Privacy Policy
GENERAL PROVISIONS
This privacy policy of the website available at the internet address www.gwarant-transport.com (hereinafter referred to as: the “Site” or the “Website“) is informational in nature, which means that it is not a source of obligations for users of the Site. The privacy policy sets out, in particular, the rules governing the processing of personal data by the Controller on the Website, including the legal bases, purposes and scope of the processing of personal data, as well as the rights of data subjects, together with information on the use of cookies and analytical tools on the Website.
The controller of the personal data collected via the Website, and its owner, is:
the company GWARANT TRANSPORT MEDYCZNY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office in Westrza, entered in the register of entrepreneurs of the National Court Register under number 0000391127, the registry court holding the company’s records being: Sąd Rejonowy Poznań – Nowe Miasto i Wilda w Poznaniu, IX Wydział Gospodarczy Krajowego Rejestru Sądowego, registered office address and address for service: ul. Orzechowa 1, 63-405 Westrza, NIP 6222761837, REGON 301714040, e-mail address: contact@gwarant.delivery, telephone number: +48 517 279 794 (charged at the rate for a standard telephone call, in accordance with the service provider’s tariff plan)
(hereinafter referred to as the “Controller” or the “Owner”)
Quick contact with us:
- e-mail: contact@gwarant.delivery
- telephone: +48 517 279 794 (charged at the rate for a standard telephone call, in accordance with the service provider’s tariff plan)
- in writing or in person at the address: Orzechowa 1, 63-405 Westrza
Personal data on the Website is processed by the Controller in accordance with the applicable provisions of law, in particular in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter referred to as the “GDPR” or the “GDPR Regulation”. The official text of the GDPR: http://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX%3A32016R0679
Use of the Website is voluntary. Similarly, the related provision of personal data by a user making use of the Website is voluntary, subject to cases where it is necessary in order to make use of certain functionalities of the Website, including, for example, the contact form. Failure to provide, in the relevant cases and to the required extent, the personal data necessary to make use of a given functionality of the Site results in the inability to use that functionality. The scope of data required to use a given functionality of the Site is indicated by the Controller on the Website on each occasion (e.g. before completing the contact form).
The Controller exercises particular diligence in order to protect the interests of the data subjects whose personal data it processes, and in particular is responsible for, and ensures, that the data it collects is: (1) processed lawfully; (2) collected for specified, lawful purposes and not further processed in a manner incompatible with those purposes; (3) substantively correct and adequate in relation to the purposes for which it is processed; (4) kept in a form which permits identification of the data subjects for no longer than is necessary to achieve the purpose of the processing; and (5) processed in a manner ensuring appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, by means of appropriate technical or organisational measures.
Taking into account the nature, scope, context and purposes of the processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, the Controller implements appropriate technical and organisational measures to ensure, and to be able to demonstrate, that processing is performed in accordance with this Regulation. Those measures are reviewed and updated where necessary. The Controller applies technical measures to prevent the acquisition and modification, by unauthorised persons, of personal data transmitted electronically.
LEGAL DISCLAIMER
This Site is informational in nature; it enables users to become acquainted with the products or services of the Owner of the Site and to contact the Owner, including by submitting a request for a quotation via the contact form. A newsletter may also be available on the Site, the purpose of which will be to inform recipients about the activities of the Owner of the Site, news, and new products and services offered by the Owner of the Site. Polish law is the governing law for the Site and for these terms and conditions and any agreements concluded on their basis.
The Site is not an online shop, and it is not possible to conclude a contract of sale by means of the Site (this means, among other things, that advertisements, price lists and other information about products published on the Site should not be treated as an offer, but at most as an invitation to conclude a contract). A contract of sale may be concluded as a result of a request for a quotation addressed to the Owner of the Site, and only after the parties have agreed on the detailed terms of such a contract – however, the conclusion and terms of such a contract are governed by a separate contract of sale or separate general terms and conditions of sale of products by the Owner of the Site, which will be made available by the Owner.
