This document awaits operator details and confirmation of the service and data processing arrangements. It is not the final version.
Operator and contact details
- Contact
- kontakt@ppwrlink.pl
1. The controller and processing roles
This policy covers the PPWR Link public website, user accounts and platform features. Privacy contact details appear in the operator section.
The operator is responsible for information used to run the service, manage accounts and respond to enquiries. Customer organisations decide which supplier, customer and other third-party information they enter. The operator’s role and processing instructions for that information must be defined in a data processing agreement.
2. Information handled by the platform
Information comes from people using forms and accounts, authorised organisation members, suppliers responding to document requests and connected systems.
- Enquiries: name, email, optional company name, topic and message.
- Accounts: identity information, email, password security information, language, memberships and permissions.
- Organisation workflows: business and contact details, documents, comments, operation history and information connected to packaging and material flows.
- Technical information: session and request identifiers, browser and connection information, IP addresses at the server layer and security-related events.
3. Purposes and legal bases
Enquiry information is used to respond and understand requirements. Requests about entering a contract in your own name rely on GDPR Article 6(1)(b). Business representative correspondence relies on the legitimate interest in business communication under Article 6(1)(f).
Contracts with individuals rely on Article 6(1)(b). Customer employee or representative contact and team access rely on Article 6(1)(f). Legal obligations rely on Article 6(1)(c). Security and legal claims serve the operator’s legitimate interests under Article 6(1)(f).
The form does not subscribe you to a newsletter. Providing information is voluntary, but required fields are needed to reply or provide an account.
4. Who may receive information
Organisation access depends on roles and permissions. Transfers to other systems may follow integration settings or an authorised user’s action. Infrastructure, email, technical support and AI providers may receive information needed to provide their services.
A public passport can be read by someone with its address or QR code. Review the disclosure scope before publishing. Information may be disclosed to competent authorities where required by law.
5. AI-assisted document analysis
At a user’s request, the platform reads document content and proposes packaging information. With the Google Gemini integration, text and packaging context are sent to an external API; reading a scan may require sending the file. Manually transcribed page information is also included.
Uploading a document alone does not start AI analysis. Results require review and approval. The feature does not independently make decisions about individuals with legal or similarly significant effects.
Remove unnecessary personal information before requesting analysis. The API provider handles submitted content under its service terms; retention and further use depend on the applicable terms and account configuration.
6. Processing outside the European Economic Area
External services may involve processing outside the EEA. The recipient, location and transfer mechanism must be established before that processing begins. The platform’s web address alone does not mean all information remains in Poland or the EU.
Contact the operator for information about applicable safeguards and how to obtain a copy. The detailed provider list and transfer bases must be completed before publishing the final policy.
7. Retention
The platform database copy of a contact enquiry is scheduled for deletion after 90 days. Email correspondence and backups are separate records and need their own retention arrangements.
Account and organisation information is needed during service use and subsequently to meet legal obligations or support justified legal claims. Documents and audit records may require continued retention. Removing user access does not automatically delete organisation history.
Specific retention periods for logs, backups and closed accounts must be aligned with the operator’s agreed retention policy.
8. Form protection — Google reCAPTCHA
Contact, registration, sign-in and password recovery forms use Google reCAPTCHA v3 to limit spam and automated abuse. The script loads when you interact with a protected form. The provider may analyse IP addresses, browser information, cookies and interaction signals to assess automation risk.
Before submission, the server verifies the result, domain and action. A negative result or an unavailable verification blocks that attempt; entered information remains available for correction or retry. This protects the service rather than delivering marketing messages. If the issue persists, use the email contact.
Google processes information under its privacy policy and service terms. Use of this tool may involve processing outside the EEA; the applicable entity, terms and transfer safeguards must be reflected in the operator’s final configuration and documentation.
9. Cookies and browser settings
The service uses essential cookies for sessions, sign-in and form security. Language is stored in the session and, for signed-in users, in their profile.
The website uses Cookiebot to display a cookie banner and remember your choices. The banner provides cookie information and the available consent categories. Adding the banner does not itself enable advertising or analytics tools.
You can delete or block cookies in your browser. Blocking essential cookies may prevent sign-in and form submission. Their retention depends on session behaviour and browser settings.
10. Your rights and contact
You can request access, correction, deletion or restriction. Portability and objection to processing based on legitimate interests apply where their conditions are met. Where consent is the basis, you may withdraw it for future processing.
Send requests to the contact address. Necessary identity confirmation may be requested. For information entrusted by a customer organisation, we will identify the appropriate controller. You may complain to the President of the Polish Personal Data Protection Office.
11. Policy changes
The update date and version appear at the top of this page. Changes to features, providers or processing must be reflected in the policy. Where additional notification or consent is required, publishing revised text alone does not replace it.