SBS Europe’s Privacy and Cookies Policy.
Version effective from: 18 July 2026
1. Data Controller and contact details
- The data controller is SBS EUROPE spółka z ograniczoną odpowiedzialnością, with its registered office in Bydgoszcz, ul. Toruńska 145B, 85-880 Bydgoszcz, KRS 0001064839, NIP 9532799451, REGON 526720721, hereinafter referred to as the “Controller” or “SBS Europe”.
- For matters relating to personal data, please contact us:
- by email: b2b@sbseurope.eu;
- by post: SBS Europe sp. z o.o., ul. Toruńska 145B, 85-880 Bydgoszcz, marked ‘Personal data’.
- This Policy applies to individuals using the SBS Europe website, contacting the Controller, representing business partners, submitting enquiries, participating in the fulfilment of orders, and using customer accounts once this functionality is launched.
- The website operates exclusively on a B2B basis; however, in connection with providing services to businesses, the Controller processes the data of natural persons, in particular sole traders, representatives, employees, associates, contact persons and recipients of consignments.
2. What data may we process
Depending on how the Website is used, the Controller may process:
- identification and business details, e.g. first name, surname, job title, company name, tax identification number (NIP), EU VAT number, REGON or other registration number;
- contact details, e.g. business email address, telephone number, postal address, delivery address and details of the person collecting the parcel;
- data relating to enquiries, pro forma invoices, orders, products, payments, invoices, deliveries, complaints and correspondence;
- billing details or information on payment status, although the Controller should not receive any authentication details for the user’s bank or Revolut account;
- customer account details, activity history and order history – once this functionality has been activated;
- technical data, e.g. IP address, device and browser identifiers, operating system type, approximate location derived from the IP address, date and time of visit, pages visited, referral source, server logs and error information;
- identifiers and information collected via cookies and similar technologies — currently limited to those that are technically necessary (point 10); following the potential implementation of optional tools — in accordance with the user’s selection in the consent panel;
- other data provided voluntarily in correspondence, forms or complaints, where necessary to handle the matter.
Please do not provide any unnecessary data, special category data or personal data unless it is necessary to handle a specific matter.
3. Purposes, legal bases and processing periods
3.1. Enquiries, preparation of pro forma invoices and conclusion of the Contract
- Data is processed for the purposes of receiving an enquiry, checking availability, preparing a pro forma invoice, negotiating terms and concluding the Contract.
- The legal basis is:
- Article 6(1)(b) of the GDPR – where the data subject is a party to the Contract or is taking steps prior to entering into it;
- Article 6(1)(f) of the GDPR – where the individual acts as a representative, employee or contact person of a business partner; the legitimate interest is to maintain business relationships and conclude B2B contracts.
- The data is retained for the duration of the negotiations and subsequently for the period necessary to demonstrate the course of those negotiations and to defend against claims. If no contract is concluded, the data will, as a rule, be erased or restricted once the purpose has ceased to apply and the relevant limitation period has expired.
3.2. Contract performance, payments, dispatch and customer service
- Data is processed for the purposes of sales, accepting payments, order fulfilment, dispatch, communication, after-sales service, and the establishment and pursuit of claims.
- The legal basis is Article 6(1)(b) of the GDPR or Article 6(1)(f) of the GDPR. The legitimate interest is the proper performance of the Contract concluded with the entity represented by the individual concerned, ensuring operational contact and protecting the Controller’s rights.
- The data is retained for the duration of the Contract and thereafter until the expiry of the limitation periods for claims or the resolution of any dispute.
3.3. Tax, accounting and legal obligations
- Data contained in invoices, accounting documents, intra-Community supply of goods documentation and other documents required by law are processed for the purpose of fulfilling tax, accounting, customs and archiving obligations.
- The legal basis is Article 6(1)(c) of the GDPR.
- Data is retained for the period specified by the relevant regulations, generally for 5 years from the end of the year in which the relevant tax deadline expired, and for longer if required by ongoing proceedings or a specific provision.
3.4. Contact, forms and correspondence
- Data is processed for the purpose of providing responses, conducting correspondence and documenting arrangements.
- The legal basis is Article 6(1)(f) of the GDPR; the legitimate interest is communication with users and business partners. If the contact is directly aimed at concluding a contract with a natural person carrying out a business activity, the legal basis may also be Article 6(1)(b) of the GDPR.
- Data is retained until the matter is resolved, and thereafter for the period necessary to demonstrate the course of correspondence and to defend against claims.
3.5. Complaints, individually agreed returns and claims
- Data is processed for the purpose of receiving and handling complaints, verifying damage, cooperating with the manufacturer or carrier, and establishing, pursuing or defending claims.
- The legal basis is Article 6(1)(b), (c) or (f) of the GDPR, depending on the nature of the case. The legitimate interest is the processing of complaints and the protection of the Controller’s rights.
- The data is retained until the matter is resolved, and thereafter until the expiry of the relevant limitation period for claims or the mandatory retention period.