LEGAL BASES FOR DATA PROCESSING
The Controller is authorised to process personal data in cases where, and to the extent that, at least one of the following conditions is met: (1) the data subject has given consent to the processing of his or her personal data for one or more specific purposes; (2) processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract; (3) processing is necessary for compliance with a legal obligation to which the Controller is subject; or (4) processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
The processing of personal data by the Controller requires, on each occasion, the existence of at least one of the legal bases indicated above. The specific legal bases for the Controller’s processing of the personal data of Service Recipients of the Website are set out in the next section of the privacy policy, in relation to the given purpose of the processing of personal data by the Controller.
PURPOSE, LEGAL BASIS AND PERIOD OF DATA PROCESSING ON THE WEBSITE
The purpose, legal basis, scope and recipients of the personal data processed by the Controller on each occasion result from the actions taken by the given Service Recipient on the Website.
The Controller may process personal data on the Website for the following purposes, on the following legal bases, for the following periods and to the following extent:
Purpose of data processing | Legal basis for data processing | Data retention period |
Performance of a contract for the provision of an Electronic Service, or taking steps at the request of the data subject prior to entering into a contract | Article 6(1)(b) GDPR (performance of a contract) – processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract | Data is stored for the period necessary for the performance, termination or other expiry of the concluded contract for the provision of electronic services with the Controller. |
Sending commercial information, including direct marketing, using telecommunications terminal equipment (e.g. e-mail, telephone) or automated calling systems | Article 6(1)(f) GDPR (legitimate interest of the controller) – processing is necessary for the purposes of the legitimate interests pursued by the Controller, which include direct marketing – consisting in safeguarding the interests and good reputation of the Controller, its business activity, and pursuing the sale of products or services – for example in connection with the data subject’s prior consent (e.g. when signing up to the Newsletter) to receive commercial information using telecommunications terminal equipment, such as e-mail or telephone, depending on the scope of the consent given | Data is stored for the period during which the legitimate interest pursued by the Controller exists, but not longer than the limitation period for claims of the Controller against the data subject arising from the Controller’s business activity. The limitation period is determined by the provisions of law, in particular the Civil Code (Kodeks cywilny) (the basic limitation period for claims connected with the conduct of business activity is three years, and for a Contract of Sale, two years). The Controller may not process data for direct marketing purposes where the data subject has effectively objected in this respect. Additionally, where the basis for processing is consent given, the data is stored until the data subject withdraws consent to the further processing of his or her data for the purpose specified in that consent, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal. |
Establishment, pursuit or defence of claims that may be raised by the Controller or that may be raised against the Controller | Article 6(1)(f) GDPR – processing is necessary for the purposes of the legitimate interests pursued by the Controller, consisting in the establishment, pursuit or defence of claims that may be raised by the Controller or that may be raised against the Controller | Data is stored for the period during which the legitimate interest pursued by the Controller exists, but not longer than the limitation period for claims against the data subject arising from the Controller’s business activity. The limitation period is determined by the provisions of law, in particular the Civil Code (the basic limitation period for claims connected with the conduct of business activity is three years). |
Use of the Website and ensuring its proper functioning | Article 6(1)(f) GDPR (legitimate interest of the controller) – processing is necessary for the purposes of the legitimate interests pursued by the Controller, consisting in operating and maintaining the Website | Data is stored for the period during which the legitimate interest pursued by the Controller exists, but not longer than the limitation period for claims of the Controller against the data subject arising from the Controller’s business activity. The limitation period is determined by the provisions of law, in particular the Civil Code (the basic limitation period for claims connected with the conduct of business activity is three years). |
Keeping statistics and analysing traffic on the Website | Article 6(1)(f) GDPR (legitimate interest of the controller) – processing is necessary for the purposes of the legitimate interests pursued by the Controller, consisting in keeping statistics and analysing traffic on the Website for the purpose of improving the functioning of the Website | Data is stored for the period during which the legitimate interest pursued by the Controller exists, but not longer than the limitation period for claims of the Controller against the data subject arising from the Controller’s business activity. The limitation period is determined by the provisions of law, in particular the Civil Code (the basic limitation period for claims connected with the conduct of business activity is three years). |
RECIPIENTS OF DATA ON THE WEBSITE
For the Website to function properly, it is necessary for the Controller to use the services of external entities (such as, for example, a software provider). The Controller uses only the services of such processors as provide sufficient guarantees of implementing appropriate technical and organisational measures, so that the processing meets the requirements of the GDPR and protects the rights of data subjects.
