Privacy Notice

v2.0.0

As of: May 26, 2026

Privacy Notice — Supplier Portal

Information per Art. 13 GDPR

Version 1.1.0 · effective 2026-05-19

§ 1 Controller and Processor

(1) The Controller within the meaning of Art. 4(7) GDPR for processing in this platform is the Buyer organisation that invited you as supplier. Exact contact details appear in your supplier profile under "Invited by".

(2) P&P Unternehmensgruppe Marco Pavlov Pereira (the platform operator) processes your data as a Processor under Art. 28 GDPR on behalf of the Buyer organisation. Operator address and contact appear in the imprint at the foot of this document.

(3) Privacy requests should be directed to the Buyer organisation; the platform operator forwards incoming requests.

§ 2 Purposes and Legal Bases

PurposeLegal basis
Initiation and performance of business relationshipArt. 6(1)(b) GDPR
Audit logging of security-critical changes (in particular IBAN changes)Art. 6(1)(f) — fraud prevention
Platform operation, security logs, authenticationArt. 6(1)(f) — IT security
Statutory retention obligationsArt. 6(1)(c) — §§ 257 HGB, 147 AO, ProdHaftG
System notificationsArt. 6(1)(b)

Processing of special categories under Art. 9 does not take place. Technical documents (mill certs, conformity declarations) contain only technical data.

§ 3 Data Categories

  • Master data: company name, address, VAT ID, HRB, legal form, GLN, DUNS, EORI;
  • Contact data: name, salutation, role, email, phone, mobile;
  • Authentication: email, password hash, MFA token;
  • Bank details: IBAN, BIC, holder;
  • Contract data: orders, offers, prices, certificates, mill certs;
  • Usage data: login times, IP, user agent, audit trail;
  • Acceptance records: timestamp, IP, user agent, hash of accepted version.

§ 4 Recipients

(1) Within the Controller (Buyer): authorised personnel under confidentiality obligation.

(2) Processors (under Art. 28): see the subprocessor list (Annex 4 to the Usage Agreement; in particular hosting on Vercel and Supabase, EU region).

(3) Disclosure to public authorities only where legally required.

§ 5 Third-Country Transfers

(1) Processing takes place within the EU (Frankfurt / EU-Central-1).

(2) Subprocessors with US parent (Vercel Inc., Supabase Inc.): physical processing in the EU, TIA prepared and available on request.

§ 6 Retention

CategoryRetention
Master / contract dataterm of contract + 10 years (§ 147 AO, § 257 HGB)
Bank details / IBAN audit logsterm of contract + 10 years
Mill certs, EMPB, conformity declarationsmin. 10 years from market placement (ProdHaftG)
Login / security logs12 months
Acceptance records10 years after contract end (§ 199(4) BGB)
Soft-deleted recordsfurther 30 days, then physical deletion subject to retention obligations

§ 7 Your Rights

You have the following rights vis-à-vis the Controller (Art. 12–22 GDPR): access, rectification, erasure, restriction, portability, objection. Exercise via the Buyer organisation; platform operator supports technically.

§ 8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority (Art. 77). Generally the authority at the Controller's seat is competent.

§ 9 Automated Decisions / AI

(1) The platform makes no decisions based solely on automated processing producing legal or similarly significant effects (Art. 22).

(2) Rule-based heuristics in the platform (e.g. document auto-categorisation) are not AI within the meaning of AI Act 2024/1689.

(3) Should AI-based functions with significant impact be introduced, you will be informed separately. The current AI/heuristic inventory is maintained in the platform's internal features overview and provided by the operator on request.

§ 10 Data Security

The platform implements suitable technical and organisational measures per Art. 32, in particular: tenant-level Row Level Security; encryption in transit (TLS 1.3) and at rest (AES-256); optional 2FA recommended for privileged roles; audit logs for security-critical actions; soft-delete with recovery.

§ 10a Support Telemetry (proactive error observation)

For the purpose of proactive error remediation and session stability, the platform records technical error events from your browser session (error codes, stack-trace heads, affected route, anonymised user-agent) and an anonymised presence heartbeat (last-active timestamp + current path). Before persistence the payload is client-side redacted — UUIDs, email addresses, JWTs, IBAN, phone numbers, and E2EE ciphertext are replaced with placeholders. Cleartext business content never leaves your session in readable form.

  • Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in proactive support and security of processing per Art. 32 GDPR).
  • Recipients: exclusively P&P Unternehmensgruppe Marco Pavlov Pereira acting as processor (platform operator support). No third-party disclosure.
  • Retention: unresolved error events 20 days; resolved events 90 days; presence data 30 days. Automated sweep per § 6.
  • Transparency (Art. 28 + Art. 15): every platform-support access to your organisation's telemetry is recorded in an audit trail visible to you (Organisation settings → "Platform support access").
  • Your rights: you may object to processing pursuant to Art. 21 GDPR. Upon objection, residual session diagnostics remain available, but proactive support is reduced.

§ 11 Amendments

Material amendments are announced at least 30 days in advance. You will be prompted for renewed active confirmation; tacit consent is excluded.

§ 12 Language

In case of conflict with translations, the German version is binding.


Operator (Imprint)

P&P Unternehmensgruppe Marco Pavlov Pereira

Deutschland

Email: info@nexusm.de


SHA-256: 7aa73b6240585e48393e13f2b4f0eb9395e8ff3c0ab4b1cbc69df6e5ac731983