Privacy policy
This Privacy Policy sets out the rules for the processing of personal data and the use of cookies within the Rafcom B2B Platform (hereinafter referred to as the “B2B Platform”), in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation or “GDPR”), as well as Article 399 of the Polish Electronic Communications Law of 12 July 2024.
The provisions of this Privacy Policy (hereinafter referred to as the “Policy”) refer to the terms and definitions set out in the Terms and Conditions of the Rafcom B2B Platform and the General Terms and Conditions of Sale of the Rafcom B2B Platform. Please refer to those documents to determine the meaning of capitalised terms, including in particular: User, Customer, B2B Platform, Goods, Customer Account and Alternative Channels, as well as other terms also used in this Policy.
1. Who is the controller of your personal data?
The Controller of personal data processed within the B2B Platform and through Alternative Channels is Rafcom sp. z o.o., with its registered office in Reguły (05-816), at ul. Stanisława Bodycha 97, Tax Identification Number (NIP): 5342663114, whose company records are kept by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register, under KRS number 0001029234, with a share capital of PLN 500,000.
2. Contact point
For matters relating to personal data protection, you may contact us by post at: Rafcom sp. z o.o., ul. Stanisława Bodycha 97, 05-816 Reguły, Poland, or by email at: rodo@rafcom.waw.pl
3. Who is this Policy intended for and what situations does it cover?
This Policy applies to:
· persons visiting the B2B Platform without registering, e.g. browsing publicly available content,
· persons using the B2B Platform as registered Users within a Customer Account,
· persons using Alternative Channels.
The B2B Platform is intended for business customers. Access to its full functionality, including placing Orders, requires a Customer Account.
4. Where do we obtain your data from?
We obtain your data directly from you if you use the B2B Platform yourself or use Alternative Channels such as telephone, email, chat, WhatsApp, Microsoft Teams or Signal to contact us, including when you register a Customer Account and register yourself as a User.
We may also obtain your data from the Customer, i.e. the organisation for which you work or with which you cooperate, where that organisation has created a Customer Account on the B2B Platform and provided your details as one of its Users. Your data is most commonly provided by the User who creates the Customer Account or who has administrative permissions allowing new Users to be added.
5. Purposes and legal bases for processing personal data
A) Visiting the B2B Platform without registering (server logs and IP address)
Purpose: ensuring that the website operates properly, maintaining security, performing diagnostics, compiling technical statistics and preventing misuse.
Legal basis: Article 6(1)(f) GDPR (the Controller’s legitimate interest in maintaining the operation, stability and security of the service). In certain situations, Article 6(1)(b) GDPR may also apply, where processing is necessary to fulfil a request to display content or provide communication.
B) Registration and maintenance of the Customer Account and User accounts
Purpose: creating and verifying accounts, enabling login, managing Users and permissions and providing functions available after login, such as Order history and settlements.
Legal basis: Article 6(1)(b) GDPR (performance of a contract and provision of electronic services in accordance with the Terms and Conditions) and Article 6(1)(f) GDPR (security, accountability and the establishment, pursuit or defence of claims).
C) Provision of services, placing and fulfilling Orders and sale of Goods
Purpose: accepting and fulfilling Orders, delivery, settlements, transactional communication and after-sales service.
Legal basis: Article 6(1)(b) GDPR.
D) Claims and handling of requests
Purpose: accepting, processing and resolving claims and requests, including those relating to the B2B Platform or sales, and communicating in connection with such matters.
Legal basis: Article 6(1)(b) GDPR (implementation of procedures connected with a contract) and Article 6(1)(f) GDPR (establishment, pursuit or defence of claims).
E) Legal obligations (accounting, taxation and record retention)
Purpose: complying with statutory obligations, including tax and accounting obligations, issuing invoices, the mandatory submission of invoices to the Polish National e-Invoicing System (KSeF), and retaining accounting records.
Legal basis: Article 6(1)(c) GDPR.
F) Security, audits, accountability and fraud prevention
Purpose: monitoring system events, detecting incidents, preventing misuse and establishing or pursuing claims.
Legal basis: Article 6(1)(f) GDPR.
G) Newsletter and marketing communications
Purpose: sending newsletters and commercial information.
Legal basis: Article 6(1)(a) GDPR (consent) or Article 6(1)(f) GDPR (direct marketing of the Controller’s own products and services, where permitted).
H) Communication and Alternative Channels
Purpose: handling enquiries received by email, telephone and messaging services such as WhatsApp and Microsoft Teams. Important: Rafcom may retain correspondence conducted through these channels for evidentiary purposes.
Legal basis: Article 6(1)(f) GDPR (the Controller’s legitimate interest).
6. Categories of personal data we process and whether providing such data is mandatory or voluntary
Depending on how you use the B2B Platform, we may process, among other things:
• identification and professional data: first name, surname, login/User ID, position or role, if provided,
• contact details: email address and telephone number,
• Customer/company details: name, legal form, NIP, KRS/REGON numbers, address details and other information provided during registration or sales support,
• transaction and settlement data: Order history, settlements, invoices and delivery notes, delivery and payment details, to the extent required to complete sales and settlements,
• data relating to claims and requests: the content of the claim or request, case number and supporting evidence such as photographs or printouts, if you provide them,
• technical and usage data: server logs, IP address, date and time, request parameters, device and browser identifiers, error information and security events,
• account activity data (system event logs): operations performed within the system may be recorded for security and accountability purposes.
If you voluntarily provide other personal data in a request, for example in a claim, such data will only be processed to the extent necessary to handle the matter.
