This Policy explains how IoT Squad P.S.A. uses personal data when you visit our websites, use our hardware catalogue or other online services, contact us, or work with us.
It applies to iotsquad.tech, its language versions and subdomains, including shop.iotsquad.tech, and other IoT Squad services that link to this Policy.
IoT Squad P.S.A.
ul. Kijowska 44, 85-703 Bydgoszcz, Poland
Privacy questions:
Depending on how you interact with us, we may process:
Please do not send us special categories of personal data covered by Article 9 GDPR unless they are genuinely necessary for a particular matter.
Usually, we receive your data directly from you.
In B2B relationships, we may also receive professional contact details from your employer, colleagues, customers, suppliers or business partners, or from publicly available professional sources such as company websites, business registers and professional profiles.
If we received your data from someone else or from a public source, we provide the information required by Article 14 GDPR where applicable.
We process personal data only where we have a legal basis under the GDPR.
Websites and security. We use technical data to operate and secure our websites and services, prevent misuse and diagnose problems. Our legal basis is our legitimate interest in providing secure and reliable services.
Enquiries and correspondence. We use your information to answer questions, prepare quotations, discuss projects and maintain business relationships. Depending on the situation, this is necessary to take steps towards a contract or is based on our legitimate interest in conducting business and communicating with customers, suppliers and partners.
Business contacts. If you represent a company or another organisation, we process your professional contact details on the basis of our legitimate interest in managing our relationship with that organisation.
Accounts and orders. We use your data to manage accounts, quotations and orders, arrange delivery and payment, and provide support. Where you personally are the contracting party, this may be necessary to perform our contract with you. Where you represent an organisation, we normally rely on our legitimate interest in managing that business relationship.
Legal obligations. We process information where required by tax, accounting or other applicable laws.
Security and legal claims. We may retain or use information to prevent fraud, investigate security incidents, protect our rights and establish, exercise or defend legal claims. Our legal basis is our legitimate interest in protecting the business and our rights.
Marketing. We may process professional contact details to market our own products and services. Our legal basis is our legitimate interest in direct marketing, or your consent where you have signed up to hear from us.
We use e-mail, telephone, messaging or similar electronic channels for commercial information or direct marketing only where permitted by applicable electronic communications law, including obtaining prior consent where required.
Providing your data is voluntary. However, without certain information we may not be able to answer an enquiry, prepare a quotation, open an account or process an order. Where the law requires us to collect particular information, we will tell you at the time.
We use cookies and similar technologies.
Technologies that are strictly necessary for security, login, sessions, shopping baskets, privacy choices or other functions requested by you may operate without optional consent where permitted by law.
Non-essential analytics, functional and marketing technologies only run after you agree.
Where a service uses non-essential cookies or similar technologies, we provide controls that allow you to accept, reject or manage them. You can change or withdraw your choices using the cookie controls available on that service.
Information about the cookies and similar technologies used by a particular service, including their purposes and retention periods, is available through those controls or on the relevant service.
Where necessary, we may share data with providers that support our business, such as:
Providers processing data on our behalf are required to protect it and process it only for the agreed purposes and in accordance with applicable law.
Some service providers may process or access personal data outside the European Economic Area.
Where this happens, we use a transfer mechanism permitted by the GDPR, such as a European Commission adequacy decision or Standard Contractual Clauses, together with additional safeguards where necessary.
You can contact us for information about the safeguards applying to a particular transfer.
We keep personal data only for as long as it is needed for the purpose for which it was collected.
Business correspondence and relationship records may be retained while the relationship remains relevant and afterwards where necessary for legal record-keeping or to establish, exercise or defend legal claims.
Contracts, orders, invoices and payment information are retained for the periods required by applicable law and for relevant limitation periods.
Account data is normally kept while the account is active, although transaction or legal records may need to be kept longer.
Where processing is based on consent, we stop that processing when consent is withdrawn unless another legal basis requires us to retain the information.
Marketing processing stops when you object or withdraw the relevant consent. We may keep a minimal record of your decision so that it continues to be respected.
Depending on the circumstances, you may have the right to:
Withdrawing your consent does not affect the lawfulness of processing carried out before it was withdrawn.
You may object to direct marketing at any time. If you do, we will stop using your personal data for direct marketing.
You may also object to processing based on our legitimate interests where your particular situation gives you grounds to do so.
To exercise your rights, contact .
You also have the right to complain to a data protection supervisory authority. In Poland this is:
President of the Personal Data Protection Office
(Prezes Urzędu Ochrony Danych Osobowych)
ul. Stanisława Moniuszki 1A
00-014 Warsaw, Poland
You may also be entitled to complain to the supervisory authority in the country where you live or work.
We do not make decisions about individuals based solely on automated processing where those decisions produce legal or similarly significant effects within the meaning of Article 22 GDPR.
We may update this Policy when our services, processing activities or applicable law change.
The current version and its revision date will always be published here.
Last updated: 4 September 2026
Privacy Policy © IoT Squad 2020–2026
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |