GENERAL INFORMATION

1. This policy applies to the Website operating at the url address: https://www.tradycja.biz

2. The website operator and the personal data Controller is: Tradycja Fabryka Okien sp. z o.o. sp.k. ul. Elektrodowa 47 33-300 Nowy Sącz

3. Operator's email contact address: sekretariat@tradycja.biz

4. The Operator is the Controller of your personal data in relation to the data provided voluntarily on the website.

5. The website uses personal data for the following purposes:

- Keeping the newsletter

- Handling inquiries via the form

- Preparation, packaging, shipment of goods

6. The Website obtains information about users and their behavior in the following way:

- Through data entered voluntarily in forms, which are entered into the Operator's systems.

- By saving cookie files in end-devices.


1. ABOUT US

Tradycja Fabryka Okien sp. z o.o. sp.k. with its registered office in Nowy Sącz, ul. Elektrodowa 47, 33-300, NIP [tax identification number] 7343374726, REGON 120928657 (hereinafter “Controller", "we"/"us"/"our") - we are the entity responsible for the processing of personal data obtained from or about you (“you", “yours", "Panelist"). As our registered office is located in the territory of the European Union, we process personal data in accordance with European data protection regulations and other applicable statutory provisions.


2. WHAT IS PERSONAL DATA?

Personal data is information that allows you to be directly or indirectly identified as a natural person ("indirectly", i.e. in combination with other information) based on elements such as: first name and last name, postal address, email address, telephone number or unique device ID.


3. USE OF PERSONAL DATA

We use your personal data for the purposes described below. We do not collect or process more or other types of personal data than is necessary for the respective purposes. We use personal data only in accordance with the provisions of this Privacy Policy, unless you have given separate consent to the other use of your personal data. If we plan to use your personal data processed with your consent for purposes other than those specified in such consent, we will inform you about it in advance, and then - if you give your consent - we will start processing the data in other purposes.


1. Personal data

We collect your personal data necessary to provide our services. This is data such as: first name and last name, postal address, telephone number or email address, tax identification number, bank account number. We use the data to communicate with you, present the service offer, our terms and regulations, conclude and perform the contract, and make financial settlements. We also use personal data and the content of communication to answer questions that arise during the contact.

 

2. Legal obligations and legal defense

We may be required to use and archive personal data for legal and legal compliance purposes - for example, to detect, investigate, prevent data loss and fraud, and combat other abuse of our IT services and systems. We also have the right to use your personal data to comply with internal and external control requirements, ensure information security, protect and exercise our rights, protect our privacy, ensure the safety of persons and property, or protect the property of others.


3. Use of the website ("Portal")

This Privacy Policy also applies to the use of our website www.tradycja.biz ("Portal") with respect to the following privacy-related elements.


Log files:

In the Portal, we collect data, including personal data that is publicly available about your device when it connects to the Internet. That data includes, but is not limited to, the IP address (internet protocol address), the type and version of the operating system and browser, as well as - if possible - the manufacturer and model of the device, and the date and time when each inquiry was sent to our servers.


4. OBTAINING PERSONAL DATA FROM OTHER SOURCES

1. As a general rule, when we obtain your personal data from other sources, we make sure that the company has already contacted you to notify you about the transfer of data or we provide this information to you as part of the first contact, at the same time providing other required legal information.


5. PROVIDING PERSONAL DATA 

We disclose personal data of users for the purposes described below only to the entities indicated below - unless with your express consent to transfer your personal data to third parties includes other categories mentioned elsewhere. We take all steps to ensure that your personal data is processed, protected and transferred in accordance with the law.

 

1. External Service Providers

If necessary, we commission other companies and individuals to perform certain tasks related to our services on our behalf under data processing agreements. We may, for example, provide personal data to agents, contractors or partners to host our databases and applications, provide data processing services, or provide you with the information you have requested. Data made available to external service providers is transferred only to the extent required for a specific purpose. External service providers may not use the personal data received from us for any other purpose, in particular for their own benefit or the benefit of third parties. The external service providers are contractually bound to the confidentiality of your personal data.

