Legal
Privacy Policy
- This Privacy Policy sets out the rules for processing personal data obtained via the GTRAX.EU website (hereinafter: the “Website”).
- The owner of the Website and the data controller is Glimat sp. z o.o., with its registered office in Gliwice (44-109), ul. Główna 1c, entered into the register of entrepreneurs of the National Court Register kept by the District Court in Gliwice, X Commercial Division of the National Court Register, under KRS number 0000075984, with share capital of PLN 210,000, NIP: 6312333447, REGON: 277647008, hereinafter referred to as “Glimat”.
- Personal data collected by Glimat via the Website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter “GDPR”.
- Glimat makes every effort to respect the privacy of Customers visiting the Website.
§ 1 Types of data processed, purposes and legal basis
- Glimat collects information concerning natural persons performing a legal act not directly related to their activity, natural persons conducting business or professional activity on their own behalf, and natural persons representing legal persons or organizational units without legal personality to which the law grants legal capacity, conducting business or professional activity on their own behalf, hereinafter jointly referred to as “Customers”.
- Customers’ personal data are collected when:
- submitting an inquiry or order via the form on the Website, for the purpose of performing a sales contract. Legal basis: necessity for the performance of a sales contract (Article 6(1)(b) GDPR);
- When using the form for communication — inquiry or order of goods — the Customer provides the following data:
- e-mail address;
- address data:
- postal code and city;
- country;
- street with house/apartment number.
- first and last name;
- phone number.
- In the case of Entrepreneurs, the above scope of data is additionally extended by:
- the Entrepreneur’s company name;
- VAT number (NIP).
- While using the Website, additional information may be collected, in particular: IP address assigned to the Customer’s computer or external IP address of the Internet provider, domain name, browser type, access time, type of operating system.
- Navigation data may also be collected from Customers, including information about links and references which they decide to click or other actions taken on our Website. Legal basis — legitimate interest (Article 6(1)(f) GDPR), consisting in facilitating the use of services provided by electronic means and improving the functionality of these services.
- For the purpose of establishing, pursuing and enforcing claims, certain personal data provided by the Customer when using the functionalities on the Website may be processed, such as: name, surname, data concerning the use of services, if the claims result from the way the Customer uses the services, and other data necessary to prove the existence of a claim, including the amount of damage suffered. Legal basis — legitimate interest (Article 6(1)(f) GDPR), consisting in establishing, pursuing and enforcing claims and defending against claims in proceedings before courts and other state bodies.
- Personal data provided to Glimat are provided voluntarily in connection with the sales contracts or services concluded via the Website, with the reservation that failure to provide certain data in the forms during Registration prevents Registration and creation of a Customer Account; in the case of placing an order without Registration of a Customer Account, failure to provide such data will prevent the submission and fulfilment of the Customer’s order.
§ 2 Disclosure and retention of data
- The Customer’s personal data are transferred to service providers used by Glimat in operating the Website. Service providers to whom personal data are transferred, depending on contractual arrangements and circumstances, either act on instructions from Glimat as to the purposes and means of processing such data (processors) or independently determine the purposes and means of their processing (controllers).
- Processors. Glimat uses suppliers who process personal data solely on the instructions of Glimat. These include, inter alia, hosting service providers, accounting services, marketing systems, systems for analysing Website traffic, and systems for analysing the effectiveness of marketing campaigns;
- Controllers. Glimat uses suppliers who do not act solely on instructions and independently determine the purposes and means of using Customers’ personal data. They provide electronic payment and banking services.
- Location. Service providers are based mainly in Poland and in other countries of the European Economic Area (EEA).
- Customers’ personal data are stored:
- Where the legal basis for processing personal data is consent, the Customer’s personal data are processed by Glimat until the consent is withdrawn, and after withdrawal of consent for a period corresponding to the limitation period for claims which Glimat may bring and which may be brought against it. Unless a specific provision provides otherwise, the limitation period is ten years, and for claims for periodic benefits and claims related to conducting business activity — three years.
- Where the legal basis for processing is the performance of a contract, the Customer’s personal data are processed by Glimat for as long as necessary to perform the contract, and after that time for a period corresponding to the limitation period for claims. Unless a specific provision provides otherwise, the limitation period is ten years, and for claims for periodic benefits and claims related to conducting business activity — three years.
