Privacy Notice
v2.0.0As of: May 26, 2026
Privacy Notice — Supplier Portal
Information per Art. 13 GDPR
Version 1.1.0 · effective 2026-05-19
§ 1 Controller and Processor
(1) The Controller within the meaning of Art. 4(7) GDPR for processing in this platform is the Buyer organisation that invited you as supplier. Exact contact details appear in your supplier profile under "Invited by".
(2) P&P Unternehmensgruppe Marco Pavlov Pereira (the platform operator) processes your data as a Processor under Art. 28 GDPR on behalf of the Buyer organisation. Operator address and contact appear in the imprint at the foot of this document.
(3) Privacy requests should be directed to the Buyer organisation; the platform operator forwards incoming requests.
§ 2 Purposes and Legal Bases
| Purpose | Legal basis |
|---|---|
| Initiation and performance of business relationship | Art. 6(1)(b) GDPR |
| Audit logging of security-critical changes (in particular IBAN changes) | Art. 6(1)(f) — fraud prevention |
| Platform operation, security logs, authentication | Art. 6(1)(f) — IT security |
| Statutory retention obligations | Art. 6(1)(c) — §§ 257 HGB, 147 AO, ProdHaftG |
| System notifications | Art. 6(1)(b) |
Processing of special categories under Art. 9 does not take place. Technical documents (mill certs, conformity declarations) contain only technical data.
§ 3 Data Categories
- Master data: company name, address, VAT ID, HRB, legal form, GLN, DUNS, EORI;
- Contact data: name, salutation, role, email, phone, mobile;
- Authentication: email, password hash, MFA token;
- Bank details: IBAN, BIC, holder;
- Contract data: orders, offers, prices, certificates, mill certs;
- Usage data: login times, IP, user agent, audit trail;
- Acceptance records: timestamp, IP, user agent, hash of accepted version.
§ 4 Recipients
(1) Within the Controller (Buyer): authorised personnel under confidentiality obligation.
(2) Processors (under Art. 28): see the subprocessor list (Annex 4 to the Usage Agreement; in particular hosting on Vercel and Supabase, EU region).
(3) Disclosure to public authorities only where legally required.
§ 5 Third-Country Transfers
(1) Processing takes place within the EU (Frankfurt / EU-Central-1).
(2) Subprocessors with US parent (Vercel Inc., Supabase Inc.): physical processing in the EU, TIA prepared and available on request.
§ 6 Retention
| Category | Retention |
|---|---|
| Master / contract data | term of contract + 10 years (§ 147 AO, § 257 HGB) |
| Bank details / IBAN audit logs | term of contract + 10 years |
| Mill certs, EMPB, conformity declarations | min. 10 years from market placement (ProdHaftG) |
| Login / security logs | 12 months |
| Acceptance records | 10 years after contract end (§ 199(4) BGB) |
| Soft-deleted records | further 30 days, then physical deletion subject to retention obligations |
§ 7 Your Rights
You have the following rights vis-à-vis the Controller (Art. 12–22 GDPR): access, rectification, erasure, restriction, portability, objection. Exercise via the Buyer organisation; platform operator supports technically.
§ 8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority (Art. 77). Generally the authority at the Controller's seat is competent.
§ 9 Automated Decisions / AI
(1) The platform makes no decisions based solely on automated processing producing legal or similarly significant effects (Art. 22).
(2) Rule-based heuristics in the platform (e.g. document auto-categorisation) are not AI within the meaning of AI Act 2024/1689.
(3) Should AI-based functions with significant impact be introduced, you will be informed separately. The current AI/heuristic inventory is maintained in the platform's internal features overview and provided by the operator on request.
§ 10 Data Security
The platform implements suitable technical and organisational measures per Art. 32, in particular: tenant-level Row Level Security; encryption in transit (TLS 1.3) and at rest (AES-256); optional 2FA recommended for privileged roles; audit logs for security-critical actions; soft-delete with recovery.
§ 10a Support Telemetry (proactive error observation)
For the purpose of proactive error remediation and session stability, the platform records technical error events from your browser session (error codes, stack-trace heads, affected route, anonymised user-agent) and an anonymised presence heartbeat (last-active timestamp + current path). Before persistence the payload is client-side redacted — UUIDs, email addresses, JWTs, IBAN, phone numbers, and E2EE ciphertext are replaced with placeholders. Cleartext business content never leaves your session in readable form.
- Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in proactive support and security of processing per Art. 32 GDPR).
- Recipients: exclusively P&P Unternehmensgruppe Marco Pavlov Pereira acting as processor (platform operator support). No third-party disclosure.
- Retention: unresolved error events 20 days; resolved events 90 days; presence data 30 days. Automated sweep per § 6.
- Transparency (Art. 28 + Art. 15): every platform-support access to your organisation's telemetry is recorded in an audit trail visible to you (Organisation settings → "Platform support access").
- Your rights: you may object to processing pursuant to Art. 21 GDPR. Upon objection, residual session diagnostics remain available, but proactive support is reduced.
§ 11 Amendments
Material amendments are announced at least 30 days in advance. You will be prompted for renewed active confirmation; tacit consent is excluded.
§ 12 Language
In case of conflict with translations, the German version is binding.
Operator (Imprint)
P&P Unternehmensgruppe Marco Pavlov Pereira
Deutschland
Email: info@nexusm.de
SHA-256: 7aa73b6240585e48393e13f2b4f0eb9395e8ff3c0ab4b1cbc69df6e5ac731983