). The scope of data transmitted in the chat is described in § X. Conversation content and uploaded photographs are not used to train AI models; the provider may retain them for a limited period solely for abuse detection and service security, in accordance with its commercial terms.
    • Google Ireland Ltd. - provider of Google Analytics 4 (visit statistics), activated only after consent is given in the cookie banner (Ireland; data may be transferred to Google LLC in the USA on the basis of the EC adequacy decision - DPF)
    • GitHub, Inc. - hosting of the Platform's source code and running the automatic site rebuild (USA, DPF). Only data of persons operating the Controller's panel is transmitted (the email address of the operator triggering the rebuild and the rebuild description); no Customer data is transmitted.
  2. Data may also be transferred to:
    • the accounting office servicing the Controller (on the basis of an entrustment agreement)
    • couriers delivering orders (to the extent necessary for delivery)
    • state authorities to the extent required by law (e.g. the tax office, the public prosecutor, the court, on the basis of a summons)
  3. Order data (company data, NIP, address, email, telephone, notes, line items) is transferred to the Controller's sales and accounting system (Subiekt), run on the Controller's own infrastructure, in order to issue sales documents and handle warehouse operations; document statuses and stock levels flow back from that system to the Platform.
  4. The Controller does not sell personal data to third parties for marketing or other commercial purposes.
§ VII

Transfers of data to third countries

  1. Some of the service providers listed in § VI have their registered office outside the European Economic Area (EEA), in particular in the United States.
  2. Data is transferred to the USA on the basis of:
    • the European Commission implementing decision of 10 July 2023 confirming an adequate level of data protection (the Data Privacy Framework) - for providers certified under the DPF
    • Standard Contractual Clauses (SCC) approved by the European Commission by implementing decision 2021/914 of 4 June 2021 - for the remaining cases
    • additional technical and organisational measures ensuring a level of protection equivalent to the GDPR (encryption, pseudonymisation, security audits)
  3. A list of the providers and their current DPF certifications is available on request by contacting the Controller.
§ VIII

Data retention period

  1. Data processed for the performance of the contract (orders, transactional correspondence): for the duration of the contract and 6 years after its termination - the limitation period for claims.
  2. Data processed for the purpose of issuing invoices and keeping accounting records: 5 years, counted from the beginning of the year following the financial year in which the invoice was issued (Article 70 § 1 of the Tax Ordinance).
  3. Customer Account data: until the Account is closed at the Customer's request (§ V of the Terms and Conditions) or by the Controller after 24 months of inactivity (following prior notification to the Customer). Cart and saved carts: until deleted by the Customer or until the Account is closed.
  4. Technical logs (technical data): no longer than 12 months. HTTP request logs are kept by the infrastructure provider (Cloudflare) for a short period resulting from its settings; the Controller keeps no log archive of its own.
  5. Product availability notifications: a sign-up not confirmed within 24 hours expires; unconfirmed and dispatched entries are deleted during the periodic review, no later than 12 months after sign-up.
  6. Data processed on the basis of legitimate interest (security, pursuing claims): for the time necessary to pursue that interest, no longer than 3 years from the occurrence of the event.
  7. The Controller carries out a periodic retention review (at least once a year). Data whose retention period has elapsed is deleted or anonymised in the systems of the Controller and its processors.
§ IX

Your rights

  1. The right of access (Article 15 of the GDPR) - you can obtain information on what data of yours the Controller processes and receive a copy of it.
  2. The right to rectification (Article 16 of the GDPR) - you can request the correction of inaccurate data or the completion of incomplete data. You can edit most of the data yourself in the Customer Account panel.
  3. The right to erasure (Article 17 of the GDPR, the "right to be forgotten") - you can request the erasure of data when it is no longer needed for the purposes for which it was collected. This right does not cover data that the Controller is required to retain on the basis of legal obligations (e.g. data on invoices for 5 years).
  4. The right to restriction of processing (Article 18 of the GDPR) - you can request the temporary suspension of processing (e.g. during the period of verifying the accuracy of the data).
  5. The right to data portability (Article 20 of the GDPR) - you can receive your data in a structured, machine-readable format (CSV/JSON) or request its transfer to another controller.
  6. The right to object (Article 21 of the GDPR) - you can object to the processing of data that is based on the legitimate interest of the Controller.
  7. The right to withdraw consent (Article 7(3) of the GDPR) - to the extent that processing is carried out on the basis of consent (currently this applies only to Google Analytics 4 analytics cookies).
  8. The right to lodge a complaint with a supervisory authority - the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
  9. To exercise any of these rights, contact the Controller at rodo@excellentpro.app. The Controller will respond within 30 days of receiving the request (with the possibility of an extension to 60 days in complex cases).
§ X

