Nivor Trade Platform Privacy Policy
§1 Data Controller
The controller of personal data processed in connection with the use of the Nivor Trade platform is Adrian Podgórski NIVOR TRADE, registered office at ul. Marcina Szeligiewicza 2/9, 40-074 Katowice, Poland, Tax ID (NIP): 6492265019 (hereinafter: the "Controller"). For all matters relating to personal data protection, please contact: hallo@nivortrade.com.
§2 Scope and purposes of data processing
The Nivor Trade platform is intended exclusively for business (B2B) customers — we do not sell to consumers. We process the personal data of individuals representing our Customers (e.g. the registered contact person) for the following purposes:
- registering and maintaining a company account on the Platform, including verifying and approving the application,
- fulfilling Orders, including communication about delivery and billing,
- issuing accounting documents (invoices) and complying with tax obligations,
- handling inquiries and complaints sent to our contact address.
§3 Legal basis for processing
Personal data is processed on the basis of Article 6(1) of the General Data Protection Regulation (GDPR):
- point (b) — processing necessary for the performance of a contract (account registration, Order fulfillment),
- point (c) — processing necessary for compliance with a legal obligation (tax and accounting law),
- point (f) — the Controller's legitimate interest (e.g. handling inquiries, ensuring Platform security, pursuing claims).
§4 Recipients of data
In connection with operating the Platform, personal data may be shared with the following processors acting on behalf of the Controller:
| Entity | Role | Location |
|---|---|---|
| Vercel Inc. | Platform hosting and infrastructure | USA |
| Neon, Inc. | Database | USA |
| Google LLC (Gmail) | Transactional email delivery | USA |
| Fakturownia (InvoiceOcean sp. z o.o.) | Order documentation / accounting | Polska |
| PayU S.A. | Online payment processing | Polska |
The Controller has entered into, or is in the process of entering into, appropriate data processing agreements with each of the above entities, ensuring the level of data protection required by the GDPR.
§5 International data transfers
Some of our processors (hosting, database, email provider) are based in the United States. Transfers of personal data to these entities are based on Standard Contractual Clauses approved by the European Commission, or another GDPR-compliant mechanism ensuring an adequate level of data protection.
§6 Data retention period
Customer account data is retained for as long as the account remains active on the Platform, and for the period necessary to defend against claims after its closure. Data related to Order fulfillment (including data on accounting documents) is retained for the period required by tax and accounting law (typically 5 years from the end of the year in which the tax obligation arose).
§7 Rights of data subjects
Every individual whose data is processed has the right to:
- access their personal data,
- rectify (correct) their data,
- erase their data, to the extent this does not conflict with the Controller's legal obligations,
- restrict processing,
- data portability,
- object to processing based on the Controller's legitimate interest.
Every individual also has the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO) if they believe the processing of their data violates the GDPR.
§8 Cookies
The Platform uses cookies necessary for its proper operation — in particular, to remember the selected interface language and to maintain a logged-in Customer's session. These cookies are essential for providing the service and do not require separate consent. The Platform does not use third-party marketing or analytics cookies.
§9 Data security
The Controller applies technical and organizational measures designed to ensure the security of processed personal data, including encrypted connections (HTTPS/TLS), secure password storage (hashing), and access to data limited to authorized individuals only.
§10 Changes to this Privacy Policy
The Controller reserves the right to make changes to this Privacy Policy. The current version is always available on the Platform. Changes take effect from the date the new version is published.
