Privacy policy

1. This Privacy Policy defines the rules for processing personal data obtained through the website mbsbag.pl, hereinafter referred to as the „Website”.

2. The owner of the Website and at the same time the Data Controller is MBS Trade sp. z o.o., 90-422 Łódź, ul. Piotrkowska 71/14, NIP: 7272696893, hereinafter referred to as the Administrator.

3. Personal data collected by the Administrator via the Website are processed in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as GDPR.

4. The Administrator takes particular care to respect the privacy of Clients visiting the Website.

§ 1 Type of processed data, purposes and legal basis

1. The Administrator collects information concerning natural persons performing legal actions not directly related to their business activity, natural persons conducting business or professional activities on their own behalf, and natural persons representing legal entities or organizational units that are not legal entities but have legal capacity granted by law, conducting business or professional activities on their own behalf, hereinafter collectively referred to as Clients.

2. The Administrator processes personal data of Clients when using the contact form service on the Website to the extent necessary to perform the contract or take action prior to its conclusion – the legal basis for processing is Article 6(1)(b) of the GDPR.

3. When using the contact form service, the Client provides the following data:

  • email address
  • first name
  • phone number

4. While using the Website, additional information may be collected, in particular: the IP address assigned to the Client’s computer or the external IP address of the Internet provider, domain name, browser type, access time, and type of operating system. Clients’ navigation data may also be collected, including information about links and references clicked or other actions taken on the Website for the purpose of providing services, as well as for technical, administrative, analytical, and statistical purposes – in this regard, the basis for processing is also Article 6(1)(f) of the GDPR, i.e. the necessity for the purposes arising from the legitimate interests of the Administrator, such as ensuring IT security, managing the Website, and improving the functionality of the Website and the provided services.

§ 2 Data recipients

1. The Client’s personal data are transferred to service providers used by the Administrator while operating the Website. Depending on contractual arrangements and circumstances, these service providers either act on the instructions of the Administrator regarding the purposes and methods of data processing (processors), or independently determine the purposes and methods of processing (controllers).

  • 1.1. Processors. The Administrator uses providers who process personal data solely on the instructions of the Administrator. These include, among others, providers of hosting services, accounting services, marketing systems, website traffic analysis systems, and marketing campaign effectiveness analysis systems.

  • 1.2. Controllers. The Administrator uses providers who do not act solely on instruction and independently determine the purposes and methods of processing Clients’ personal data. They provide electronic payment and banking services.

2. Location. Service providers are mainly based in Poland and other countries of the European Economic Area (EEA).

3. Upon request, the Administrator may provide personal data to authorized state authorities, in particular to organizational units of the Prosecutor’s Office, the Police, the President of the Personal Data Protection Office, the President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications.

§ 3 Data storage period

1. Clients’ personal data are stored as follows:

  • 1.1. If the basis for processing personal data is consent, the Client’s personal data are processed by the Administrator until the consent is withdrawn, and after withdrawal – for a period corresponding to the limitation period for claims that may be raised by or against the Administrator. Unless otherwise provided by special legislation, the limitation period is six years, and for periodic performance claims and claims related to business activity – three years.

  • 1.2. If the basis for processing personal data is the performance of a contract, the Client’s personal data are processed by the Administrator as long as it is necessary to perform the contract, and thereafter for a period corresponding to the limitation period for claims. Unless otherwise provided by special legislation, the limitation period is six years, and for periodic performance claims and claims related to business activity – three years.

§ 4 Cookie mechanism, IP address

1. The Website uses small files called cookies. They are stored by the Administrator on the end device of the person visiting the Website if the web browser allows it. A cookie file usually contains the domain name from which it originates, its „expiration time” and an individual randomly selected identification number for the file. The information collected using these files helps tailor the products offered by the Administrator to the individual preferences and actual needs of the persons visiting the Website.

2. The Administrator uses two types of cookies:

  • 2.1. Session cookies: after the session of a given browser ends or the computer is turned off, the stored information is deleted from the device’s memory. The session cookie mechanism does not allow for the collection of any personal data or any confidential information from Clients’ computers.
  • 2.2. Persistent cookies: are stored in the Client’s end device memory and remain there until they are deleted or expire. The persistent cookie mechanism does not allow for the collection of any personal data or any confidential information from the Client’s computer.

3. The Administrator uses its own cookies for the purpose of:

  • 3.1. analysis and research, and audience measurement, in particular to create anonymous statistics that help understand how Clients use the Website, enabling the improvement of its structure and content.

4. The Administrator uses external cookies for the purpose of:

  • 4.1. displaying, on the Website’s information pages, a map indicating the location of the Administrator’s office, using the online service maps.google.com (external cookie administrator: Google Inc., based in the USA).

5. The cookie mechanism is safe for Clients’ computers visiting the Website. In particular, it is not possible for viruses or other unwanted or malicious software to infiltrate Clients’ computers through this method. Nevertheless, Clients can limit or disable cookies in their browsers. If this option is used, the use of the Website will still be possible, except for functions that by their nature require cookies.

