Privacy Policy for Users of the b2b.lvt.com.pl Store

Effective September 18, 2026

1. Who Is the Data Controller

The controller of personal data is LVT sp. z o.o., with its registered office at ul. Piecewska 19, 80-288 Gdańsk, entered in the Register of Entrepreneurs of the National Court Register under KRS number 0000966232, NIP 5891996988, REGON 221181602 (hereinafter: “LVT” or “Controller”).

For matters regarding the processing of personal data, you may contact the Controller at: handlowy@lvt.com.pl, by phone at 58 355 01 38, or by mail at the registered office address.

2. Who Is Covered by This Policy and What Data It Covers

This policy applies in particular to users of the B2B website, representatives and employees of business customers, persons authorized to place orders, contact persons, recipients of shipments, persons submitting complaints or inquiries, and newsletter subscribers.

Depending on how you use the service, we may process:

  1. Identification and contact information, including first name, last name, email address, phone number, job title, or position;
  2. Company data, including name, address, tax ID number, billing information, and details of representatives or contact persons;
  3. B2B account data, including username, encrypted password, account status, permissions, and activity history;
  4. Data regarding orders, payments, deliveries, returns, complaints, and correspondence;
  5. Technical and usage data, including IP address, cookie identifiers, device and browser information, and security logs;
  6. Email address and marketing consent information—when you subscribe to the newsletter or provide separate marketing consent.

3. Purposes, Legal Bases, and Retention Periods

We process data only to the extent necessary for a specific purpose. The table below outlines the main purposes of processing.

Purpose Legal Basis Retention period
Creating, managing, and securing an account on the website; enabling access to prices and placing orders. Article 6(1)(b) of the GDPR—performance of a contract or pre-contractual measures; Article 6(1)(f) of the GDPR—security and protection against abuse. For the duration of the account’s activity, and after its closure, for the period necessary for settlement of accounts, defense against claims, and fulfillment of legal obligations.
Order fulfillment, delivery, payment processing, and commercial communications regarding the contract. Article 6(1)(b) of the GDPR. For the duration of the contract and thereafter until the statute of limitations on claims expires.
Invoicing, accounting, and tax obligations. Article 6(1)(c) of the GDPR—legal obligation Up to 5 years from the end of the calendar year in which the tax payment deadline expired, or longer if required by law.
Handling complaints, returns, inquiries, disputes, and the assertion or defense of claims. Article 6(1)(b) of the GDPR and Article 6(1)(f) of the GDPR—the Controller’s legitimate interest. Until the matter is resolved, and then until the expiration of the applicable statute of limitations for claims.
Marketing of our own products or services to existing business customers, where permitted by law. Article 6(1)(f) of the GDPR—the Controller’s legitimate interest; in the case of channels requiring consent—also consent required by specific regulations. Until an objection is raised or the required consent is withdrawn; proof of consent may be retained until the expiration of the statute of limitations for claims.
Newsletter and electronic marketing. Article 6(1)(a) of the GDPR—consent; consent required by regulations governing electronic communications. To withdraw consent or unsubscribe from the newsletter; proof of consent—for the period necessary to demonstrate that consent was obtained.
Compiling statistics, ensuring website security, preventing fraud, and pursuing claims. Article 6(1)(f) of the GDPR—the Controller’s legitimate interest. For the period necessary to achieve the purpose, but no longer than until the expiration of the statute of limitations, unless regulations require longer retention.

4. Is providing data mandatory?

Providing the data marked as required in the form is necessary to create an account, process an inquiry, fulfill an order, or meet billing obligations. Failure to provide this data may prevent us from providing the relevant service. Providing data for the newsletter and granting marketing consents is voluntary; failure to consent does not affect the ability to use the website’s other features, with the exception of receiving marketing communications.

