PRIVACY AND COOKIES POLICY

RULES FOR THE PROCESSING OF PERSONAL DATA WHEN USING THE SUBKO.CO WEBSITE

We process your personal data in accordance with applicable law, including Regulation (EU)

2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and the repeal of the directive 95/46/EC (General Data Protection Regulation) – the so-called GDPR and other provisions regarding the processing of personal data.

This privacy and cookie policy contains information about the processing of personal data by us and information about the purpose of using cookies by the website.

Who does this Privacy Policy apply to?

This Privacy Policy (hereinafter referred to as PP) applies to the processing of personal data of natural persons, natural persons conducting sole proprietorship and persons acting on behalf of legal persons, i.e. persons appointed to represent a legal person, proxies, employees and / or associates acting on behalf of a legal person. The categories of personal data concerned are natural persons acting alone, natural persons acting on behalf of organizational units without legal personality, natural persons acting on behalf of legal persons (e.g. as members of their bodies, proxies, contact persons), e.g. at the beginning of preceding the conclusion of the contract or after its conclusion.

Personal data controller

The administrator of your personal data is the company operating under the name – subko&co Spółka z ograniczoną odpowiedzialnością Spółka komandytowa with its registered office in Warsaw, address: ul. Stanisława Wyspiańskiego 6/8/33, 01-577 Warszawa, entered into the Register of Entrepreneurs of the National Court Register under the KRS number: 0000574921 , REGON number: 362483995, NIP: 5252631323 .

Contact with the personal data administrator

Please, be informed that the Controller did not appoint the Data Protection Officer. You can contact us via e-mail – contact@subko.co 

Information about Joint controllers

Facebook

  1. Please be advised that the Controller runs a fanpage (s) on Facebook and Instagram (https://www.facebook.com/SUBKOandCO/; https://www.instagram.com/subko_co/),
  2. Please be advised that in connection with running a fanpage on FB and Instagram, there is co-administration (Article 26 of the GDPR). The Joint controllers with regard to personal data processed on the fanpage are or may be:
  1. subko&co,
  2. Meta Platforms Ireland Limited, 
  1. Please be advised that the Joint controllers made common arrangements. Information on co-administration and responsibilities is available at: https://www.facebook.com/legal/controller,
  2. Please be advised that regardless of the arrangements made between the Joint controllers, the data subject may exercise his rights under the GDPR with respect to each of the data Controllers separately,
  3. Contact details to the Data Protection Officer:
  1. please be informed that the subko&co did not appoint the Data Protection Officer,
  2. contact details to the Data Protection Officer on behalf of Facebook Ireland Limited are available at: https://www.facebook.com/privacy/explanation
  3. We hereby inform that due to the co-administration, the supervisory authorities competent for the Controllers are:
  1. for subko&co – President of the Personal Data Protection Office (Personal Data Protection Office), 2 Stawki Street, 00-193 Warsaw, Poland,
  2. for Facebook Ireland Limited – Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland: https://www.dataprotection.ie/

LinkedIn

  1. Please be advised that the Controller runs a fanpage (s) on LinkedIn (https://www.linkedin.com/company/subko-&-co/),
  2. Please be advised that in connection with running a fanpage on LinkedIn, there is co-administration (Article 26 of the GDPR). The Joint controllers with regard to personal data processed on the fanpage are or may be:
  1. subko&co,
  2. LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, 
  1. Please be advised that the Joint controllers made common arrangements. Information on co-administration and responsibilities is available at: https://legal.linkedin.com/pages-joint-controller-addendum
  2. Please be advised that regardless of the arrangements made between the Joint controllers, the data subject may exercise his rights under the GDPR with respect to each of the data Controllers separately,
  3. Contact details to the Data Protection Officer:
  1. please be informed that subko&co did not appoint the Data Protection Officer,
  2. contact details to the Data Protection Officer on behalf of LinkedIn are available at: https://www.linkedin.com/legal/privacypolicy?src=direct%2Fnone&veh=direct%2Fnone,   
  3. We hereby inform that due to the co-administration, the supervisory authorities competent for the Controllers are:
  1. for subko&co – President of the Personal Data Protection Office (Personal Data Protection Office), 2 Stawki Street, 00-193 Warsaw, contact to the supervisory body is available at: https://uodo.gov.pl/en/484,  
  2. for LinkedIn – Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland: https://www.dataprotection.ie/

What are personal data and the processing of personal data

Personal data is any information relating to an identifi ed or identifi able natural person. The processing of personal data is any activity with the use of personal data, regardless of whether it is automated or not. The processing of personal data includes, inter alia, their collection, storage, recording, ordering, viewing, modifying, using, limiting, deleting or destroying.

We process your personal data on the terms set out by law, regulations and this privacy policy.

What personal data we process, why and how we obtain it

We obtain your personal data primarily from you. Personal data is obtained by us when you are using the website, as well as when you are actively using the website’s functionality, such as fi lling out forms or sending messages.

