Privacy policy

Privacy Policy

effective from [date]

WHAT IS A PRIVACY POLICY?

We would like to acquaint you with the details of how we process your personal data to provide you with full knowledge and comfort in using our website. As we operate in the online industry, we understand the importance of protecting your personal data. Therefore, we make special efforts to safeguard your privacy and the information you provide to us.

We carefully select and apply appropriate technical measures, especially those of a programming and organizational nature, to ensure the protection of processed personal data. Our website uses encrypted data transmission (SSL), providing protection for the data that identifies you.

In our Privacy Policy, you will find all the essential information regarding the processing of your personal data. Please take the time to read it, and we promise it won't take more than a few minutes.

WHO IS THE ADMINISTRATOR OF THE WEBSITE [WEBSITE NAME]?

The administrator of the website is FULL REGISTRATION DETAILS: COMPANY NAME, ADDRESS, TAX ID, PHONE NUMBER, EMAIL ADDRESS

PERSONAL DATA

Which legal act regulates the processing of your personal data?

Your personal data is collected and processed in accordance with the provisions of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons concerning the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Official Journal of the European Union L 119, p. 1), commonly known as GDPR. In areas not covered by the GDPR, the processing of personal data is regulated by the Act on the Protection of Personal Data of 10 May 2018.

Who is the administrator of your personal data?

The administrator of your personal data is FULL REGISTRATION DETAILS: COMPANY NAME, ADDRESS, TAX ID, PHONE NUMBER, EMAIL ADDRESS

For matters related to your personal data, you can contact us via:

Email: EMAIL ADDRESS

Traditional mail: CORRESPONDENCE ADDRESS

Phone: PHONE NUMBER

HOW DO WE PROCESS YOUR PERSONAL DATA THAT YOU PROVIDE TO US?

What personal data do we process and for what purposes do we process it? On our website, we offer you various services, for which purposes we process different personal data based on various legal grounds.

Purpose

Personal Data

Legal Basis for Processing

Data Storage Period

Conclusion and Performance of the Contract

name, surname, correspondence address, Tax Identification Number (NIP), email address, phone number, bank account number

art. 6(1)(b) GDPR, i.e., processing for the purpose of taking steps at your request prior to entering into a contract and processing necessary for the performance of a contract to which you are a party

until the expiration of the limitation period for claims related to the performance of the contract

Contact Form

name, surname, email address, phone number, Tax Identification Number (NIP)

art. 6(1)(f) GDPR, i.e., processing for the purpose of pursuing our legitimate interests, consisting in maintaining continuity of communication and enabling contact with us regarding business activities

until objection to the processing of personal data is raised

Contact Form "SEND INQUIRY"

First name, last name, email address, phone number, Tax Identification Number (NIP)

Article 6(1)(f) of the General Data Protection Regulation (GDPR), i.e., processing for the purpose of pursuing our legitimate interest, consisting of maintaining communication continuity and enabling contact with us regarding our business activities.

until the objection to the processing of personal data is raised

Analysis of Traffic on the Online Store's Website

IP address, browser data

art. 6(1)(f) GDPR, i.e., processing for the purpose of pursuing our legitimate interests, consisting in analyzing the traffic of customers on the store's website

until objection to the processing of personal data is raised

Direct Marketing of Own Goods and Services, Including Remarketing

IP address, browser data

art. 6(1)(f) GDPR, i.e., processing for the purpose of pursuing our legitimate interests, consisting in direct marketing of our own services, including remarketing

until objection to the processing of personal data is raised

Establishing, Investigating, and Enforcing Claims and Defense against Claims in Proceedings before Courts and Other State Authorities

name, surname, address of residence, PESEL number, Tax Identification Number (NIP), National Business Registry Number (REGON), email address, phone number, IP address, bank account number, payment card number

art. 6(1)(f) GDPR, i.e., processing for the purpose of pursuing our legitimate interests, consisting in establishing, investigating, and enforcing claims, as well as defending against claims in proceedings before courts and other state authorities

until the expiration of the limitation period for claims related to the performance of the contract

Fulfillment of Legal Obligations Arising from Legal Provisions, Especially Tax and Accounting Regulations

name, surname, company name, PESEL number, Tax Identification Number (NIP) or National Business Registry Number (REGON), email address, phone number, correspondence address, payment card number

art. 6(1)(c) GDPR, i.e., processing is necessary for the fulfillment of legal obligations incumbent upon us, arising from legal provisions, especially tax and accounting regulations

until the expiration of the legal obligations incumbent upon the Administrator that justified the processing of personal data

 

Voluntariness of providing personal data

Providing the required personal data is voluntary but is a condition for us to provide services to you (e.g., sending offers or quotations).

 

Automated decision-making (including profiling)

We use tools to send personalized advertisements to you. Based on your actions on the Store, especially the selection of viewed content and the time spent on Store subpages, we tailor and display marketing content that is relevant to you. Through such profiling, we can direct marketing messages that are more desirable to you, benefiting both us and you, as we limit marketing messages related to goods and services outside your areas of interest.

 

Will we transfer your personal data outside the EEA or to an international organization?

To use Google and YouTube tools, your personal data may be transferred to the United States, where Google LLC servers are located.

