This Privacy Policy sets out the rules for processing and protecting personal data provided by Users in connection with using our services through the website. We respect the right to privacy and take care of data security. This document was prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and the Act of 10 May 2018 on the Protection of Personal Data.

In this document you'll find information about:

  • who is the controller of your data;
  • what data we collect and for what purpose;
  • on what legal basis we process data;
  • what rights you have regarding the processing of your data;
  • how we protect your personal data.

Data Controller

The controller of personal data is [Company Name] with its registered office in [City], ul. [Address], [Postal Code], entered in the National Court Register under KRS number [number], NIP: [number], REGON: [number]. For matters concerning the protection of personal data, you can contact us at the e-mail address: kontakt@firma.pl or in writing to our registered office address.

  • the type and scope of data collected;
  • the purposes of processing;
  • the legal bases for processing;
  • data retention periods;
  • categories of data recipients;
  • the rights of the data subjects.
Important: the controller has not appointed a Data Protection Officer, but if you have any questions about the processing of personal data, please contact us at the e-mail address provided.

Purposes and Legal Bases for Processing Data

Performance of a contract

We process personal data to perform a contract or to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR). This applies in particular to order handling, service provision and account management.

We process data in particular for the purposes of:

  • fulfilling orders and providing services;
  • maintaining a user account;
  • handling inquiries and complaints;
  • issuing invoices and accounting documents;
  • conducting web analytics.

Legitimate interest

We process data based on our legitimate interest (Article 6(1)(f) GDPR) for the purposes of direct marketing, web analytics, fraud prevention, and the establishment and defense of legal claims.

User consent is a separate basis for processing data for marketing purposes, newsletter delivery and profiling — you can withdraw it at any time without affecting the lawfulness of processing carried out before its withdrawal.

Scope of Personal Data Collected

The scope of data collected depends on the nature of the relationship with the User and the type of services provided. We only collect data necessary to achieve specific processing purposes.

1.

Identification and contact data

As part of contact forms and account registration, we collect: first and last name, e-mail address, phone number, correspondence address, and — for businesses — company name and tax ID (NIP).

2.

Automatically collected data

While using the site, the following are collected automatically:

  • device IP address;
  • browser type and version;
  • operating system;
  • time spent on the site;
  • pages visited;
  • referral source;
  • cookie data.

3.

Sensitive data

We do not collect sensitive data (so-called special categories of data), unless required by law or with the User's explicit consent.

Rights of Users

Right
Description
Legal basis
Right of access
Obtaining information about processed data
Art. 15 RODO
Right to rectification
Correcting inaccurate data
Art. 16 RODO
Right to erasure
Requesting deletion of personal data
Art. 17 RODO
Right to restriction
Limiting the scope of processing
Art. 18 RODO
Right to data portability
Receiving data in a machine-readable format
Art. 20 RODO
Right to object
Objecting to the processing of data
Art. 21 RODO

Data Retention Period and Security

Statutory period

We retain personal data for the period necessary to achieve the purposes for which it was collected. After this period, the data is deleted or anonymized, unless the law requires longer retention.

Data retention periods result from:

  • tax and accounting obligations (5 years);
  • the limitation period for civil claims (3–6 years);
  • the duration of consent given;
  • contract performance and after-sales support;
  • the period the user account remains active.
Data security is our priority. We apply technical and organizational measures to protect processed data, including SSL encryption, access control, regular backups and staff training.
This Privacy Policy may be updated. We inform Users of any changes by publishing a new version on the website. We recommend checking this document regularly. If you have any questions, please contact us at: kontakt@firma.pl.