Privacy Policy — KonnectaMED Sp. z o.o.
Legal & Compliance · GDPR (EU) 2016/679

Privacy Policy

Transparency, data minimization and pan-European regulatory adherence. Learn how KonnectaMED Sp. z o.o. collects, processes and protects personal and commercial data across our medical device and cosmeceutical distribution networks.

Last updated: September 2026
Data Controller: KonnectaMED Sp. z o.o.
Registered in: Dąbrowa Górnicza, Poland (EU)
Registry: KRS 0001240623 · VAT PL6292522428
GDPR Compliant Strict adherence to Regulation (EU) 2016/679 and Polish statutory law.
EEA Infrastructure All customer and catalog data is stored securely in encrypted EU data centres.
Zero Data Selling We never sell, rent, or monetize personal or transaction data to third-party brokers.
01

Identity of the Data Controller

This Privacy Policy governs the processing of personal data by KonnectaMED Sp. z o.o. (referred to as "KonnectaMED", "we", "us", or "our"), operating the B2B distribution platform for medical devices, cosmeceuticals, and advanced pharmaceuticals accessible at konnectamed.eu and related ordering portals.

According to the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Polish Act on the Protection of Personal Data of 10 May 2018, the entity responsible for determining the purposes and means of processing personal data is:

KonnectaMED Spółka z ograniczoną odpowiedzialnością ul. Kasprzaka 70/10, 41-303 Dąbrowa Górnicza, Poland
KRS: 0001240623 (District Court Katowice-Wschód)
NIP (Tax ID): 629-252-24-28 · REGON: 544705452
EU VAT: PL6292522428 (VIES Validated)
Official Email: info@konnectamed.eu · Legal Desk: privacy@konnectamed.eu
02

Core Principles of Data Processing

KonnectaMED operates strictly in the professional B2B sector. We adhere to the fundamental principles set forth in Article 5 of the GDPR:

  • Lawfulness, Fairness and Transparency: Personal data is processed on legitimate legal grounds and in a transparent manner towards our clients, suppliers, and partners.
  • Purpose Limitation: Data is collected only for specified, explicit, and legitimate business purposes (e.g., verifying medical licenses, fulfilling cold-chain shipments, meeting fiscal obligations) and not further processed in a manner incompatible with those purposes.
  • Data Minimisation: We restrict the collection of personal details to the exact minimum necessary to execute wholesale contracts and comply with European health safety legislation.
  • Accuracy: We ensure that recorded commercial and contact details are kept up to date, providing users with self-service tools and direct support channels.
  • Storage Limitation: Data is retained only for as long as necessary for the purposes for which it was gathered, or as mandated by Polish and EU statutory limitation periods.
  • Integrity and Confidentiality: Technical and organizational safeguards are implemented to prevent unauthorized access, accidental alteration, loss, or disclosure.
03

Categories of Personal Data We Collect

Depending on your interaction with KonnectaMED (visiting our public portal, submitting an inquiry, registering a wholesale account, or executing procurement contracts), we may collect the following data categories:

A. B2B Account & Verification Data

When you request access to restricted medical price lists or register as an authorized partner:

  • Company name, corporate registered address, operating branch address.
  • Tax Identification Number (NIP, VAT, or local fiscal ID) and business registry extract.
  • Authorized contact person: Full name, professional role/title, corporate email address, and direct telephone number.
  • Professional credentials or medical practicing licenses (where mandatory under national laws for the purchase of prescription pharmaceuticals or Class III medical injectables).

B. Order Fulfillment & Invoicing Data

  • Billing and shipping addresses, delivery contact phone number.
  • Order history, product SKUs, ordered batch numbers, transaction timestamps, and payment status.
  • Banking details or wire transfer receipts for wholesale clearing.

C. Communications & Customer Support Data

  • Content of messages submitted via the website contact form, emails sent to our corporate addresses, or inquiries initiated through the interactive assistant (Kora).
  • Records of commercial discussions, supplier agreements, and distribution inquiries.

D. Technical & Browsing Data

  • IP address (anonymized where feasible), browser user-agent, operating system, and access timestamps.
  • Essential session cookies required to authenticate user sessions and safeguard against cross-site request forgery (CSRF).
04

Purposes and Legal Bases for Processing

In accordance with Article 6 of the GDPR, KonnectaMED processes your personal data under the following legal frameworks:

05

MDR 2017/745 & CPNP Regulatory Traceability

As an authorized European distributor of Class IIa, IIb, and Class III medical devices (under EU Regulation 2017/745 — MDR) and cosmeceuticals registered on the European Cosmetic Product Notification Portal (CPNP under Regulation EC No 1223/2009):

KonnectaMED is under a strict statutory duty to maintain unbroken batch traceability from manufacturer to end-clinician. In the event of a field safety corrective action (FSCA), batch recall, or pharmacovigilance inquiry initiated by competent authorities (such as the Polish URPL, Italian AIFA, or European Commission):

  • We retain transaction records tied to specific batch numbers, production lots, and cold chain temperature logs.
  • This data cannot be erased upon request where statutory vigilance obligations mandate minimum preservation periods (typically 10 to 15 years for implantable medical devices).
  • Such processing is exclusively conducted pursuant to Article 6(1)(c) and Article 9(2)(i) of the GDPR (ensuring high standards of quality and safety of health care and medical devices).
06

