Privacy policy
§1 General Provisions
-
This document forms an integral part of the Terms and Conditions. By using our services, you entrust us with your information. This Privacy Policy is intended solely to help you understand what information and data are collected and for what purposes we use them. These data are very important to us; therefore, please read this document carefully, as it sets out the rules and methods for the processing and protection of personal data. This document also sets out the rules for the use of cookies.
-
We hereby declare that we comply with the principles of personal data protection and all legal regulations provided for by the Personal Data Protection Act and by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation – GDPR).
-
A data subject whose personal data are processed has the right to contact us in order to obtain exhaustive information about how we use their personal data. We always strive to clearly inform you about the data we collect, how we use them, the purposes they serve and to whom we disclose them, what safeguards we apply when transferring them to other entities, as well as which institutions to contact in case of doubt.
-
The Website applies technical measures such as: physical safeguards for personal data, hardware safeguards for IT and telecommunications infrastructure, safeguards within software tools and databases, and organizational measures ensuring adequate protection of processed personal data, in particular protecting personal data against disclosure to unauthorized third parties, access by an unauthorized person and use for unknown purposes, as well as accidental or intentional alteration, loss, damage, or destruction of such data.
-
Under the terms set out in the Terms and Conditions and in this document, we have exclusive access to the data. Access to personal data may also be entrusted to other entities through which payments are made, which collect, process, and store personal data in accordance with their own terms and conditions, as well as entities responsible for order fulfillment. Access to personal data is granted to the aforementioned entities only to the extent necessary and solely to ensure the provision of services.
-
Personal data are processed only for those purposes for which you have given consent by selecting the relevant fields in the form placed on the Website or in another explicit manner. The legal basis for processing your personal data is consent to processing or the necessity of processing for the performance of a service (e.g., ordering a product or service), pursuant to Article 6(1)(a) and (b) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation – GDPR).
§2 Privacy Principles
-
We take privacy seriously. We are guided by respect for privacy and by ensuring the highest possible level of convenience in using our services.
-
We value the trust that Users place in us by providing their personal data for the purpose of fulfilling an order. We always use personal data fairly and in a manner that does not betray this trust, only to the extent necessary for order fulfillment, including its processing.
-
The User has the right to obtain clear and complete information about how we use their personal data and for what purposes it is needed. We always clearly inform about the data we collect, how and to whom we disclose them, and we provide information about the entities to contact in case of doubts, questions, or comments.
-
In the event of doubts regarding our use of the User’s personal data, we will promptly take action to clarify such doubts, responding fully and comprehensively to all related questions.
-
We will take all reasonable measures to protect Users’ data against improper and uncontrolled use and to secure it comprehensively.
-
Information regarding the Controller of your personal data can be found in the “Contact” tab on the Website.
-
The legal basis for processing your personal data is Article 6(1)(b) GDPR. The provision of data is not mandatory, but it is necessary to take appropriate steps preceding the conclusion of a contract and for its performance. We will transfer your personal data to other recipients entrusted with the processing of personal data on our behalf and for our account. Your data will be transferred on the basis of Article 6(1)(f) GDPR, where the legitimate interest is the proper performance of contracts/orders. Furthermore, we will share your personal data with other business partners. The personal data collected are stored within the European Economic Area (EEA), but they may also be transferred to and processed in a country outside this area. Each transfer of personal data is carried out in accordance with applicable law. If data are transferred outside the EEA, we apply standard contractual clauses and other appropriate safeguards with respect to countries for which the European Commission has not determined an adequate level of data protection.
-
Your personal data related to the conclusion and performance of a contract will be processed for the duration of its performance, and also for a period not longer than provided by law, including the provisions of the Civil Code and the Accounting Act, i.e., no longer than ten years from the end of the calendar year in which the last contract was performed.
-
Your personal data processed for the purpose of concluding and performing future contracts will be processed until an objection is raised.
-
You have the right to: access your personal data and receive a copy of the personal data undergoing processing; rectify inaccurate data; request the deletion of data (“right to be forgotten”) in the circumstances provided for in Article 17 GDPR; request restriction of processing in the cases indicated in Article 18 GDPR; object to processing in the cases indicated in Article 21 GDPR; and data portability with respect to data processed by automated means.
-
If you believe that your personal data are being processed unlawfully, you may lodge a complaint with the supervisory authority (the President of the Personal Data Protection Office, ul. Stawki 2, Warsaw, Poland). If you require additional information related to the protection of personal data or wish to exercise your rights, please contact us by post at our correspondence address.
