Excellent PRO
Excellent PRO

Protection of personal data

Privacy Policy

Version 1.0 | oem.excellentpro.app

This Privacy Policy sets out the principles for the processing of the personal data of users of the OEM platform oem.excellentpro.app in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the GDPR) and the Personal Data Protection Act of 10 May 2018.

§ I

The Data Controller

  1. The Controller of your personal data is Gurgul Investment sp. z o.o., with its registered office at ul. Polna 3, 44-285 Kobyla, NIP: 6392018818, REGON: 384767161, KRS: 0000812023, entered in the Register of Entrepreneurs maintained by the District Court in Gliwice, Commercial Division of the National Court Register (KRS).
  2. Contact with the Controller on matters relating to the protection of personal data:
  3. The Controller operates the OEM platform (oem.excellentpro.app) and the excellentpro.app wholesale service. The Customer Account is shared across both platforms - the account data is processed jointly, on the terms set out in this Policy and in the excellentpro.app privacy policy.
  4. The Controller has not appointed a Data Protection Officer (DPO), as the processing does not require one to be appointed under Article 37 of the GDPR. All enquiries addressed to the Controller are handled directly.
  5. The Controller takes care to ensure the security of personal data and processes it in accordance with applicable law, applying appropriate technical and organisational measures.
§ II

Definitions

GDPR
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (the General Data Protection Regulation).
Personal data
Any information relating to an identified or identifiable natural person (e.g. first name, surname, e-mail, the NIP of a natural person, IP address).
Processing
Operations performed on personal data: collection, recording, storage, modification, disclosure, erasure.
Controller
Gurgul Investment sp. z o.o. - the entity determining the purposes and means of the processing of data.
Processor
An entity that processes personal data on behalf of the Controller (e.g. a hosting provider, an e-mail service provider).
Customer / User
A natural person conducting business activity, or a person representing an entrepreneur, using the OEM Platform.
OEM Platform
The B2B service available at oem.excellentpro.app (and excellentpro.app/oem), carrying out the wholesale sale of OEM products packaged to order for professional entities.
§ III

Purposes of data processing

  1. Performance of the contract of sale concluded via the OEM Platform and the handling of orders (receipt, packaging, delivery).
  2. Setting up and servicing the Customer Account, including verification of entrepreneur status. The Account is shared across the OEM Platform and the excellentpro.app wholesale service operated by the Controller.
  3. Handling enquiries concerning documentary support for OEM products (INCI composition, label design, safety report, CPNP notification) submitted via the contact form or by e-mail.
  4. Issuing invoices (including Pro-Forma invoices) and maintaining accounting records in accordance with accounting and tax legislation.
  5. Handling complaints.
  6. Communication with Customers: transactional notifications (order confirmations, statuses, account activation), responses to enquiries.
  7. Fulfilment of the legal obligations incumbent on the Controller (e.g. arising from tax legislation, AML, the DSA).
  8. Ensuring the security of the Platform: detecting abuse, protection against attacks (rate limiting by IP address, log monitoring).
  9. Pursuing claims or defending against claims (the legitimate interest of the Controller).
§ IV

Legal bases for processing

  1. Article 6(1)(b) of the GDPR - performance of a contract or taking steps prior to entering into a contract (registration, orders, packaging, delivery, complaints, enquiries about documentary support).
  2. Article 6(1)(c) of the GDPR - compliance with a legal obligation (issuing invoices, accounting records, tax reporting, AML obligations, obligations arising from the DSA).
  3. Article 6(1)(f) of the GDPR - the legitimate interest of the Controller:
    • ensuring the security of the Platform (detecting and blocking abuse)
    • pursuing claims or defending against claims
    • keeping internal technical statistics, including traffic measurement that stores nothing on the User’s device (Cloudflare Web Analytics) - without profiling
  4. Article 6(1)(a) of the GDPR - the consent of the data subject - solely in respect of analytics cookies (visit statistics). Consent is voluntary, given in the banner, and you may withdraw it at any time via the "Cookie settings" link in the footer. The Controller carries out no marketing or profiling activities.
§ V

