Privacy Policy
Last updated: 2026-06-22
This Privacy Policy explains how OLPO Sp. z o.o. processes personal data when you use the OLPO Customer Portal, in accordance with the GDPR and applicable Polish data protection law.
1. Data controller
The controller of personal data processed through the Portal is OLPO Sp. z o.o., Poland ("OLPO", "we"). For data protection enquiries, contact your OLPO sales manager or the address published on olpo.pl.
2. Categories of data we process
We process: account data (name, email, role, language preference); company data (company name, VAT, billing and delivery addresses, contact persons); usage and audit data (sign-in events, approvals, uploads, status changes); communication data (emails sent via the Portal, reminder preferences); and technical data (IP address, browser type, session cookies required for authentication).
3. Purposes and legal bases
We process data to provide and secure the Portal, manage quotes and orders, send transactional and reminder emails, comply with legal obligations, and improve our services.
Legal bases include: performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR); legitimate interests such as security and fraud prevention (Art. 6(1)(f)); consent where required, e.g. optional marketing (Art. 6(1)(a)); and legal obligation (Art. 6(1)(c)).
4. Recipients and transfers
Data may be shared with authorised OLPO staff, subprocessors providing hosting (Supabase), email delivery (Resend or equivalent), and PDF generation — under data processing agreements where required.
Data is primarily stored in the EU/EEA. If a transfer outside the EEA occurs, we implement appropriate safeguards (e.g. Standard Contractual Clauses).
5. Retention
Account and order-related data is retained for the duration of the business relationship and thereafter as required for accounting, tax, and legal claims (typically up to 5–10 years depending on document type).
Audit logs and security records may be kept for a shorter period aligned with security needs. Invitation tokens and expired sessions are deleted or anonymised when no longer needed.
6. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict processing, data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting prior lawful processing.
You may lodge a complaint with the Polish supervisory authority (UODO). We will respond to rights requests within one month.
7. Cookies and security
The Portal uses strictly necessary cookies for authentication and session management. We do not use third-party advertising cookies.
We apply access controls, encryption in transit, row-level security in the database, and role-based permissions to protect your data.
8. Changes to this policy
We may update this Privacy Policy when our processing activities or legal requirements change. The "Last updated" date at the top indicates the current version.
Material changes affecting existing customers will be communicated via the Portal or email where appropriate.