Profiling and automated decisions

  1. The Controller does not make decisions based solely on automated processing of data, including profiling, which produce legal effects concerning the Customer or similarly significantly affect the Customer (Article 22 of the GDPR).
  2. The Excellent PRO AI assistant available on the Platform:
    • does not build a user profile or store a history of queries beyond a single chat session
    • does not use user data to train AI models; the model provider (Anthropic PBC) does not train models on data sent via the API and may retain conversation content for a limited period solely for security purposes
    • for a logged-in Customer, a short Account context is attached to every query: company name, price group, activation status and the number of lines and pieces in the cart - so that the assistant quotes the prices and minimum quantities applicable to your group and can handle your cart; this context is transmitted to the model provider together with the question
    • at your request the assistant may additionally read your order history and the full cart contents; this data is then transmitted to the model provider to the extent necessary to provide the answer
    • generates responses on the basis of the question, the Controller's knowledge base and the Account context above; the assistant builds no behavioural profile and does not remember conversations between sessions
  3. Importing an order from a photograph (OCR): if the Customer uses the feature that reads an order list from a photograph, the uploaded image file is transferred to Anthropic PBC (USA, SCC) solely in order to read the codes, product names and quantities from it. The photograph is not stored on the Controller's servers and is not used to train AI models. The Customer should not upload photographs containing personal data or any other information unrelated to the goods being ordered; use of this feature is entirely voluntary, and an order list can also be entered manually, pasted from a CSV file or scanned as EAN codes.
  4. The Customer may stop using the AI assistant at any time without affecting the other functions of the Platform.
  5. Purchasing-activity summaries: the Controller's panel provides purchasing-activity summaries of Customers (companies): order frequency and value, sales documents from the sales system and the resulting classification of cooperation (e.g. new, active, ordering less often, no orders). The summaries concern the business, not a natural person, serve commercial support (assigning a price group, contacting the Customer, stock planning) and are reviewed by the Controller's staff. They lead to no automated decisions, are not used for advertising and are not shared with third parties. Legal basis: Article 6(1)(f) of the GDPR; you may object (§ IX(6)).
§ XI

Cookies

  1. The Platform uses strictly necessary cookies and browser storage for the functioning of the service (login session, basket, language, price display currency, technical preferences) and - only once you have given your consent - analytics cookies (Google Analytics 4). We do not use marketing or profiling cookies. We additionally measure traffic with Cloudflare Web Analytics, which stores no files on your device and identifies no User.
  2. For a detailed list of cookies, their purposes and retention time, see the Cookies Policy.
  3. Necessary cookies do not require consent in accordance with Article 399(3)(2) of the Electronic Communications Law - they are directly related to the provision of the service requested by the user. Analytics cookies are activated only after your consent (Article 399(1) of the Electronic Communications Law, Article 6(1)(a) of the GDPR).
  4. You can manage cookies in your browser settings, and change or withdraw your consent at any time via the "Cookie settings" link in the footer. Disabling session cookies will make it impossible to log in and place an order.
§ XII

Data security

  1. The Controller applies technical and organisational measures ensuring data protection appropriate to the risk:
    • encryption of connections using the HTTPS protocol (TLS 1.3) with enforcement (HSTS)
    • hashing of passwords using the bcrypt algorithm with an individual salt
    • multi-factor authentication for administrative accounts
    • regular database backups with AES-256 encryption
    • row-level access control (Row Level Security) in the database
    • log monitoring and automatic anomaly detection (rate limiting per IP)
    • regular security audits of the source code
    • updating of libraries and dependencies in response to newly discovered vulnerabilities (CVE)
  2. In the event of a personal data breach, the Controller reports the incident to the supervisory authority (the President of the PUODO) within 72 hours of becoming aware of it, in accordance with Article 33 of the GDPR. Where there is a high risk to the rights and freedoms of the data subjects, the Controller informs them directly (Article 34 of the GDPR).
  3. Access to personal data is granted solely to authorised employees and associates of the Controller and the staff of the system operator (the processor), all bound to maintain confidentiality.
§ XIII

Changes to the Privacy Policy

  1. The Controller reserves the right to amend this Privacy Policy in the event of:
    • changes in the law
    • changes in the way services are provided on the Platform
    • changes in the technologies used
    • changes to the entities processing the data
  2. The Controller will inform Customers holding an active account of any material change to the Policy by email, at least 14 days before the changes take effect.
  3. The current version of the Policy is always available at excellentpro.app/en/privacy-policy, together with information on the version number and effective date.
§ XIV

Contact regarding data protection

For matters relating to the processing of personal data, the exercise of your rights, or in the event of any doubts regarding this Policy, contact the Controller:

The Controller will make every effort to respond to your enquiry within 30 days of receiving it. In particularly complex cases, this period may be extended to 60 days - in such a situation you will be informed accordingly.

This Privacy Policy version 1.3 comes into effect on 23 September 2026 (version 1.2 applied from 3 September 2026, version 1.0 from 1 May 2026).

Related documents: Terms and Conditions · Cookies Policy