Data Retention Periods

We retain personal data strictly for the period necessary to achieve the specific purposes for which it was gathered, in compliance with applicable Polish and European statutory requirements:

  • Commercial Contract & Invoicing Records: Stored for 5 years starting from the end of the calendar year in which the tax payment deadline expired, pursuant to the Polish Tax Ordinance (Ordynacja podatkowa).
  • Medical Device Vigilance Records: Retained for a minimum of 10 years (or 15 years for implantable devices) from the date the last device of the batch was distributed, as prescribed by MDR 2017/745 Annex IX.
  • Active B2B User Accounts: Kept for the duration of the commercial relationship. Accounts inactive for more than 24 consecutive months may be archived or deleted following notification.
  • General Inquiries & Lead Forms: Retained for up to 12 months following resolution of the inquiry, unless converted into an ongoing commercial engagement.
  • Server Access Logs: Automatically rotated and purged after 90 days, unless required for active security investigations.
07

Recipients and Processors of Personal Data

KonnectaMED does not sell, trade, or license personal data. We only share necessary information with trusted third-party service providers acting as Data Processors under formal Article 28 GDPR Data Processing Agreements (DPAs):

  • Logistics & Cold-Chain Freight Carriers: Specialized GDP-compliant transport providers responsible for delivering temperature-monitored consignments directly to your designated facility.
  • Hosting & Infrastructure Providers: ISO/IEC 27001 certified server providers hosting our web servers and databases within data centres located inside the European Union.
  • Financial & Banking Partners: Regulated European banking institutions handling payment clearances and electronic wire transfers.
  • Auditors & Legal Counsel: External legal advisors, chartered accountants, and fiscal auditors bound by strict statutory confidentiality rules.
  • Public Authorities & Health Regulators: Legally authorized government bodies (such as customs offices, tax revenue authorities, and medical vigilance agencies) strictly upon formal lawful requests.
08

International Transfers Outside the EEA

KonnectaMED maintains its corporate headquarters, operational warehouse, and IT database infrastructure within Poland and the European Economic Area (EEA).

When collaborating with select international manufacturers (e.g., in South Korea for K-beauty innovation or Japan for aesthetic technology), personal data relating to European clients is not transferred overseas unless strictly necessary for custom product certifications or direct container dropshipment requested by the client.

In any rare event where data leaves the EEA, KonnectaMED guarantees that appropriate safeguards under Chapter V of the GDPR are in place, including European Commission Adequacy Decisions (such as the EU-Republic of Korea Adequacy Decision) or Standard Contractual Clauses (SCCs).

09

Your Statutory Rights Under GDPR

As an individual whose personal data is processed by KonnectaMED, you possess comprehensive statutory rights under Articles 15–22 of the GDPR:

  • Right of Access (Art. 15): You have the right to obtain confirmation as to whether your personal data is being processed and to receive a copy of that data.
  • Right to Rectification (Art. 16): You may request the prompt correction of inaccurate personal data or completion of incomplete information.
  • Right to Erasure / "Right to be Forgotten" (Art. 17): You may demand the deletion of your data, provided statutory retention grounds (such as tax laws or MDR batch records) do not require its continued preservation.
  • Right to Restriction of Processing (Art. 18): You may request the freezing of data processing under certain contested circumstances.
  • Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format (CSV/JSON) or request its direct transmission to another controller.
  • Right to Object (Art. 21): You may object at any time to processing based on legitimate interests (Art. 6(1)(f)). Upon objection, we will cease processing unless demonstrating compelling legitimate grounds that override your interests.
  • Right to Withdraw Consent (Art. 7(3)): Where processing relies on your consent (e.g., voluntary newsletter), you may withdraw it at any time with immediate effect for the future.
Right to Lodge a Complaint with a Supervisory Authority If you believe that our processing infringes your rights under the GDPR, you have the right to lodge a complaint with the competent supervisory authority:

In Poland: Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa · Web: uodo.gov.pl
You may also appeal to the national data protection authority in your EU member state of habitual residence or place of business.

10

Technical Security & Encryption Measures

To safeguard against unauthorized access, destruction, or interception, KonnectaMED maintains comprehensive technical and organizational controls:

  • Transport Layer Security (TLS/SSL): 256-bit cryptographic encryption across all web traffic, APIs, and administrative access points.
  • Role-Based Access Control (RBAC): Access to wholesale client directories and order ledgers is restricted strictly to authorized logistics, compliance, and accounting personnel on a need-to-know basis.
  • Network Protection & Firewalls: Continuous intrusion detection, DDoS mitigation, and daily automated encrypted off-site backups.
  • Data Segregation: Distinct logical isolation between public informational browsing logs and confidential B2B purchasing databases.
11

Data Protection Inquiries & Contact Desk

To exercise any of your GDPR rights, update your registered company profile, or seek clarification regarding our health vigilance data practices, please contact our designated privacy team directly:

KonnectaMED Data Protection Desk Email: privacy@konnectamed.eu
Postal Address: KonnectaMED Sp. z o.o. — Legal & Compliance, ul. Kasprzaka 70/10, 41-303 Dąbrowa Górnicza, Poland
Response Time: Within one calendar month pursuant to Article 12(3) GDPR (free of charge).
Submit a GDPR Request