6. The Administrator may collect Clients’ IP addresses. An IP address is a number assigned to the computer of a person visiting the Website by an Internet service provider. The IP number enables access to the Internet. In most cases, it is assigned dynamically, i.e., it changes with each Internet connection and is therefore commonly treated as non-personal information. The IP address is used by the Administrator to diagnose technical problems with the server, create statistical analyses (e.g., determining which regions record the most visits), manage and improve the Website, and for security purposes as well as possible identification of automatic programs that burden the server by browsing the Website’s content.

§ 5 Rights of data subjects

1. The right to withdraw consent – the legal basis: Article 7(3) of the GDPR.

1.1. The Client has the right to withdraw any consent given to the Administrator.

1.2. Withdrawal of consent has effect from the moment of withdrawal.

1.3. Withdrawal of consent does not affect the processing lawfully carried out by the Administrator before its withdrawal.

1.4. Withdrawal of consent does not entail any negative consequences for the Client, but it may prevent further use of services or functionalities that, under the law, the Administrator can provide only with consent.

2. The right to object to data processing – the legal basis: Article 21 of the GDPR.

2.1. The Client has the right to object at any time to the processing of their personal data, including profiling, if the Administrator processes the data based on a legitimate interest, e.g. marketing products and services, conducting statistical analyses on how the Website is used, and satisfaction surveys.

2.2. Opting out of marketing communications about products or services will mean the Client objects to the processing of their personal data for marketing purposes, including profiling for such purposes.

2.3. If the Client’s objection is justified and the Administrator has no other legal basis for processing personal data, the Client’s personal data will be deleted, against which the Client has objected.

3. The right to erasure („right to be forgotten”) – legal basis: Article 17 of the GDPR.

3.1. The Client has the right to request the erasure of all or some personal data.

3.2. The Client has the right to request the erasure of personal data if:

  • 3.2.1. personal data are no longer necessary for the purposes for which they were collected or processed;
  • 3.2.2. the Client withdrew specific consent, and there is no other legal basis for processing;
  • 3.2.3. the Client objects to the processing of their personal data in cases where the legal basis for processing is the legitimate interest of the Administrator, and there are no overriding legitimate grounds for processing;
  • 3.2.4. the Client’s personal data have been processed unlawfully;
  • 3.2.5. personal data must be erased to comply with a legal obligation under Union or Member State law to which the Administrator is subject;
  • 3.2.6. personal data were collected in connection with offering information society services.

3.3. Despite submitting a request to erase personal data, the Administrator may retain certain data to the extent necessary for establishing, pursuing, or defending claims, as well as to comply with legal obligations. This applies, in particular, to the following data: name, surname, email address – retained for complaint handling purposes and claims related to the use of the Administrator’s services, or additionally, the address and order data if a contract was concluded or a complaint was filed.

4. The right to restrict processing – legal basis: Article 18 of the GDPR.

4.1. The Client has the right to request restriction of the processing of their personal data. Submitting such a request prevents the use of specific services or functionalities that require the processing of restricted data.

4.2. The Client has the right to request restriction of data processing in the following cases:

  • 4.2.1. when the Client contests the accuracy of their personal data – the Administrator restricts processing for a period allowing verification of accuracy;
  • 4.2.2. when the processing is unlawful and the Client opposes the erasure of data, requesting restriction instead;
  • 4.2.3. when the Administrator no longer needs the data for processing purposes, but the Client requires them to establish, pursue, or defend claims;
  • 4.2.4. when the Client objects to the processing of their data – pending verification whether the Administrator’s legitimate grounds override the Client’s objection.

5. The right of access to data – legal basis: Article 15 of the GDPR.

5.1. The Client has the right to obtain from the Administrator confirmation whether their personal data are being processed, and if so, to access them, as well as obtain information on: the purposes of processing, categories of data, recipients or categories of recipients, the intended storage period or the criteria for determining it, the rights of the data subject under the GDPR, and the right to lodge a complaint with the supervisory authority, the source of the data, automated decision-making (including profiling), and safeguards used when transferring data outside the EU.

5.2. The Client also has the right to receive a copy of their personal data processed by the Administrator.

6. The right to rectification – legal basis: Article 16 of the GDPR.

6.1. The Client has the right to request the Administrator to immediately rectify inaccurate personal data concerning them. Considering the processing purposes, the Client has the right to have incomplete personal data completed, including by providing an additional statement.

7. The right to data portability – legal basis: Article 20 of the GDPR.

7.1. The Client has the right to receive personal data concerning them that they have provided to the Administrator, in a structured, commonly used, machine-readable format, and has the right to transmit those data to another controller.

7.2. The Client also has the right to request that personal data be transmitted directly by the Administrator to another controller, where technically feasible.

8. The right to lodge a complaint with a supervisory authority.

8.1. The Client has the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office in Poland – if they consider that the processing of their personal data violates the provisions of the GDPR.

§ 6 Final provisions

1. The Website may contain links to other websites. The Administrator encourages you to read the privacy policies of these websites after visiting them. This privacy policy applies only to this Website.

2. The Administrator reserves the right to amend this Privacy Policy in order to update it and adapt to changes in the law or applied technological solutions. Any changes will be published on this Website.