- In the event of making a purchase from Glimat, personal data may be transferred to forwarding agents and transport companies for the purpose of delivering ordered goods.
- Navigation data may be used to provide Customers with better service, analyse statistical data and adapt the Website to Customers’ preferences, as well as to administer the Website.
- Glimat, upon request, discloses personal data to authorised state bodies, in particular to organisational units of the prosecutor’s office, the Police, the President of the Personal Data Protection Office, the President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications.
§ 3 Cookies and IP address
- The Website uses small files called cookies. They are saved by Glimat on the end device of a person visiting the Website, if the web browser allows it. A cookie file usually contains the name of the domain from which it originates, its “expiry time” and an individual, randomly selected number identifying the file. Information collected by means of such files helps to adapt the products offered by Glimat to the individual preferences and actual needs of persons visiting the Website. It also makes it possible to develop general statistics of visits to presented products.
- Glimat uses two types of cookies:
- Session cookies: after the session of a given browser is ended or the computer is turned off, the saved information is removed from the device’s memory. The session cookies mechanism does not allow any personal data or any confidential information to be downloaded from Customers’ computers.
- Persistent cookies: they are stored in the end device’s memory of the Customer and remain there until they are deleted or expire. The persistent cookies mechanism does not allow any personal data or any confidential information to be downloaded from Customers’ computers.
- Glimat uses its own cookies for the purpose of:
- analyses and research and audience auditing, in particular for creating anonymous statistics that help understand how Customers use the Website, enabling the improvement of its structure and content.
- The cookies mechanism is safe for the computers of the Website Customers. In particular, viruses or other unwanted or malicious software cannot enter Customers’ computers this way. Nevertheless, Customers have the option in their browsers to limit or disable access of cookies to computers. If this option is used, the use of the Website will be possible, except for functions that by their nature require cookies.
- Below we show how to change the settings of popular web browsers regarding the use of cookies:
- Internet Explorer;
- Microsoft Edge;
- Mozilla Firefox;
- Google Chrome;
- Safari;
- Opera.
- Glimat may collect Customers’ IP addresses. An IP address is a number assigned to the computer of a person visiting the Website by the Internet service provider. The IP number enables access to the Internet. In most cases it is assigned to the computer dynamically, i.e. it changes with each connection to the Internet and for this reason is commonly treated as non-personal identifying information. The IP address is used by Glimat for diagnosing technical problems with the server, creating statistical analyses (e.g. determining from which regions we record the most visits), as information useful in administering and improving the Website, as well as for security purposes and possible identification of programs burdening the server and unwanted automatic programs browsing the Website content.
- The Website contains links and references to other websites. Glimat is not responsible for the privacy protection rules applicable on them.
§ 4 Rights of data subjects
- Right to withdraw consent — legal basis: Article 7(3) GDPR.
- The Customer has the right to withdraw any consent given to Glimat.
- Withdrawal of consent has effect from the moment of withdrawal.
- Withdrawal of consent does not affect processing carried out by us in accordance with the law before its withdrawal.
- Withdrawal of consent does not entail any negative consequences for the Customer, but may make it impossible to further use services or functionalities which Glimat may lawfully provide only with consent.
- Right to object — legal basis: Article 21 GDPR.
- The Customer has the right to object at any time to the use of his or her personal data, including profiling, if Glimat processes his or her data on the basis of legitimate interest, e.g. marketing of Glimat products and services, conducting statistics on the use of individual Website functionalities and facilitating the use of the Website, as well as satisfaction surveys.
- Opting out by e-mail message from receiving marketing communications concerning products or services will mean the Customer’s objection to the processing of his or her personal data, including profiling, for these purposes.
- If the Customer’s objection proves justified and Glimat has no other legal basis for processing personal data, the personal data concerning the use of which the Customer has objected will be deleted.
- Right to erasure (“right to be forgotten”) — legal basis: Article 17 GDPR.
- The Customer has the right to request the deletion of all or some personal data.
- The Customer has the right to request the deletion of personal data if:
- personal data are no longer necessary for the purposes for which they were collected or processed;
- he or she has withdrawn specific consent, to the extent that personal data were processed on the basis of his or her consent;
- he or she has objected to the use of his or her data for marketing purposes;
- personal data are processed unlawfully;
- personal data must be deleted in order to comply with a legal obligation under Union or Member State law to which Glimat is subject;
- personal data were collected in connection with the offering of information society services.