3.6. Customer account – planned functionality
- Once customer accounts are launched, data will be processed for the purposes of creating, securing and managing the account, storing company details, enquiry and order history, and providing account-related functions.
- The legal basis will be Article 6(1)(b) of the GDPR – performance of the contract for the provision of the account service – and Article 6(1)(f) of the GDPR in relation to security, preventing fraud and pursuing claims.
- The data will be stored until the account is deleted or the service is terminated, and thereafter, to a limited extent, until the expiry of the limitation periods or for the period required by law.
3.7. Security, logs and fraud prevention
- Technical data and logs are processed to ensure the security of the Website, diagnose errors, detect abuse, protect accounts and infrastructure, and compile technical statistics.
- The legal basis is Article 6(1)(f) of the GDPR; the legitimate interest is to ensure the secure and proper functioning of the Website.
- Logs are retained for a period justified by security and diagnostic needs, generally for no longer than 12 months, unless an incident requires them to be retained for a longer period.
3.8. Analytics and development of the Website
- With the user’s consent, the Controller may use analytics tools, including Google Analytics, to measure traffic, sources of visits, user behaviour, conversions and the quality of the Website.
- The basis for storing or reading information on a device and for processing personal data for this purpose is the user’s consent – Article 6(1)(a) of the GDPR and the relevant provisions of the Electronic Communications Act.
- Data is processed until consent is withdrawn or for the period specified in the settings of the relevant tool as indicated in the cookies panel, whichever occurs first, taking into account aggregated data which no longer constitutes personal data.
3.9. Advertising, remarketing and campaign measurement
- With the user’s consent, the Controller may use Google Ads, Meta Pixel, TikTok Pixel or similar tools to measure campaign effectiveness, create audience groups, carry out remarketing and tailor adverts.
- The legal basis is the user’s consent – Article 6(1)(a) of the GDPR and the relevant provisions of the Electronic Communications Act.
- Data is processed until consent is withdrawn or for the period specified for the relevant tool in the cookies panel. The user may change their settings at any time.
3.10. Direct marketing
- The controller may process contact details for the purpose of presenting its own B2B offer on the basis of Article 6(1)(f) of the GDPR, provided that such contact is in line with the reasonable expectations of the recipient.
- The use of email, telephone or other end devices to send commercial information or for direct marketing purposes shall take place only after the required consent has been obtained or where another explicit legal basis exists.
- The recipient may withdraw their consent or object to direct marketing at any time. Once an objection has been raised, the data will no longer be used for this purpose.
4. Where the data comes from
- We obtain data primarily directly from the data subject or from the entity they represent.
- Data may also be obtained:
- from an employer, client or business partner who designates a contact person, a recipient of a delivery or a person responsible for the performance of the Contract;
- from public registers of businesses and taxpayers, such as the National Court Register (KRS), the Central Registration and Information on Business Activity (CEIDG), the VAT register and the VIES system;
- from banks, Revolut, carriers, logistics operators and other entities involved in the processing of payments or deliveries;
- from providers of analytical and advertising tools – provided the user has given their consent.
- If we have received data from a business partner, we may process, in particular, the first name, surname, job title, business contact details, scope of authorisation and data relating to the matter being handled or the delivery.
5. Recipients of the data
Data may only be disclosed to the extent necessary:
- to providers of hosting, cloud infrastructure, email, website maintenance, cybersecurity and IT support;
- the provider of the IDEA ERP system (ideaerp.pl) or any other system used by SBS Europe to manage its product range, business partners, warehouse, documents and orders;
- banks, Revolut and entities involved in payment processing;
- courier companies, carriers, logistics operators, freight forwarders and transport insurers;
- accountancy firms, auditors, tax advisers, law firms, debt collection agencies and insurers;
- manufacturers, distributors or service providers, where necessary to handle complaints;
- providers of account management, communication, CRM or automation tools, where these are implemented;
- Google, Meta Platforms and TikTok, and their affiliated entities – solely in relation to tools activated after the required consent has been obtained;
- public authorities and other authorised entities, where the obligation to disclose arises from the law.
Data processors acting on behalf of the Controller operate on the basis of contracts and may use the data only in accordance with the Controller’s instructions, unless they act as separate controllers on the basis of their own legal obligations.
6. Transfer of data outside the European Economic Area
- External hosting, the ERP system and basic sales support should be configured so that data is processed within the European Economic Area, where possible.
- The use of services provided by Google, Meta, TikTok, Revolut or certain cloud providers may involve the transfer of data outside the EEA, in particular to the United States.
- In such cases, the transfer takes place on the basis of a legally permissible mechanism, e.g. a European Commission decision confirming an adequate level of protection, the recipient’s certification under the EU–US Data Privacy Framework, or the European Commission’s Standard Contractual Clauses, together with additional safeguards where necessary.
- Information on the transfer mechanism used can be obtained by contacting the Controller.