 

2. Transfer of assets

In the event of a reorganization, restructuring, merger or sale or any other type of asset transfer (collectively an "asset transfer"), we may provide information, including personal data, to an acceptable scale and as necessary, provided that the receiving party agrees to your data being treated in a manner consistent with applicable data protection law. We are committed to continuing to protect the confidentiality of personal data and to notify relevant users in the event that their personal data becomes subject to a different privacy policy.

 

3. Public administration authorities

We disclose your personal data to public administration authorities if required by applicable law. For example, we respond to requests from courts, law enforcement agencies, regulatory authorities and other public administration institutions, including authorities outside your country of residence.

 

4. Transfer of personal data abroad

If it is necessary to send your personal data to countries outside the European Union (EU) and the European Economic Area (EEA), i.e. to the so-called "Third countries" we shall notify you about this. This Privacy Policy also applies when we transfer personal data to third countries where a level of data protection different than the one in your country of residence may apply.

5. The Controller, via the Website and other forms of communication, collects and processes the Users' personal data listed below, provided during registration processes on the Website:

first name and last name, address, email address, telephone number ... etc.

6. Purpose -> The processing of your personal data allows us to provide services, including maintaining your account, processing orders, contact related to the performance of the contract, as well as sending marketing information (including the newsletter).”

7. Time -> Personal data shall be kept for the duration of the agreement and for the period in accordance with applicable regulations, including the limitation of claims and tax obligations.

8. The personal data for the processing of which you have given your consent shall be kept until you withdraw your consent.

9. The User shall have the right to access and change his/her personal data at any time, as well as request the Controller to remove it immediately ("the right to be forgotten")."

10. The requests regarding the processing of personal data may be submitted by email to the address of the data controller

11. Your personal data may be transferred to the payment operator and courier company.


6. HOSTING

The Website is hosted (technically maintained) on the operator's server: NETMARK


7. SAFETY

We take data security very seriously. We apply appropriate security measures and implement appropriate physical, electronic and administrative procedures aimed at protecting the collected information against accidental or unlawful destruction, loss, modification, unauthorized disclosure, gaining access to personal data transferred, archived or processed. 

Our information security policies and procedures have been adapted to generally recognized international standards. They are regularly reviewed and updated to take into account business needs, technological changes and regulatory requirements. Access to your personal data is granted only to employees, service providers and entities that need it in connection with their duties.


8. YOUR RIGHTS

Each data subject has certain rights in relation to the personal data collected. This applies to the entire data processing process described in this Privacy Policy. We respect the rights of the individuals and we approach your concerns accordingly.

The list below provides information on your rights under data protection law:

Right to withdraw the consent: If the processing of personal data is based on your consent, you may withdraw it at any time applying the provisions of the procedure described in the appropriate consent form. We guarantee the possibility of withdrawing consent in the same way as it was granted, e.g. by electronic means. 

Right to correct data: You may receive from us the correction of personal data concerning you. We strive to ensure that the personal data in our possession or under our control and used on an ongoing basis is accurate, complete, current, relevant and based on the latest available information. Where appropriate, we provide access to the portal where the user can view and correct his/her personal data.

Right to limit data processing: You may receive an assurance from us that the processing of your personal data shall be restricted if:

- you dispute the accuracy of this information for the period in which we need to verify its appropriateness,

- data processing is unlawful, and you have submitted a request for restriction instead of deletion of personal data,

- Your data is no longer needed by us, but you need it in connection with the establishment, exercise or defense of legal claims, or

- you do not consent to the processing of data when we check whether our rights override your rights.

The right to access personal data: You may ask us to provide information about the personal data we hold about you, including the categories of personal data that we hold or control, about what this data is that data used for, where we received it (if not directly from you) and to whom it was disclosed (if applicable). You may receive from us one copy of the personal data we hold about you free of charge. We reserve the right to impose fees for each additional copy issued.

Right to transfer data: At your request, we shall transfer your personal data to another controller, if technically possible, provided that the processing occurs with your consent or is necessary for the performance of the agreement. Instead of receiving a copy of your personal data, you can choose the option according to which we transfer this data to another controller designated directly by you.

