1. Data controller
The data controller for personal data processed in connection with the use of the website polentex.pl Jest
POLENTEX Limited Liability Company
based in Rusocin,
10 Gdańska Street,
83-031 Rusocin (post office: Łęgowo),
entered in the register of entrepreneurs National Court Register at number: 0000124267,
NIP 584-030-48-39,
REGON 190048321.
For matters related to personal data processing, you can contact the Administrator:
- by email: biuro@polentex.pl,
- in writing POLENTEX Ltd., ul. Gdańska 10, 83-031 Rusocin.
Scope of the Privacy Policy
The privacy policy applies to personal data processed in connection with:
- 1. use of the internet service polentex.pl,
- 2. sending an inquiry via the contact or offer form,
- 3. by phone, email, or traditional mail,
- 4. handling commercial, offer, and service inquiries,
- 5. entering into and executing commercial agreements, particularly in B2B relationships,
- 6. order processing, deliveries, settlements, complaints, and warranties,
- 7. sending a newsletter, if the user has consented to it,
- 8. conducting marketing activities regarding the Administrator's own products and services,
- 9. the use of cookies and similar technologies.
3. Categories of Processed Data
Depending on the form of contact or use of the service, we may process the following categories of personal data:
- 1. Full name,
- 2. Company name,
- 3. position or title within the company, if provided,
- 4. email address,
- 5. Phone number,
- 6. mailing address,
- 7. registered office or place of business address,
- 8. invoice data, including VAT ID,
- 9. order, inquiry, complaint, or service request details,
- 10. The content of correspondence conducted with the Administrator,
- 11. technical data related to the use of the service, such as IP address, cookie identifiers, device data, browser, operating system, activity on the service and approximate location data resulting from device settings or IP address.
We do not ask users to provide special categories of personal data, i.e., so-called sensitive data. If a user voluntarily provides such data, the Administrator may delete it, unless its processing is necessary for the purpose of handling a specific request and complies with the law.
The service is not directed at minors, and the Administrator does not intentionally collect data from minors.
4. Purposes and legal bases for data processing
We process personal data only when there is a proper legal basis. Depending on the situation, data may be processed for the following purposes:
4.1. Handling Contact and Quote Requests
We process personal data only when there is a legal basis for it. Depending on the case, if the user contacts us using a form, email, phone, or in any other way, we process their data to provide a response, prepare an offer, conduct correspondence, and take actions prior to the potential conclusion of a contract.
Legal basis:
- Art. 6(1)(b) GDPR — when contact is aimed at the conclusion or performance of a contract,
- Art. 6(1)(f) GDPR — when the legal basis is the legitimate interest of the Controller, consisting of conducting communication with persons contacting the company.
4.2. Execution of Commercial Agreements, Orders, and Service Contracts
We process data for the purpose of concluding and fulfilling contracts, processing orders, deliveries, settlements, complaints, warranty claims, service, and ongoing business cooperation.
Legal basis:
- Art. 6 para. 1 lit. b GDPR — in the case of data of a contracting party,
- Art. 6 sec. 1 lit. f GDPR — in the case of data of contractor representatives, contractor employees, or contact persons designated for the performance of the agreement; the legitimate interest lies in the possibility of proper execution of economic cooperation.,
- art. 6(1)(c) GDPR — to the extent that processing is necessary for the performance of legal obligations, in particular tax, accounting, and warranty-related obligations.
4.3. Issuing and Storing Invoices and Accounting Documentation
We process data for the purpose of issuing invoices, maintaining accounting, tax, and bookkeeping records, and fulfilling obligations arising from legal provisions.
Legal basis:
- art. 6(1)(c) GDPR — a legal obligation incumbent on the Controller.
4.4. Claims Investigation and Defense
Data may be processed for the establishment, investigation, or defense against any claims arising from the use of the service, correspondence, commercial cooperation, concluded agreements, complaints, or other relationships with the Administrator.
Legal basis:
- Art. 6(1)(f) GDPR — the legitimate interest of the Controller consisting in the protection of its rights.