-
We make every effort to protect against unauthorized access, unauthorized modification, disclosure, and destruction of information in our possession. In particular:
a) We control the methods of collecting, storing, and processing information, including physical security measures, to protect against unauthorized access to the system.
b) Access to personal data is granted only to those employees, contractors, and representatives who need access to it. Under contract, they are obliged to maintain strict confidentiality and to allow us to verify compliance with their duties; failure to comply may entail consequences. -
We will comply with all applicable data protection laws and regulations and cooperate with data protection authorities and competent law enforcement bodies. In the absence of data protection provisions, we will proceed in accordance with generally accepted data protection principles, principles of good faith and fair dealing, and established customs.
-
The detailed method of protecting personal data is set out in the Personal Data Protection Policy (including the security policy, personal data protection regulations, and IT system management instructions). For security reasons, due to the procedures described therein, it is available for inspection only to state supervisory authorities.
-
If you have questions regarding the manner in which we handle personal data, please contact us via the page from which you were redirected to this Privacy Policy. Your request will be promptly forwarded to the person appointed for this purpose.
-
The User always has the right to notify us if they:
a) no longer wish to receive information or messages from us in any form;
b) wish to receive a copy of their personal data held by us;
c) wish to correct, update, or delete their personal data in our records;
d) wish to report violations, misuse, or processing of their personal data. -
To help us respond to or address the information provided, please state your first name, surname, and further relevant details.
§3 Scope and Purpose of Personal Data Collection
-
We process the personal data necessary for the provision of services and for accounting purposes, including:
a) placing an order;
b) concluding a contract, handling complaints, and withdrawal from a contract;
c) issuing a VAT invoice or other receipt;
d) monitoring traffic on our websites;
e) collecting anonymous statistics to determine how users use our website;
f) determining the number of anonymous users of our pages;
g) monitoring how often selected content is shown to users and which content is most frequent;
h) monitoring how often users select a given service or from which service contact most frequently occurs;
i) examining newsletter sign-ups and contact options;
j) using a personalized recommendation system for e-commerce;
k) using tools for communication both by email and, subsequently, by telephone;
l) integrating with social media portals;
m) enabling potential online payments. -
We collect, process, and store the following user data:
a) first name and surname;
b) residential address;
c) delivery address (if different from the residential address);
d) Tax Identification Number (NIP);
e) email address;
f) telephone number (mobile or landline);
g) date of birth;
h) Personal Identification Number (PESEL);
i) information about the web browser used;
j) other personal data voluntarily provided to us. -
The provision of the above data is entirely voluntary but also necessary for the full performance of services.
-
The purposes of collecting, processing, or using data include:
a) direct marketing and archival purposes relating to advertising campaigns;
b) performance of obligations imposed by law through the collection of information on undesirable activities. -
We may transfer personal data to servers located outside the user’s country of residence or to affiliated entities or third parties established in other countries, including countries within the European Economic Area (EEA – a free trade area and common market encompassing the Member States of the European Union and the European Free Trade Association, EFTA), for the purpose of processing personal data by such entities on our behalf, in accordance with this Privacy Policy and applicable laws, customs, and data protection regulations.
-
We store your personal data no longer than necessary to ensure an appropriate quality of service and, depending on the mode and purpose of its acquisition, we store it for the duration of the service and thereafter for the following purposes:
a) fulfillment of obligations arising from legal provisions, tax and accounting regulations;
b) prevention of abuse or criminal offenses;
c) statistical and archival purposes;
d) marketing activities — for the duration of the contract or for the period covered by separate consent to such processing, until the completion of activities related to transaction handling, until you object to such processing, or until consent is withdrawn;
e) sales-related and promotional activities — e.g., contests, promotional campaigns — for the duration and settlement of such activities;
f) operational activities — until the limitation periods for obligations imposed by the GDPR and relevant national provisions expire, for the purpose of demonstrating diligence in personal data processing;
g) pursuing any claims related to the executed contract. -
Considering that many countries to which personal data are transferred do not provide the same level of legal protection of personal data as that applicable in the user’s country, access to the user’s personal data stored in another country may be obtained, in accordance with the law in force in that country, by courts, law enforcement authorities, and national security bodies. Subject to lawful requests for disclosure, we undertake to require entities processing personal data outside the user’s country to take measures to protect the data in a manner adequate to the regulations of their national law.
§4 Rights and Obligations
-
We have the right, and in cases specified by law also a statutory obligation, to transfer selected or all information regarding personal data to public authorities or third parties that submit a request for such information on the basis of applicable Polish law.