Google LLC is listed in the Data Privacy Framework program (link: https://www.dataprivacyframework.gov/s/participant-search), and the protection of personal data is adequate in relation to the regulations applicable in the European Union, according to the Commission Implementing Decision (EU) C(2023) 4745 of July 10, 2023, on the adequate level of protection of personal data under the EU-US Data Privacy Framework (link: https://commission.europa.eu/system/files/2023-07/Adequacy%20decision%20EU-US%20Data%20Privacy%20Framework.pdf).

To use Facebook tools, your personal data may be transferred to the United States, where Meta Platforms Inc. servers are located.

Meta Platforms Inc. is listed in the Data Privacy Framework program (link: https://www.dataprivacyframework.gov/s/participant-search), and the protection of personal data is adequate in relation to the regulations applicable in the European Union, according to the Commission Implementing Decision (EU) C(2023) 4745 of July 10, 2023, on the adequate level of protection of personal data under the EU-US Data Privacy Framework (link: https://commission.europa.eu/system/files/2023-07/Adequacy%20decision%20EU-US%20Data%20Privacy%20Framework.pdf).

WHAT ARE YOUR RIGHTS IN CONNECTION WITH OUR PROCESSING OF YOUR PERSONAL DATA?

Under the GDPR, you have the right to:

- request access to your personal data,

- request rectification of your personal data,

- request erasure of your personal data,

- request restriction of processing of your personal data,

- object to processing of your personal data,

- request data portability.

 

If you make any of the above requests to us without undue delay—in any case, within one month of receiving the request—we will provide you with information about the actions taken in relation to your request. If necessary, we may extend the one-month period by an additional two months due to the complexity of the request or the number of requests. In any case, we will inform you within one month of receiving the request of the extension and provide you with the reasons for the delay.

Right of access to personal data (Article 15 GDPR)

You have the right to obtain information as to whether we process your personal data. If we process your personal data, you have the right to:

- access to your personal data,

- information about the purposes of processing, the categories of personal data processed, recipients or categories of recipients of this data, the planned period of storage of your data or the criteria for determining this period, your rights under the GDPR, and the right to lodge a complaint with the President of the Personal Data Protection Office, the source of this data, automated decision-making, including profiling, and safeguards applied in connection with the transfer of this data outside the European Union;

- obtain a copy of your personal data.

If you want to request access to your personal data, please submit your request to the EMAIL ADDRESS.

Right to rectify personal data (Article 16 GDPR)

If your personal data is incorrect, you have the right to request the immediate correction of your personal data from us. You also have the right to request that we complete your personal data. If you want to request correction or completion of your personal data, please submit your request to the EMAIL ADDRESS.

Right to erasure of personal data, the "right to be forgotten" (Article 17 GDPR)

You have the right to request the deletion of your personal data when:

- your personal data is no longer necessary for the purposes for which it was collected or otherwise processed;

- you have withdrawn specific consent, to the extent that personal data has been processed based on your consent;

- your personal data has been processed unlawfully;

- you have objected to the processing of your personal data for direct marketing purposes, including profiling, to the extent that the processing of personal data is related to direct marketing;

- you have objected to the processing of your personal data in connection with the processing necessary to perform a task carried out in the public interest or in the exercise of official authority or for purposes arising from our legitimate interests or the legitimate interests of a third party.

 

Despite submitting a request for the deletion of personal data, we may continue to process your data for the purpose of establishing, investigating, or defending claims, of which you will be informed.

If you want to request the deletion of your personal data, please submit your request to the EMAIL ADDRESS.

 

Right to request restriction of processing of personal data (Article 18 GDPR)

You have the right to request the restriction of processing of your personal data when:

- you question the accuracy of your personal data—in such a case, we will limit the processing of your personal data for a period allowing us to verify the accuracy of this data;

- processing of your data is unlawful, and instead of deleting personal data, you request a restriction on processing your personal data;

- your personal data is no longer necessary for the purposes of processing, but it is needed to establish, investigate, or defend your claims;

- you have objected to the processing of your personal data—until it is established whether our legitimate interests take precedence over the grounds indicated in your objection.

If you want to request a restriction of processing of your personal data, please submit your request to the EMAIL ADDRESS.

Right to object to the processing of personal data (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data, including profiling, in connection with:

- processing necessary to perform a task carried out in the public interest or processing necessary for purposes arising from our legitimate interests or the legitimate interests of the personal data controller or a third party;

- processing for direct marketing purposes.

If you want to object to the processing of your personal data, please submit your request to the EMAIL ADDRESS.

Right to request data portability (Article 20 GDPR)

You have the right to receive your personal data from us in a structured, commonly used, machine-readable format and to transmit this data to another personal data controller. We will normally provide you with your personal data in CSV format. If you prefer your data to be provided in a different format, indicate the preferred format in your request. We will try to provide you with data in the format you prefer as much as possible.

You can also request that we send your personal data directly to another controller (if technically feasible).

If you want to request the transfer of your personal data, please submit your request to the EMAIL ADDRESS.

Can you withdraw your consent to the processing of personal data?

You can withdraw your consent to the processing of your personal data at any time. Withdrawal of consent to the processing of personal data does not affect the lawfulness of processing carried out by us based on your consent before its withdrawal.

If you want to withdraw your consent to the processing of your personal data, please submit your request to the EMAIL ADDRESS.

Complaint to the supervisory authority

If you believe that the processing of your personal data violates the provisions of data protection law, you have the right to lodge a complaint with the supervisory authority, especially in the Member State of your habitual residence, your place of work, or the place of the alleged violation.