The right to delete data: You may receive an assurance from us that your personal data shall be deleted if:

- the data is no longer needed for the purposes for which it was collected or processed;

- you shall have the right to object to the further processing of your personal data (see below) and you decide to exercise this right;

- the processing is based on your consent, you have withdrawn your consent and there are no longer legal grounds justifying the processing of data;

- the processing of personal data was unlawful; data processing is not necessary

- as regards the fulfillment of a legal obligation that requires us to process it;

- in particular, the statutory data archiving requirements apply;

- it is connected with the establishment, exercise or defense of legal claims.

Right to object:

You shall have the right to object - at any time - to the processing of your personal data due to a specific situation, provided that the data processing is not based on your consent, but it based on our legitimate interest or the interest of a third party, in which case we shall stop processing your personal data, unless we are able to provide convincing legal evidence and demonstrate an overriding interest relating to the processing or the establishment, exercise or defense of legal claims. If you object to the processing of data, you must specify whether it is about deletion or restriction of its processing by us.

Right to lodge a complaint: If you suspect a breach of applicable data protection laws, you can lodge a complaint with the data protection supervisory authority in your country of residence or in the country where the alleged breach occurred.

Period: We shall endeavor to fulfill your request within 30 days. However, this period may be extended for reasons relating to the specific law or the complexity of the request.

Access restrictions: In some cases, we cannot provide you with access to all or part of your personal data due to statutory provisions. In the event of refusal to access data, we provide the reason.

No identification possible: In some cases, we are unable to check your personal data due to the identifiers you provided in your request. Personal data that we cannot find if you provide your name and email address include: data obtained via cookies in your browser.

In the event that we are unable to identify you as the data subject, we cannot comply with your request to exercise your rights under this section - unless we receive additional information that enables such identification.

Exercise of your rights: In order to exercise your rights, please contact us in writing, e.g. via email or traditional mail. Contact information at the end of this Privacy Policy.


9. STORAGE OF YOUR PERSONAL DATA

Basically, we shall delete your personal data as soon as it is no longer needed for the purposes for which it was collected. Nevertheless, statutory requirements may require us to store your personal data for a longer period, e.g. an obligation to report adverse effects.

In addition, we do not delete all of your personal data if you have asked us not to try to contact you again in the future. For this purpose, we keep records with information about persons who do not want to be contacted by us in the future (e.g. via newsletters, email). We consider such requests as consent to the storage of your personal data, unless otherwise instructed by you.

In matters not covered by the regulations, the provisions of the Civil Code and relevant acts of Polish law, as well as European Union law, in particular the GDPR (The Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and the repeal of Directive 95/46/EC) shall apply.

Provisions of Sections: 3., 6. i 11. of Annex 4 to the Agreement to provide the purchase formula "Buy with Twisto" - "Information of the personal data controller prepared pursuant to Article 13. paragprahs 1. and 2. of the General Data Protection Regulation (GDPR)” shall apply.


10. INFORMATION REGARDING THE PERSONAL DATA CONTROLLER

1. The Controller of your personal data is Tradycja Fabryka Okien sp.z o.o. sp.k.; contact details - phone number: (18) 444 40 28; email adress: sekretariat@tradycja.biz 

2. The appointed Personal Data Protection Officer can be contacted by writing to the postal address, preferably including the following annotation: "Personal Data Inspector" or email address.

3. The processing of your personal data allows us to provide services, including maintaining your account, processing orders, contact related to the performance of the contract, as well as sending marketing information (including the newsletter).

4. The online store processes your personal data for the following purposes: transferring your personal data to ING Bank Śląski S.A. in conjunction with:

- provision by the Bank for the online store of the service of providing infrastructure for handling payments over the Internet (legal basis: Article 6 paragraph 1, point f) of the Regulation)

- service and settlement by the Bank of payments made by customers of the Online Store via the Internet using payment instruments (legal basis: Article 6 paragraph 1 point f) of the Regulation).

- in order for the Bank to verify the proper performance of agreements concluded with the Online Store, in particular to ensure the protection of the interests of payers in connection with their complaints (legal basis: Article 6 paragraph 1 point f) of the Regulation).