Personal data is also collected when the Customer (you) initiates contact with us, including for the purpose of carrying out the complaint process or the right to withdraw from the contract.

We process your personal data in the following scope:

  • first name and last name, 
  • company name,
  • Address,
  • HQ address,
  • delivery address (for delivery),
  • NIP number
  • e-mail address,
  • Phone number,
  • information on how the website is used in connection with cookies (if you give your consent),
  • information about the device used from which the website is accessed and about its settings, including information on the browser used, screen resolution),
  • history of your contacts with us,
  • data from publicly available sources (such as KRS or CEiDG),
  • additional information that you provided to us when contacting us,
  • information about your consents.

Remember that the provision of personal data is not obligatory.

When providing us with personal data, remember that it must be true and complete.

Purposes of personal data processing and the basis for their processing

We process your personal data for the purpose of running our website, sales and for marketing purposes. As part of the website www.subko.co, we process your data to ensure the functionality of our website.

As part of the sale, we process your personal data in order to complete your order and carry out the sale transaction, including receipt of payment, issuing sales documents, delivery of goods or services, enabling the exercise of the rights of the Customer, performance of a service or delivery of goods or services.

As part of marketing purposes, we process your personal data to promote our offer and services and improve their quality. For this purpose, we use profiling that does not affect your rights and freedoms (profiling will not lead to automated decision-making that could have legal effects on your person). If you give your voluntary consent (which you will be able to withdraw at any time) for commercial communication by e-mail or telephone, we will use your data (including email address, name and surname, telephone number, address of the registered office) in order to provide our commercial offer.

Your personal data is processed, incl. for the purpose and on the basis of:

  • in order to perform sales contracts and agreement concluded with the Customer – on the basis of an agreement concluded with the administrator, by accepting the website regulations, art. 6 section 1 lit. b), f) GDPR. Please, be informed that processing of personal data in order to prepare, conclude and implement the provisions of the contract, agreement is contractual, and failure to provide personal data will result in the inability to prepare, conclude and implement the provisions of the contract, agreement,
  • in order to answer questions about our goods and services, before concluding a contract – pursuant to art. 6 section 1 lit. f) GDPR. Please, be informed that providing personal data is voluntary, but failure to provide personal data will result in the inability to respond to inquiries or correspondence Please, be informed the the legitimate purpose of the controller for processing personal data is to answer any received questions and providing the ongoing correspondence,in order to handle complaints, handle claims, pursue claims – art. 6 section 1 lit. c), f) GDPR. Please, be informed that providing personal data is necessary to handle complaints, handle claims, pursue claim if applicable. Please, be informed the the legitimate purpose of the controller for processing personal data is defense against claims, 
  • in order to implement our so-called legally justified interests occurring in the case of, for example, establishing, existence, and pursuing claims – Art. 6 sec. 1 f) GDPR. Please, be informed that providing personal data is necessary to implement our so-called legally justified if applicable, Please, be informed the the legitimate purpose of the controller for processing personal data is defense against claims,if the Customer agrees separately, in order to send commercial information and offer regarding the our services, including promotional offers to the e-mail address or telephone number provided, the basis for data processing is consent, which is not mandatory and may be withdrawn at any time – Art. 6 section 1 lit. a), f) GDPR. Please, be informed that providing the information in voluntary, and failure to provide personal data will result in the inability to prepare and send the commercial, marketing information. Please, be informed the the legitimate purpose of the controller for sending the marketing information is the ongoing relationship with the clients for example the current agreement.
  • personal data processed in connection with participation in the survey in order to prepare commercial information and send the offer – the lawfulness of processing in art. 6 (1) a) GDPR – consent of natural person. Please, be informed that providing the information in voluntary, and failure to provide personal data will result in the inability to take a part in the survey and preparing and sending the commercial information,
  • We also process your personal data for marketing purposes in order to present offers and promotions, to obtain customer opinions about products and services, and to present the Customer with personalized marketing messages when using the website, e.g. in the form of a purchase suggestion using profiling. The messages will be prepared on the basis of, for the analysis of purchases made by the customer – based on the legitimate interest of the Administrator – art. 6 section 1 lit. f) GDPR. Please, be informed that providing the information in voluntary, and failure to provide personal data will result in the inability to prepare and send the commercial, marketing information. Please, be informed the the legitimate purpose of the controller for sending the marketing information is the ongoing relationship with the clients for example the current agreement. 

How long do we process your personal data

The time during which we process your personal data is related to the basis for their processing. We do not process personal data for a period longer than that resulting from the legal grounds for processing.

If your consent is the basis for data processing, we process the data until it is revoked. After this time, we will process your data for purposes related to the accountability of our activities, within the scope of obligations under the provisions on the protection of personal data and for the period of limitation of claims related to the contract.

