Data controller
The controller of personal data processed in connection with SFXM.NETWORK is SYSTEM FX MANAGEMENT BEATA SUCHENEK, ul. Grochowska 23/31, 04-186 Warszawa, Polska, NIP 1132341721, REGON 015262665 (the “Controller”).
Scope of this Policy
This Policy describes processing connected with the public SFXM.NETWORK service, including the initial SFXM Business Signal, company applications, B2B communication, service security and privacy settings.
SFXM.NETWORK is a B2B service intended for adults acting on behalf of companies and organizations. Information that identifies a natural person remains personal data even when it is used in a business context.
Data we may process
- the content and context of an initial SFXM Business Signal, including direction, title, market, description and earlier business choices;
- application data: name, position, company, company website, business email address, country and stated business need;
- data related to SFXM Company Verification, including company identification and registry data, verification status and history, information about persons acting for the company, and additional information or documents supplied to resolve discrepancies;
- membership payment and settlement data if paid membership is launched, including the payer name or identifier, transaction reference or payment title, account number to the extent made available to the Operator by the bank or settlement system, amount, currency, payment date and the result of linking the payment to the company;
- information contained in correspondence;
- technical and security data such as IP address, HTTP request information, timestamps, session identifiers and diagnostic data;
- language, theme and privacy choices stored in the browser;
- analytics or marketing data only if the relevant tools are activated and an appropriate legal basis exists, including consent where required.
- email-verification data: confirmation status, cryptographic token hash, verification-message date, expiry date, confirmation date and delivery status of the verification message;
- Terms-acceptance data: date and time of acceptance and the Terms version identifier applicable to the application;
- re-application control data: a technical company identifier derived from application data, the date of the valid application and the end date of the 12-month re-application period;
Do not submit special-category personal data, trade secrets or other confidential information unless it is necessary for handling the application, verification or membership.
Initial SFXM Business Signal and company application
The process may begin by storing an initial SFXM Business Signal without the contact details requested in the company form. If the user continues, company and contact-person information is stored in the application and linked server-side to the relevant SFXM Business Signal.
The complete application is stored server-side first. Email is a notification channel and is not the only place where the application is retained. At this stage, neither the SFXM Business Signal nor the application data is automatically published as a public company profile.
Business email verification and application validity
After the form is submitted, SFXM.NETWORK sends the stated business email address a message containing the application reference and a secure confirmation link.
The confirmation link is valid for 30 days from submission. The system stores only a cryptographic hash of the verification token, not the token in plain text.
If the email address is not confirmed within that period, the application expires. Personal data contained in the unconfirmed application and the linked initial SFXM Business Signal are removed from the active database, subject to a limited set of technical or security data that must be retained for fraud prevention, compliance with a legal obligation, or the establishment, exercise or defence of legal claims.
Confirming an email address confirms access to that mailbox. It does not by itself prove authority to represent the company and is not a guarantee of the company’s reliability.
Purposes and legal bases
We process data to receive and handle applications, conduct B2B communication, assess whether an application may proceed, perform SFXM Company Verification, confirm company information and required payment-related links, enter into and perform membership agreements, handle payments and settlements, protect the service, prevent abuse and fraud, and establish, exercise or defend legal claims.
Depending on the specific processing activity, the legal basis may include Article 6(1)(b) GDPR for steps necessary to enter into or perform a contract, Article 6(1)(c) GDPR for compliance with legal obligations, including tax and accounting obligations, and Article 6(1)(f) GDPR for the Controller’s legitimate interests, including business communications, company and payment verification, protection of SFXM.NETWORK, fraud prevention and legal-claims protection. Where personal data relates to a person acting on behalf of a company, the applicable basis depends on that person’s role and the purpose of the specific processing. Optional technologies are activated on the basis of consent where consent is required by law.
Recipients
Data may be made available only to recipients needed to operate the service or handle an application, such as hosting, email, IT and security providers, providers of external website resources, professional advisers and authorities entitled to receive data by law, in each case only to the extent necessary. The service currently loads typography resources from Google Fonts; loading those resources may disclose technical connection data to Google, such as an IP address and request information.
If paid membership is launched, recipients may also include banks and providers of settlement, accounting or tax services to the extent necessary for payment processing, verification, bookkeeping and compliance with legal obligations.
Transfers outside the EEA
The core application infrastructure is designed to use hosting in Poland or the European Union. External resources, including Google Fonts, may result in technical connection data being sent to a global provider. Where personal data is transferred outside the European Economic Area, an appropriate transfer mechanism available under the GDPR should be used for the relevant transfer. The Controller aims to reduce unnecessary dependencies on external resources.
Retention
We keep data no longer than necessary for the purpose for which it was collected. Application data and correspondence may be kept while the contact is being handled and afterwards for a period justified by legal-claims protection, documentation of the communication or legal obligations.
Membership, SFXM Company Verification and payment data may be retained for the duration of the relationship with the company and afterwards for periods required by tax, accounting or other legal obligations and for the time necessary to establish, exercise or defend legal claims. Technical and security data is retained for a period proportionate to the diagnostic and protective purpose.
After the email address is confirmed and the review process is completed, where membership is not activated, the Operator may retain a limited control record relating to the company and the history of the valid application for the period needed to enforce the one-valid-application-per-12-months rule and prevent abuse. The record should be limited to data necessary for that purpose.
Your rights
Where provided by the GDPR, you may request access, rectification, erasure, restriction or portability of your data, and you may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Requests can be sent to contact@sfxm.network. We may request information reasonably necessary to verify the identity of the requester.
Supervisory authority
If you believe your personal data is being processed unlawfully, you may lodge a complaint with the competent supervisory authority. In Poland, this is the President of the Personal Data Protection Office (UODO).
Automated decisions
The public application process is not currently used to make decisions about users that produce legal effects solely by automated means. A company’s possible progression to a later stage is not presented as an automatic guarantee or an algorithmic decision.
Cookies and similar technologies
Information about the application session, browser local storage, language and privacy settings and any optional technologies is available in the Cookie Policy.
Language versions and mandatory law
This Policy is available in Polish, English and Simplified Chinese. The English and Chinese texts are translations provided for accessibility. If there is a discrepancy, the Polish text is the reference version to the extent permitted by applicable mandatory law. Mandatory rights available under the laws of another applicable jurisdiction are not waived.
Changes to this Policy
We may update this Policy when the service, providers, technology configuration or applicable law changes. The current version is published on SFXM.NETWORK with its version date.