Skip to content
Global Trade Group

Privacy policy: how we process your personal data

Last updated: 23 September 2026

This is a translation of the Polish privacy policy. If the two versions differ, the Polish version prevails.

This privacy policy explains how Global Trade Group sp. z o.o. processes the personal data of people who contact us through globaltradegroup.pl and through forms in ads on Facebook and Instagram. It is the information required by Articles 13 and 14 of the GDPR, the EU General Data Protection Regulation (EU) 2016/679.

Who is the controller of your data?

The controller of your personal data is Global Trade Group sp. z o.o., Al. Jerozolimskie 133/2, 02-304 Warszawa, KRS 0001096244, NIP 5342677352. The controller is the organisation that decides why and how personal data is processed. For anything concerning your personal data, email sales@globaltradegroup.pl or call +48 516 126 213.

We have not appointed a data protection officer (DPO), so please bring every data matter directly to us, at the email address or phone number above.

What data do we collect, and where does it come from?

We process three kinds of data. The first is what you type into the forms on the website. The second is data from Meta lead forms on Facebook and Instagram, and the third is technical data created when you use the website, such as your IP address. Each kind is described below.

Website forms. These are the quote request (for example on Import from China to Poland), the product quote in our catalogue and the form on a campaign landing page. We collect:

  • your first and last name, email address and, if you give them, your company name and phone number;
  • your message and the details of your enquiry, e.g. product, quantity, target unit price, delivery terms and destination;
  • the language of the site and the page the form was sent from;
  • the referring website, meaning the page whose link brought you to us, and campaign parameters, e.g. utm_source, utm_medium, utm_campaign, gclid and fbclid, when they appear in the address;
  • your IP address.

Meta lead forms. If you fill in a form in an ad on Facebook or Instagram, Meta Platforms Ireland Limited passes the data you entered to us. The data goes into a Google spreadsheet and is then imported into our CRM, the system we use to manage enquiries and clients. The source of this data is therefore Meta (Article 14 GDPR).

Technical data. The website is hosted by Vercel Inc. (USA), which records technical data such as IP addresses in its server logs. We measure website traffic with Umami, which uses no cookies.

We process data to answer your enquiry, prepare a quote and perform a contract. We also process it to meet accounting, tax and customs obligations, keep the website secure and compile statistics. We send no newsletter and do not pass enquiry data to other companies for their own purposes.

The table shows the legal basis for each purpose under Article 6(1) GDPR.

PurposeLegal basis
Answering your enquiry and quoting when you ask on your own behalf (steps taken at your request before entering into a contract)Art. 6(1)(b) GDPR
Concluding and performing a contractArt. 6(1)(b) GDPR
Answering an enquiry sent on behalf of a companyArt. 6(1)(f) GDPR — our legitimate interest in answering business-to-business (B2B) enquiries
Accounting, tax and customs obligationsArt. 6(1)(c) GDPR
Security of the website and formsArt. 6(1)(f) GDPR
Website and ad campaign statisticsArt. 6(1)(f) GDPR

A legitimate interest is a purpose of the controller that allows data to be processed unless your interests, rights and freedoms override it. You can object to processing based on this ground.

Who may receive your data?

Hosting and IT providers may receive your data, as may Google and Meta, through which enquiries from ads pass. Companies of the MEYİS group receive data when they carry out customs formalities, and carriers when you place an order. Public authorities receive data only where the law requires it.

  • Hetzner Online GmbH — our CRM runs on its servers in Falkenstein, Germany.
  • Vercel Inc. (USA) — hosts the website and records technical data, such as IP addresses, in server logs.
  • Google — enquiries from Meta lead forms pass through a Google Sheets spreadsheet.
  • Meta — runs the forms in ads on Facebook and Instagram.
  • Companies of the MEYİS group — when they carry out customs formalities for your shipment.
  • Carriers and freight forwarders (companies that organise transport) — when you place an order.
  • Public authorities — where the law requires it.

Does your data leave the European Economic Area?

It may go to the USA. Our CRM runs on Hetzner Online GmbH servers in Falkenstein, Germany, which is inside the European Economic Area (EEA: the EU plus Iceland, Liechtenstein and Norway). Vercel, Meta and Google, however, are US companies, so using their services may involve transferring data to the USA.

These transfers rely on the EU–US Data Privacy Framework (DPF) or on standard contractual clauses approved by the European Commission (Article 46(2)(c) GDPR). For companies taking part in the DPF, the Commission found an adequate level of data protection in Implementing Decision (EU) 2023/1795 of 10 July 2023.

As of 23 September 2026, Vercel Inc., Meta Platforms, Inc. and Google LLC were listed as active in the official DPF participant list (Vercel, Meta, Google). On request, we will tell you which safeguards we use and how to obtain a copy of them.

How long do we keep your data?

Enquiry data that leads to no contract is kept for up to 24 months from the last contact, or until you object, if sooner. Contract, accounting and customs records are kept as long as the law requires. Umami statistics are not personal data: Umami uses no cookies, collects nothing that identifies you and anonymises the data it collects (Umami documentation).

The main statutory periods:

Does the website use cookies?

We store no cookies and no data in your browser for analytics or advertising. Cookies are small files that a website saves in your browser. We measure traffic with Umami, which we host ourselves and which works without cookies and builds no user profiles across websites.

Umami records page views, events (such as a button click), the referring page, device and browser type, and country.

What are your rights?

You have the right to access your data, to have it rectified or erased, to restrict its processing and to data portability. Where processing is based on your consent, you can withdraw that consent at any time; this does not affect the lawfulness of processing before the withdrawal. To exercise your rights, email sales@globaltradegroup.pl or call +48 516 126 213.

If you believe we process your data unlawfully, you can lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stanisława Moniuszki 1A, 00-014 Warszawa (uodo.gov.pl), under Article 77 GDPR.

How can you object to the processing of your data?

You can object at any time to processing of your data that we base on our legitimate interest (Article 6(1)(f) GDPR). This covers answering enquiries sent on behalf of a company, website security and statistics. The objection must rest on grounds relating to your particular situation.

Once you object, we stop processing the data. The exception is where we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or grounds for the establishment, exercise or defence of legal claims (Article 21(1) GDPR). Send your objection to sales@globaltradegroup.pl.

Do you have to provide your data?

Providing data is voluntary, but without it we cannot answer your enquiry. We need at least your first and last name and your email address, so that we know whom to send the quote to and where. Your phone number is optional: give it if you prefer a quick call to an exchange of emails.

Do we make automated decisions?

No. We make no decisions about you that are based solely on automated processing of data and produce legal effects. An example of such a decision would be an automatic refusal to enter into a contract, issued by a system without any human involvement. Article 22 GDPR sets the rules for such decisions.

Legal status verified: September 2026.