Privacy & Data Protection Policy — SPEEDx

SPEEDx

Privacy & Data Protection Policy

SPEEDx Platform
Effective: 21 May 2026
GDPR Compliant
B2B Only

This Privacy and Data Protection Policy („Policy”) describes how APPGRADE Sp. z o.o. (operator of the SPEEDx platform, NIP: PL6342979935, Katowice, Poland) collects, processes, and protects data in the context of providing its B2B SaaS services. This Policy applies exclusively to business clients and their authorised representatives. It is drafted in compliance with Regulation (EU) 2016/679 (GDPR) and applicable Polish data protection law.

1Data Controller

The Data Controller for personal data processed through the SPEEDx platform is:

APPGRADE Sp. z o.o.
Katowice, Poland
NIP: PL6342979935
Email: info@speedx.com.pl

The platform is operated under the SPEEDx brand, owned exclusively by APPGRADE Sp. z o.o.

2Categories of Data Processed

SPEEDx processes two categories of data:

A. Personal data of authorised representatives (contact persons acting on behalf of the Client company):

Data categoryPurposeLegal basis
Full nameAccount identification, report personalisationContract performance (Art. 6(1)(b) GDPR)
Business email addressAccount access, delivery of reports and notificationsContract performance (Art. 6(1)(b) GDPR)
Business phone number (if provided)Support and account verificationLegitimate interest (Art. 6(1)(f) GDPR)

B. Business data provided by the Client (not personal data under GDPR, but processed under confidentiality obligations):

  • Company name, registered address, VAT ID
  • Tender documentation (RFQ, SOP, TSC, annexes) uploaded for analysis
  • Transport lane data (loading/delivery locations, postal codes, countries, equipment types, shipment volumes)
  • Carrier rate data and historical shipment data, where included in uploaded documents

3Purposes and Legal Bases for Processing

PurposeLegal basis
Registration and account managementContract performance (Art. 6(1)(b))
Delivery of analysis reports and platform outputsContract performance (Art. 6(1)(b))
Sending transactional emails (reports, lane selection, geocoding results)Contract performance (Art. 6(1)(b))
Maintenance of lane distance cache for service optimisationLegitimate interest (Art. 6(1)(f))
Compliance with legal obligations (invoicing, record keeping)Legal obligation (Art. 6(1)(c))
Platform security and fraud preventionLegitimate interest (Art. 6(1)(f))

4Data Retention

  • Account data — retained for the duration of the active account relationship and for 3 years after account closure, in accordance with applicable commercial and tax law.
  • Submission data and uploaded documents — retained for 90 days from submission, unless the Client requests earlier deletion.
  • Lane distance cache — retained indefinitely in anonymised form (country/postal code pairs and distances only, without client identification) to optimise future processing.
  • Financial records — retained for 5 years as required by Polish accounting law.

5Data Processors and Third-Party Services

SPEEDx uses the following third-party processors in the delivery of its services:

ProcessorRoleLocation
Google LLC (Google Workspace, Google Drive, Google Sheets)Document storage, data storage, workflow dataEEA / USA (SCCs apply)
OpenAI, L.P.AI-powered document analysisUSA (SCCs apply)
HERE TechnologiesGeocoding and route distance calculationEEA
n8n GmbH (n8n Cloud)Workflow automation and process orchestrationEEA
Cloudflare, Inc.Network security and CDNEEA / USA (SCCs apply)

All processors are bound by data processing agreements and appropriate safeguards for international transfers where applicable.

6Data Subject Rights

Authorised representatives of Client companies have the following rights under GDPR:

  • Right of access — to obtain confirmation of whether personal data concerning them is processed and to receive a copy.
  • Right to rectification — to request correction of inaccurate personal data.
  • Right to erasure — to request deletion of personal data where retention is no longer necessary or lawful.
  • Right to restriction of processing — in circumstances defined by GDPR Art. 18.
  • Right to data portability — to receive personal data in a structured, machine-readable format.
  • Right to object — to processing based on legitimate interest.

Requests should be submitted to: info@speedx.com.pl. SPEEDx will respond within 30 days.

If you believe your rights have not been respected, you have the right to lodge a complaint with the Polish supervisory authority: Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.

7Security

SPEEDx implements appropriate technical and organisational measures to protect processed data, including:

  • Logical data isolation between client accounts in the multi-tenant environment.
  • Encrypted data transmission (TLS) for all platform communications.
  • Access controls limiting data access to authorised personnel only.
  • Regular review of third-party processor security standards.

8Cookies and Tracking

The SPEEDx platform uses only technically necessary cookies required for session management and authentication. No advertising cookies, cross-site tracking, or profiling are used. The SPEEDx marketing website (speedx.com.pl) may use analytics tools; a separate cookie notice is provided on that site.

9Changes to this Policy

SPEEDx reserves the right to update this Policy to reflect changes in the platform, applicable law, or processing activities. Clients will be notified of material changes by email. The current version is always available at speedx.com.pl.

SPEEDx — Privacy & Data Protection Policy · Effective 21 May 2026speedx.com.pl · APPGRADE Sp. z o.o. · NIP: PL6342979935