The disclosure of data by the Controller does not occur in every case, nor to all of the recipients or categories of recipients indicated in the privacy policy – the Controller discloses data only where this is necessary to achieve a given purpose of the processing of personal data, and only to the extent necessary to achieve it.
Personal data may be transferred by the Controller to a third country, provided that the Controller ensures that, in such a case, this will take place in relation to a country ensuring an adequate level of protection – in accordance with the GDPR, and, in the case of other countries, that the transfer will take place on the basis of standard data protection clauses. The Controller ensures that the data subject has the possibility of obtaining a copy of his or her data. The Controller discloses the personal data collected only in the case of, and to the extent necessary to achieve, a given purpose of data processing consistent with this privacy policy.
The personal data of users of the Website may be disclosed to the following recipients or categories of recipients:
- providers of services supplying the Controller with technical, IT and organisational solutions, enabling the Controller to conduct its business activity, including the Website and the electronic services provided through it (in particular providers of computer software for operating the Website, providers of e-mail and hosting services, and providers of software for company management and for providing technical support to the Controller) – the Controller discloses the personal data collected on a user of the Site to the selected provider acting on its instructions only in the case of, and to the extent necessary to achieve, a given purpose of data processing consistent with this privacy policy.
- providers of legal and advisory services providing the Controller with accounting, marketing, legal or advisory support (in particular a law firm) – the Controller discloses the personal data collected on a user of the Site to the selected provider acting on its instructions only in the case of, and to the extent necessary to achieve, a given purpose of data processing consistent with this privacy policy.
PROFILING ON THE SITE
The GDPR imposes on the Controller an obligation to provide information about automated decision-making, including profiling, referred to in Article 22(1) and (4) GDPR, and – at least in those cases – meaningful information about the rules for taking such decisions, as well as the significance and the envisaged consequences of such processing for the data subject. With this in mind, the Controller provides in this section of the privacy policy information regarding possible profiling.
The Controller may use profiling on the Site for direct marketing purposes, but the decisions taken by the Controller on that basis do not concern the conclusion or refusal to conclude a contract, or the ability to make use of electronic services. The effect of the use of profiling on the Site may be, for example, granting a given person a discount, sending them a discount code, sending a product proposal that may correspond to the interests or preferences of the given person, or proposing better terms compared to the standard offer. Despite the profiling, it is the given person who freely decides whether they wish to make use of the discount, or better terms, obtained in this way and to make a purchase.
Profiling on the Site consists in the automated analysis or forecasting of a given person’s behaviour on the Site, for example through browsing the page of a specific Product on the Site. Such profiling is conditional on the Controller holding the personal data of the given person, so as to be able subsequently to send them, for example, a discount code.
The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
RIGHTS OF THE DATA SUBJECT
Right of access, rectification, restriction, erasure or portability – the data subject has the right to request from the Controller access to his or her personal data, the rectification or erasure thereof (“the right to be forgotten”) or the restriction of processing, and has the right to object to processing, as well as the right to data portability. The detailed conditions for exercising the rights indicated above are set out in Articles 15-21 GDPR.
Right to withdraw consent at any time – a data subject whose data is processed by the Controller on the basis of consent given (pursuant to Article 6(1)(a) or Article 9(2)(a) GDPR) has the right to withdraw consent at any time, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
Right to lodge a complaint with a supervisory authority – a data subject whose data is processed by the Controller has the right to lodge a complaint with a supervisory authority, in the manner and pursuant to the procedure set out in the provisions of the GDPR and of Polish law, in particular the Act on the Protection of Personal Data (ustawa o ochronie danych osobowych). The supervisory authority in Poland is the President of the Personal Data Protection Office.
