Privacy Policy
KEY FOODS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Website: keyfoods.pl | Version: 5 August 2026 | KRS: 0001042859
This Privacy Policy explains what personal data KEY FOODS processes, for what purposes, on what legal bases, to whom such data may be disclosed, and what rights data subjects have. It covers the use of the Website, contacts and orders, B2B relationships, logistics, recruitment and marketing.
1. Purpose and Scope of the Privacy Policy
This Privacy Policy, hereinafter referred to as the "Policy", describes the rules governing the processing of personal data by KEY FOODS spółka z ograniczoną odpowiedzialnością in connection with operating the website available at https://keyfoods.pl, handling inquiries and orders, conducting business communications and carrying out activities including, in particular, domestic, intra-EU and international trade in sugar and other food products, as well as organising related deliveries.
The Policy applies to persons visiting the Website, using forms, submitting inquiries or orders, customers and potential customers who are natural persons, as well as employees, associates, members of corporate bodies, attorneys-in-fact, representatives, contact persons and beneficial owners of customers, suppliers, carriers, freight forwarders, warehouse operators, intermediaries, service providers and other business partners. It also applies to candidates for employment or cooperation and persons contacting the Controller in any other manner.
Information relating to a legal person or other organisational entity does not constitute personal data unless it relates to an identified or identifiable natural person. An employee's or contractor's first and last name, business email address, business telephone number, position, function and signature constitute personal data.
The Policy shall be applied together with the Terms and Conditions for the Provision of Services by Electronic Means, the terms and conditions for placing and fulfilling orders, the Cookie Policy and additional information clauses. The Policy does not specify the commercial or civil-law terms governing the acceptance or fulfilment of an order. Detailed rules concerning the use of cookies and similar technologies are set out in a separate Cookie Policy available on the Website.
The terms "GDPR" and "ECA" used in this Policy mean, respectively, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 and the Polish Act of 12 July 2024 – Electronic Communications Law. "Website" means the keyfoods.pl website together with its subpages and forms.
2. Controller and Data Protection Officer
The controller of personal data is KEY FOODS spółka z ograniczoną odpowiedzialnością, with its registered office in Warsaw at ul. Jana Kasprowicza 119A lok. 151, 01-949 Warsaw, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 12th Commercial Division of the National Court Register, under KRS number 0001042859, NIP 1182264158, REGON 525626820, with share capital of PLN 10,000.00, hereinafter referred to as the "Controller" or "KEY FOODS".
The Controller has appointed a Data Protection Officer. This function is performed by Łukasz Kiernicki. The Data Protection Officer may be contacted by email at iodo@keyfoods.pl or by post at the Controller's registered office, marked "Data Protection Officer".
The Data Protection Officer is the point of contact for matters concerning the processing of personal data and the exercise of rights under the GDPR. Contacting the Data Protection Officer does not limit the possibility of contacting the Controller directly or the right to lodge a complaint with a supervisory authority. The Controller is responsible for ensuring that processing complies with applicable law.
3. Data Processing Principles
The Controller processes data lawfully, fairly and transparently. Data are collected for specific and legitimate purposes, limited to what is necessary for those purposes, kept accurate and up to date, stored for no longer than necessary, and secured in a manner appropriate to the risk.
Special categories of personal data referred to in Article 9 of the GDPR, data concerning criminal convictions and offences, or copies of identity documents should not be provided in ordinary correspondence, forms or free-text fields unless the Controller expressly requests them and specifies the purpose and appropriate legal basis. The Controller does not collect data "in advance" and applies the principle of data minimisation.
4. Sources and Categories of Data
The Controller receives data directly from the data subject, in particular through the Website, forms, email, telephone, meetings, industry events, commercial and recruitment documents. Data may also be provided by an employer, principal, contractor, customer, supplier, carrier, freight forwarder, warehouse operator, intermediary, bank, insurer or another person involved in preparing or carrying out a transaction.
