Privacy policy of the Diamond Hub service
Last update: September 11, 2026.
1. Data Administrator
The administrator of personal data is:
DIAMOND HUB LLC.
Closed Street 10/1.5
30-554 Kraków, Poland
KRS: 0001249560
NIP: 6793369446
REGON: 545084383
Contact regarding personal data matters:
Hereinafter, the administrator is referred to as "Diamond Hub" or "Administrator".
2. Scope of the policy
The policy describes the processing of data of individuals using the Diamond Hub service, in particular:
- individuals submitting a contact form or a B2B access request;
- people submitting applications through the form in the Diamond Hub advertisement on Facebook or Instagram;
- representatives, employees, and collaborators of companies interested in cooperation;
- users invited to the B2B platform;
- people placing orders and users representing companies that have entered into a contract with Diamond Hub, including individuals designated as recipients of shipments;
- individuals contacting Diamond Hub via email;
- people contacting Diamond Hub through Diamond Hub's profiles on Facebook or Instagram (messages, comments, reactions);
- visitors to the website.
3. What data do we process
Depending on how the service is used, we may process:
- first and last name;
- business email address;
- phone number;
- company name;
- NIP or VAT ID;
- position or role in the company, if provided;
- subject, category, and content of the request;
- data provided in the form in the advertisement on Facebook or Instagram: first and last name, email address, phone number, company name, and answers to the form questions;
- account and access data for the platform;
- data on orders, invoices, payments, and deliveries: delivery address, billing information, account number, order history, and settlements;
- history of correspondence and handling of the request;
- information about the verification of the company;
- data needed to verify the company and compliance with sanctions regulations: data of individuals representing the company and beneficial owners obtained from KRS, CEIDG, CRBR, VAT taxpayer lists, VIES, and sanction lists;
- IP address, browser type, session identifiers, and security events;
- other information voluntarily provided in the message.
Please do not provide special category data in the form, such as information about health, beliefs, origin, convictions, or identity documents.
4. Data sources
We primarily obtain data directly from the person using the form, email, or platform.
If the application was submitted through the form in the advertisement on Facebook or Instagram, we receive the data from Meta Platforms Ireland Limited to the extent filled out by the person in the form. Meta provides us with this data at our request; at the same time, as the platform operator, it processes user data under the terms described in Meta's Privacy Policy.
For company verification, we may also use public registers, such as KRS, CEIDG, VAT taxpayer lists, or VIES. From the registers, we can obtain the company name, address, registration identifiers, business status, and data of authorized representatives.
In order to verify the company and ensure transaction compliance with sanctions regulations, we may use the Central Register of Beneficial Owners and publicly available sanction lists of the European Union and the Republic of Poland.
5. Purposes and legal bases for processing
We process data for the following purposes:
Handling B2B inquiries and requests
Data is processed to provide responses, qualify requests, verify the company, and take actions before entering into a contract.
As part of handling the request, we contact the person via email or phone, using the data provided in the request, for the purpose of verifying the company, determining the scope of access, and answering questions. This also applies to requests sent through the form in advertisements on Facebook or Instagram.
The basis is:
- Article 6(1)(b) of the GDPR – taking actions at the request of the data subject before entering into a contract;
- Article 6(1)(f) of the GDPR – the legitimate interest of Diamond Hub in handling contact with company representatives and developing business relationships.
Creation and management of a B2B account
Data is processed to verify the user, send an invitation, create an account, authenticate, and provide the appropriate features of the platform.
The basis is Article 6(1)(b) of the GDPR or – in the case of a company representative – Article 6(1)(f) of the GDPR.
Submitting the form alone does not automatically create an account. Access is granted after manual verification and sending an invitation.
Order fulfillment and settlements
Data is processed for the purpose of accepting and confirming the order, issuing pro forma invoices and invoices, handling payments, preparing and delivering the shipment, and managing complaints and settlements.
The basis is Article 6(1)(b) of the GDPR (contract) and Article 6(1)(c) of the GDPR regarding tax and accounting obligations, including issuing invoices in the National e-Invoice System. We provide the recipient's data to the carrier to the extent necessary for delivery.
Company verification, compliance with sanctions regulations, and prevention of abuse
Before establishing cooperation and during it, we verify the company, the individuals representing it, and the beneficial owners in public registers and on sanction lists.
