Privacy Policy
Last updated: August 25, 2026
Table of Contents
1. Personal Data Controller
The controller of personal data collected through the LogiMarket B2B platform (logimarket.pl / logimarket.eu) is PF CONSULTING Piotr Fiszer with its registered office at ul. Promienista 114/2, 60-142 Poznań, Poland, Tax ID (NIP): 7792017326.
2. Privacy Contact
For matters relating to personal data protection and the exercise of data subject rights, you may contact the Controller via email at: kontakt@logimarket.pl or by post to the Controller's registered address. The Controller has not appointed a formal Data Protection Officer (DPO).
3. Scope of the Policy
This Privacy Policy sets out the rules for processing personal data of users, business clients, contact persons, and representatives of commercial partners using the LogiMarket B2B marketplace platform.
4. Categories of Processed Data
We process data necessary for B2B operations: company details (company name, tax ID), representative and contact person details (full name, business email address, phone number), data contained in requests for quotation (RFQ) and B2B orders, message and note contents, as well as technical session identifiers and telemetry data necessary for the operation of the service.
5. Purposes and Legal Bases for Data Processing
Personal data are processed for the following purposes:
- Handling requests for quote (RFQ) and preparing commercial offers – legal basis: Art. 6(1)(b) GDPR (for sole proprietorships who are party to the request) or Art. 6(1)(f) GDPR (legitimate interest of the Controller and partner in handling B2B commercial communication for employees/representatives);
- Processing B2B orders and verifying availability – legal basis: Art. 6(1)(b) GDPR (pre-contractual steps for sole proprietors) or Art. 6(1)(f) GDPR (business transaction handling for representatives);
- Authentication and administrative access management – legal basis: Art. 6(1)(f) GDPR (security and access control);
- Outbound offer redirection – the service handles safe technical redirections (/go/[id]); active session-based attribution tracking is currently disabled and does not generate cookies or perform profiling;
- Maintaining the active shopping cart session – legal basis: Art. 6(1)(b) and (f) GDPR and Art. 399(3) of the Electronic Communications Law (strictly necessary session cookies);
- Managing B2B partner relationships and KYB verification – legal basis: Art. 6(1)(f) GDPR and Art. 6(1)(b) GDPR (in connection with partner agreements).
6. Distinction of Legal Bases for Businesses and Representatives
For natural persons conducting business as sole proprietors who are themselves party to an inquiry or order, the legal basis is Art. 6(1)(b) GDPR (necessity for the performance of a contract or to take steps prior to entering into a contract). For individuals representing legal entities or employees of third parties, the legal basis is Art. 6(1)(f) GDPR (legitimate interest in conducting B2B transactions).
7. Legitimate Interests of the Controller
Legitimate interests pursued by the Controller (Art. 6(1)(f) GDPR) include: handling ongoing B2B commercial communications and inquiries, ensuring platform security and integrity, fraud prevention, operating secure technical redirects, and establishing, exercising, or defending legal claims.
8. Data Recipients
Data may be disclosed to: (1) authorized personnel and contractors of the Controller; (2) IT and technical infrastructure service providers acting as data processors, including Supabase (with its primary database region in West EU / Ireland); (3) selected Partners and Sellers registered on the platform – solely when a user submits an RFQ or order concerning that Partner's offer and routing is active to fulfill the transaction.
9. Transfers of Data Outside the European Economic Area (EEA)
The primary database infrastructure of the platform is located in the European Economic Area (Ireland). Within the IT infrastructure vendor chain (including Supabase and sub-processors), data may be processed in third countries outside the EEA. Data transfers rely on appropriate legal mechanisms under Chapter V GDPR, in particular European Commission Standard Contractual Clauses (SCC 2021/914) and adequacy decisions.
10. Data Retention Periods
Personal data and session identifiers are subject to distinct retention principles: (1) The session identifier ('session_hash' cookie) is stored strictly in the browser for the duration of the active session and expires upon closing the browser; (2) Backend datasets are retained in accordance with established retention criteria – RFQ inquiries generally up to 12 months from last activity, order records (platform PII) up to 3 years for legal claim defense, historical technical and security logs up to 12 months, and accounting records for statutory tax periods. Database data retention is managed under our internal data retention policy.
11. Data Subject Rights
Each data subject has the right to: access their data (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure ('right to be forgotten', Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and the right to object to processing based on legitimate interest (Art. 21 GDPR). To exercise these rights, please contact: kontakt@logimarket.pl.
12. Right to Lodge a Complaint with a Supervisory Authority
Data subjects have the right to lodge a complaint with the competent supervisory authority – in Poland, the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw – if they believe that the processing of their personal data breaches the GDPR.
13. Voluntary Nature of Providing Data
Providing personal data in RFQ and B2B order forms is voluntary, but necessary to transmit an inquiry to a Partner or initiate the order process. Failure to provide data prevents the provision of these services.
14. Automated Decision-Making and Profiling
LogiMarket does not apply automated decision-making producing legal effects concerning natural persons or profiling within the meaning of Art. 22 GDPR.
16. Updates to the Privacy Policy
The Controller reserves the right to update this Privacy Policy in the event of changes in legislation, technical architecture of the platform, or expansion of services. The current version of the document is always published at /polityka-prywatnosci.