4.5. Newsletter
If the user subscribes to the newsletter, we process their data to send industry, commercial, product, or marketing information about the Administrator's activities.
Legal basis:
- Art. 6(1)(a) GDPR — user consent.
Subscribing to the newsletter is voluntary. You can withdraw your consent at any time, in particular by clicking the unsubscribe link in the newsletter message or by contacting the Administrator.
Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
Regardless of the legal basis for processing personal data under GDPR, sending commercial information by electronic means or conducting marketing via terminal telecommunications equipment may require separate consent as stipulated by the regulations on electronic communications.
4.6. Marketing own products and services
Data may be processed for the purpose of marketing the Administrator's own products and services, in particular for directing information about the offer to current or potential contractors.
Legal basis:
- Art. 6(1)(f) GDPR — the legitimate interest of the Controller consisting in promoting its own products and services.
If marketing is carried out via electronic mail, telephone, or other electronic means of communication, the Controller shall also apply the relevant regulations on consent to marketing communications.
The data subject may object at any time to the processing of personal data for direct marketing purposes.
4.7. Analytics, Statistics, and Service Development
Service usage data may be processed for analytical and statistical purposes, in particular to check the number of visits, how individual subpages are used, the effectiveness of marketing activities, and to improve the functionality of the service.
Legal basis:
- art. 6(1)(f) GDPR — the Controller's legitimate interest consisting in the analysis of the website's operation and improvement of its quality,
- Art. 6(1)(a) GDPR — to the extent that the use of certain analytical tools requires user consent, particularly for analytical cookies.
4.8. Ensuring Service Security
Technical data, such as IP address, server logs, browser information, and site activity, may be processed to ensure the security of the service, detect abuse, protect against attacks, diagnose technical errors, and maintain the proper functioning of the website.
Legal basis:
- Art. 6(1)(f) GDPR - the Controller's legitimate interest consisting in ensuring the safety, continuity, and proper functioning of the service.
5. Voluntary provision of data
Providing personal data is voluntary, but in some cases necessary to use certain features or services.
Failure to provide data may result in:
- 1. inability to respond to the inquiry,
- 2. inability to prepare an offer,
- 3. inability to conclude or perform the agreement,
- 4. inability to issue an invoice,
- 5. inability to handle complaints or service requests,
- 6. inability to receive the newsletter.
6. Data retention period
We store personal data for the period necessary to fulfill the purposes for which it was collected, and then for the period required by law or justified by the protection of the Administrator's rights.
In particular:
- 1. data from the contact form or quote request, if cooperation is not established, are generally stored by us for a period of up to 12 months from the end of correspondence;
- 2. data related to the performance of the contract are stored for the duration of the contract, and then for the period required by law or the statute of limitations for claims;
- 3. data contained in invoices, accounting, and tax documents are stored for the period resulting from the applicable accounting and tax regulations, as a general rule for 5 years, counted according to these regulations;
- 4. data processed based on consent, in particular for the purpose of sending newsletters, is stored until consent is withdrawn, unless earlier deletion of data results from legal regulations or the Administrator's decision;
- 5. data processed for direct marketing purposes based on legitimate interest is stored until an effective objection is raised;
- 6. data processed for the purpose of pursuing claims or defending against claims are stored until the expiration of the applicable statute of limitations for claims;
- 7. Technical data and server logs are stored for the period necessary to ensure the security and proper functioning of the service, and in case of security incidents – for the period necessary to clarify and document them.
7. Data recipients
Personal data may be transferred to entities that support the Controller in conducting business and servicing the website. These may include, in particular:
- IT service providers,
- 2. hosting providers,
- 3. email service providers,
- 4. ERP system providers,
- 5. CRM system providers,
- 6. analytical and marketing tool providers,
- 7. Cookie consent management tool providers,
- 8. courier, transport, and logistics companies — to the extent necessary for delivery,
- 9. Payment providers - if payment is made electronically,
- 10. accounting offices, tax advisors, law firms, auditors, and other professional advisors,
- 11. banks and financial institutions,
- 12. entities providing service, administrative, or technical services,
- 13. state bodies, courts, offices, or other authorized entities – if the obligation to transfer data arises from legal provisions.