Data may originate from public registers and lists, including the National Court Register (KRS), Central Register and Information on Business Activity (CEIDG), Central Register of Beneficial Owners (CRBR), VAT taxpayer register, VIES, EORI registers, foreign business registers and sanctions lists, as well as company websites, public professional profiles, lawful industry databases, business information agencies, business information bureaus and persons referring the contact.
| Category | Example scope | Typical source |
|---|---|---|
| Identification and professional data | First name, last name, position, function, employer or represented entity, signature, scope of authority. | Person, contractor, public register, authorisation document. |
| Contact details | Business or private email, telephone number, correspondence address, communication language and contact history. | Form, correspondence, meeting, business card, contractor. |
| Registration and verification data | Company, address, KRS, NIP, REGON, EU VAT number, EORI, representatives' and beneficial owners' data, sanctions status. | Public registers and lists, contractor, business information agency. |
| Inquiries, orders and contracts | Content of inquiry, product, origin, quantity, packaging, price, Incoterms, deadlines, delivery location, complaints and attachments. | Person, customer, supplier, commercial documents. |
| Logistics, quality and customs data | Data of persons involved in loading, transportation and receipt, vehicle registration numbers, routes, CMRs, warehouse, customs and quality documents. | Supply-chain participants, operational documentation. |
| Financial and settlement data | Bank account, payer and payee details, invoices, payment status, trade credit limit, debts and settlement history. | Contractor, bank, accounting department, settlement operator. |
| Communications | Content of emails, reports, complaints, calls, chats and meetings, as well as materials and notes provided. | Person, communication tool, meeting participants. |
| Technical data | IP address, date and time, requested resource, referrer, identifiers, device and browser type, logs and error information. | Device, server and security systems. |
| Recruitment data | CV, experience, education, qualifications, availability, references and recruitment correspondence. | Candidate, recruitment portal, referring person. |
| Consents and preferences | Content, scope and date of granting or withdrawing consent, objection and selected communication channel. | Consent form and correspondence. |
If data have not been obtained directly from the data subject, the Controller fulfils its information obligation in accordance with the rules and deadlines specified in Article 14 of the GDPR, in particular upon first contact, upon first disclosure of the data, or no later than one month after obtaining them, unless an exception specified in Article 14(5) of the GDPR applies.
5. Purposes and Legal Bases for Processing
The legal basis depends on the nature of the relationship and the specific process. Article 6(1)(b) of the GDPR applies where a natural person is a party to a contract or requests steps to be taken prior to entering into a contract. Data of an employee, associate, member of a corporate body or attorney-in-fact of a contractor are generally processed under Article 6(1)(f) of the GDPR because the contract is concluded with the represented entity, and the legitimate interest is to conduct communications and conclude, perform and document B2B cooperation.
| Process | Purpose | Legal basis |
|---|---|---|
| Website and logs | Providing content, maintaining operation, diagnostics, security and preventing abuse. | Article 6(1)(f) GDPR. |
| Inquiries and offers | Handling contact, determining needs, preparing offers, negotiations and documenting arrangements. | Article 6(1)(b) or (f) GDPR. |
| Orders and contracts | Accepting and confirming orders, sales, delivery, payment, complaints and after-sales service. | Article 6(1)(b), (c) or (f) GDPR – depending on the person's role and the applicable obligation. |
| Logistics and quality | Transportation, freight forwarding, warehousing, customs clearance, quality control, batch traceability and product recalls. | Article 6(1)(b), (c) or (f) GDPR. |
| Contractor verification | Verification of authority, registers, bank account, reliability, fraud risk, sanctions and credit risk. | Article 6(1)(c) or (f) GDPR. |
| Accounting and taxes | Invoicing, accounting records, taxes, customs duties, reporting, audits and operation of systems required by law. | Article 6(1)(c) GDPR; additionally Article 6(1)(f) GDPR. |
| Claims and compliance | Establishing, pursuing or defending claims, proceedings, inspections, audits and accountability. | Article 6(1)(c) or (f) GDPR. |
| B2B contacts | Establishing and maintaining relationships, identifying persons responsible for sales, purchasing, logistics, quality and settlements. | Article 6(1)(f) GDPR. |
| Marketing | Sending requested commercial information through the selected channel; traditional marketing and direct business contact. | Article 6(1)(a) GDPR and Article 398 ECA; for marketing not involving electronic communications – Article 6(1)(f) GDPR. |
| Recruitment | Assessing candidates, contact, employment or cooperation, future recruitment and defence against claims. | Article 6(1)(a), (b), (c) or (f) GDPR; Article 9(2) GDPR where applicable. |
In certain processes, several legal bases may apply simultaneously to different elements of an operation. Acknowledgement of having read the Policy does not constitute consent to the processing of data necessary to handle an inquiry, order or contract. Consent to electronic marketing is obtained separately and voluntarily.