- Despite a request to delete personal data due to an objection or withdrawal of consent, Glimat may retain certain personal data to the extent necessary for the purposes of establishing, pursuing or defending claims. This applies in particular to personal data including: name, surname, e-mail address, which are kept for the purposes of handling complaints and claims related to the use of Glimat services, or additionally the address of residence/correspondence address, order number, which are kept for the purposes of handling complaints and claims related to concluded sales contracts or services.
- Right to restriction of processing — legal basis: Article 18 GDPR.
- The Customer has the right to request restriction of processing of his or her personal data. Submitting a request, until it is considered, prevents the use of certain functionalities or services, the use of which will involve processing of data covered by the request. Glimat will also not send any messages, including marketing messages.
- The Customer has the right to request restriction of the use of personal data in the following cases:
- when he or she contests the accuracy of his or her personal data — then Glimat restricts their use for the time necessary to verify the accuracy of the data, but not longer than 7 days;
- when data processing is unlawful and instead of deleting the data the Customer requests restriction of their use;
- when personal data are no longer necessary for the purposes for which they were collected or used but are needed by the Customer for the purposes of establishing, pursuing or defending claims;
- when he or she has objected to the use of his or her data — then restriction takes place for the time necessary to consider whether, due to the particular situation, the protection of the Customer’s interests, rights and freedoms overrides the interests pursued by the Controller by processing the Customer’s personal data.
- Right of access to data — legal basis: Article 15 GDPR.
- The Customer has the right to obtain from the Controller confirmation as to whether personal data are being processed, and if so, the Customer has the right to:
- obtain access to his or her personal data;
- obtain information on the purposes of processing, categories of personal data concerned, recipients or categories of recipients of such data, the envisaged period for which the personal data will be stored or the criteria used to determine that period, the rights of the Customer under the GDPR and the right to lodge a complaint with a supervisory authority, the source of such data, automated decision-making, including profiling, and safeguards applied in connection with the transfer of such data outside the European Union;
- obtain a copy of his or her personal data.
- The Customer has the right to obtain from the Controller confirmation as to whether personal data are being processed, and if so, the Customer has the right to:
- Right to rectification — legal basis: Article 16 GDPR.
- The Customer has the right to request from the Controller the rectification without undue delay of inaccurate personal data concerning him or her. Taking into account the purposes of processing, the data subject has the right to have incomplete personal data completed, including by means of providing an additional statement, by sending a request to the e-mail address in accordance with § 6 of the Privacy Policy.
- Right to data portability — legal basis: Article 20 GDPR.
- The Customer has the right to receive his or her personal data which he or she has provided to the Controller, and then send them to another controller of his or her choice. The Customer also has the right to request that personal data be sent directly by us to such other controller, provided that this is technically possible. In such case the Controller will send the Customer’s personal data in the form of a CSV file, which is a commonly used format, machine-readable and allowing the received data to be transferred to another controller.
- In the event of the Customer exercising any of the rights arising from the above rights, the Controller shall comply with the request or refuse to comply with it without undue delay, but no later than within one month of receiving it. However, if — due to the complex nature of the request or the number of requests — the Controller is unable to comply with the request within one month, it shall comply with it within the following two months, informing the Customer in advance of the intended extension.
- The Customer may submit complaints, inquiries and requests to the Controller concerning the processing of his or her personal data and the exercise of his or her rights.
- The Customer has the right to request from Glimat a copy of the standard contractual clauses by sending a request in the manner indicated in § 6 of the Privacy Policy.
- The Customer has the right to lodge a complaint with the President of the Personal Data Protection Office, in the event of a breach of his or her right to personal data protection or other rights granted under the GDPR.
§ 5 Security management
- Glimat provides Customers with a secure and encrypted connection when transmitting personal data and when logging into the Customer Account. Glimat uses an SSL certificate issued by GeoTrust, Inc., one of the world’s leading companies in the field of security and encryption of data transmitted over the Internet.
§ 6 Changes to the Privacy Policy
- The Privacy Policy may change, about which Glimat will inform Customers 7 days in advance.
- Questions regarding the Privacy Policy should be directed to: office@gtrax.eu
- Date of last modification: 25.05.2018.