7. Is providing personal data mandatory?
Data required to create a Customer Account and use the functions available after logging in to the B2B Platform, usually marked as mandatory, is necessary for us to provide the services specified in the Terms and Conditions, including fulfilling Orders placed by Customers.
Providing other data is voluntary, although it may be necessary to fulfil a specific request, such as responding to an enquiry or handling a claim.
8. Recipients of personal data
Your data may be disclosed to:
• processors acting on behalf of the Controller, such as providers of hosting services, IT system maintenance and development, email services and security tools,
• entities involved in completing sales and settlements, such as courier and transport companies and payment service providers,
• providers of legal and accounting services,
• authorised authorities and institutions where disclosure is required by law, e.g. tax authorities in connection with reporting to the KSeF system,
• providers of Alternative Channels where messaging services such as WhatsApp or Microsoft Teams are used. By using these channels, you acknowledge that their providers act as separate controllers in relation to their own infrastructure,
• manufacturers and warrantors where a warranty claim is handled directly by the manufacturer and Rafcom assists in transferring the data.
We ensure that your data is disclosed only to the extent connected with the services provided by the entities listed above and only to the extent necessary, in accordance with the data-minimisation principle.
9. Transfers of personal data to third countries or international organisations
We do not intend to transfer your personal data to a third country or an international organisation.
10. Data retention periods
Customer Account and profile data: we retain this data for the duration of the agreement for the provision of Customer Account services and until the agreement ends or the account is deleted. It is then retained for 36 months for the purposes of securing claims and ensuring accountability under Article 6(1)(f) GDPR.
Transaction and settlement data, including accounting records: we retain this data for the period required under tax and accounting legislation, generally for five years calculated from the end of the year in which the tax payment deadline expired, pursuant to Article 6(1)(c) GDPR.
Claims and correspondence: we retain this data for 36 months from the end of the year in which the claim or correspondence was created, including the period required to handle the matter. In the event of a dispute, the data will be retained until the proceedings have been finally concluded and the applicable limitation periods have expired.
Server logs, including the IP addresses of unregistered visitors: 24 months.
Security events and audit logs, such as login records, administrative operations and incidents: 24 months.
11. Your rights
You have the right to request access to your personal data from the Controller, as well as its rectification, erasure or restriction of processing. You also have the right to object to processing and the right to data portability.
Where we process your data on the basis of your consent, you have the right to withdraw that consent at any time. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
You also have the right to lodge a complaint with the supervisory authority—the President of the Polish Personal Data Protection Office.
12. Server logs
Even if you do not have a Customer Account and use the B2B Platform as an unregistered or logged-out User, our servers automatically record technical data while you browse the B2B Platform.
This may include your IP address, date and time, browser information, request and response parameters such as an HTTP status code, error information and the referring page address (referrer), where you accessed the Platform through a link.
This data is used to ensure the security and stability of the system, including protection against DDoS attacks, and is deleted once it is no longer technically useful.
13. Cookies
Pursuant to Article 399 of the Polish Electronic Communications Law of 12 July 2024, we hereby provide information about the function and purpose of software or data that does not form part of the content of the service and is placed by the Service Provider in the telecommunications and information system used by the User. In the case of the B2B Platform, this refers to so-called “cookies”.
What are cookies?
The website uses cookies, i.e. small text files sent by a website to the browser used by the User and sent back by the User’s browser whenever the website is visited again. Cookies are stored in the persistent memory, such as the hard drive, of the device used to access the website, e.g. a desktop computer, laptop, tablet or smartphone. Cookies are a legally permitted and useful tool used, for example, to maintain the User’s connection to the website, remember actions taken by the User, including shopping activities, analyse the effectiveness of the website’s design and advertising, and verify the identity of Users conducting online transactions.
How does the B2B Platform use cookies? Rafcom uses the following types of cookies:
Strictly necessary cookies: Strictly necessary cookies ensure that the website functions correctly and enable you to use the services we offer conveniently. They respond to actions taken by you, including setting your privacy preferences, logging in and completing forms. These cookies allow the website to operate without disruption.
Functional and personalisation cookies: These cookies allow the website to remember the settings you have selected and personalise certain functions or displayed content.
They allow us to make the website more convenient to use by adapting it to your individual preferences. Consent to functional and personalisation cookies makes additional website functions available.
Analytics cookies: Analytics cookies help us develop our services and adapt them to your needs.
Analytics cookies provide information about how the website is used and where and how frequently our websites are visited. This data allows us to evaluate the popularity of our websites among Users. The collected information is processed in anonymised form. Consent to analytics cookies ensures that all related functions are available.
Advertising cookies: Advertising cookies enable us to present the most relevant information and news to you on our partners’ websites. Promotional cookies are used to display our communications based on an analysis of your preferences and browsing habits. Promotional content may appear on the websites of third parties, our business partners or other service providers. These companies act as intermediaries displaying our content in the form of messages, offers and social media communications.
How can the User control the use of cookies?
When you access the B2B Platform for the first time, you will be asked to consent to the use of specific types of cookies. By default, only the “Strictly necessary” cookies option is selected, as disabling these cookies may prevent the B2B Platform from operating correctly. In all other respects, the decision whether to consent to our use of cookies is yours.
You may also restrict or disable cookies on your device at any time by changing the settings of the web browser you use. Information on changing browser settings can be found, among other places, on the following pages:
Firefox: Mozilla Firefox – Manage cookies
Edge: Microsoft Edge – Manage cookies
Chrome: Google Chrome – Manage cookies
Opera: Opera – Manage cookies