6. Use of the Website and Technical Logs
When using the Website, the server and security mechanisms may automatically record the IP address, date and time of the request, requested resource address, response code, referring page address, browser type and version, operating system, device type, session identifier, error information and security-related events.
This data is processed to display the Website, maintain its availability, manage traffic, diagnose errors, protect forms and systems, prevent automated attacks, fraud and other abuse, and investigate incidents. The Controller's legitimate interest is to operate a secure and efficient Website and protect information and infrastructure.
Technical logs are generally retained for no longer than 12 months. Data related to an incident, attempted abuse or claim may be retained longer, until the matter has been resolved or the applicable limitation period has expired.
7. Contact, Forms, Orders and Contracts
Data provided through a form, email, telephone or during a meeting are processed to identify the sender, receive and handle the matter, provide a response, determine business needs, prepare an offer, conduct negotiations and retain a history of arrangements. Inquiries that did not result in a contract are generally retained for up to 24 months from the last material contact, unless they cease to be useful earlier or have evidentiary significance.
An order form may be used to submit a request for quotation, provide data necessary to prepare an offer or place an order. The civil-law effect of submitting a form follows from its content, the applicable terms and conditions and subsequent arrangements. The Policy itself does not determine whether submission of the form constitutes an order, an invitation to submit an offer or a request for contact.
The scope of data may include the customer's details and those of the person placing the order, information concerning authority, invoicing and delivery details, product specification, quantity, packaging, price, deadline, delivery terms, logistics notes, history of arrangements, delivery documents and payment status. Required fields are indicated in the form. Failure to complete them may prevent preparation of an offer, verification of the contractor, acceptance of an order or performance of the contract.
The Controller's forms are not intended to collect complete payment-card details, in particular the card number, expiry date or security code. In the case of online payment, payment data will be processed by the designated payment operator in accordance with the information provided during the payment process.
Telephone conversations are not recorded unless, before recording begins, the caller is informed about the recording, its purpose, legal basis, retention period and applicable rights. During online meetings, the participant's first and last name, account name, business contact details, image or voice shared by the participant, chat content and materials provided may be processed. Recording a meeting requires separate prior information and an appropriate legal basis.
8. Performance of Contracts, Logistics, Quality and International Trade
The Controller processes data necessary to negotiate, conclude and perform contracts for the sale, delivery, transportation, freight forwarding, warehousing, brokerage, insurance, financing, quality control and other contracts related to trading in sugar and food products.
Processing includes, in particular, agreeing availability, price and commercial terms, organising deliveries, notifying loading and unloading, contacting the driver, dispatcher, warehouse and recipient, issuing commercial, transport, warehouse, quality, customs and settlement documents, confirming receipt, controlling the origin and traceability of batches, handling payments, complaints, transport damage and product recalls.
Data of persons involved in a delivery may be exchanged between the Controller, customer, supplier, manufacturer, carrier, freight forwarder, warehouse or terminal operator, customs agent, laboratory, quality-control body, certification body and insurer. The scope of the disclosure is limited to data necessary at the relevant stage of the supply chain.
The legal basis for processing is Article 6(1)(b) GDPR with respect to a natural person who is a party to a contract, Article 6(1)(f) GDPR with respect to persons acting on behalf of business entities, and Article 6(1)(c) GDPR where processing results from tax, customs, accounting, food-safety, transport, sanctions or other regulations applicable to the transaction.
A contractor providing the Controller with data of a driver, warehouse worker, recipient, person responsible for quality or another person involved in the transaction should enable that person to familiarise themselves with the Policy. This does not exclude the Controller's information obligations under the GDPR.
