Legal
Privacy policy
NordLabels is committed to respecting and protecting your privacy. This policy explains what personal data we may collect about you when you visit our website or use our services, how we use and protect it, and the choices you have.
1. Who we are
This Policy is issued by NORDLABELS spółka z ograniczoną odpowiedzialnością (NORDLABELS sp. z o.o.), with its registered office at Konwaliowa 10, 05-805 Kanie, Poland, entered in the Register of Entrepreneurs of the National Court Register (KRS) under number 0001254509, NIP 5342714834, share capital 5,000 PLN (“NordLabels”, “we”, “us”), acting as data controller under Regulation (EU) 2016/679 (the “GDPR”).
You can contact us about privacy matters at contact@nordlabels.com or by post at the address above. Given the scale and nature of our processing activities, NordLabels is not required to appoint a Data Protection Officer under Article 37 GDPR; the contact above handles all data protection enquiries.
2. Scope of this policy
This Policy covers personal data we process in connection with our website at https://www.nordlabels.com/, enquiries and quote requests, our relationships with business customers and suppliers (specifically, the individuals who represent them — contact persons, purchasing staff, or sole traders), and marketing communications you have subscribed to.
NordLabels currently sells to business customers only; if we begin selling to individual consumers, this Policy will be updated accordingly before that happens.
Our website may contain links to other websites. These are outside our control and are not covered by this Policy. If you follow a link to another site, the privacy notice of that site’s operator will apply, not this one.
3. How we collect your personal data
We may collect personal data when you visit our website, make an enquiry or request a quotation, place an order, subscribe to our newsletter, or otherwise get in touch with us. Where we need certain data to respond to you or fulfil an order, we will make this clear; otherwise, providing it is voluntary.
When you visit our website, our server also records basic technical information about the request — such as IP address, the page requested, the time, and browser type — so that we can keep the site available and secure. We set no cookies, and the analytics we use store nothing on your device; Section 5 explains this in more detail.
4. Information we collect and how we use it
Where you provide personal data to us — for example your name, job title, company, email address, phone number, or enquiry details — we process it for our legitimate business purposes, including to: provide our Products and respond to your enquiries or orders; manage our relationships with customers and suppliers; issue invoices and meet our accounting and tax obligations; develop and improve our Products; operate and improve our website; market our Products to you, where permitted; organise or take part in trade events and exhibitions; conduct customer or product surveys; and comply with our other legal obligations.
The table below sets out, for each category of person, the personal data involved, why we process it, and the legal basis we rely on under Article 6 GDPR.
| Who | What we collect | Why | Legal basis (GDPR) |
|---|---|---|---|
| Website visitors | IP address, browser and device data, pages requested, timestamps — from server logs and cookieless analytics; no cookies and no device identifiers are used | Keep the website available, secure and working correctly | Legitimate interest (Art. 6(1)(f)) |
| Enquiry / quote-request senders | Name, email, phone, company, country, message content and any files you attach | Respond to enquiries and prepare quotations | Pre-contractual steps (Art. 6(1)(b)); consent (Art. 6(1)(a)) for anything you send us beyond what we need |
| Business contacts at customers and suppliers | Name, work email, phone, job title, company | Manage the business relationship; perform and administer contracts | Legitimate interest (Art. 6(1)(f)); or contract performance (Art. 6(1)(b)) where the counterparty is a sole trader contracting directly |
| Invoicing / accounting records | Name, address, NIP, transaction details | Issue invoices; meet tax and accounting obligations | Legal obligation (Art. 6(1)(c)) |
| Newsletter subscribers | Name, email address | Send product updates and marketing communications | Consent (Art. 6(1)(a)) |
5. Cookies and similar technologies
This website sets no cookies and runs no advertising or cross-site tracking technologies. Nothing is stored on or read from your device, so there is no consent banner to accept.
