Excellent PRO
Excellent PRO

Personal Data Protection

Privacy Policy

Version 1.1 · excellentpro.app

This Privacy Policy sets out the rules for processing the personal data of users of the excellentpro.app platform in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the GDPR) and the Personal Data Protection Act of 10 May 2018.

§ I

Data Controller

  1. The Controller of your personal data is Gurgul Investment sp. z o.o., with its registered office at ul. Polna 3, 44-285 Kobyla, NIP: 6392018818, REGON: 384767161, KRS: 0000812023, entered in the register of entrepreneurs kept by the District Court in Gliwice, Commercial Division of the National Court Register (KRS).
  2. Contact with the Controller on matters relating to personal data protection:
  3. The Controller has not appointed a Data Protection Officer (DPO), as the processing does not require such an appointment under Article 37 of the GDPR. All enquiries addressed to the Controller are handled directly.
  4. The Controller takes care to keep personal data secure and processes it in accordance with the applicable law, applying appropriate technical and organisational measures.
§ II

Definitions

GDPR
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (the General Data Protection Regulation).
Personal data
Any information relating to an identified or identifiable natural person (e.g. first name, surname, email, a natural person's NIP, IP address).
Processing
Operations performed on personal data: collection, recording, storage, modification, disclosure, erasure.
Controller
Gurgul Investment sp. z o.o. - the entity that determines the purposes and means of processing the data.
Processor
An entity that processes personal data on behalf of the Controller (e.g. a hosting provider, an email service provider).
Customer / User
A natural person conducting business activity, or a person representing an entrepreneur, who uses the Platform.
Platform
The B2B service available at excellentpro.app, conducting wholesale sales to professional entities.
§ III

Purposes of data processing

  1. Performance of the sales contract concluded via the Platform and the handling of orders (acceptance, fulfilment, delivery).
  2. Setting up and maintaining the Customer Account on the Platform, including verification of entrepreneur status.
  3. Issuing invoices and keeping accounting records in accordance with accounting and tax regulations.
  4. Handling complaints and returns.
  5. Communication with Customers: transactional notifications (order confirmations, statuses, account activation) and responses to enquiries.
  6. Fulfilment of the legal obligations incumbent on the Controller (e.g. those arising from tax regulations, AML and the DSA).
  7. Ensuring the security of the Platform: detecting abuse and protection against attacks (rate limiting by IP address, log monitoring).
  8. Pursuing claims or defending against claims (the legitimate interest of the Controller).
§ IV

Legal bases for processing

  1. Article 6(1)(b) of the GDPR - performance of the contract or taking steps prior to entering into a contract (registration, orders, delivery, complaints).
  2. Article 6(1)(c) of the GDPR - compliance with a legal obligation (issuing invoices, accounting records, tax reporting, AML obligations, obligations arising from the DSA).
  3. Article 6(1)(f) of the GDPR - the legitimate interest of the Controller:
    • ensuring the security of the Platform (detecting and blocking abuse)
    • pursuing claims or defending against claims
    • keeping internal technical statistics (without profiling)
  4. Article 6(1)(a) of the GDPR - the consent of the data subject - the Controller does not rely on this legal basis, as it does not carry out any marketing or profiling activities that require consent.
§ V

Scope of the data processed

  1. Data provided during account registration:
    • company name, NIP, REGON
    • business address (street, postcode, city)
    • email address (business)
    • contact telephone number
    • the first name and surname of the person representing the Customer (optional)
  2. Technical data collected automatically:
    • the device's IP address
    • the date and time of connection
    • session identifier (cookie)
    • browser type and operating system (User-Agent)
    • pages visited on the Platform (server logs)
  3. Data related to orders:
    • order number and date
    • list of ordered products (SKU codes, quantities, prices)
    • order value (net, gross, VAT)
    • delivery address (if different from the registered office)
    • order notes
  4. Invoice data (in addition to the registration data): payment method, payment status, accounting document numbers.
  5. The Controller does not collect so-called special categories of personal data (Article 9 of the GDPR): data concerning health, ethnic origin, sexual orientation, political opinions, religious beliefs, etc.
§ VI