9. Verification of Contractors, Authority, Reliability and Sanctions
Before establishing cooperation and during its course, the Controller may verify the contractor's registration and tax data, method of representation and powers of attorney, beneficial owners, VAT and EU VAT status, EORI number, payment accounts, payment history, business reliability and the presence of the contractor, its representatives or beneficial owners on relevant sanctions lists.
The verification is intended to ensure legal compliance, prevent fraud, assess the risk of non-performance or non-payment, protect the Controller's assets and those of other participants in trade, and confirm that the transaction can be legally and safely performed. The legal basis is Article 6(1)(c) GDPR where the obligation arises from law, and Article 6(1)(f) GDPR in other cases.
The results of verification may lead to a request for additional documents or explanations, a change in payment terms, refusal to grant a trade credit limit or withdrawal from the transaction. Such decisions are not made solely by automated means without the possibility of human involvement.
10. Business Contacts and Marketing
The Controller processes business contact details of persons acting on behalf of existing and potential customers, suppliers and other partners in order to establish and maintain contact, identify persons responsible for purchasing, sales, logistics, quality or settlements, present the Controller's activities and develop B2B relationships. The legal basis is Article 6(1)(f) GDPR, and the legitimate interest is conducting and developing business activities and ensuring efficient industry communication.
Sending commercial information, including direct marketing, by email, telephone, messenger or another telecommunications end device takes place after obtaining the prior consent required by Article 398 ECA. Where the Controller also obtains consent as the legal basis for processing personal data, Article 6(1)(a) GDPR applies. Marketing by traditional mail or during a meeting, without the use of a telecommunications end device, is based on Article 6(1)(f) GDPR, while respecting the right to object.
Marketing consent is voluntary, specific and assigned to the selected channel. It may be withdrawn at any time without affecting the lawfulness of actions taken before its withdrawal, in particular by using an unsubscribe link or contacting the Data Protection Officer. Opting out of marketing does not affect messages necessary for fulfilling an order, settling accounts or handling a request.
A person has an unconditional right to object to the processing of data for direct marketing purposes. Following an objection, the data are no longer used for this purpose. The Controller may retain a minimal record of withdrawal of consent or objection for the purpose of demonstrating compliance and preventing unwanted communications from being sent again.
11. Recruitment and Establishing Cooperation
In employee recruitment, the Controller processes data that it may request pursuant to Article 22¹ of the Labour Code, on the basis of Article 6(1)(c) GDPR. In recruitment for civil-law cooperation, the legal basis for processing data necessary to assess the candidate and agree the terms is Article 6(1)(b) GDPR.
Additional data not required by law or by the Controller are processed on the basis of voluntary consent, provided that they remain adequate for the recruitment purpose. Special categories of personal data may be processed only where the conditions of Article 9 GDPR and the relevant employment-law provisions are met. A candidate should not provide a photograph, health information, family information, information about origin, views or other information unrelated to the requirements of the position unless there is a clear need and legal basis for doing so.
Data are processed until the recruitment process is completed and, thereafter, generally for 3 months for the purpose of documenting the process. A limited scope of data necessary to establish, pursue or defend claims may be retained until the applicable limitation period expires, but no longer than 3 years, where this is justified and proportionate in the specific case.
Data for future recruitment purposes are processed solely on the basis of separate consent, for the period specified in the consent, but no longer than 12 months. Withdrawal of consent does not affect participation in the recruitment process for which the data were originally provided.
12. Social Media, External Content and Links
The Controller maintains profiles on social media services and processes data of persons following the profile, reacting to publications or contacting the Controller through the platform for the purposes of operating the profile, communication, presenting activities and analysing statistics. The legal basis on the Controller's side is Article 6(1)(f) GDPR, and in the case of voluntarily requested marketing communications – Article 6(1)(a) GDPR, where consent is required.
The platform operator may process data as a separate controller, and joint controllership may arise to a certain extent, in particular in connection with creating statistics concerning the profile. Detailed rules are set out in the privacy policy of the relevant operator.
Merely placing a link to an external website does not result in the transfer of data to its operator. Embedded videos, maps, social-media plugins and other external content may result in the transfer of data once activated and are therefore blocked until the required consent is obtained where storage of or access to information on the device or further processing requires consent.