7. Rights of data subjects
In accordance with the provisions of the GDPR, a data subject may have the right to:
- access their data and obtain a copy thereof;
- rectify their data;
- erasure of their data;
- restrict processing;
- data portability, where processing is based on consent or a contract and is carried out by automated means;
- object to processing based on a legitimate interest, on grounds relating to their particular situation;
- to object at any time to direct marketing;
- to withdraw consent at any time, without affecting the lawfulness of any processing carried out prior to such withdrawal;
- to lodge a complaint with the President of the Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, https://uodo.gov.pl.
Requests may be sent to b2b@sbseurope.eu. For data protection purposes, the Controller may ask for information to verify the applicant’s identity and their connection to the data.
8. Voluntary provision of data
- The provision of data is, in principle, voluntary, but may be necessary to receive a reply, prepare a pro forma invoice, conclude and perform the Contract, make a delivery, issue an invoice or handle a complaint.
- Failure to provide the data required in the form or by law may prevent the fulfilment of the relevant purpose.
- Consent to analytical and marketing cookies is voluntary. Refusal to give consent shall not block access to the basic functions of the Website, although some additional functions may operate to a limited extent.
9. Automated decision-making and profiling
- Data from analytics and advertising tools may be used to create audience segments and tailor adverts, which may constitute profiling.
- The Controller does not make decisions on this basis that produce legal effects concerning the user or similarly significantly affect them.
- The assessment of a contractor’s creditworthiness and the granting of deferred payment may take into account financial information and the history of cooperation, but the final decision should be made or approved by a human.
10. Cookies and similar technologies
10.1. What are cookies?
Cookies are small pieces of information stored on the user’s device. The Website may also use similar technologies, such as browser local storage, tags, pixels and web identifiers.
10.2. Categories
- Essential – these enable the Website to function, ensure security, remember your shopping basket or enquiries, maintain your session, preserve your privacy settings and – once activated – allow you to log in. These are used without separate consent, as they are necessary to provide the service requested by the user or to ensure transmission.
- Functional – these remember additional preferences and make the Website easier to use. If they are not essential, they are activated following consent.
- Analytical – these help measure traffic, sources of visits and how the Website is used, e.g. via Google Analytics. They are activated only upon consent.
- Marketing – these are used for campaign measurement, remarketing and ad targeting, e.g. via Google Ads, Meta Pixel or TikTok Pixel. They are activated only upon consent.
10.3. Current status and consent management
- Currently, the Website uses only technically necessary cookies and the browser’s local storage to the extent described in section 10.4. The Website does not use analytical, marketing or functional cookies requiring consent — therefore, it does not display a consent panel; the message visible on the first visit is for information purposes only.
- Prior to the potential implementation of any analytical or marketing tools, the Controller will implement a consent panel which will allow users to:
- accept all optional cookies;
- reject all optional cookies just as easily as accepting them;
- make separate selections for individual categories;
- read information about specific providers, purposes and retention periods; along with a permanently available ‘Cookie Settings’ link in the footer of the Website, enabling users to change or withdraw their consent just as easily as they granted it.
- A lack of action on the part of the user, scrolling down the page or pre-ticked boxes shall not constitute consent.
- Optional analytics and marketing scripts will not be activated until the appropriate consent has been obtained.
- You may also delete or block cookies in your browser settings. However, this may affect the functioning of features that rely on essential cookies.
10.4. List of technologies currently in use
The website stores only the following on the user’s device:
- session cookie
session— to maintain the user’s session: shopping basket contents/enquiries, login to the dashboard and form security (CSRF, captcha); valid for a maximum of 14 days; - browser local storage (localStorage):
cookieNoteOk— to remember that the cookie notice has been closed, andcat_view— catalogue view preference (list/tiles).
None of these technologies are used for analytics, advertising or user tracking. The tools listed in sections 3.8, 3.9 and 10.2 may be implemented in the future; their mere inclusion in this Policy does not mean that they are currently active — the consent panel described in section 10.3 will be implemented before they are activated.
11. External websites and social media
- The website may contain links to WhatsApp, social media platforms, payment providers or other external websites.
- Once you have navigated to an external service, its operator processes data as a separate data controller in accordance with its own privacy policy.
- Simply displaying a link should not result in data being transferred to the external operator before the link is clicked, unless the user has given the required consent for the embedded feature.
12. Data security
The controller implements technical and organisational measures appropriate to the risk, in particular access control, transmission encryption, backups, updates, event logging, restriction of access rights and contracts with data processors. However, no system can guarantee the complete elimination of risk; therefore, users should protect their devices and access credentials.
13. Changes to the Policy
- The Policy may be updated in response to changes in legislation, functionality, suppliers, the ERP system, customer accounts, or analytical and advertising tools.
- The current version will be published on the Website together with its effective date. If a change significantly affects the manner of processing, the Controller will issue an appropriate additional notice.
- A change to the Policy does not constitute grounds for using data for a new purpose requiring consent without first obtaining that consent.