-
The User has the right to access the content of their personal data that they have provided. The User may correct or supplement this data at any time and also has the right to request that it be deleted from our databases or that its processing be discontinued, without stating any reason. In order to exercise their rights, the User may at any time send an appropriate message to the email address or by another means that delivers/transmits such a request.
-
The processing of personal data of natural persons who are our clients is based on:
a) the legitimate interest of the controller (e.g., creating a database, analytical and profiling activities, including analysis of the use of products, direct marketing of our own products, securing documentation for the purpose of defending against potential claims or for the purpose of pursuing claims);
b) consent (including, in particular, consent to email marketing or telemarketing);
c) performance of a concluded contract;
d) obligations arising from the law (e.g., tax law or accounting regulations). -
The processing of personal data of natural persons who are potential clients is based on:
a) the legitimate interest of the controller (e.g., creating a database, direct marketing of our own products);
b) consent (including, in particular, consent to email marketing or telemarketing). -
A User’s request to delete personal data or to discontinue its processing may result in the complete inability to provide services or in a significant limitation of such services.
-
We attach particular importance to profiling and state that:
a) for profiling purposes, we generally process data that have previously been subject to SSL encryption;
b) we use typical data for this purpose: email address and IP address or cookies;
c) we profile in order to analyze or predict the personal preferences and interests of persons using our Services or products, and to adjust the content present in our Services or products to these preferences;
d) we profile for marketing purposes, i.e., to tailor the marketing offer to the aforementioned preferences. -
We undertake to act in accordance with applicable legal provisions and the principles of good faith and fair dealing.
-
Information on out-of-court consumer dispute resolution. The entity authorized within the meaning of the Act on out-of-court resolution of consumer disputes is the Financial Ombudsman, whose website address is: www.rf.gov.pl.
§5 Basic Security Rules
-
Each user should take care of their own data security and the security of their devices used to access the Internet. Such a device should have antivirus software with a current, regularly updated database of virus definitions, a secure version of the web browser used, and an enabled firewall. The User should check whether the operating system and programs installed on it have the latest and compatible updates, since attacks exploit vulnerabilities detected in installed software.
-
Access data to services offered on the Internet — e.g., logins, passwords, PINs, electronic certificates, etc. — should be secured in a place inaccessible to others and impossible to compromise from the Internet. They should not be disclosed or stored on the device in a form that allows unauthorized access and reading by unauthorized persons.
-
Exercise caution when opening suspicious attachments or links in email messages that were not expected, e.g., from unknown senders or from the spam folder.
-
It is recommended to enable anti-phishing filters in the web browser — tools that verify whether the displayed website is authentic and not used to obtain information fraudulently, e.g., by impersonating a person or institution.
-
Files should be downloaded only from trusted locations, services, and websites. We do not recommend installing software from unverified sources, especially from unknown publishers with an unproven reputation. This also applies to mobile devices, e.g., smartphones and tablets.
-
When using a home Wi-Fi wireless network, a password should be set that is secure and difficult to break; it should not be a pattern or character string that is easy to guess (e.g., street name, host’s name, date of birth, etc.). It is also recommended to use the highest available Wi-Fi encryption standards that can be enabled on the equipment in use, e.g., WPA2.
§6 Use of Social Media Plugins
-
Plugins (so-called plug-ins) of social networking sites such as Facebook.com and Twitter, as well as others, may be present on our pages. Related services are provided by Meta Platforms Inc. and X Corp., respectively.
-
Facebook is operated by Meta Platforms Inc., 1601 Willow Road, Menlo Park, California 94025, USA. To view Facebook plugins, visit: https://developers.facebook.com/docs/plugins
-
Twitter is operated by X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, United States. To view Twitter plugins, visit: https://dev.twitter.com/web/tweet-button
-
The plugin transmits to its provider only information about which of our websites you accessed and at what time. If, while viewing or staying on our site, the user is logged into their account on, for example, Facebook or Twitter, the provider is able to link your interests, information preferences, and other data obtained, for example, by clicking the “Like” button, leaving a comment, or entering a profile name in search. Such information is also transmitted by the browser directly to the provider.
-
More detailed information on the collection and use of data by Facebook or Twitter and on privacy protection can be found at the following pages:
a) Data protection/privacy guidance issued by Facebook: http://www.facebook.com/policy.php
b) Data protection/privacy guidance issued by Twitter: https://twitter.com/privacy -
To avoid the recording by Facebook or Twitter of your visit to a given user account on our website, you must log out of your account before you begin browsing our websites.