Privacy Policy

Effective date: 7/7/2025

This Privacy Policy explains how Karavaev Aleksei, sole entrepreneur, trading as NewBusinessAlerts ("we", "our", or "us") processes personal data when providing the NewBusinessAlerts platform (the "Service").

Our Service has two distinct data subjects:

  1. Subscribers – professional bookkeepers (or other professionals) who create an account and pay to receive business leads.
  2. Entrepreneurs – individuals whose business contact details are published in the Polish CEIDG register and whose data we include in our leads.

We comply with the EU General Data Protection Regulation (GDPR) and relevant Czech & Polish data‑protection laws. All terms used in this Policy have the meaning given by the GDPR.


1. Who is the data controller?

Controller: Karavaev Aleksei, sole entrepreneur (trading as NewBusinessAlerts)
Reg. No 23286105
V Bažantnici 2639, Kladno, 27201, Czech Republic
Email: support@newbusinessalerts.com

We have not appointed a Data Protection Officer because our scale of processing does not require one (GDPR Art. 37).

2. What personal data do we process?

2.1 Data about Subscribers

Category Details Source Purpose
Account identifiers Name, business name, VAT/NIP/IČO or REGON, email, phone Provided by subscriber Create & manage account (Art. 6 (1)(b))
Login & security Password (hash), login timestamps, IP logs Generated during use Authenticate & secure Service (Art. 6 (1)(b) / 6 (1)(f))
Billing Invoicing address, VAT ID, payment reference, amount, dates Payment processor (PayU, Stripe, etc.) Issue invoices, comply with tax law (Art. 6 (1)(c))

2.2 Data about Entrepreneurs (CEIDG Leads)

We collect only what is already public in the CEIDG register and relevant to bookkeepers. The exact fields we store are visible in the code snippet above and include:

Sensitive data: CEIDG does not publish special‑category data (GDPR Art. 9); therefore we do not process any sensitive categories.

3. For what purposes and on what legal basis?

PurposeData subjectsLegal basis
Provide the Service (account creation, delivering hourly updates, customer support)SubscribersContract necessity – GDPR Art. 6 (1)(b)
Issue invoices & comply with bookkeeping rulesSubscribersLegal obligation – Art. 6 (1)(c) (Czech VAT Act, AO 593/1992 Coll.)
Detect abuse, secure servers, resolve bugsSubscribers & EntrepreneursLegitimate interest – Art. 6 (1)(f)
Aggregate CEIDG entries and forward leads to subscribersEntrepreneursLegitimate interest – Art. 6 (1)(f)
Direct transparency notice (Art. 14 GDPR emails)EntrepreneursLegal obligation – Art. 6 (1)(c)
Analytics cookies (optional)Subscribers & site visitorsConsent – Art. 6 (1)(a)

3.1 Legitimate-interest balancing test

We performed a Legitimate Interests Assessment and concluded that our interests are not overridden by data‑subject rights because:

4. How do we collect the data?

5. Who receives the data?

RecipientCountrySafeguard
Subscriber bookkeepers (only if the entrepreneur does not object)EEA (mostly Poland)Each subscriber is an independent controller; they must comply with GDPR and Polish e‑marketing law.
Infrastructure hosting (e.g., Hetzner, OVH)EEAData‑processing agreement (Art. 28) in place.
Email delivery provider (e.g., Mailgun EU region)EEAArt. 28 DPA & encryption in transit.
Payment processor (e.g., PayU, Stripe)EEA or USStandard Contractual Clauses if outside EEA.

We do not sell or rent personal data. No automated decision‑making or profiling with legal effects is carried out.

6. International transfers

Our servers are located in the EU. If we use any service provider outside the European Economic Area, we rely on Standard Contractual Clauses or an adequacy decision (GDPR Chapter V). Details are available on request.

7. Data retention

Data setRetention period
Subscriber account & billing records10 years from end of fiscal year (Czech accounting law)
CEIDG LeadsUntil: (a) 12 months after collection, or (b) entrepreneur objects, whichever is earlier. A hashed suppression list is kept indefinitely to enforce opt‑outs.
Server logs90 days (security); aggregated thereafter.
Analytics cookiesAs specified in the Cookie Policy or until consent withdrawn.

8. Your rights

Data subjects have the following rights (GDPR Arts. 15‑22):

Exercising your rights: Email support@newbusinessalerts.com or write to the address above. We will respond within 30 days.

9. Security measures

10. Cookies & tracking

We use essential cookies for session management and CSRF protection. With your consent we may set analytics cookies (e.g., Google Analytics with IP anonymization). Details and opt‑out options are described in our separate Cookie Policy.

11. Changes to this Policy

We may update this Policy from time to time. We will notify subscribers by e‑mail of any material changes at least 14 days before they take effect. The latest version is always available at https://newbusinessalerts.com/privacy.

Last updated: 7/7/2025

Contact