Terms and Conditions

Definitions

  1. Controller (We) – ekspol.com EKSPOL S.A. ul. Magazynowa 8A, 62-030 Luboń
  2. Personal Data – all information about an identified or identifiable natural person through one or several specific factors defining the physical, physiological, genetic, mental, economic, cultural, or social identity, including device IP, location data, online identifier, and information collected via cookies and other similar technologies.
  3. Policy – this Privacy Policy.
  4. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
  5. Service – the website operated by us at ekspol.com
  6. User (You) – any natural person visiting the Service or using one or several services or functionalities described in the Policy

Data processing in connection with the use of the service

  • In connection with your use of the Service, we collect your data to the extent necessary to provide specific offered services, as well as information about your activity within the Service. Detailed rules and purposes of processing personal data collected during your use of the Service are described below.

Purposes and legal bases for data processing in the service

Using the service

  1. We process personal data of all persons using the Service (including: IP address or other identifiers and information collected via cookies or other similar technologies), who are not registered Users (i.e., persons without a profile in the Service) for the following purposes:
    1. for the purpose of providing services electronically regarding making content collected in the Service available to Users – in this case, the legal basis for processing is the necessity of processing for the performance of the contract (Art. 6(1)(b) GDPR);
    2. for analytical and statistical purposes – in this case, the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR) consisting of conducting analyses of Users’ activity, as well as their preferences in order to improve the functionalities used and services provided;
    3. for the purpose of potential establishment and pursuit of claims or defense against them – the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR) consisting of the protection of our rights;
    4. for marketing purposes (ours and our partners’), in particular related to presenting behavioral advertising – the rules for processing personal data for marketing purposes are described in the „MARKETING” section.
  2. Your Activity in the Service, including your personal data, is recorded in system logs. Information collected in logs is processed primarily for purposes related to the provision of services. We also process it for technical and administrative purposes, to ensure the security of the IT system and management of this system, as well as for analytical and statistical purposes – in this regard, the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR).

Using paid services in the service

  1. If you place an order (purchase of goods or service) in the Service, we will process your personal data for the following purposes:
    1. for the purpose of fulfilling the placed order – the legal basis for processing is the necessity of processing for the performance of the contract (Art. 6(1)(b) GDPR); regarding data provided optionally, the legal basis for processing is consent (Art. 6(1)(a) GDPR);
    2. for the purpose of fulfilling legal obligations incumbent on us, resulting in particular from tax and accounting regulations – the legal basis for processing is a legal obligation (Art. 6(1)(c) GDPR);
    3. for analytical and statistical purposes – the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR) consisting of conducting analyses of your activity in the Service, as well as your purchasing preferences in order to improve the functionalities used;
    4. for the purpose of potential establishment and pursuit of claims or defense against them – the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR) consisting of the protection of our rights.

Contact forms

  1. In the Service, we provide the possibility to contact us using electronic contact forms. Using the form requires providing your personal data necessary for us to contact you and answer the question asked. In the form, you may also provide other data to facilitate our contact or handling of the inquiry. Providing data marked as mandatory is required to accept and handle the inquiry, and failure to provide it will result in our inability to handle your question. Providing other data is voluntary.
  2. Personal data that you send us via the contact form is processed:
    1. for the purpose of identifying you as the sender and handling your inquiry sent via the provided form – the legal basis for processing is the necessity of processing for the performance of the service contract (Art. 6(1)(b) GDPR);
    2. for analytical and statistical purposes – the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR) consisting of keeping statistics of inquiries submitted by Users via the Service in order to improve its functionality.

Marketing

  1. We process your personal data for the purpose of carrying out marketing activities, which may consist of:
    1. displaying marketing content that is not tailored to your preferences (contextual advertising);
    2. displaying marketing content corresponding to your interests (behavioral advertising);
    3. sending e-mail notifications about interesting offers or content, which in some cases contain commercial information (newsletter service);
    4. conducting other types of activities related to direct marketing of goods and services (sending commercial information electronically and telemarketing activities).
  2. In order to carry out marketing activities, in some cases we use profiling (if you consent to it). This means that through automatic data processing, we evaluate selected factors concerning natural persons to analyze their behavior or create a forecast for the future.

Direct marketing

  1. Your Personal Data may also be used by us so that we can direct marketing content to you through various channels, i.e., via e-mail, MMS / SMS, or by phone. We undertake such activities only if you have consented to them, which you may withdraw at any time.

Social media portals

  1. We process your personal data when you visit our profiles maintained on social media (Facebook, YouTube, Instagram, Twitter). This data is processed solely in connection with maintaining the profile, including for the purpose of informing you about our activity and promoting various types of events, services, and products. The legal basis for processing personal data for this purpose is our legitimate interest (Art. 6(1)(f) GDPR) consisting of promoting our own brand.

Cookies and similar technology

  1. Cookies are small text files installed on your device when you browse the Service. Cookies collect information facilitating the use of the website – e.g., by remembering your visits to the Service and actions performed by you. Within the Service, we may use the following types of cookies:

’Service’ cookies

  1. We use so-called service cookies primarily to provide you with services supplied electronically and to improve the quality of these services. Therefore, we and other entities providing analytical and statistical services to us use cookies, storing information or accessing information already stored in your telecommunications terminal equipment (computer, phone, tablet, etc.). Cookies used for this purpose include:
    1. user input cookies (session ID) for the duration of the session;
    2. authentication cookies used for services requiring authentication for the duration of the session;
    3. user centric security cookies, e.g., used to detect abuses regarding authentication;
    4. multimedia player session cookies (e.g., flash player cookies), for the duration of the session;
    5. persistent user interface customization cookies, for the duration of the session or slightly longer;
    6. cookies used to monitor traffic on the website, i.e., data analytics, including Google Analytics cookies (these are files used by Google to analyze how you use the Service, to create statistics and reports regarding the functioning of the Service). Google does not use the collected data to identify the User nor does it combine this information to enable identification. Detailed information about the scope and principles of data collection in connection with this service can be found at: https://www.google.com/intl/pl/policies/privacy/partners.