Scope of the data processed

  1. Data provided when registering an account:
    • company name, NIP, REGON
    • business address (street, postcode, town)
    • e-mail address (business)
    • contact telephone number
    • the first name and surname of the person representing the Customer (optional)
  2. Technical data collected automatically:
    • device IP address
    • date and time of connection
    • session identifier (cookie)
    • browser type and operating system (User-Agent)
    • pages visited on the Platform (server logs)
  3. Data relating to OEM orders:
    • order number and date
    • list of the variants ordered (SKU codes, capacities, packaging, quantities, prices)
    • colour breakdown within an order item
    • order value (net, gross, VAT)
    • delivery address (if different from the registered office)
    • order notes
  4. Invoicing data (in addition to registration data): payment method, payment status, accounting document numbers.
  5. The Controller does not collect what are known as special categories of personal data (Article 9 of the GDPR): data concerning health, ethnic origin, sexual orientation, political opinions, religious beliefs, and the like.
§ VI

Data recipients

  1. Personal data may be disclosed to the following categories of recipients (on the basis of data processing agreements in accordance with Article 28 of the GDPR):
    • Cloudflare, Inc. - provider of hosting infrastructure and CDN (USA, EC adequacy decision + Standard Contractual Clauses)
    • Supabase Inc. - provider of database and authentication services (USA, EC adequacy decision + SCC)
    • Resend, Inc. - provider of the transactional e-mail delivery service (USA, SCC)
    • Zoho Corporation - provider of e-mail mailboxes (India, SCC)
    • Anthropic PBC - provider of the AI model for the chat assistant (USA, SCC). Chat queries are processed in a mode with no data retention for model training.
  2. Data may also be transferred to:
    • the accounting firm servicing the Controller (on the basis of a data processing agreement)
    • the couriers carrying out the delivery of orders (to the extent necessary for delivery)
    • the payment operators handling online payments (if the Customer uses such an option)
    • state authorities to the extent required by law (e.g. the tax office, the public prosecutor, a court, on the basis of a summons)
  3. The Controller does not sell personal data to third parties for marketing or other commercial purposes.
§ VII

Transfer of data to third countries

  1. Some of the service providers listed in § VI have their registered office outside the European Economic Area (EEA), in particular in the United States.
  2. The transfer of data to the USA takes place on the basis of:
    • the Implementing Decision of the European Commission of 10 July 2023 finding an adequate level of data protection (the Data Privacy Framework) - for providers certified under the DPF
    • the Standard Contractual Clauses (SCC) approved by the European Commission by Implementing Decision 2021/914 of 4 June 2021 - for the remaining cases
    • additional technical and organisational measures ensuring a level of protection equivalent to the GDPR (encryption, pseudonymisation, security audits)
  3. A list of the providers and their current DPF certifications is available on request by contacting the Controller.
§ VIII

Data retention period

  1. Data processed for the performance of the contract (orders, transactional correspondence): for the duration of the contract and for 6 years after its termination - the limitation period for claims.
  2. Data processed for the purpose of issuing invoices and accounting records: 5 years counted from the beginning of the year following the financial year in which the invoice was issued (Article 70 § 1 of the Tax Ordinance).
  3. Customer Account data: until the account is deleted by the Customer or by the Controller after 3 years of inactivity (following prior notification of the Customer).
  4. Server logs (technical data): a maximum of 12 months, after which they are automatically deleted or anonymised.
  5. Data processed on the basis of legitimate interest (security, pursuing claims): for the time necessary to pursue that interest, no longer than 3 years from the occurrence of the event.
  6. Upon expiry of the periods indicated, the data is permanently deleted from the systems of the Controller and its processors.
§ IX

