Information clause for business partners
I. Personal Data Controller
In the light of the applicable provisions of law, in particular pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), commonly referred to as the GDPR, the controller of your personal data (hereinafter: the Personal Data Controller) is the company RYS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ with its registered office in Bielsko-Biała (43-300) at ul. Podwale 47, entered in the register of entrepreneurs kept by the District Court in Bielsko-Biała, VIII Commercial Division of the National Court Register under KRS number: 0001006923, NIP: 5472234742, REGON: 523865502, represented by Wojciech Maciej Piszczek – President of the Management Board.
Contact with the Personal Data Controller is possible in the following manner:,
by e-mail message: rodo@rysagency.com,
The person designated for contact in GDPR matters on behalf of the Personal Data Controller is Ms Marta Kamińska, who can be contacted using the contact details indicated above.
The Personal Data Controller has not appointed a Data Protection Officer.
The Personal Data Controller is responsible for using personal data in a secure manner and in compliance with the applicable provisions of law.
II. Purpose and legal basis for the processing of personal data
Your personal data are processed for the purpose of:
- conducting the Personal Data Controller's day-to-day business activity, consisting in particular of:
- supporting entrepreneurs in developing online sales on the largest e-commerce and marketplace platforms,
- providing expert advice in the field of e-commerce, in order to improve sales results and online profitability,
- handling Marketplace platforms on behalf of Clients, managing the account and preparing the strategy and handling of sales within marketplaces for Clients,
- providing support to Clients consisting of the analysis of potential, through expansion planning, up to the effective management of PCC advertising and the optimisation of offers,
- conducting business activity related to the provision of marketing agency services,
- concluding and performing agreements with Clients,
- operational contact with Clients/conducting sales talks, preparing offers and analysing potential, contact by telephone and e-mail in order to establish cooperation,
– legal basis for the processing of personal data – Article 6(1)(b) GDPR, i.e. the necessity of processing personal data in order to perform the Agreement,
- conducting cooperation with contractors, including in particular managing relations with suppliers of IR tools, paying subscriptions, cooperating with the accounting office – legal basis for the processing of personal data – Article 6(1)(b) GDPR, i.e. the necessity of processing personal data in order to perform the Agreement,
- concluding and performing other agreements in connection with the business activity conducted – legal basis for the processing of personal data – Article 6(1)(b) GDPR, i.e. the necessity of processing personal data in order to perform the Agreement,
- fulfilling the legal obligations incumbent on the Personal Data Controller (e.g. in order to issue a VAT invoice) – legal basis Article 6(1)(c) GDPR in conjunction with Article 74(2)(4) of the Act of 29 September 1994 on Accounting (consolidated text: Journal of Laws of 2026, item 522) in conjunction with Article 86 § 1 and Article 70 § 1 of the Act of 29 August 1997 – Tax Ordinance (consolidated text: Journal of Laws of 2025, item 111, as amended),
- establishing, defending and pursuing claims – legal basis Article 6(1)(f) GDPR, i.e. the legitimate interest of the Personal Data Controller consisting in the establishment, defence and pursuit of claims,
- conducting the marketing of own services – legal basis Article 6(1)(a) GDPR, i.e. the consent of the data subject.
III. Transfer of personal data outside the European Economic Area
- In connection with the Personal Data Controller's use of IT tools and services provided by entities having their registered office or infrastructure outside the European Economic Area (EEA), personal data may be transferred to third countries, in particular to the United States of America.
- The transfer of personal data outside the EEA takes place solely with the appropriate safeguards required by the provisions of Chapter V of the GDPR, in particular on the basis of:
- adequacy decisions issued by the European Commission – in the case of entities covered by the EU–US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795),
- standard contractual clauses (SCC) adopted by European Commission Decision (EU) 2021/914 of 4 June 2021,
- additional technical and organisational measures, including in particular cryptographic measures, access control and restrictions on data transfer in accordance with the transfer impact assessment (TIA – Transfer Impact Assessment).
3. The Personal Data Controller uses in particular the following suppliers:
- Suppliers of e-mail, cloud and office software,
- Suppliers of CRM, process automation and project management systems,
- Suppliers of marketing and analytical tools and of newsletters,
- Suppliers of meeting booking and e-signature systems,
- Suppliers of graphic tools and of tools supporting website maintenance,
- Suppliers of cybersecurity solutions.
- In each case the Personal Data Controller verifies whether a given supplier ensures that the processing of personal data complies with the GDPR, and the transfer of data takes place to the minimum necessary extent. Data subjects may obtain a copy of the safeguards applied with regard to the transfer of data to third countries, or information about where they are made available, by contacting the Personal Data Controller at the address: rodo@rysagency.com.
IV. Categories of personal data processed
The Personal Data Controller processes the following categories of data: first name and surname, job position, company name, business correspondence address, business e-mail address and business telephone number, bank account number, NIP.
Where the Personal Data Controller requests the provision of personal data, their provision is not obligatory, however it is necessary for the purposes of establishing and conducting business cooperation between the Controller and the contractor.
