Privacy Policy
Document ID: FDT-PRIV-2026-v1.3-EN
Version: 1.3
Last updated: 13 July 2026
1. Controller and contact
This Policy explains how Jan Panek, autónomo, trading as Freeze-drying.tech, Liofilizacion.es and Liofilizacao.pt, processes personal data relating to website visitors, enquirers, business buyers, representatives, suppliers and service contacts.
Controller: Jan Panek, autónomo
Spanish NIF: Y2362080V
EU VAT number: ESY2362080V
Address: Rotonda de Versalles 23, 28512 Villar del Olmo, Madrid, Spain
Privacy contact: [email protected]
Telephone: +34 614 332 324
We are established in Spain and apply the GDPR, Spanish data-protection and electronic-communications rules and, where relevant to activities directed to Portugal, applicable Portuguese rules.
2. Relationship with the Cookie Policy
This Policy covers personal-data processing. The Cookie Policy separately explains cookies, pixels, local storage, analytics, session replay, advertising and payment-domain technologies.
A GDPR lawful basis does not remove a separate consent requirement for non-essential access to or storage of information on a user’s device. Non-essential analytics, session replay and advertising technologies are therefore disabled until the relevant consent is given.
3. Data we collect
3.1 Enquiries and quotations
We may collect:
- name, company, role and business activity;
- email, telephone and other business contact details;
- country and optional delivery city/postcode;
- product interest, intended use, production volume and technical requirements;
- messages, attachments and correspondence;
- source, campaign and referral information.
3.2 B2B eligibility, orders and contract evidence
Where an order request is made, we may collect:
- business/consumer-status declaration;
- legal and trading name;
- company or professional registration information;
- NIF/VAT number and country;
- VIES request, result, validation time and returned name/address where available;
- billing and delivery address;
- representative name, position and authority declaration;
- intended business use;
- Products, configuration, displayed price and tax indication;
- accepted Terms document ID, version, language, URL, checkbox wording, timestamp, IP, user-agent and document/text hash or snapshot;
- Order Acknowledgement, Order Confirmation, changes, cancellation and acceptance records.
3.3 Payment, invoicing, tax and logistics
We may collect:
- Stripe customer/payment/session identifiers, authorisation, capture, refund, dispute and fraud-risk status;
- limited card metadata supplied by Stripe, such as card brand and last four digits, where available;
- we do not receive or store full card numbers or security codes through Stripe’s hosted checkout;
- invoice, pro forma, advance, final and corrective-document information;
- tax classification, VAT basis and tax-review status;
- expected and actual dispatch country, destination, fulfilment route, Incoterm and named place;
- carrier, tracking, delivery, importer/exporter and customs information;
- transport evidence, customs declarations, MRN/DUA and proof of delivery;
- warranty, support, commissioning and service records.
3.4 Technical, security and consent data
We may collect:
- IP address and approximate location;
- device, browser, operating system and user-agent;
- pages, timestamps, referrer and UTM parameters;
- Cloudflare security, Turnstile, bot and honeypot results;
- application, error, security and audit logs;
- cookie and marketing-consent records.
3.5 Analytics, session replay and advertising
After the relevant cookie consent, Google Analytics 4, Microsoft Clarity and advertising technologies may process identifiers, pages, interactions, device data, approximate location and campaign data.
Microsoft Clarity must use strict masking and must not load on contact, quote, checkout or other form-bearing pages. We do not permit form fields, free-text messages, email addresses, telephone numbers, VAT numbers, order identifiers or payment information to be transmitted to analytics or advertising tools.
3.6 Email engagement tracking
Email open and individual click tracking are currently disabled. If we propose enabling them in future, we will first implement separate optional consent and update this Policy. Ordinary delivery, bounce and security logs may still be processed to deliver messages and protect the service.