- transfer of your personal data to Twisto Polska sp.z o.o. in connection with the possibility of offering payment for the purchased goods or service by Twisto Polska sp.z o.o. under the contract of mandate covering the "Buy with Twisto" purchasing formula and making this purchasing formula available by the Online Store, as well as for verification by Twisto Polska Sp. z o.o. proper performance of such contracts of mandate (legal basis: Article 6 paragraph 1 point f) of the Regulation).

5. In addition to the purposes set out in paragraph 3 (primary purpose), the Online Store may process your personal data for other legally permissible purposes (secondary purpose), when the primary and secondary purpose are closely related. As part of such processing, the Online Store, acting pursuant to Article 6 paragraph 1 point f) of the Regulation, provides for the processing of personal data also for the following secondary purposes.

6. The processing of your personal data for the purposes set out in paragraph 3 and in paragraph 4 shall take place in connection with the existence of a legitimate interest pursued by the Online Store.

7. In connection with the processing of personal data for the purposes set out in paragraphs 3 and 4, your personal data may be made available by the Online Store to other recipients or categories of recipients of personal data, which may include:

ING Bank Śląski S.A.

Twisto Polska sp. z o.o.

8. Your personal data shall be processed for the period justified to achieve the purposes indicated in paragraph 3.

9. In connection with the processing of your personal data, you shall have:

- the right to access your personal data,

- the right to rectify it, if it is inconsistent with the actual state,

- the right to remove it or limit data processing,

- the right to object to the processing of personal data,

- the right to transfer data.

10. In the event that the processing of your personal data is based on consent, you shall have the right to withdraw such consent at any time. Withdrawal of consent does not affect the processing of data prior to the withdrawal of consent or the legal basis for this processing.

11. The supervisory authority for the Online Store in the field of personal data is the President of the Office for Personal Data Protection. You shall have the right to lodge a complaint with the supervisory authority.

12. If you provide your personal data in order to conclude an agreement with the Online Store, providing your personal data is a condition for the conclusion of that agreement. Providing personal data in this situation is voluntary, but the consequence of not providing this data shall be the inability to conclude an agreement with the Online Store.

- In the event that you provide your personal data in order to transfer your personal data to Twisto Polska sp.z o.o. before concluding an agreement for the sale of goods (or services) purchased in the Online Store, providing that data shall be a condition for concluding a sales agreement in connection with the business model adopted by the Online Store.

- If you provide your personal data to the Bank in connection with the handling and settlement of payments made by you to the Online Store via the Internet using payment instruments, the provision of data is required in order to make the payment and provide confirmation of its payment by the Bank to the Online Store.

- In the case of transferring your personal data to the Bank in order for the Bank to verify the proper performance of agreements concluded with the Online Store, in particular to ensure the protection of the interests of payers in connection with their complaints providing this data shall be required to enable the performance of the agreement concluded between the Online Store and the Bank.

- If the transfer of your personal data to Twisto Polska sp.z o.o. in connection with the possibility of offering payment for the purchased goods or service by Twisto Polska sp.z o.o. under the contract of mandate covering the "Buy with Twisto" formula and making this purchasing formula available by the Online Store, providing that data and processing it for this purpose shall be required in connection with the business model adopted by the Online Store and in order to perform the agreement concluded between the Online Store and Twisto Polska Sp. z o.o.


11. AMENDMENTS TO THE PRIVACY POLICY

We reserve the right to make amendments - at our sole discretion - to our privacy practices and to amend this Privacy Policy at any time. Therefore, we encourage you to regularly review the provisions of this Privacy Policy. This Privacy Policy is effective as of the date indicated as the “last amendment” date above. If you do not have an account on our Portal, in the event of any amendments, we shall inform you by email or traditional mail and send you an updated version of the Privacy Policy. We undertake to treat your personal data in a manner consistent with the Privacy Policy under which the data has been obtained, unless we receive your consent to treat it differently.


12. CONTACT INFO

All questions regarding data protection, as well as requests relating to the exercise of your rights, should be directed to Tradycja Fabryka Okien sp.z o.o. sp.k. to the following email address - sekretariat@tradycja.biz.