Right to object – the data subject has the right, at any time, to object – on grounds relating to his or her particular situation – to the processing of personal data concerning him or her which is based on Article 6(1)(e) (public interest or the exercise of official authority) or (f) (legitimate interest of the controller), including profiling on the basis of those provisions. In such a case, the Controller shall no longer be permitted to process that personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or grounds for the establishment, exercise or defence of legal claims.
Right to object with regard to direct marketing – where personal data is processed for the purposes of direct marketing, the data subject has the right to object at any time to the processing of personal data concerning him or her for the purposes of such marketing, including profiling, to the extent that the processing is related to such direct marketing.
In order to exercise the rights referred to in this section of the privacy policy, the Controller may be contacted by sending an appropriate message in writing or by e-mail to the Controller’s address indicated at the beginning of the privacy policy.
COOKIES ON THE WEBSITE AND ANALYTICS
Cookies are small pieces of text information in the form of text files, sent by the server and stored on the device of a person visiting the Website (e.g. on the hard drive of a computer, laptop, or on the memory card of a smartphone – depending on which device the visitor to our Website is using). Detailed information regarding cookies, as well as the history of their development, can be found, among other places, here: https://pl.wikipedia.org/wiki/HTTP_cookie.
The Controller may provide on the Site a tool for the easy and active management of cookies – available upon first entering the Site, and subsequently available in the footer of the Site. Active management allows, among other things, for checking which cookies are or may be stored while using the Site, as well as for selecting and subsequently changing the scope and purposes of the use of cookies in relation to the device and the person visiting the Site. On beginning to use the Site, the visitor will be asked to select settings regarding cookies. It is possible to change these later by changing the settings within this tool available on the site.
In the privacy policy, the Controller provides a range of information regarding the use of cookies on the Site, their types and purposes of use, and their management using, for example, web browser settings and/or the cookie management tool available on the Site. The Controller encourages the use of the cookie management tool available on the Site, which allows for easy, active management of cookies while using the Site, and, if it is unavailable, encourages review of the information below regarding, among other things, the management of cookies at browser level.
Cookies which may be sent by the Website can be divided into various types, according to the following criteria:
Due to their provider: 1) first-party cookies (created by the Controller’s Website) and 2) cookies belonging to third parties/entities (other than the Controller) | Due to the period for which they are stored on the device of the person visiting the Website: 1) session cookies (stored until the Website is left or the web browser is closed) and 2) persistent cookies (stored for a specified period, defined by the parameters of each file, or until manually deleted) | Due to the purpose of their use: 1) necessary cookies (enabling the proper functioning of the Website), 2) functional/preference cookies (enabling the Website to be adapted to the preferences of the person visiting the site), 3) analytical and performance cookies (gathering information about the manner in which the Website is used) 4) marketing, advertising and social media cookies (collecting information about the person visiting the Website in order to display advertisements to that person, personalise them, measure their effectiveness and conduct other marketing activities, including also on websites separate from this Site, such as social networking sites or other sites belonging to the same advertising networks as the Website) |
The Controller may process the data contained in cookies while visitors are using the Website for the following specific purposes:
Purposes of the use of cookies on the Controller’s Website | remembering data entered in completed forms (necessary and/or functional/preference cookies) |
adapting the content of the Website to the individual preferences of the user (e.g. regarding colours, font size, page layout) and optimising the use of the Website (functional/preference cookies) | |
keeping anonymous statistics showing the manner in which the Website is used (analytical and performance cookies) | |
displaying and rendering advertisements, limiting the number of times advertisements are displayed and ignoring advertisements which the user does not wish to view, measuring the effectiveness of advertisements, as well as personalising advertisements, that is, examining the behavioural characteristics of persons visiting the Website through the anonymous analysis of their actions (e.g. repeated visits to specific pages, keywords, etc.) in order to create a profile of them and provide them with advertisements matched to their anticipated interests, including also when they visit other websites within the advertising network of Google Ireland Ltd., LinkedIn Ireland Unlimited Company and Facebook, i.e. Meta Platforms Ireland Ltd. (marketing, advertising and social media cookies) |
It is possible to check which cookies are being sent at a given time by the website of the Online Shop, regardless of the web browser, using tools available, for example, at: https://www.cookiemetrix.com or https://www.cookie-checker.com.