Your rights

  1. The right of access to data (Article 15 of the GDPR) - you can obtain information on what data of yours the Controller processes and receive a copy of it.
  2. The right to rectification of data (Article 16 of the GDPR) - you can request the correction of inaccurate data or the completion of incomplete data. You can edit most of the data yourself in the Customer Account panel.
  3. The right to erasure of data (Article 17 of the GDPR, the "right to be forgotten") - you can request the erasure of data when it is no longer needed for the purposes for which it was collected. This right does not cover data that the Controller is required to retain on the basis of legal obligations (e.g. invoice data for 5 years).
  4. The right to restriction of processing (Article 18 of the GDPR) - you can request the temporary suspension of processing (e.g. during the period of verifying the accuracy of data).
  5. The right to data portability (Article 20 of the GDPR) - you can receive your data in a structured, machine-readable format (CSV/JSON) or request that it be transferred to another controller.
  6. The right to object (Article 21 of the GDPR) - you can object to the processing of data based on the legitimate interest of the Controller.
  7. The right to withdraw consent (Article 7(3) of the GDPR) - to the extent that processing is carried out on the basis of consent (the Controller does not currently process data on the basis of consent).
  8. The right to lodge a complaint with the supervisory authority - the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
  9. To exercise any of these rights, contact the Controller at rodo@excellentpro.app. The Controller will respond within 30 days of receiving the request (with the possibility of extension to 60 days in complex cases).
§ X

Profiling and automated decision-making

  1. The Controller does not take decisions based solely on the automated processing of data, including profiling, that produce legal effects concerning the Customer or similarly significantly affect them (Article 22 of the GDPR).
  2. The AI chat assistant available on the Platform:
    • does not build a user profile or store a query history beyond a single chat session
    • does not use user data to train AI models (Anthropic PBC operates in a zero-retention mode for business API clients)
    • generates responses on the basis of the question and the Controller's knowledge base, not on the basis of a Customer profile
  3. The Customer may cease using the AI assistant at any time without affecting the other functions of the Platform.
§ XI

Cookies

  1. The OEM Platform uses strictly necessary cookies for the functioning of the service (login session, basket, technical preferences) and - only once you have given your consent - analytics cookies (Google Analytics 4). We do not use marketing or profiling cookies. We additionally measure traffic with Cloudflare Web Analytics, which stores no files on your device and identifies no User.
  2. For a detailed list of cookies, their purposes and retention periods - see the Cookies Policy.
  3. Strictly necessary cookies do not require consent under Article 173(3)(2) of the Telecommunications Law Act - they are directly related to the provision of the service requested by the user.
  4. You can manage cookies in your browser settings, and change or withdraw your consent at any time via the "Cookie settings" link in the footer. Disabling session cookies will make it impossible to log in and place an order.
§ XII

Data security

  1. The Controller applies technical and organisational measures ensuring data protection appropriate to the risk:
    • encryption of connections using the HTTPS protocol (TLS 1.3) with enforcement (HSTS)
    • hashing of passwords using the bcrypt algorithm with an individual salt
    • multi-factor authentication for administrative accounts
    • regular database backups with AES-256 encryption
    • row-level access control (Row Level Security) in the database
    • log monitoring and automatic anomaly detection (rate limiting per IP)
    • regular security audits of the source code
    • updating libraries and dependencies in response to newly discovered vulnerabilities (CVEs)
  2. In the event of a personal data breach, the Controller reports the incident to the supervisory authority (the President of the PUODO) within 72 hours of becoming aware of it, in accordance with Article 33 of the GDPR. In the event of a high risk to the rights and freedoms of the data subjects, the Controller informs them directly (Article 34 of the GDPR).
  3. Access to personal data is granted only to authorised employees and associates of the Controller who have been bound to maintain confidentiality.
§ XIII

Changes to the Privacy Policy

  1. The Controller reserves the right to amend this Privacy Policy in the event of:
    • changes in the law
    • changes in the manner of providing services on the Platform
    • changes in the technologies used
    • changes to the data processors
  2. The Controller will inform Customers holding an active account of any material change to the Policy by e-mail at least 14 days before the changes come into force.
  3. The current version of the Policy is always available at oem.excellentpro.app/en/privacy-policy, together with information about the version number and effective date.
§ XIV

Contact regarding data protection

For matters relating to the processing of personal data, the exercise of your rights, or in the event of any doubts concerning this Policy - contact the Controller:

The Controller will make every effort to respond to your enquiry within 30 days of receiving it. In particularly complex cases this period may be extended to 60 days - in which case you will be informed accordingly.

This Privacy Policy comes into force on 3 July 2026.

Related documents: Terms and Conditions | Cookies Policy