BUDVAR
Legal documents

Privacy Policy

Privacy and cookies policy of BUDVAR Sp. z o.o.

Controller

The controller of your personal data is Budvar Sp. z o.o., with its registered office in Warsaw (02-676), ul. Postępu 10, hereinafter referred to as the "Controller".

Contact

For any matters related to the protection of personal data, you can contact our Data Protection Officer:

  • by post: ul. Przemysłowa 36, 98-220 Zduńska Wola,
  • by e-mail to: iod@budvar.pl

Glossary

For the purposes of this Policy, capitalised terms mean:

  • "Service" – the main website at https://budvarwindows.com/ and its subpages;
  • "Policy" – means this document, i.e. the privacy policy;
  • "GDPR" – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;
  • "Fanpage" – the Budvar fanpage that we operate on Facebook.

Contact via form / e-mail / phone

For what purpose do we process your data?

We want to provide a complete answer to your questions, resolve your matter and prepare an offer, so we need to be able to identify you. We do not ask for more than your name, surname, phone number or e-mail address.

Is providing your data mandatory?

It is voluntary, but without providing your data we will not be able to contact you back to give you an answer.

What is the basis for processing your data?

Art. 6(1)(f) GDPR, i.e. our legitimate interest.

How should our legitimate interest be understood?

It is providing an answer, contacting you for this purpose and preparing an offer for you.

Who can access your data?

Your data is very valuable to us. Only the provider that hosts this website for us can access it – when using the contact form on the Service.

How long will we process your data?

For as long as necessary to provide an answer. However, we may retain your data for the limitation period of claims related to your case.

Business cooperation

For what purpose do we process your data?

Your personal data is processed for the conclusion of a cooperation agreement (or another commercial contract) or its proper performance. We need data that uniquely identify you: name, surname, address, PESEL/NIP, ID card number.

We also process personal data for analytical and statistical purposes to improve our services.

We also fulfil statutory obligations – hence your data is shared with state authorities.

We may also process your data in case of the need to establish, pursue or defend against claims.

We also conduct marketing activities to inform about our offer. For phone or e-mail contact, we obtain your consent.

Is providing data mandatory?

It is voluntary, but without providing the data we will not be able to conclude and perform the contract.

What is the basis for processing your data?

The basis is primarily the necessity to conclude or perform the contract (Art. 6(1)(b) GDPR). If you act as a representative, proxy or employee of the cooperating party, the basis is our legitimate interest (Art. 6(1)(f) GDPR).

For analytical and statistical purposes, the basis is the legitimate interest (Art. 6(1)(f) GDPR).

For the fulfilment of statutory obligations – Art. 6(1)(c) GDPR.

Establishing, pursuing or defending against claims – legitimate interest (Art. 6(1)(f) GDPR). Marketing – legitimate interest (Art. 6(1)(f) GDPR) and Art. 10 of the Act on Providing Electronic Services and Art. 172 of the Telecommunications Law.

How should our legitimate interest be understood?

It is the possibility of contacting you to perform or conclude a contract, improving the quality of our services, effectively pursuing and defending against claims, and informing about our offer.

Who can access your data?

Your data is very valuable to us. Only service providers (accounting, IT, legal) with whom we have concluded data processing agreements can access it. Data is also shared with authorities.

How long will we process your data?

For as long as necessary to conclude and perform the contract. However, we may retain the data for the limitation period of claims and tax obligations.

Complaint form

For what purpose do we process your data?

The quality of our products is our priority, so we want to respond to your complaint and solve your problem. We only ask for name, surname, phone, e-mail, town, postal code and installation location.

Is providing data mandatory?

It is voluntary, but without providing the data we cannot contact you back to respond to your complaint.

What is the basis for processing your data?

Art. 6(1)(b) GDPR, i.e. performance of the contract.

Who can access your data?

Your data is very valuable to us. Only the provider that hosts this website for us can access it – when using the complaint form. Installers or other persons commissioned, e.g. to repair the complained window, may also have access.

How long will we process your data?

For as long as necessary to handle your complaint. However, we may retain your data for the limitation period of claims related to the matter.

Newsletter

For what purpose do we process your data?

We want to show you our offer, find out whether it interests you and what content you prefer. Our purpose is therefore the marketing of our services and products. We process your first name and e-mail address.

Is providing data mandatory?

It is voluntary, but without providing the data you will not be able to subscribe to our newsletter.

What is the basis for processing your data?