13. Data Recipients
Data may be entrusted to providers of hosting, email, servers, backups, cybersecurity, form handling, office tools, CRM or ERP systems, order systems, archiving, IT support, accounting, auditing, legal and tax advisory services, debt collection, communications, online meetings and marketing. Providers processing data on behalf of the Controller act on the basis of an agreement and documented instructions.
Data may be disclosed to separate controllers where this is necessary to prepare or perform a transaction. Such recipients may include customers, suppliers, manufacturers, sugar mills, refineries, commercial intermediaries, warehouses, terminals, carriers, freight forwarders, couriers, customs agents, laboratories, quality-control and certification bodies, insurers, brokers, banks, payment operators, trade receivables insurers, business information agencies and postal operators.
Data may be transferred to entities affiliated with the Controller by capital or organisational ties only where they actually participate in the relevant process, an appropriate legal basis exists and the scope of data is necessary. Merely designating an entity as a "partner" does not constitute a basis for disclosure. The Controller does not sell personal data.
Data may be transferred to tax and customs authorities, inspection bodies, courts, prosecutors, the Police, bailiffs, supervisory authorities and other authorised institutions where the obligation or right to transfer the data arises from law or from a properly submitted request.
14. Transfers of Data Outside the European Economic Area
Due to the international nature of its business, business data of contact persons and data contained in commercial, transport, customs, quality and settlement documentation may be transferred to recipients outside the European Economic Area where this is necessary to prepare, conclude or perform a specific transaction. IT, cloud or communications service providers may also process data outside the EEA or enable access to data from a third country.
Transfers are carried out in accordance with Chapter V GDPR. If the European Commission has issued an adequacy decision concerning a country, territory, sector or category of recipients, data may be transferred pursuant to Article 45 GDPR to the extent covered by that decision.
With respect to the United States, a transfer may be based on Commission Implementing Decision (EU) 2023/1795 concerning the EU-U.S. Data Privacy Framework, provided that the recipient holds active certification covering the relevant type of data. The recipient's status is verified in the official list of certified organisations.
If the recipient is not covered by an applicable adequacy decision, the Controller may use standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 or another instrument under Article 46 GDPR. Where required, the Controller assesses the law and practice of the recipient country and applies supplementary measures such as encryption, pseudonymisation, limitation of the scope of data or additional organisational commitments.
The derogations under Article 49 GDPR are applied only in exceptional and occasional situations, after the conditions of the relevant derogation have been satisfied, and are not used as a basis for regular, repeated transfers to a permanent service provider. Information about the transfer mechanism used and the possibility of obtaining a copy of the safeguards may be obtained from the Data Protection Officer. A copy may be limited to the extent necessary to protect trade secrets and the rights of other persons.
15. Data Retention Periods
The Controller retains data no longer than necessary for the purpose for which they were collected, taking into account legal obligations, applicable limitation periods, the risk of claims, the principle of accountability and the need to ensure security. Retention periods may overlap; in such a case, the longest justified period applies.
| Process | Retention period or principle |
|---|---|
| Inquiries without a contract | Up to 24 months from the last material contact, unless the data cease to be useful earlier or are needed for longer as evidence of a claim. |
| Orders and contracts | For the period of preparation and performance of the contract, and thereafter until the applicable limitation period for claims expires. For business claims, this is often up to 3 years, although specific provisions may provide for a different period. |
| Accounting, taxes and customs | For the period required by the applicable regulations, generally 5 years calculated in accordance with the rules applicable to the relevant type of documentation; longer in the event of an inspection or proceedings. |
| Logistics, quality and traceability | For the period required by regulations concerning food, transport, customs and product documentation, and thereafter to the extent necessary for complaints and claims. |
| B2B contacts | For the duration of the relationship and while the data remain current, generally no longer than 3 years from the last material contact, unless the data are necessary for a contract, legal obligation or claims. |
| Marketing | Until consent is withdrawn or an objection is made. A minimal record of consent, its withdrawal or objection may be retained for the period necessary for accountability and defence against claims. |
| Technical logs | Generally up to 12 months; longer if they relate to an incident, abuse or claim. |
| Recruitment | Until the recruitment process is completed and generally 3 months after its completion; necessary evidentiary data for up to 3 years where justified; future recruitment for up to 12 months based on separate consent. |
| Exercise of GDPR rights | For the duration of handling the request and, thereafter, for up to 3 years to a limited extent for the purpose of demonstrating proper handling and defending claims. |
Data contained in backup copies are deleted in accordance with the backup rotation cycle. Until deletion, they remain isolated from active use unless restoration is necessary for security, business continuity or a legal obligation.