Data processors acting on behalf of the Controller operate based on appropriate data processing agreements and are obliged to ensure adequate data protection.
8. Transfer of data outside the European Economic Area (EEA)
As a general rule, the Administrator does not intend to transfer personal data to countries outside the European Economic Area.
However, it may happen that due to the use of specific IT, analytical, marketing, cloud, or communication tools, data will be transferred outside the European Economic Area, in particular to countries where the providers of these tools or their subcontractors are based.
In such cases, data transfer takes place exclusively when an appropriate mechanism legalizing the transfer is ensured, in particular:
- 1. European Commission decision on an adequate level of data protection in a given country,
- 2. standard contractual clauses approved by the European Commission,
- 3. another mechanism provided for by the GDPR.
If the user wishes to obtain more information about the data transfer security measures used, they may contact the Administrator.
9. Automated decision-making and profiling
The administrator does not make decisions based solely on automated data processing that would produce legal effects concerning users or similarly significantly affect them.
Data can be used for simple marketing or analytical profiling if the user consents to the relevant cookies or similar technologies. This profiling may involve, in particular, analyzing how the service is used, interest in specific content, or the effectiveness of marketing campaigns. However, it does not lead to automated decision-making with legal effects on the user.
Last updated: May 11, 2026.
10. Rights of data subjects
The data subject has the following rights:
- 1. right of access to personal data,
- 2. the right to receive a copy of the data,
- 3. right to rectification of data,
- 4. the right to erasure of data,
- 5. right to restrict processing,
- 6. right to data portability,
- 7. the right to object to the processing of data,
- 8. the right to withdraw consent at any time, if the data is processed based on consent,
- 9. The right to lodge a complaint with the President of the Personal Data Protection Office.
You may object to the processing of your data for direct marketing purposes at any time. Once you have objected, your data will no longer be processed for this purpose.
To exercise your rights, please contact the Administrator at the email address biuro@polentex.pl or in writing to the Administrator's registered office.
The Administrator shall respond to data subject requests within the periods provided for by the GDPR. If the fulfillment of the request is not possible, the Administrator shall inform about the reasons for refusal.
11. Right to lodge a complaint with a supervisory authority
If the data subject considers that their personal data is being processed unlawfully, they have the right to lodge a complaint with a supervisory authority.
In Poland, the supervisory body is:
President of the Personal Data Protection Office
Stawki Street 2
00-193 Warsaw
More information on how to file a complaint can be found on the website of the Personal Data Protection Office.
12. Cookies and similar technologies
The website polentex.pl uses cookies and similar technologies, such as internet identifiers, tags, pixels, scripts, or data stored in the browser's memory.
Cookies are small text files saved on the user's device when using a website. They can be read by the website on subsequent visits.
Cookies can be used for the following purposes:
- 1. ensuring the proper functioning of the service,
- 2. maintaining user session,
- 3. remembering user preferences,
- 4. ensuring service security,
- 5. traffic statistics and analysis,
- 6. measuring marketing campaign effectiveness,
- 7. conducting remarketing or advertising activities — if the user has given appropriate consent.
13. Types of cookies used on the site
The following cookie categories may be used on the website:
13.1. Essential cookies
They are necessary for the proper functioning of the service. They enable, among other things, the use of basic website functions, ensuring security, remembering privacy settings, and correct content display.
These files may be used without the user's consent if they are necessary for providing a service electronically or for the proper functioning of the website.
13.2. Analytical Cookies
They help us understand how users use the service, which subpages are visited most often, and how to improve the website's functionality.
Analytical cookies are used with user consent, unless legal regulations permit their use without consent in a specific case.
13.3. Marketing Cookies
They are used for conducting marketing activities, measuring the effectiveness of advertising campaigns, tailoring advertising content, and conducting remarketing.
Marketing cookies are used only after obtaining user consent.
13.4. Functional Cookies
They allow remembering user choices, such as preferences for how the page is displayed or interface settings.
