Privacy Policy
1. General Information
-
1
This policy applies to the Website operating at the URL: olewnik.com.pl
-
2
The website operator and the Personal Data Administrator is: Olewnik Sp. z o.o., Świerczynek 10A, 09-210 Drobin
-
3
The operator’s contact email address is: kontakt@olewnik.com.pl
-
4
The Operator is the Data Controller of your personal data with respect to the data provided voluntarily on the Website.
-
5
The Website uses personal data for the following purposes:
-
Running a newsletter
-
Conducting online chats
-
Providing ordered services
-
Presenting offers or information
-
-
6
The Website collects information about users and their behavior in the following ways:
-
Through data voluntarily entered into forms, which is then introduced into the Operator’s systems.
-
By saving cookie files (so-called “cookies”) on end-user devices.
-
2. Selected data protection methods applied by the Operator
-
1
Login pages and personal data entry points are protected in the transmission layer (SSL certificate). As a result, personal data and login credentials entered on the website are encrypted on the user’s computer and can only be read on the destination server.
-
2
Personal data stored in the database is encrypted in such a way that only the Operator, who possesses the key, can read it. As a result, the data is protected in the event that the database is stolen from the server.
-
3
User passwords are stored as hashes. The hashing function is one-way, meaning it cannot be reversed, which is the current industry standard for password storage.
-
4
Two-factor authentication is used on the Website, providing an additional layer of security for logging in.
-
5
The Operator regularly updates its administrative passwords.
-
6
To protect data, the Operator regularly performs backups.
-
7
A key component of data protection is the regular updating of all software used by the Operator for personal data processing, which specifically includes routine updates of software components.
3. Hosting
-
1
The Website is hosted (technically maintained) on the operator’s servers: home.pl
4. Your rights and additional information regarding data processing
-
1
In certain situations, the Data Controller has the right to transfer your personal data to other recipients if it is necessary for the performance of a contract concluded with you or to fulfill obligations incumbent on the Data Controller. This applies to the following categories of recipients:
-
hosting company on a data entrustment basis
-
law firms and debt collectors
-
payment operators
-
authorized employees and associates who use the data to achieve the operational purpose of the website
-
companies providing marketing services to the Data Controller
-
-
2
Your personal data will be processed by the Data Controller for no longer than is necessary to perform the related activities specified by separate regulations (e.g., on accounting). With regard to marketing data, the data will not be processed for longer than 3 years.
-
3
You have the right to request from the Data Controller:
-
access to personal data concerning you,
-
its rectification,
-
erasure,
-
restriction of processing,
-
and data portability.
-
-
4
You have the right to object to the processing of personal data for the purpose of legitimate interests pursued by the Data Controller, including profiling, as specified in point 3.3 c). However, the right to object cannot be exercised if there are valid, legitimate grounds for processing that override your interests, rights, and freedoms, in particular for the establishment, exercise, or defense of legal claims.
-
5
You have the right to lodge a complaint against the actions of the Data Controller with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland.
-
6
Providing personal data is voluntary, but necessary for the operation of the Website.
-
7
Automated decision-making, including profiling, may be applied to you for the purpose of providing services under the concluded contract and for the purpose of direct marketing conducted by the Data Controller.
-
8
Personal data is not transferred to third countries within the meaning of personal data protection regulations. This means that we do not transfer it outside the European Union.
5. Information in forms
-
1
The Website collects information provided voluntarily by the user, including personal data, if provided.
-
2
The Website may record connection log data (such as time stamps and IP addresses).
-
3
In certain cases, the Website may record information to help link the data provided in a form with the email address of the user filling it out. In this event, the user’s email address is included within the URL of the page displaying the form.
-
4
The data entered into the form is processed for purposes specific to the function of that particular form, such as handling a service request, commercial contact, or service registration. In every instance, the context and description of the form clearly indicate its purpose.
6. Admin logs
-
1
Informacje zachowaniu użytkowników w serwisie mogą podlegać logowaniu. Dane te są wykorzystywane w celu administrowania serwisem.
7. Istotne techniki marketingowe
-
1
The Operator applies statistical analysis of website traffic via Google Analytics (provided by Google LLC/Inc., USA). The Operator does not provide personal data to this service provider, but only anonymized information. The service relies on the use of cookies on the user’s terminal device. With respect to user preference information collected by the Google ad network, the user can review and edit cookie-based details using the following tool: https://www.google.com/ads/preferences/
-
2
The Operator utilizes remarketing techniques to match advertising content with user behavior on the site. Although this may give the impression that the user’s personal data is being used to track them, in practice, no personal data is shared by the Operator with ad networks. A prerequisite for these activities is that cookie support is enabled.
-
3
The Operator utilizes tools to analyze user behavior through heatmaps and session recordings. This data is anonymized before it is sent to the service provider, meaning it cannot be linked to any specific individual. Crucially, typed passwords and other personal data are never recorded.
-
4
The Operator utilizes automation tools to manage interactions with users on the Website. For example, the system may trigger an email after a user visits a specific subpage, provided that the user has consented to receive commercial communications from the Operator.