Data recipients

  1. Personal data may be disclosed to the following categories of recipients (on the basis of processing entrustment agreements in accordance with Article 28 of the GDPR):
    • Cloudflare, Inc. - provider of hosting infrastructure and CDN (USA, EC adequacy decision + Standard Contractual Clauses)
    • Supabase Inc. - provider of database and authentication services (USA, EC adequacy decision + SCC)
    • Resend, Inc. - provider of the transactional email sending service (USA, SCC)
    • Zoho Corporation - provider of email mailboxes (India, SCC)
    • Anthropic PBC - provider of the AI model for the Excellent PRO AI assistant and for reading photographs of an order list (the import-order-from-photo feature) (USA, SCC). Chat queries and uploaded photographs are processed in a mode with no data retention for model training.
  2. Data may also be transferred to:
    • the accounting office servicing the Controller (on the basis of an entrustment agreement)
    • couriers delivering orders (to the extent necessary for delivery)
    • payment operators handling online payments (if the Customer uses such an option)
    • state authorities to the extent required by law (e.g. the tax office, the public prosecutor, the court, on the basis of a summons)
  3. The Controller does not sell personal data to third parties for marketing or other commercial purposes.
§ VII

Transfers of data to third countries

  1. Some of the service providers listed in § VI have their registered office outside the European Economic Area (EEA), in particular in the United States.
  2. Data is transferred to the USA on the basis of:
    • the European Commission implementing decision of 10 July 2023 confirming an adequate level of data protection (the Data Privacy Framework) - for providers certified under the DPF
    • Standard Contractual Clauses (SCC) approved by the European Commission by implementing decision 2021/914 of 4 June 2021 - for the remaining cases
    • additional technical and organisational measures ensuring a level of protection equivalent to the GDPR (encryption, pseudonymisation, security audits)
  3. A list of the providers and their current DPF certifications is available on request by contacting the Controller.
§ VIII

Data retention period

  1. Data processed for the performance of the contract (orders, transactional correspondence): for the duration of the contract and 6 years after its termination - the limitation period for claims.
  2. Data processed for the purpose of issuing invoices and keeping accounting records: 5 years, counted from the beginning of the year following the financial year in which the invoice was issued (Article 70 § 1 of the Tax Ordinance).
  3. Customer Account data: until the account is deleted by the Customer, or by the Controller after 3 years of inactivity (following prior notification to the Customer).
  4. Server logs (technical data): a maximum of 12 months, after which they are automatically deleted or anonymised.
  5. Data processed on the basis of legitimate interest (security, pursuing claims): for the time necessary to pursue that interest, no longer than 3 years from the occurrence of the event.
  6. After the indicated periods have elapsed, the data is permanently deleted from the systems of the Controller and its processors.
§ IX

Your rights

  1. The right of access (Article 15 of the GDPR) - you can obtain information on what data of yours the Controller processes and receive a copy of it.
  2. The right to rectification (Article 16 of the GDPR) - you can request the correction of inaccurate data or the completion of incomplete data. You can edit most of the data yourself in the Customer Account panel.
  3. The right to erasure (Article 17 of the GDPR, the "right to be forgotten") - you can request the erasure of data when it is no longer needed for the purposes for which it was collected. This right does not cover data that the Controller is required to retain on the basis of legal obligations (e.g. data on invoices for 5 years).
  4. The right to restriction of processing (Article 18 of the GDPR) - you can request the temporary suspension of processing (e.g. during the period of verifying the accuracy of the data).
  5. The right to data portability (Article 20 of the GDPR) - you can receive your data in a structured, machine-readable format (CSV/JSON) or request its transfer to another controller.
  6. The right to object (Article 21 of the GDPR) - you can object to the processing of data that is based on the legitimate interest of the Controller.
  7. The right to withdraw consent (Article 7(3) of the GDPR) - to the extent that processing is carried out on the basis of consent (the Controller does not currently process data on the basis of consent).
  8. The right to lodge a complaint with a supervisory authority - the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
  9. To exercise any of these rights, contact the Controller at rodo@excellentpro.app. The Controller will respond within 30 days of receiving the request (with the possibility of an extension to 60 days in complex cases).
§ X

