Privacy Policy
Your data, our responsibility
This Privacy Policy describes the rules for how we process information about you, including personal data and cookies.
1. General information
This policy applies to the website operating at: drewmet-pro.pl.
The website operator and personal-data controller is: DREWMET 2 SP. z o.o., 38-420 Korczyna, Wola Komborska 39.
Contact e-mail address of the operator: info@maszyny-drewmet.pl.
The Operator is the Controller of your personal data with respect to data you voluntarily provide on the Website.
The Website uses personal data for the following purposes:
Running a newsletter
Providing online chat conversations
Handling inquiries sent via forms
Preparing, packing and shipping goods
Presenting offers or information
The Website collects information about users and their behaviour in the following ways:
Through data voluntarily entered in forms, which are then entered into the Operator’s systems.
By storing cookies on end-user devices.
2. Selected data-protection methods used by the Operator
Login areas and places where personal data are entered are protected at the transport layer (SSL certificate). This means the personal data and login details you enter on the site are encrypted on your device and can be read only on the target server.
Personal data stored in the database are encrypted so that only the Operator holding the key can read them. This protects the data if the database is stolen from the server.
User passwords are stored in hashed form. Hashing functions are one-way—reversing them is not possible, which is the current standard for password storage.
Two-factor authentication is used on the Website as an additional layer of login protection.
The Operator periodically changes administrative passwords.
To protect data, the Operator regularly creates backups.
An important element of data protection is regularly updating all software used by the Operator to process personal data, in particular programming components.
3. Hosting
The Website is hosted (technically maintained) on servers of the provider: seohost.pl
For technical reliability, the hosting company keeps server-level logs, which may include:
resources identified by URL (addresses of requested resources—pages, files),
time of the request,
time of the response,
client station name—identified by the HTTP protocol,
information about errors that occurred during HTTP transactions,
URL of the page previously visited by the user (referrer) if the transition to the Website occurred via a link,
information about the user’s browser,
IP address information,
diagnostic information related to self-ordering services via on-site forms,
information related to handling e-mail sent to and from the Operator.
4. Your rights and additional information on data use
In some situations the Controller has the right to transfer your personal data to other recipients if this is necessary to perform the contract concluded with you or to fulfil the Controller’s legal obligations. This applies to the following groups of recipients:
hosting company on an entrusted-processing basis,
payment operators,
online chat solution providers,
authorised employees and collaborators who use the data to operate the site,
companies providing marketing services for the Controller.
Your personal data are processed by the Controller no longer than necessary for activities specified by separate regulations (e.g., accounting). For marketing data, processing will not exceed 3 years.
You have the right to request from the Controller:
access to your personal data,
rectification,
erasure,
restriction of processing,
and data portability.
You have the right to object to processing referred to in point 3.2 with respect to processing for the purposes of the Controller’s legitimate interests, including profiling; however, the objection may not be effective where there are compelling legitimate grounds for processing which override your interests, rights and freedoms, in particular the establishment, exercise or defence of legal claims.
You may lodge a complaint about the Controller’s actions with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw.
Providing personal data is voluntary but necessary to use the Website.
Automated decision-making, including profiling, may be applied to you in order to provide services under the contract and for the Controller’s direct marketing.
Personal data are not transferred to “third countries” within the meaning of data-protection regulations. This means we do not send them outside the European Union.
5. Information in forms
The Website collects information voluntarily provided by the user, including personal data if supplied.
The Website may store information about connection parameters (time stamp, IP address).
In some cases, the Website may save information that helps link form data with the e-mail address of the user who filled in the form. In such a case the user’s e-mail address appears inside the URL of the page containing the form.
Data provided in a form are processed for the purpose resulting from the function of a given form (e.g., handling a service request or sales contact, service registration, etc.). The context and description of each form clearly indicate what it is used for.
6. Administrator logs
Information about user behaviour on the Website may be logged. These data are used to administer the Website.
7. Important marketing techniques
The Operator uses statistical analysis of site traffic via Google Analytics (Google Inc., USA). The Operator does not provide this service with personal data, only anonymised information. The service uses cookies stored on the user’s device. Users can view and edit information arising from cookies collected by Google’s ad network using: https://www.google.com/ads/preferences/
The Operator uses remarketing techniques to tailor advertising messages to user behaviour on the site, which may give the impression that personal data are used to track the user; in practice no personal data are transmitted by the Operator to ad operators. These activities require cookies to be enabled.
The Operator uses the Facebook pixel. This technology causes Facebook (Facebook Inc., USA) to know that a registered user has visited the Website. It relies on data for which Facebook is the controller; the Operator does not transmit any additional personal data to Facebook. The service uses cookies stored on the user’s device.
The Operator uses a solution that studies user behaviour by creating heat maps and recording on-site behaviour. This information is anonymised before being sent to the service provider, so the provider does not know which natural person it concerns. In particular, entered passwords and other personal data are not recorded.
The Operator uses a solution that automates the Website’s operation in relation to users, e.g., sending an e-mail to a user after visiting a specific subpage, provided the user has consented to receive commercial correspondence from the Operator.
8. Information about cookies
The Website uses cookies.
Cookies are IT data, in particular text files, stored on the Website User’s end device and intended for using the Website’s pages. Cookies usually contain the name of the website they come from, the time of storage on the end device and a unique number.
The entity placing cookies on the Website User’s end device and accessing them is the Website Operator.
Cookies are used for the following purposes:
maintaining the Website User’s session (after logging in), so the user does not have to re-enter login and password on each subpage;
achieving the purposes specified above in “Important marketing techniques”.
The Website uses two basic types of cookies: “session” cookies and “persistent” cookies. Session cookies are temporary and stored on the User’s end device until logging out, leaving the website or closing the browser. Persistent cookies are stored on the User’s end device for the time specified in the cookie parameters or until deleted by the User.
Web-browsing software (web browser) usually allows cookies to be stored on the User’s device by default. Users can change these settings. The browser allows deletion of cookies; it is also possible to automatically block cookies. Details can be found in your browser’s help or documentation.
Restricting the use of cookies may affect some of the functionalities available on the Website.
Cookies placed on the Website User’s device may also be used by entities cooperating with the Operator, in particular: Google (Google Inc., USA), Facebook (Facebook Inc., USA), Twitter (Twitter Inc., USA).
9. Managing cookies — how to give and withdraw consent in practice?
If you do not wish to receive cookies, you can change your browser settings. Please note that disabling cookies essential for authentication, security or maintaining user preferences may hinder or, in extreme cases, prevent use of the website.
To manage cookie settings, select your browser from the list below and follow the instructions:
Edge • Internet Explorer • Chrome • Safari • Firefox • Opera
Mobile devices:
Android • Safari (iOS) • Windows Phone