Privacy Policy
Privacy and cookies policy of BUDVAR Sp. z o.o.
Controller
The controller of your personal data is Budvar Sp. z o.o., with its registered office in Warsaw (02-676), ul. Postępu 10, hereinafter referred to as the "Controller".
Contact
For any matters related to the protection of personal data, you can contact our Data Protection Officer:
- by post: ul. Przemysłowa 36, 98-220 Zduńska Wola,
- by e-mail to: iod@budvar.pl
Glossary
For the purposes of this Policy, capitalised terms mean:
- "Service" – the main website at https://budvarwindows.com/ and its subpages;
- "Policy" – means this document, i.e. the privacy policy;
- "GDPR" – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;
- "Fanpage" – the Budvar fanpage that we operate on Facebook.
Contact via form / e-mail / phone
For what purpose do we process your data?
We want to provide a complete answer to your questions, resolve your matter and prepare an offer, so we need to be able to identify you. We do not ask for more than your name, surname, phone number or e-mail address.
Is providing your data mandatory?
It is voluntary, but without providing your data we will not be able to contact you back to give you an answer.
What is the basis for processing your data?
Art. 6(1)(f) GDPR, i.e. our legitimate interest.
How should our legitimate interest be understood?
It is providing an answer, contacting you for this purpose and preparing an offer for you.
Who can access your data?
Your data is very valuable to us. Only the provider that hosts this website for us can access it – when using the contact form on the Service.
How long will we process your data?
For as long as necessary to provide an answer. However, we may retain your data for the limitation period of claims related to your case.
Business cooperation
For what purpose do we process your data?
Your personal data is processed for the conclusion of a cooperation agreement (or another commercial contract) or its proper performance. We need data that uniquely identify you: name, surname, address, PESEL/NIP, ID card number.
We also process personal data for analytical and statistical purposes to improve our services.
We also fulfil statutory obligations – hence your data is shared with state authorities.
We may also process your data in case of the need to establish, pursue or defend against claims.
We also conduct marketing activities to inform about our offer. For phone or e-mail contact, we obtain your consent.
Is providing data mandatory?
It is voluntary, but without providing the data we will not be able to conclude and perform the contract.
What is the basis for processing your data?
The basis is primarily the necessity to conclude or perform the contract (Art. 6(1)(b) GDPR). If you act as a representative, proxy or employee of the cooperating party, the basis is our legitimate interest (Art. 6(1)(f) GDPR).
For analytical and statistical purposes, the basis is the legitimate interest (Art. 6(1)(f) GDPR).
For the fulfilment of statutory obligations – Art. 6(1)(c) GDPR.
Establishing, pursuing or defending against claims – legitimate interest (Art. 6(1)(f) GDPR). Marketing – legitimate interest (Art. 6(1)(f) GDPR) and Art. 10 of the Act on Providing Electronic Services and Art. 172 of the Telecommunications Law.
How should our legitimate interest be understood?
It is the possibility of contacting you to perform or conclude a contract, improving the quality of our services, effectively pursuing and defending against claims, and informing about our offer.
Who can access your data?
Your data is very valuable to us. Only service providers (accounting, IT, legal) with whom we have concluded data processing agreements can access it. Data is also shared with authorities.
How long will we process your data?
For as long as necessary to conclude and perform the contract. However, we may retain the data for the limitation period of claims and tax obligations.
Complaint form
For what purpose do we process your data?
The quality of our products is our priority, so we want to respond to your complaint and solve your problem. We only ask for name, surname, phone, e-mail, town, postal code and installation location.
Is providing data mandatory?
It is voluntary, but without providing the data we cannot contact you back to respond to your complaint.
What is the basis for processing your data?
Art. 6(1)(b) GDPR, i.e. performance of the contract.
Who can access your data?
Your data is very valuable to us. Only the provider that hosts this website for us can access it – when using the complaint form. Installers or other persons commissioned, e.g. to repair the complained window, may also have access.
How long will we process your data?
For as long as necessary to handle your complaint. However, we may retain your data for the limitation period of claims related to the matter.
Budvar fanpage on Facebook
Who is the controller?
If you have a Facebook account, that platform is the controller of your personal data.
We, BUDVAR Sp. z o.o., are the controller of your data if:
- you make posts or comments on our profiles,
- you follow our profile,
- you correspond with us as the profile administrator,
- you register for events we organise.
For what purpose do we process your data?
We want to: reply to private messages, respond to comments, inform you about our services through new posts, know how many people follow us, what interests them and our reach.
Within our profile, we may also enable newsletter subscriptions and the sending of informational materials. So our purpose is direct marketing and analytical/statistical goals.