By default, most web browsers available on the market accept the storing of cookies as standard. Everyone has the ability to determine the conditions for the use of cookies by means of their own web browser settings. This means that it is possible, for example, to partially restrict (e.g. temporarily) or completely disable the storing of cookies – in the latter case, however, this may affect certain functionalities of the Website.
Web browser settings regarding cookies are significant from the point of view of consent to the use of cookies by our Website – in accordance with the applicable provisions, such consent may also be expressed through web browser settings. Detailed information on changing cookie settings and on deleting cookies independently in the most popular web browsers is available in the help section of the relevant web browser and at the links below (simply click on the relevant link):
in the Chrome browser
in the Firefox browser
in the Opera browser
in the Safari browser
in the Microsoft Edge browser
The Controller may use, on the Website, the Google Analytics and Universal Analytics services provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). These services help the Controller to keep statistics and analyse traffic on the Website. The data collected is processed within the above services in order to generate statistics helpful in administering the Website and analysing traffic on the Website. This data is aggregate in nature. In using the above services on the Website, the Controller gathers data such as the sources and medium by which visitors reach the Website and the manner of their behaviour on the Website, information about the devices and browsers from which they visit the site, IP address and domain, geographic data, and demographic data (age, gender) and interests.
It is possible for a given person to easily block the disclosure to Google Analytics of information about their activity on the Website – for this purpose, for example, a browser add-on provided by Google Ireland Ltd. may be installed, available here: https://tools.google.com/dlpage/gaoptout?hl=pl
In connection with the possible use by the Controller on the Website of services provided by Google Ireland Ltd., the Controller indicates that full information on the rules governing the processing, by Google Ireland Ltd., of the data of persons visiting the Website (including information stored in cookies) can be found in the privacy policy of Google’s services, available at the following internet address: https://policies.google.com/technologies/partner-sites
The Controller may use on the Site the Meta Pixel and/or Instagram service provided by Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). This service helps the Controller to measure the effectiveness of advertisements and to analyse the actions taken by visitors to the Site, as well as to display matched advertisements to those persons. The creation of remarketing lists based on cookies collected by the Meta Pixel takes place within the Facebook or Instagram panel. Data collected or disclosed by the Meta Pixel may include information about actions on the Site – including information about the device, websites visited, purchases, advertisements displayed, entry to the Site and the manner of use of the services, as well as information regarding any interaction outside the Site with the Controller’s accounts on social networking sites, and interactions with the Controller’s advertisements displayed outside the Site. Detailed information on how the Meta Pixel operates can be found at the following internet address: https://www.facebook.com/business/help/742478679120153?helpref=page_content and https://pl-pl.facebook.com/business/tools/meta-pixel
Management of the operation of the Meta Pixel (advertising preferences) is possible by changing the advertisement settings in one’s account on Facebook.com: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen
LINKS TO OTHER WEBSITES
The Site may contain links to other websites. The Controller encourages users, after navigating to other websites, to review the terms and conditions and privacy policy established there. This privacy policy applies only to this Site.
CONTACT US
In the event of any problems or questions related to the use of the Site, or other questions, please contact the Owner of the Site:
- e-mail: contact@gwarant.delivery
- telephone: +48 517 279 794 (charged at the rate for a standard telephone call, in accordance with the service provider’s tariff plan)
- in writing or in person at the address: Orzechowa 1, 63-405 Westrza