16. Rights of Data Subjects
| Right | Scope |
|---|---|
| Access | The right to obtain information about processing, access personal data and receive a copy thereof. |
| Rectification | The right to correct inaccurate data and complete incomplete data. |
| Erasure | The right to request erasure of data where a ground under Article 17 GDPR applies and no exception exists. |
| Restriction | The right to request restriction of processing in the cases specified in Article 18 GDPR. |
| Data portability | The right to receive data provided to the Controller and transfer them to another controller where processing is automated and based on consent or a contract. |
| Objection | The right to object, on grounds relating to the data subject's particular situation, to processing based on Article 6(1)(f) GDPR; in the case of direct marketing, the objection is unconditional. |
| Withdrawal of consent | The right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. |
A request may be submitted to the Data Protection Officer at iodo@keyfoods.pl or by post to the Controller's registered office. The Controller may request information necessary to confirm identity where there are reasonable doubts, but the scope of verification will be proportionate to the risk and will not result in the collection of excessive data.
A response is provided without undue delay, generally within one month of receiving the request. The period may be extended by a further two months due to the complexity or number of requests; information about the extension and its reasons is provided within the first month.
The exercise of rights is generally free of charge. If a request is manifestly unfounded or excessive, in particular because of its repetitive nature, the Controller may charge a reasonable fee reflecting administrative costs or refuse to act in accordance with Article 12(5) GDPR.
A person who believes that their data are being processed unlawfully has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland.
17. Voluntary and Mandatory Provision of Data
Browsing publicly available Website content does not require the provision of data other than technical information necessary for transmission and operation of the requested function. Providing data in an inquiry, order, contract, complaint or recruitment process is generally voluntary, but may be necessary to identify the person or contractor, provide a response, prepare an offer, perform a delivery, settle accounts or assess a candidate.
Where the obligation to provide data arises from law, in particular tax, accounting, customs, food-safety or employment-law provisions, failure to provide the data may prevent an action from being performed, a document from being issued, a transaction from being completed or employment from being offered. Marketing consents are voluntary, and refusal to provide consent may not be made a condition for fulfilling an order or accessing functions for which such consent is not necessary.
18. Automated Decision-Making and Children's Data
The Controller does not make decisions concerning individuals based solely on automated processing, including profiling, which would produce legal effects or similarly significantly affect them within the meaning of Article 22 GDPR. Statistics, message filtering, security mechanisms and marketing segmentation do not result, on the Controller's side, in such decisions without human involvement.
The Website and commercial forms are not directed at children and are not intended for transactions to be entered into by children. The Controller does not knowingly collect children's data for marketing purposes. A child's data provided without an appropriate legal basis will be deleted or restricted following appropriate verification.
19. Security and Confidentiality
The Controller applies technical and organisational measures appropriate to the risk, including access and permission controls, authentication, transmission security, backups, event logging, updates, protection of devices and email, confidentiality rules, training, incident procedures, data-processing agreements and risk assessments.
Access to data is limited to authorised persons and entities that need the data to perform their tasks and are subject to confidentiality obligations. The Controller requires processors to provide data-protection safeguards appropriate to the risk.
No transmission method or IT system completely eliminates risk. In the event of a personal data breach, the Controller assesses and documents the incident and, where required by Articles 33 or 34 GDPR, reports it to the President of the Personal Data Protection Office and notifies the affected data subjects.
20. Changes to the Privacy Policy
The Policy is reviewed in the event of changes in law, Website functionality, methods of placing and fulfilling orders, business processes, categories of recipients, technology providers or processing purposes. The current version is published on the Website together with the date of update.
If a change materially affects the manner in which data are processed or the rights of individuals, the Controller shall provide appropriate information. An amendment to the Policy does not extend previously given consent to a new purpose; where consent is required, the Controller shall obtain it before commencing the processing.