’Marketing’ cookies

  1. We and our trusted partners also use cookies for marketing purposes, e.g., in connection with directing behavioral advertising to you. For this purpose, we and our trusted partners store information or access information already stored in your telecommunications terminal equipment (computer, phone, tablet, etc.). The use of cookies and personal data collected through them for marketing purposes, in particular regarding the promotion of services and goods of third parties, requires your consent, which may be withdrawn at any time.

Managing cookies

  1. If you do not want to receive cookies, you can change your browser settings. We reserve that disabling cookies necessary for authentication processes, security, maintaining user preferences may make it difficult to use the Service.
  2. To manage cookie settings, select the web browser you are using from the list below and follow the instructions:
    1. Edge
    2. Internet Explorer
    3. Chrome
    4. Safari
    5. Firefox
    6. Opera
    7. Mobile devices:
    8. Android
    9. Safari (iOS)
    10. Windows Phone

Significant marketing techniques

  1. The purpose and scope of data collection and its further processing and use by service providers, as well as the possibility of contact and User rights in this regard, are described in the privacy policies of the service providers.
  2. We may use remarketing techniques allowing for the matching of advertising messages to your behavior in the Service, which may give the illusion that your personal data is being used for tracking, however, in practice, we do not transfer any of your personal data to advertising operators. The technological condition for such activities is enabled cookie support.
  3. We may use a solution examining user behavior by creating heat maps and recording behavior in the Service. This information is anonymized before being sent to the service operator so that they do not know which natural person it concerns. In particular, entered passwords and other personal data are not subject to recording.

Period of personal data processing

  1. The period for which we process your data depends on the type of service provided and the purpose of processing. As a rule, data is processed for the duration of the service provision or order fulfillment, until you withdraw your expressed consent or lodge an effective objection to data processing (in cases where the legal basis for data processing is our legitimate interest).
  2. The data processing period may be extended if processing is necessary to establish and pursue potential claims or defend against them, and after this time only if and to the extent required by law.
  3. After the processing period expires, your data is irreversibly deleted or anonymized.

Your rights

  1. Due to the fact that we process your personal data, you have the following rights:
    1. right to information about personal data processing – on this basis, upon your request, we will provide you with information about data processing, including primarily about the purposes and legal bases for processing, the scope of data held, entities to whom it is disclosed, and the planned date of data deletion;
    2. right to obtain a copy of data – on this basis, upon your request, we will provide you with a copy of the processed data concerning the person making the request;
    3. right to rectification – upon your request, we are obliged to remove any inconsistencies or errors in the processed personal data and supplement them if they are incomplete;
    4. right to deletion of data – on this basis, you can request the deletion of data whose processing is no longer necessary to achieve any of the purposes for which it was collected;
    5. right to restriction of processing – on this basis, upon your request, we will cease performing operations on your personal data – except for operations to which you have consented – and their storage, in accordance with accepted retention rules or until the reasons for restricting data processing cease;
    6. right to data portability – on this basis – to the extent that your data is processed in connection with a concluded contract or expressed consent – we will issue you the data provided by you in a format allowing it to be read by a computer. You may also request that we send this data to another entity – provided, however, that we have the appropriate technical capabilities to do so.
    7. right to object to data processing for marketing purposes – you may at any time object to the processing of personal data for marketing purposes, without the need to justify such an objection;
    8. right to object to other purposes of data processing – You may at any time object to the processing of personal data that takes place on the basis of our legitimate interest (e.g., for analytical or statistical purposes or for reasons related to property protection); an objection in this regard should contain a justification;
    9. right to withdraw consent – if data is processed on the basis of your consent, you have the right to withdraw it at any time, which, however, does not affect the lawfulness of the processing carried out before the withdrawal of consent.
    10. right to lodge a complaint – if you consider that the way we process your personal data violates the provisions of the GDPR or other regulations regarding personal data protection, you may lodge a complaint with the President of the Personal Data Protection Office.

Data recipients

  1. Since we want to provide the best possible services for you, we will disclose your personal data to our trusted partners, including in particular suppliers responsible for operating IT systems, entities such as banks and payment operators, entities providing accounting services, couriers (in connection with order fulfillment), marketing agencies (in the scope of marketing services), and our affiliated entities.
  2. Your personal data will be made available to other entities for their own purposes, including marketing purposes, only if you consent to it.

Data transfer outside the EEA

  1. The level of personal data protection outside the European Economic Area (EEA) may differ from that provided by European law. For this reason, we will transfer your personal data outside the EEA only when necessary, and with the assurance of an appropriate level of protection. You will be notified of this each time.

Security of personal data

  1. Know that we take all steps to ensure that your personal data is processed by us securely – ensuring primarily that access to your data is granted only to authorized persons and only to the extent necessary due to the tasks performed by them.
  2. We take all necessary actions so that our subcontractors and other cooperating entities guarantee the application of appropriate security measures in each case when they process your personal data on our behalf.

Contact details

  1. In all matters referred to in this policy, in particular related to the processing of your personal data, you can contact us via:
    1. e-mail biuro@ekspol.com