Art. 6(1)(f) GDPR (legitimate interest) and the so-called "channel consent" (Art. 10 of the Act on Providing Electronic Services and Art. 172 of the Telecommunications Law), expressed by clicking "Subscribe to the newsletter".

How should our legitimate interest be understood?

It is informing you about our news and offer, as well as analysing the quality of our content and tailoring the newsletter to you.

Who can access your data?

Only the hosting provider of this site and the provider of the mailing tool can access your data.

How long will we process your data?

For as long as you do not object to our activities.

Budvar fanpage on Facebook

Who is the controller?

If you have a Facebook account, that platform is the controller of your personal data.

We, BUDVAR Sp. z o.o., are the controller of your data if:

  • you make posts or comments on our profiles,
  • you follow our profile,
  • you correspond with us as the profile administrator,
  • you register for events we organise.

For what purpose do we process your data?

We want to: reply to private messages, respond to comments, inform you about our services through new posts, know how many people follow us, what interests them and our reach.

Within our profile, we may also enable newsletter subscriptions and the sending of informational materials. So our purpose is direct marketing and analytical/statistical goals.

Is providing data mandatory?

It is voluntary, but sending a query or commenting on our fanpage will reveal your name. We may also have access to the information you post on your public profile.

What is the basis for processing your data?

Art. 6(1)(f) GDPR, i.e. our legitimate interest.

How should our legitimate interest be understood?

It is providing an answer and contacting you for this purpose. Informing about our offer, collecting data to analyse the quality of our services.

Who can access your data?

Facebook Ireland Ltd. and related entities have access to your data, which means your data will be transferred outside the EEA – to the United States.

How long will we process your data?

For as long as necessary to respond. We may retain your data for the limitation period of claims. The retention period also depends on whether you still follow our profile or have a Facebook account.

Cookies

On your end device (computer, tablet, smartphone) we install cookies – small text files. They collect information that facilitates the use of the website – e.g. remembering visits, gathering data on how you moved through the site and what interested you, displaying ads based on user behaviour.

Analytics tools

We use tools such as Google Analytics, which allows us to track traffic on our site and better adapt to your needs. We do not process your personal data for this purpose.

We use the tool Hotjar Ltd. to better understand the needs and experience of our Users and optimise our online services (e.g. session length, mouse movement, click locations). We collect: IP (captured and stored only in anonymous form), screen size, browser info, geolocation (country only), preferred language, click maps and other charts, as well as session recordings.

We also use the tool SmartLook. It allows us to collect information such as operating system and browser, time spent on the site, traffic source, and visited subpages.

Our service also has the Facebook pixel. It is an analytical tool that lets us measure the effectiveness of our marketing activities. Thanks to it we know what actions visitors take on the Service, and we can reach people who may be interested in our offer. We do not process personal data when using this tool.

For the same purpose we use the LinkedIn pixel.

Bot protection

To protect our contact forms and tools (including the AI visualiser, quote and contact forms) from abuse, spam and bot attacks, we use the service Cloudflare Turnstile (operator: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA). For bot/human verification, the device IP address, browser identifier (User-Agent) and selected behavioural signals (e.g. mouse movements) are transmitted to Cloudflare. The data is processed solely to secure our services and is not used for marketing profiling. Legal basis: our legitimate interest (Art. 6(1)(f) GDPR) — protection from automated abuse. Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/.

How to remove cookies

You can configure your browser to prevent cookies being stored on your computer, phone or tablet. You can delete cookies after they have been saved using the appropriate browser functions.

We do not use profiling based on personal data. Even when we use personalised advertising, no processing of your personal data takes place within the tools we use.

Personal data security

All personal data you provide on the Service or when contacting us is processed by us as the Controller in accordance with the GDPR.

We strive to apply the technical measures required by current data protection regulations to prevent loss, destruction or modification of the personal data we hold.

We inform you that your personal data is not subject to automated decision-making, including profiling. We do not transfer your data to a third country or international organisation.

Your rights regarding personal data

We process your personal data, therefore:

  • you have the right to access your personal data,
  • you can rectify them,
  • you can request their deletion when GDPR allows it,
  • you have the right to restriction of processing, as defined in the GDPR,
  • the right to object (in particular when we process data based on our legitimate interests),
  • the right to lodge a complaint with the President of the Data Protection Office if we process your data unlawfully.

If you would like to exercise your rights or simply find out more, do not hesitate to contact us – our contact details are at the beginning of the Policy.