Profiling and automated decisions

  1. The Controller does not make decisions based solely on automated processing of data, including profiling, which produce legal effects concerning the Customer or similarly significantly affect the Customer (Article 22 of the GDPR).
  2. The Excellent PRO AI assistant available on the Platform:
    • does not build a user profile or store a history of queries beyond a single chat session
    • does not use user data to train AI models (Anthropic PBC operates in zero-retention mode for business API customers)
    • generates responses on the basis of the question and the Controller's knowledge base, not on the basis of the Customer's profile
  3. Importing an order from a photograph (OCR): if the Customer uses the feature that reads an order list from a photograph, the uploaded image file is transferred to Anthropic PBC (USA, SCC) solely in order to read the codes, product names and quantities from it. The photograph is not stored on the Controller's servers and is not used to train AI models (zero-retention mode). The Customer should not upload photographs containing personal data or any other information unrelated to the goods being ordered; use of this feature is entirely voluntary, and an order list can also be entered manually, pasted from a CSV file or scanned as EAN codes.
  4. The Customer may stop using the AI assistant at any time without affecting the other functions of the Platform.
§ XI

Cookies

  1. The Platform uses strictly necessary cookies only, for the functioning of the service (login session, basket, technical preferences). We do not use marketing, analytical or profiling cookies.
  2. For a detailed list of cookies, their purposes and retention time, see the Cookies Policy.
  3. Necessary cookies do not require consent in accordance with Article 173(3)(2) of the Telecommunications Act - they are directly related to the provision of the service requested by the user.
  4. You can manage cookies in your browser settings. Disabling session cookies will make it impossible to log in and place an order.
§ XII

Data security

  1. The Controller applies technical and organisational measures ensuring data protection appropriate to the risk:
    • encryption of connections using the HTTPS protocol (TLS 1.3) with enforcement (HSTS)
    • hashing of passwords using the bcrypt algorithm with an individual salt
    • multi-factor authentication for administrative accounts
    • regular database backups with AES-256 encryption
    • row-level access control (Row Level Security) in the database
    • log monitoring and automatic anomaly detection (rate limiting per IP)
    • regular security audits of the source code
    • updating of libraries and dependencies in response to newly discovered vulnerabilities (CVE)
  2. In the event of a personal data breach, the Controller reports the incident to the supervisory authority (the President of the PUODO) within 72 hours of becoming aware of it, in accordance with Article 33 of the GDPR. Where there is a high risk to the rights and freedoms of the data subjects, the Controller informs them directly (Article 34 of the GDPR).
  3. Access to personal data is granted solely to authorised employees and associates of the Controller, who have been bound to maintain confidentiality.
§ XIII

Changes to the Privacy Policy

  1. The Controller reserves the right to amend this Privacy Policy in the event of:
    • changes in the law
    • changes in the way services are provided on the Platform
    • changes in the technologies used
    • changes to the entities processing the data
  2. The Controller will inform Customers holding an active account of any material change to the Policy by email, at least 14 days before the changes take effect.
  3. The current version of the Policy is always available at excellentpro.app/en/privacy-policy, together with information on the version number and effective date.
§ XIV

Contact regarding data protection

For matters relating to the processing of personal data, the exercise of your rights, or in the event of any doubts regarding this Policy, contact the Controller:

The Controller will make every effort to respond to your enquiry within 30 days of receiving it. In particularly complex cases, this period may be extended to 60 days - in such a situation you will be informed accordingly.

This Privacy Policy comes into effect on 1 May 2026.

Related documents: Terms and Conditions · Cookies Policy