4. Purposes, lawful bases and retention
| Purpose | Lawful basis | Typical retention |
|---|---|---|
| Respond to business enquiries | GDPR Art. 6(1)(f): legitimate interest in responding and operating a B2B service | Up to 18 months from last meaningful contact |
| Prepare a quotation or requested pre-contract step for an individual contracting in their own name | Art. 6(1)(b) | Up to 18 months if no order; order record if converted |
| Communicate with directors, employees or representatives of a company | Art. 6(1)(f): legitimate interest in business communications and contract administration | Enquiry period or order record |
| Verify B2B eligibility, authority, VAT identity and inconsistent information | Art. 6(1)(f): fraud, misuse, tax-risk and contract protection | 18 months if no accepted order; generally six years with an accepted order or dispute |
| Accept, perform and administer an order for an individual/sole trader | Art. 6(1)(b) | Generally six years after the relevant financial year, longer for an active claim |
| Administer a corporate order through its representatives | Art. 6(1)(f) | Generally six years after the relevant financial year, longer for an active claim |
| Payment authorisation, capture, refund, chargeback and fraud prevention | Art. 6(1)(b) and 6(1)(f) | Transaction records generally six years; provider records under provider terms |
| Invoicing, accounting, VAT, VIES, customs and regulatory compliance | Art. 6(1)(c) | Statutory period, generally four to six years and longer where an audit or claim requires |
| Direct manufacturer fulfilment, freight, customs, delivery and installation | Art. 6(1)(b) for an individual contracting party; Art. 6(1)(f) for corporate representatives | Order and claim period |
| Warranty, technical support and legal claims | Art. 6(1)(b), 6(1)(f) and 6(1)(c) where applicable | Warranty/support period plus applicable claim period |
| Website and information security | Art. 6(1)(f) | Normally up to 12 months unless an incident requires longer |
| Analytics, session replay and advertising | Art. 6(1)(a) consent, plus ePrivacy consent | Until consent withdrawal and according to the Cookie Policy/settings |
| Evidence of consent or withdrawal | Art. 6(1)(c) and 6(1)(f) | Generally four years after expiry or withdrawal |
| Direct electronic marketing | Art. 6(1)(a), unless another lawful route is documented | Until withdrawal; suppression record retained to respect the objection |
We may retain information longer where needed for a legal claim, audit, fraud investigation, tax review or enforcement. We delete or anonymise data when no longer required.
5. B2B checkout and automated routing
The online checkout is limited to declared business/professional buyers. Automated rules may:
- block a declared Consumer from online payment;
- validate or reject a VAT number;
- compare VAT country, destination and business details;
- flag an order for business, fraud, sanctions or tax review;
- prevent capture or invoice generation while review is pending.
These rules do not themselves form the sales contract. A human-authorised written Order Confirmation is required. We do not use solely automated decision-making that produces legal or similarly significant effects without meaningful human involvement.
6. Recipients and service providers
We disclose data only where necessary to operate the service, assess or perform an order, meet legal duties or protect claims.
Recipients may include:
- Stripe for hosted card checkout, payment authorisation, capture, fraud prevention, disputes and regulatory compliance. Stripe may act as processor and, for certain payment/fraud purposes, as an independent controller;
- BitFactura / InvoiceOcean for invoice and accounting-document generation;
- Supabase for database and application infrastructure;
- Cloudflare for hosting/security, Turnstile, content delivery, consent/tag management and technical logs;
- Resend for transactional email delivery;
- Kommo CRM and our email/mailbox provider for lead, customer and communication management;
- Google, Microsoft and Meta only for consented analytics or advertising purposes described in the Cookie Policy;
- manufacturers and suppliers in Poland, Czechia, Slovenia and other relevant locations, who may receive configuration, contact and delivery information for direct fulfilment, warranty or support;
- carriers, freight forwarders, customs representatives, insurers, installers and service technicians;
- VIES, tax, customs and public authorities;
- accountants, gestoría, legal advisers, debt-recovery providers, banks and insurers.
Providers receive only data reasonably necessary for their role.
7. International transfers
We prefer EU/EEA processing and EU regions where available. Some providers or group entities may process data outside the EEA.
Where required, transfers rely on an adequacy decision, the EU–US Data Privacy Framework for certified entities, Standard Contractual Clauses or another lawful safeguard. Details of relevant safeguards may be requested through the privacy contact.
Direct fulfilment may require data to be sent to a manufacturer, carrier, customs representative or destination-country service provider outside the EEA. We limit the data to what is necessary and apply the appropriate legal mechanism where required.
8. Security
We use measures appropriate to the risk, including access controls, encrypted transport, provider security, logging, role restrictions, anti-bot controls, backups and separation of payment-card entry from our systems.
No internet system is completely secure. Please do not send card details, passwords, health data or other unnecessary sensitive information in free-text fields.
9. Your rights
Subject to applicable law, you may request:
- access;
- correction;
- deletion;
- restriction;
- portability;
- objection to processing based on legitimate interests;
- withdrawal of consent at any time, without affecting prior lawful processing;
- information about safeguards for international transfers.
Contact [email protected]. We may request reasonable proof of identity.
You may complain to the Spanish Data Protection Agency (AEPD) or to the supervisory authority in your habitual residence or place of the alleged infringement. Users in Portugal may also contact the CNPD.
10. Marketing choices
Submitting an enquiry does not automatically subscribe you to marketing.
Where marketing consent is offered, it is optional and unticked. You may withdraw through the message link or by contacting us. We may keep a minimal suppression record so that we do not contact you again contrary to your request.
11. Children
The websites and Products are intended for business users, not children. We do not knowingly collect children’s data.
12. Controller or business-structure changes
If the activity transfers to a Spanish company or another lawful successor, personal data may transfer as part of that business reorganisation, subject to applicable notice and legal requirements.
13. Changes
We may update this Policy for legal, technical or operational changes. The current version and date appear at the top.
14. Contact
Jan Panek, autónomo
Rotonda de Versalles 23, 28512 Villar del Olmo, Madrid, Spain
[email protected]
+34 614 332 324