1. Controller and contact
For enquiries, account administration, billing, website security and Avantwerk's own business records, the controller is Bennovate sp. z o.o., ul. Christiana Andersena 25, 94-118 Łódź, Poland, KRS 0000597272, NIP 7272799328, REGON 363700466, operating the Avantwerk brand. Data-protection contact: [email protected].
For personal data a business Customer places in its Avantwerk CRM, the Customer normally decides the purposes and means and is controller; Bennovate acts as processor under the CRM DPA. This notice does not replace that DPA or a Customer's own privacy notice.
2. Data, purposes and legal bases
| Context | Data | Purpose | Legal basis |
|---|---|---|---|
| Website enquiry, demo or contact | name, business contact details, organisation, message and response history | answer the request, qualify an organisational need and prepare an Order | steps requested before contract; legitimate interests in B2B communication |
| Account and contract administration | authorised-user, organisation, access, configuration and support records | provide, secure and support the ordered service | contract; legitimate interests in service security and administration |
| Billing and compliance | invoicing, payment status, tax and transaction evidence | invoice, account, prevent fraud and meet legal duties | contract; legal obligation; legitimate interests |
| Service communications | business contact details and service messages | operational notices, security and support | contract; legitimate interests |
| Marketing | business contact details, preference and consent evidence | permitted B2B marketing | consent where required; otherwise the applicable lawful basis and channel rule |
| Website technology | IP address, request headers, security logs, consent choice and analytics events if enabled | deliver and protect the site; optional measurement only after the required consent | legitimate interests for strictly necessary security; consent for non-essential storage or access |
Required fields are identified at collection. Without them, Bennovate may be unable to respond, open an account, accept an Order or meet a legal requirement.
3. Sources and recipients
Data come from the individual, their organisation, authorised implementation partners, connected services they select, payment-status providers and technical logs. Bennovate does not sell personal data.
Recipients are limited to personnel and authorised contractors who need access, professional advisers and public authorities where law requires it, plus vendors actually used for the relevant context. Current controller-context vendors may include Stripe for payment processing, Cloudflare for website delivery and security, and Hetzner for Bennovate-operated infrastructure. The CRM DPA and Processor and Vendor Register govern Customer CRM processing. A tool used elsewhere by Bennovate is not automatically part of a Customer's CRM chain.
4. International transfers
Where a recipient is outside the EEA or the UK, Bennovate uses the applicable adequacy decision or contractual safeguard, such as the EU Standard Contractual Clauses or a UK IDTA/Addendum, and supplementary measures where required. Information about the safeguard for a particular transfer may be requested at [email protected], subject to lawful confidentiality limits.
5. Retention
Data are kept only for the purpose, contract, legal duty, security need or documented claim period that applies. Enquiry data are removed when no longer reasonably needed; account and project records follow the contract and documented operational need; tax and accounting records follow mandatory law; consent evidence is retained while needed to demonstrate the choice. Customer CRM data follow the DPA, Order and Data Retention and Deletion Policy. Supplier recovery windows are not Bennovate retention promises.
6. Rights
Subject to the applicable law and lawful exceptions, a person may request access, rectification, erasure, restriction, portability or objection, and may withdraw consent without affecting earlier processing. The right to object to direct marketing may be exercised at any time. Requests go to [email protected]. Identity may be verified proportionately.
Complaints may be made to Poland's President of the Personal Data Protection Office (UODO). Where UK GDPR applies, a complaint may also be made to the Information Commissioner's Office (ICO).
7. Automated decisions and AI
Website enquiries and administrative records may be routed, classified or assisted by automation. Bennovate does not make a solely automated decision about these records that produces legal or similarly significant effects unless the specific process, logic, consequence, lawful basis and safeguard are disclosed before use. Customer-enabled CRM automation is configured for the Customer and remains subject to the Customer's instructions and notice duties.
8. UK representative status
Bennovate is established in Poland and the current corporate SSOT contains no recorded UK representative appointment. UK GDPR Article 27 may require a UK representative where a non-UK organisation offers services to individuals in the UK, unless a documented exception applies. Until an appointment or a qualified, recorded exception decision exists, UK data-protection enquiries may be sent directly to [email protected]. This paragraph records the present gap; it does not claim that the statutory requirement is satisfied.
9. Cookies and changes
The separate Cookie Policy explains storage and access technologies on the public domains. Material new purposes will be notified before they begin. The current version and effective date appear at the top of this notice.
