Privacy policy

Last updated: 2026-10-03

1. Introduction

PolMakers is a public catalog of Polish contract manufacturers (B2B). This policy explains who processes personal data, what we process, on what legal basis, and your rights.

2. Data controller

The controller within the meaning of the GDPR is bbdev Tomasz Biłka, Bielsko-Biała, Silesian Voivodeship, Poland, tax ID (NIP) 5472087086, email: bbdevpl@gmail.com.

3. What data we process

Visitors (no account): technical server logs (e.g. IP address, request time, URL, User-Agent); theme preference in local storage; storage of your consent choice; after consent - visit statistics via Umami (pages, referrer, device/browser parameters); email correspondence with us; when you submit the form: the data you provide (e.g. email address, company tax ID (NIP), message content) and — for 24 hours — cryptographic hashes (HMAC) of the IP address and email address, used to limit the number of attempts.

"Correct or remove company data" form (/zgloszenie-firmy): request type (correct or add data, hide selected details, or remove the profile from the catalogue), NIP and company name, optional profile link, your email address (for replies), message text (optional or required depending on request type), a short submission reference generated when you send, and a checkbox statement that you are authorised to submit on behalf of the company. With a ?nip= URL parameter we may read the published catalog profile name and link for that company solely to pre-fill the form (we do not store the submission in the database). Submissions are delivered to us by email via Resend; we do not create user accounts and we do not store form contents in the public catalog database.

Catalog company data (B2B publication): name, NIP, National Court Register (KRS) number, VAT whitelist status, city and region, industry, capability description, tags, quotes from manufacturer websites (evidence), website link, generic inboxes only (e.g. office@), map coordinates. JSON-LD: name, NIP, location, description.

We index companies listed in the National Court Register only (we do not include sole proprietorships outside KRS). We do not show full street address, REGON or management board in the UI. Personal data may appear in the catalog when a partnership name (e.g. open partnership) includes partners' names, or when a quote from a company website names a person.

Planned: RFQ forms and profile claims - we will update this policy before launch.

4. Where catalog data comes from

National Court Register (KRS), Polish VAT taxpayer whitelist and companies' public websites. We prepare descriptions using automated analysis of company websites (language model); they may contain errors - report them as described in section 10.

5. Purposes and legal bases

Operating the B2B catalog - GDPR Art. 6(1)(f); our legitimate interest is enabling businesses to find suppliers and make business contact. Handling company data request form submissions (verifying authority, replying, correcting data, hiding selected details, or withdrawing profile publication) and other correspondence - Art. 6(1)(f) (legitimate interest: fulfilling requests about catalog data and communicating with people who contact us). To submit the form you confirm authority on behalf of the company via the checkbox; text below the form names the controller and the purpose of processing form data (handling your request only, as described in this policy). Hosting logs and security - Art. 6(1)(f) (protecting the service from abuse). Protecting the form against abuse (attempt limits, Cloudflare Turnstile verification) — GDPR Art. 6(1)(f); our legitimate interest is service security and protection against spam. Visit analytics (Umami) - Art. 6(1)(a) (consent). Theme preference - storage necessary for the chosen feature; it is not personal data.

6. Recipients (processors)

Vercel Inc. (service hosting and logs), Supabase Inc. (catalog database), Hetzner Online GmbH (catalog data processing server, Germany), OpenAI (automated analysis of company website content), Cloudflare, Inc. (backups; form bot protection — Turnstile, receives IP address and browser parameters), OpenStreetMap (catalog map - receives the browser IP address), Resend, Inc. (sending form messages; processor stores data in the USA), Umami Software, Inc. (cloud visit analytics, only after consent). We have data processing agreements with these providers.

7. Transfers outside the EEA

Vercel, Supabase, OpenAI, Cloudflare, Resend and Umami Software, Inc. are based in the USA. Transfers rely on the EU-US Data Privacy Framework (European Commission decision) or Standard Contractual Clauses approved by the Commission.

8. Retention

Form safeguards (hashes of IP address and email address) — 24 hours. Form submissions — same retention as correspondence. Published profiles - until publication is withdrawn or an objection is upheld; backups - up to 90 days. Company data form submissions and other correspondence (including messages sent via Resend) - 3 years (limitation period for claims). Hosting logs - up to 1 hour (Vercel Hobby plan). Umami statistics - 180 days (after cloud Umami analytics is enabled).

9. Your rights

If your company appears in the catalog, you may object at any time to that publication (GDPR Art. 21). Email bbdevpl@gmail.com with the NIP or a link to the profile.

You have the right to access, rectify, erase, restrict processing, object, data portability (where applicable), and withdraw consent for analytics. Please contact us first - we will explain the situation and help where we can.

Send your request to bbdevpl@gmail.com with a brief description and your company NIP or profile URL.

10. Your company profile

To correct, add, hide selected details or remove a profile, use the form in the footer (/zgloszenie-firmy) — including the "Is this your company?" link on profile pages — or email bbdevpl@gmail.com with your NIP or company name. Before submitting, tick the authority statement; the form includes controller information and a link to this policy. We verify authority before changes. We respond without undue delay, within one month at the latest.

11. Security

We use encrypted transmission (HTTPS), server access only via cryptographic keys, and we limit public access to published profile data.

12. Cookies, local storage and analytics

Theme (localStorage) - functional, no profiling. Consent record (localStorage, key polmakers-consent-v1). Umami - opt-in only; measures traffic to improve the service; no behavioural ads. Umami does not use cookies.

Search terms are not sent to analytics.

Withdraw consent via "Analytics settings" in the footer or by clearing site data in your browser.

On pages with the form we load the Cloudflare Turnstile widget. It analyses browser parameters to distinguish humans from bots. It is necessary for form security and therefore does not require consent.

13. Changes

The current version is at /privacy. Material changes will update the date at the top.

14. Final provisions

Governing law: Poland. If translations differ, the Polish version prevails.

PolMakers