The basis is Article 6(1)(c) of the GDPR to the extent that the obligation arises from the EU restrictive measures regulations, and Article 6(1)(f) of the GDPR, which is the legitimate interest of Diamond Hub in preventing fraud and ensuring compliance of transactions with the law.
Service Security
Technical data is processed to protect forms, accounts, and infrastructure from spam, bots, abuse, attempts of unauthorized access, and other threats.
The basis is Article 6(1)(f) of the GDPR – the legitimate interest of the Administrator in ensuring the security of systems and information.
Transactional Correspondence
The email address and the content of the message may be processed for sending invitations, password resets, confirmations, and other messages related to account operation or handling the request.
The basis is Article 6(1)(b) or (f) of the GDPR.
Statistics and measurement of advertising effectiveness
We use Plausible analytics, which does not use cookies and does not identify individuals: the IP address is used solely to create an anonymized identifier valid for one day and is not stored. The basis is Article 6(1)(f) of the GDPR, which is the legitimate interest in measuring traffic on the site.
The Google Ads tag also operates on the service's pages to measure the effectiveness of our ads. Until the user consents in the cookie banner, the tag does not save cookies and sends only events without identifiers saved in cookies to Google, along with technical connection data such as IP address and browser information. The basis is Article 6(1)(f) of the GDPR, which is the legitimate interest in measuring the effectiveness of ads.
Upon giving consent, the tag saves Google advertising cookies. The basis is consent (Article 6(1)(a) of the GDPR and Article 399 of the Electronic Communications Act), which can be withdrawn at any time in the manner described in point 13.
Diamond Hub profiles on Facebook and Instagram
We maintain profiles on Facebook and Instagram. We process the data of individuals who write to us via Messenger or Instagram, comment, or react to our content for the purpose of responding and contacting. The basis is Article 6(1)(f) of the GDPR.
We process profile statistics (Page Insights) jointly with Meta Platforms Ireland Limited as joint controllers, under the terms specified in the agreement Page Insights Controller Addendum. Meta responds to requests from individuals regarding these statistics.
Ads on Facebook and Instagram are displayed by Meta according to its own rules. Diamond Hub receives only aggregated campaign statistics, and personal data only when the individual submits a form in the ad.
Legal Obligations and Claims Enforcement
Data may be processed to fulfill tax, accounting, and other legal obligations, as well as to establish, pursue, or defend claims.
The basis is Article 6(1)(c) and (f) of the GDPR.
Information about the offer
If a person has given consent, we send commercial information about the Diamond Hub offer via email or contact them by phone, in accordance with the scope of the granted consent. The basis is Article 6(1)(a) of the GDPR and the consent referred to in Article 398 of the Electronic Communications Law. Consent is voluntary and does not condition the handling of the application; it can be withdrawn at any time by writing to [email protected], and regarding direct marketing, an objection can also be raised (Article 21(2) of the GDPR).
6. Is providing data mandatory?
Providing data marked as required is voluntary but necessary for handling the request and verifying the company. Without providing them, we may not be able to respond or grant B2B access.
Providing a phone number is optional unless explicitly stated otherwise in a specific process.
7. Data Recipients
Access to the data may be granted to:
- authorized employees and collaborators of Diamond Hub;
- entities providing hosting, database, and infrastructure maintenance;
- transactional email providers;
- anti-spam and bot protection providers;
- advertising and analytical tool providers;
- payment operators, banks, and carriers as necessary for the settlement and delivery of the order;
- entities providing IT, legal, accounting, or auditing services, including accounting offices;
- tax authorities, also through the National e-Invoice System, to the extent resulting from regulations;
- public authorities, if the obligation to provide arises from the law.
Currently, we particularly use:
- Railway Corporation – hosting of Odoo applications, databases, and files; DPA Railway;
- Plus Five Five, Inc. (Resend) – delivery of transactional messages; DPA Resend;
- Cloudflare, Inc. – form protection using Cloudflare Turnstile; Turnstile privacy information.
- Meta Platforms Ireland Limited (Ireland) – provider of forms in ads on Facebook and Instagram and operator of our profiles; in terms of delivering the submission, acts on our behalf, and in terms of its own platform as an administrator; data may be transferred to Meta Platforms, Inc. (USA) based on certification under the EU-U.S. Data Privacy Framework and standard contractual clauses; Meta Privacy Policy;
- Google Ireland Limited (Ireland) – Google Ads tag for measuring ad effectiveness, described in point 5; data may be transferred to Google LLC (USA) based on certification under the EU-U.S. Data Privacy Framework; Google Privacy Policy;
- Plausible Insights OÜ (Estonia) – cookie-free traffic analytics, data processed in the European Union; Plausible data policy.