Depending on their nature, they can be used as essential or with user consent.
14. Cookie Consent Management
The user can manage cookie preferences using the tool provided on the website, specifically the cookie consent panel.
If the service uses the CookieYes tool, the user can select, change, or withdraw consent for individual cookie categories using the cookie banner or the cookie settings icon available on the website.
The user can also restrict or disable the support of cookies in their web browser settings. However, disabling certain cookies may affect the proper functioning of selected website features.
Refusal of consent for analytical or marketing cookies should not prevent the use of the basic functions of the service.
15. External Tools Used in the Service
The service may use external tools to support its operation, security, analytics, marketing, form handling, cookie consent management, or user communication.
These may include, in particular, tools belonging to the following categories:
- 1. Hosting and server infrastructure,
- 2. electronic mail,
- 3. CRM systems,
- 4. ERP systems,
- 5. Analytical tools,
- 6. advertising and remarketing tools,
- 7. newsletter management tools,
- 8. cookie consent management tools,
- 9. service security tools,
- 10. Plugins and technical components used in the site's content management system.
Before publishing the Privacy Policy, you must complete or verify the list of specific tools used on the website, particularly those such as Google Analytics, Google Ads, Meta Pixel, LinkedIn Insight Tag, CookieYes, newsletter system, ERP system, CRM system, hosting provider, and email provider—if they are used.
16. Data Security
The Administrator implements technical and organizational measures to ensure an appropriate level of personal data protection, taking into account the nature, scope, context, and purposes of processing, as well as the risk of infringement of the rights or freedoms of natural persons.
In particular, the Administrator implements solutions aimed at protecting data against unauthorized access, loss, destruction, alteration, or disclosure to unauthorized persons.
Serwis korzysta z szyfrowanego połączenia SSL/TLS, jeżeli jest ono aktywne i poprawnie skonfigurowane.
17. Linki do stron zewnętrznych
Serwis może zawierać linki do innych stron internetowych, w tym stron partnerów, dostawców, producentów, marketplace’ów lub profili Administratora w mediach społecznościowych.
Po przejściu na stronę zewnętrzną użytkownik podlega zasadom prywatności obowiązującym u operatora tej strony. Administrator zaleca zapoznanie się z politykami prywatności tych podmiotów.
18. Media społecznościowe
Administrator może prowadzić profile w mediach społecznościowych, takich jak Facebook, Instagram, LinkedIn, YouTube lub inne platformy.
Jeżeli użytkownik kontaktuje się z Administratorem za pośrednictwem mediów społecznościowych, komentuje treści, obserwuje profil lub wchodzi w interakcje z publikowanymi materiałami, jego dane mogą być przetwarzane zarówno przez Administratora, jak i przez operatora danej platformy społecznościowej.
Zakres i zasady przetwarzania danych przez operatorów platform społecznościowych określają ich własne regulaminy i polityki prywatności.
19. Zmiany Polityki prywatności
Administrator może zmienić niniejszą Politykę prywatności w przypadku:
- 1. zmiany przepisów prawa,
- 2. zmiany sposobu przetwarzania danych osobowych,
- 3. wprowadzenia nowych funkcjonalności serwisu,
- 4. rozpoczęcia korzystania z nowych narzędzi technicznych, analitycznych lub marketingowych,
- 5. zmiany danych Administratora lub danych kontaktowych.
O istotnych zmianach Polityki prywatności Administrator poinformuje poprzez komunikat w serwisie. Jeżeli zmiany będą dotyczyć newslettera lub innych usług wymagających komunikacji bezpośredniej, Administrator może poinformować użytkowników również za pomocą wiadomości e-mail.
20. Kontakt
W sprawach dotyczących niniejszej Polityki prywatności lub przetwarzania danych osobowych można kontaktować się z Administratorem:
E-mail: biuro@polentex.pl
Adres korespondencyjny: POLENTEX Ltd., ul. Gdańska 10, 83-031 Rusocin
Data ostatniej aktualizacji: 24 czerwiec 2026.