We do measure how the site is used, with Cloudflare Web Analytics. It reports aggregate figures — page views, referring sites, countries, page performance — and works without cookies, without device identifiers and without fingerprinting. Because nothing is written to or read from your device, the consent requirement in Article 5(3) of the ePrivacy Directive is not triggered. The processing itself relies on our legitimate interest under Article 6(1)(f) GDPR in understanding which pages are useful and keeping the site fast; we have weighed that against your interests and consider the impact minimal, since no profile is built and no individual can be singled out from the results. Cloudflare acts as our processor under Article 28 GDPR; Section 7 covers where that processing takes place and the safeguards that apply. You can object to this processing at any time using the contact details in Section 10, or by enabling your browser's Do Not Track or an ad blocker, both of which prevent the measurement script from loading.
Our web server keeps short-lived technical logs of requests, as described in Section 4. If we ever introduce cookies or any other technology that stores information on your device, we will ask for your consent before anything is set, publish the full list with purposes and retention periods, and update this Policy first. What the site stores today is set out in our cookie policy.
6. Protection and storage of personal data
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse, including access controls, encryption in transit, and confidentiality obligations for staff. Access to personal data is restricted to those who need it for the purposes described in this Policy.
We keep personal data only for as long as necessary for those purposes:
| Data | Kept for |
|---|---|
| Website server logs | 30 days |
| Enquiry and contact-form data | The duration of the enquiry and 12 months afterwards, unless it leads to a contract |
| Business contact data (customers and suppliers) | The duration of the business relationship and 3 years after its end, to handle any residual claims |
| Invoicing and accounting data | Five (5) years from the end of the calendar year in which the relevant tax became due, as required by Polish tax law |
| Newsletter data | Until you unsubscribe or withdraw consent |
7. Sharing data and international transfers
We share personal data only where necessary, with: IT and hosting providers for our website and systems; providers of the email and customer-management tools we use to handle enquiries and marketing; our accounting or bookkeeping office, for invoicing and tax purposes; logistics and courier companies, for delivering Products to business customers; professional advisers (lawyers, auditors), where necessary; and public authorities, where required by law.
In practice our principal processors are Cloudflare, Inc. (website hosting, delivery, security and cookieless audience measurement), Microsoft Ireland Operations Limited (Microsoft 365 email), and Resend (delivery of inquiry-form messages to our mailbox).
Where these recipients act as our processors, they are bound by data processing agreements meeting the requirements of Article 28 GDPR. We will not otherwise disclose your personal data except with your consent or where required by law. We never sell personal data and never share it with advertisers.
Some service providers may process data outside the European Economic Area, including in the United States. Where this occurs, we rely on European Commission adequacy decisions, Standard Contractual Clauses (SCCs), or another safeguard recognised under Chapter V GDPR. Contact us for further details of these safeguards.
8. Your rights under the GDPR
You have the right to: access your personal data and receive a copy of it; request rectification of inaccurate or incomplete data; request erasure of your data, where applicable; request restriction of processing, in certain circumstances; object to processing based on legitimate interest, including for direct marketing; receive your data in a portable format, where processing is based on consent or contract and carried out by automated means; withdraw consent at any time, without affecting the lawfulness of processing before withdrawal; and lodge a complaint with the supervisory authority (Section 12 below).
To exercise any of these rights, contact us at contact@nordlabels.com. We will respond within one month, as required by the GDPR. You may be asked to verify your identity or clarify your request.
You may also opt out of marketing communications at any time by using the “unsubscribe” link in any marketing email we send, or by contacting us directly.
9. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
10. Children
Our website is not directed at individuals under the age of 16, and we do not knowingly collect personal data from children.
11. Changes to this policy
We may update this Policy from time to time to reflect changes in our services, operations, or the law. Any changes will be posted here, together with the date they take effect.
12. How to contact us and supervisory authority
NORDLABELS sp. z o.o., Konwaliowa 10, 05-805 Kanie, Poland — contact@nordlabels.com.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office, UODO), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, tel. +48 22 531 03 00, uodo.gov.pl.
Last updated: 8 August 2026