Odoo is maintained in its own instance of Diamond Hub on Railway infrastructure. This does not automatically mean data is transferred to Odoo S.A.
8. Cloudflare Turnstile
The service uses Cloudflare Turnstile to distinguish users from automated bots and to protect forms from abuse.
Turnstile may process, among other things, IP address, browser headers, User-Agent, TLS signals, site key, and the referring address. Cloudflare indicates that this data is used for detecting and blocking bots, not for advertising to users.
The basis for processing by Diamond Hub is Article 6(1)(f) of the GDPR – ensuring the security of the service.
9. Data transfer outside the European Economic Area
Some infrastructure providers have their headquarters in the United States or use subcontractors operating outside the European Economic Area.
If such a transfer occurs, it is based on an appropriate legal mechanism, in particular the standard contractual clauses approved by the European Commission or a decision stating an adequate level of protection, where applicable.
Meta Platforms, Inc., Google LLC, and Cloudflare, Inc. are certified under the EU-U.S. Data Privacy Framework (European Commission decision of July 10, 2023). Transfers to Railway Corporation and Plus Five Five, Inc. (Resend) occur based on standard contractual clauses included in the entrusted agreements mentioned in point 7.
Detailed information can be found in the data processing documents of individual providers, as indicated in point 7.
10. Data retention period
We retain data no longer than necessary for the purpose for which it was collected:
- submissions that did not lead to cooperation – generally up to 12 months from the closure of the submission or the last contact;
- submissions from forms in ads on Facebook or Instagram – on the Meta side for up to 90 days from the submission of the form, on the Diamond Hub side under the same terms as for other submissions;
- data of an active B2B account – for the duration of the account and the business relationship;
- data after the end of cooperation – until the expiration of the relevant limitation periods for claims;
- order, invoice and settlement data as well as other documents required by tax or accounting regulations – for 5 years, counting from the end of the calendar year in which the tax payment deadline expired, or for another period resulting from the relevant regulations;
- company verification data and compliance with sanctions regulations – for the duration of cooperation and 5 years after its termination;
- security logs – typically up to 90 days, unless longer retention is necessary to clarify an incident or defend against claims;
- data processed on the basis of consent – until it is withdrawn, and then to the extent necessary to demonstrate the lawfulness of the previous processing.
After the appropriate period, the data is deleted or anonymized.
11. Rights of the data subject
The data subject may have the rights to:
- obtain information and access to data;
- receive a copy of the data;
- correction of incorrect data;
- deletion of data;
- restriction of processing;
- data portability when processing is based on consent or contract and is carried out in an automated manner;
- objecting to processing based on legitimate interests;
- to raise an objection to the processing of data for direct marketing purposes;
- withdrawal of consent at any time, if processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
To exercise these rights, please write to: [email protected]. We may ask for information needed to confirm the identity of the person making the request.
The individual also has the right to lodge a complaint with the President of the Personal Data Protection Office: uodo.gov.pl.
12. Automated decision-making
Diamond Hub does not make decisions that have legal effects or similarly significantly affect users solely in an automated manner.
Cloudflare Turnstile only automatically assesses whether a request may come from a bot. This assessment serves the security of the form and does not constitute a business decision regarding the user or their company.
13. Cookies and technical data
The service may use necessary cookies and similar mechanisms needed to:
- maintain the session;
- log in and secure the account;
- remember the language;
- operate the cart;
- protect forms and prevent abuse.
We use Plausible analytics, which does not save cookies. The Google Ads tag also operates on the pages: as long as the user does not give consent in the cookie banner, the tag does not save cookies and sends only events without identifiers saved in cookies to Google, and after consent is given, it saves Google advertising cookies used to measure the effectiveness of ads.
Consent can be withdrawn at any time by deleting the service cookies in the browser settings. The cookie banner will then be displayed again. A detailed list of files includes Cookie Policy.
14. Data Security
We implement technical and organizational measures appropriate to the nature of the data and the risk, including access control, individual employee accounts, multi-factor authentication, transmission encryption, backups, and restriction of permissions.
However, no method of transmitting or storing data guarantees complete security.
15. Policy Changes
The policy may be updated in the event of changes in the law, the way the service operates, or the suppliers used.
The date of the last update is at the beginning of the document.