In the event that the data is processed on the basis of the legitimate interest of the data controller, we process the data until the termination of the above-mentioned interest (e.g. until the statute of limitations for civil law claims) or until you object to the processing of your data – in situations where such objection is possible.

If the basis for processing is the performance of the contract, the data is processed until its performance and settlement and until the expiry of the limitation period for claims related to the contract.

If the processing of personal data is necessary due to applicable law – until the time specified in these provisions.

When and how do we share personal data with third parties? 

We can provide your data to:

  • our employees and associates who must have access to data to be able to fulfi ll our obligations,
  • advertising agencies or other entities organizing or conducting, or cooperating or
  • intermediating in the organization, or conducting our marketing campaigns,
  • entities operating our ICT systems,
  • entities providing us with advisory, consulting, audit services or legal, tax and accounting assistance,
  • entities conducting postal or courier activity – in order to deliver correspondence or parcels,
  • entities transporting goods shipments or forwarding services – in order to deliver goods shipments,
  • entities conducting payment activity (banks, payment institutions) – in order to make refunds or to ensure the operation of the direct debit service.

For each of the above purposes, we provide only the data that is necessary to achieve it.

Transferring personal data to a third country (i.e. outside the EEA)

  1. Please be advised that personal data may be transferred to a third country, i.e. outside the EEA. In the event of transferring personal data outside the European Economic Area, such transfer may only take place on the terms set out in Chapter V of the GDPR:
  1. pursuant to art. 45 GDPR – transfer based on an adequacy decision,
  2. pursuant to art. 46 GDPR – transfer subject to appropriate safeguards, including the use of standard data protection clauses adopted by the European Commission,
  3. Please be advised that the list of entities outside the EEA to which the Controller discloses personal data is available at the request of the data subject.

Your rights related to the processing of personal data by us

Due to the fact that we process your personal data, you have the following rights:

  • the right to access your personal data – you have the right to access your personal data that we process. This means that you can ask for the data that we have about you to be provided,
  • the right to request rectifi cation or supplementation of your personal data – we try to ensure that the data is up-to-date, so please provide true and current data. If you learn that the data processed by us is incorrect, you have the right to request it to be corrected
  • the right to request the deletion of your personal data – you can exercise this right if the data is no longer necessary for the purposes for which it was collected, or you have withdrawn your consent to the processing of data or in the event of objecting to the processing of data, as well as its unlawful processing. We will not be able to delete data if we have an obligation under the law to process them,
  • withdrawal of consent – if we process personal data on the basis of consent, you have the right to withdraw it at any time,
  • the right to request a restriction of the processing of personal data – if you decide that we are processing too wide a catalog of your data for specific purposes, you have the right to request that this scope be limited. This scope will be limited, as long as it does not contradict the obligations imposed on us by law, or it is not necessary to achieve the purpose of the contract,
  • the right to object due to a special situation – in accordance with art. 2 1 GDPR,
  • the right to transfer data to another administrator – in accordance with the GDPR, you can ask us to export the data you provided to us in the course of all our contacts and all cooperation to a separate file for further transfer to another data administrator, if the basis for their processing was consent and processing is done automatically.

To exercise your rights, contact us via e-mail – contact@subko.co

Consents collected from clients

We collect the following consents from our clients:

Consent to communicate by e-mail or telephone for marketing purposes – for the purpose of presenting price offers, promotions, new products&services. This consent is expressed when downloading our materials or filling out forms on our website.

Expressing consent is voluntary and the possibility of using our website or its functionality is not dependent on it.

The consent expressed may be withdrawn at any time. We make every effort to ensure that actions related to the withdrawal of consent are undertaken without undue delay. Withdrawal of consent does not affect the lawfulness of the processing that took place before its withdrawal.

Who is the supervisory authority?

We would like to inform you thet the supervisory authority is the President of the Personal Data Protection Office (UODO) with its seat at 2 Stawki Street in Warsaw, Poland, https://uodo.gov.pl/

Cookie files (cookies)

We use cookies. These fi les are saved in the memory of your device and allow, among other things, to use all the functions of the website, they do not change the settings of your device.

Cookies are small text information (text fi les) sent by the server and saved on your device as a visitor. These fi les are widely used on the Internet.

Cookies provide information about your movements on the website and the use of our website. The information recorded in cookies is used, inter alia, for advertising and statistical purposes and to adapt our websites to the individual needs of the client.

You can change cookie settings in your web browser (including deleting or blocking them). We use cookies for the following purposes:

  • personalization of the website (for example: remembering the selected font size, choosing the version for the visually impaired or the color version),
  • login service – verifi cation of the connection between the client and our servers. We do not store information identifying individual users, and this only applies to remembering the data and user choices (e.g. no need to enter the login and password each time on each subpage, remembering the login when visiting again, remembering the contents of the basket),
  • enabling interaction with social networks,
  • presenting profi led offers,
  • creating website statistics and statistics of user flow between different websites