Is providing data mandatory?
It is voluntary, but sending a query or commenting on our fanpage will reveal your name. We may also have access to the information you post on your public profile.
What is the basis for processing your data?
Art. 6(1)(f) GDPR, i.e. our legitimate interest.
How should our legitimate interest be understood?
It is providing an answer and contacting you for this purpose. Informing about our offer, collecting data to analyse the quality of our services.
Who can access your data?
Facebook Ireland Ltd. and related entities have access to your data, which means your data will be transferred outside the EEA – to the United States.
How long will we process your data?
For as long as necessary to respond. We may retain your data for the limitation period of claims. The retention period also depends on whether you still follow our profile or have a Facebook account.
Visit source (enquiry attribution)
To know which of our activities (e.g. advertising, search engine, referral) led you to send an enquiry, together with the form we record information about the source of your visit: campaign parameters (UTM), ad click identifiers, the referring page and the first subpage visited.
If you consent to marketing cookies, we store this information in the budvar_attrib cookie for 90 days (allowing earlier visits to be linked to the enquiry). Without that consent we store nothing on your device — the source of the current visit is kept only in browser memory for its duration and attached to the form upon submission. The processing basis is our legitimate interest (Art. 6(1)(f) GDPR) — analysing the effectiveness of our marketing activities.
Live chat and AI assistant
A chat is available on the Service. In AI-assistant mode, the content of your messages is transmitted to our AI provider — OpenAI (USA) — solely to generate the reply. We do not store AI-assistant conversations in our database; please do not include personal or sensitive data in them.
In consultant-conversation mode, the data you provide (first name, optional e-mail) and the conversation content reach our team via Microsoft Teams (Microsoft, Azure cloud — processing in the USA possible). Messages left outside working hours are saved as a contact enquiry. Basis: our legitimate interest — handling your enquiry (Art. 6(1)(f) GDPR).
AI visualiser
The visualiser lets you see our products on a photo of your house. The uploaded photo is transmitted to our AI provider — Google (Gemini service, USA) — solely to generate the visualisation. We do not permanently store your photos on our servers. Please do not upload photos showing people. Processing basis: your action (using the tool) and our legitimate interest (Art. 6(1)(f) GDPR).
Regional advisor (approximate location)
To point you to the right regional advisor, we determine an approximate region from your IP address — using a geolocation database running on our own server, so the IP address is neither transmitted to third parties nor stored for this purpose. You can also voluntarily provide a postal code or use GPS location — the latter requires your separate consent in the browser. The assigned advisor is remembered in the budvar_advisor cookie for 7 days. Basis: our legitimate interest — efficiently directing you to the right advisor (Art. 6(1)(f) GDPR).
Data recipients and our CRM system
Form submissions reach — in addition to our database — our internal CRM system (BConnect), hosted in the Microsoft Azure cloud, where our advisors handle customer enquiries. Recipients may also include: the Service hosting provider, the providers of the tools described in this Policy (to the extent indicated therein) and — where required by law — public authorities. All processors acting on our behalf are bound by data processing agreements.
Data transfers outside the EEA
We use services from providers whose data centres may be located outside the European Economic Area (in particular in the USA): Google (Analytics, Ads, Maps, the Gemini AI service), Meta (Facebook pixel), Microsoft (Clarity, Teams/Azure), OpenAI (AI assistant) and Cloudflare (Turnstile). Transfers take place based on a European Commission adequacy decision (EU–US Data Privacy Framework) — where the provider holds active certification — or Standard Contractual Clauses (SCC). You can obtain more information about the safeguards applied by contacting us at the address indicated in the Contact section.
Personal data security
All personal data you provide on the Service or when contacting us is processed by us as the Controller in accordance with the GDPR.
We strive to apply the technical measures required by current data protection regulations to prevent loss, destruction or modification of the personal data we hold.
We inform you that your personal data is not subject to automated decision-making producing legal effects. To the extent we use tools from providers outside the EEA, your data may be transferred outside the European Economic Area — details and safeguards are described in the "Data transfers outside the EEA" section.
Your rights regarding personal data
We process your personal data, therefore:
- you have the right to access your personal data,
- you can rectify them,
- you can request their deletion when GDPR allows it,
- you have the right to restriction of processing, as defined in the GDPR,
- the right to object (in particular when we process data based on our legitimate interests),
- the right to lodge a complaint with the President of the Data Protection Office if we process your data unlawfully.
If you would like to exercise your rights or simply find out more, do not hesitate to contact us – our contact details are at the beginning of the Policy.