5. Data of Business Customer Contacts

If you act as a contact person, employee, or representative of a business client, your data may come directly from you, from your employer or business partner, as well as from publicly available registries and professional sources. We process this data to enter into and perform a contract with the client, conduct ongoing business cooperation, handle billing, and protect our rights. In such cases, the legal basis is Article 6(1)(f) of the GDPR, i.e., the legitimate interest of the Controller and the business client in conducting business cooperation, and, where necessary, Article 6(1)(b) or (c) of the GDPR.

If the data was not obtained directly from you, we will provide the information required by Article 14 of the GDPR within the prescribed time limit, unless an exception provided for by law applies.

6. Data Recipients

Access to the data may only be granted to entities that need it to achieve the purposes described in this policy, in particular:

  1. Providers of hosting, IT systems, email, technical support, and security services;
  2. Payment processors, banks, logistics providers, and carriers;
  3. Providers of accounting, legal, debt collection, and auditing services;
  4. Providers of marketing and analytics tools—only to the extent enabled by the user in cookie settings;
  5. Public authorities or other entities authorized by law.

7. Transfer of Data Outside the European Economic Area

As a general rule, the Controller strives to process data within the European Economic Area. If you use marketing features or consent to marketing cookies, data may be transferred to providers of such tools outside the EEA, in particular to the United States. In such cases, the transfer is based on the mechanisms provided for in Chapter V of the GDPR, such as a European Commission decision confirming an adequate level of protection, where applicable, or standard contractual clauses. Information about the safeguards in place can be obtained by contacting the Data Controller.

8. Your Rights

Within the limits set forth in the GDPR, you have the right to:

  • access your data and receive a copy of it;
  • rectify your data;
  • erase your data;
  • restrict processing;
  • data portability, when the basis for processing is consent or a contract and the processing is carried out by automated means;
  • to object to processing based on the Controller’s legitimate interest, including direct marketing;
  • withdraw consent at any time, without affecting the lawfulness of processing carried out prior to its withdrawal;
  • to file a complaint with the President of the Personal Data Protection Office.

To exercise these rights, please contact the Data Controller. We may ask for information necessary to verify the identity of the person making the request.

9. Automated Decision-Making

The Data Controller does not make automated decisions regarding users, including profiling that produces legal effects concerning them or similarly significantly affects them. The use of marketing cookies may result in the display of personalized ads by the provider of a given tool, but only after you have consented to marketing cookies.

10. Cookies and Similar Technologies

The website uses cookies and similar technologies. Cookies are used because they are necessary for the website to function properly, including maintaining sessions, logging in, and remembering your cookie preferences. Statistical and marketing cookies are used only after obtaining your consent. You may withdraw or change your consent at any time through the cookie settings available on the website.

Not consenting to statistical or marketing cookies does not restrict access to the website’s basic functions. Your browser settings also allow you to delete and block cookies; however, blocking essential cookies may affect the website’s functionality.

Cookie Name / Category Provider Purpose Duration
cookieplus
(essential)
https://b2b.lvt.com.pl Saves cookie preferences. 1 year
PrestaShop-#
(essential)
https://b2b.lvt.com.pl This cookie helps maintain the user’s session while visiting the website and facilitates placing orders and many other operations, such as: the date the cookie was set, the selected language, the currency in use, the most recently visited product category, the most recently viewed products, customer identification, first name, encrypted password, email address associated with the account, and shopping cart ID. 480 hours
fr, tr, _fbp
(marketing)
Facebook Used by Facebook to deliver a range of advertising products, such as real-time bidding from third-party advertisers. session or 3 months

11. Data Security

The administrator implements organizational and technical measures appropriate to the risk, including access control, transmission security, access rights management, and incident response procedures. No security measure can completely eliminate risk, so please protect your login credentials and do not share them with unauthorized persons.

12. Policy Updates

This policy may be updated in the event of changes to regulations, the website’s operations, or data processing procedures. The current version is published on the website along with its effective date. Any changes do not limit the rights of data subjects.