Personal data are not processed for the purpose of automated decision-making, including profiling.
Personal data come directly from the data subject. If personal data do not come from the data subject, they are obtained from sources generally available on the Internet (e.g. CEIDG, KRS, the company website, etc.).
V. Entities to which personal data are entrusted
Personal data are transferred to:
- entities providing audit, consultancy, financial advisory, legal and tax services for the Personal Data Controller,
- entities operating external servers,
- entities providing IT support.
In the case of the Personal Data Controller, the aforementioned entities are:
- Providers of IT infrastructure and hosting: entities providing server maintenance services, providers of electronic mail, of office software packages and of credential management and cybersecurity systems.
- Providers of CRM and business automation systems: entities supplying tools for customer relationship management, process (workflow) automation and the coordination of tasks and projects.
- Providers of accounting, tax and invoicing services: external accounting and tax offices and providers of ICT systems for issuing invoices and for settlements in the SaaS model.
- Providers of marketing, analytical and SEO tools: companies supplying software for the analysis of website traffic, content optimisation, marketing automation, newsletter distribution and the aggregation of analytical data.
- Marketing and copywriting agencies and content platforms: entities supporting promotional activities, content creation and the distribution of articles and publications.
- Providers of communication and customer support services: operators of SMS notification systems, of ticketing (helpdesk) systems and of communication with users.
- Providers of operational and graphic design tools and of e-signature tools: companies supplying systems for concluding contracts electronically, graphic design platforms and plugins and software supporting the operation and editing of websites.
In connection with the Personal Data Controller commencing the use of the KSeF system (the National e-Invoicing System) as of 1 February 2026, the recipients of your personal data will be the Minister of Finance and the authorities of the National Revenue Administration (KAS) operating the KSeF system.
VI. Duration of the processing of personal data
- where the legal basis for the processing of personal data is Article 6(1)(b) GDPR – the personal data of contractors will be stored for the period of the business cooperation between the Personal Data Controller and the contractor, or possibly until the day on which any claims expire (claims connected with the conduct of business activity become time-barred, as a rule, after 3 years, and in other cases after 6 years, unless a specific provision provides otherwise),
- where the legal basis for the processing of personal data is Article. 6(1)(c) GDPR in conjunction with Article 74(2) of the Act of 29 September 1994 on Accounting (consolidated text: Journal of Laws of 2026, item 522) in conjunction with Article 86 § 1 and Article 70 § 1 of the Act of 29 August 1997 – Tax Ordinance (consolidated text: Journal of Laws of 2025, item 111, as amended) – the data of contractors will be processed for a period of 5 years counted from the beginning of the year following the financial year in which the matter was finally concluded, settled or became time-barred,
- where the legal basis for the processing of personal data is Article 6(1)(a) GDPR – the personal data will be processed until the consent is withdrawn by the data subject. A subsequent withdrawal of consent does not affect the lawfulness of the processing of personal data from the period before its withdrawal,
- where the legal basis for the processing of personal data is Article. 6(1)(f) GDPR in connection with the establishment, pursuit and defence of claims – the personal data will be processed until the aforementioned claims become time-barred (claims connected with the conduct of business activity become time-barred, as a rule, after 3 years, and in other cases after 6 years, unless a specific provision provides otherwise).
VII. Rights available in connection with the processing of personal data by the Controller
You have the right to:
- access to the processed personal data – the person whose data are processed has the right at any time to request access to their personal data, including the right to request that they be provided with information as to whether their personal data are being processed and with a copy of their personal data,
- rectification and supplementation of the processed personal data – the person whose data are processed has the right at any time to request the immediate rectification of their personal data, as well as the supplementation thereof, provided, however, that the Controller does not have a legal basis enabling it to refuse such rectification or supplementation,
- erasure of the processed personal data (the so-called right to be forgotten) – the person whose personal data are processed has the right to request the erasure of personal data concerning them. The Controller may, however, refuse to give effect to this right. Such a situation will arise above all where, under the applicable provisions of law, the Controller is entitled or obliged to store the personal data,
- restriction of the processing of personal data,
- raising an objection to the personal data processing activities,
- withdrawal of consent to the processing of personal data, where the legal basis for the processing of personal data was the consent of the data subject.
The above rights may be exercised by submitting an appropriate request to the Controller using the details indicated in point I. The Controller has the right to verify the identity of the person exercising the rights indicated above.
Moreover, the person whose data are processed is entitled to request that the personal data be transmitted to another controller, however only provided that the processing is carried out by automated means and that it is technically possible.
The processing of your personal data will not be based on consent
to processing.
VIII. Right to lodge a complaint with the supervisory authority
If the processing of personal data infringes the provisions of law, you have the right to lodge a complaint with the supervisory authority regarding the processing of personal data by the Personal Data Controller. A complaint may be lodged with the President of the Personal Data Protection Office (currently the Office of the President of the Personal Data Protection Office is located in Warsaw 00-014, at ul. Stanisława Moniuszki 1A).
IX. Activities