PRIVACY POLICY

1. GENERAL PROVISIONS

1. This Privacy Policy sets out the rules for the collection, use, processing and protection of personal data of users (hereinafter: “Users”) of the website ifu.poldent.pl (hereinafter: the “Website”), owned by Poldent Spółka z ograniczoną odpowiedzialnością, ul. Dzika 2, 00-194 Warsaw, Poland, KRS: 0000112777, NIP: 5240004448, REGON: 006716225. It also defines the rules governing the use of cookies on the Website.

2. The Data Controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (GDPR) is Poldent Sp. z o.o. (hereinafter: the “Controller”).

3. The Controller may be contacted by telephone: +48 (22) 351 76 50–51, by e-mail: poldent@poldent.pl or in writing at the address: ul. Dzika 2, 00-194 Warsaw, Poland.

4. Users of the Website are individuals using the services provided by the Controller via the Website.

2. PURPOSES OF PROCESSING PERSONAL DATA

1. The Controller processes Users’ personal data exclusively for the following purposes:

a) enabling Users to use the Website, including providing access to Instructions for Use (IFU) of products offered by the Controller, enabling Users to download such instructions in PDF format, and resolving technical issues related to the Website’s operation;

b) receiving and fulfilling Users’ orders for delivery—within the territory of the European Union and the European Economic Area—of printed Instructions for Use for products offered by the Controller;

c) handling Users’ complaints;

d) ensuring the security of electronically provided services, including enforcing compliance with the Terms of Use, and preventing and counteracting fraud, abuse and security incidents;

e) establishing, pursuing or defending legal claims;

f) analysing Users’ activity on the Website, creating statistical summaries, and conducting satisfaction and opinion surveys.

3. CATEGORIES OF PERSONAL DATA PROCESSED

1. The Controller collects and processes the following personal data voluntarily provided by Users:

a) first and last name;

b) delivery address for printed instructions;

c) e-mail address;

d) telephone number.

2. While using the Website, servers used by the Controller automatically store system logs, i.e. anonymous technical information such as the time of the User’s visit, IP address, URL, browser type and similar data.

4. LEGAL BASIS FOR PROCESSING PERSONAL DATA

1. The Controller processes Users’ personal data on the basis of:

a) Article 6(1)(b) GDPR – processing necessary for the performance of a contract or to take steps at the User’s request prior to entering into a contract (applies to the purposes set out in points 2.1(a)–(c) of this Policy);

b) Article 6(1)(f) GDPR – legitimate interests pursued by the Controller (applies to the purposes set out in points 2.1(d)–(f) of this Policy).

2 Providing personal data is voluntary, yet necessary for the use of the services offered through the Website.

5. RULES GOVERNING THE COLLECTION, USE AND PROCESSING OF PERSONAL DATA

1. The Controller undertakes to process and safeguard personal data in accordance with the following principles:

a) personal data are processed in compliance with GDPR, the Polish Personal Data Protection Act of 10 May 2018, and other applicable laws supplementing or implementing GDPR;

b) the Controller applies technical and organisational measures ensuring a level of security appropriate to the risks involved, protecting personal data from unauthorised access, loss, destruction or alteration;

c) personal data will not be disclosed to third parties except where:

  • the User has given explicit consent;
  • disclosure is necessary for the provision of services via the Website, and only the data necessary for
  • the proper provision of such services will be disclosed;
  • the Controller is obliged to do so under applicable law or a lawful request of public authorities;
  • disclosure is necessary for detecting or preventing fraud or for resolving security or technical issues;
  • disclosure is necessary for establishing, pursuing or defending legal claims.

2. To the extent permitted by law, personal data may be transferred to trusted third parties acting on behalf of or under contract with the Controller (such as postal or courier services, hosting providers, software providers supporting the Website), solely to the extent necessary to achieve the purposes indicated in this Privacy Policy.

3. Personal data may be used only for the purposes for which they were collected.

4. Personal data will be stored only for as long as necessary to properly provide the services available through the Website. Data processed on the basis of consent or the Controller’s legitimate interests will be processed until such consent is withdrawn or an effective objection is submitted. After the relevant period has expired, the data will be erased.

5. Personal data will not be transferred outside the European Economic Area.

6. No automated decision-making, including profiling, is used in connection with the Website.

7. The Website may contain links to third-party websites not operated by the Controller. Users should review the privacy policies, terms of use and relevant rules applicable to those websites. The Controller bears no responsibility for the processing of Users’ data by such third parties, who act as independent controllers.

6. USERS’ RIGHTS

1. Every User has the right to:

a) access their personal data processed by the Controller;

b) request rectification of personal data if they are outdated, incomplete or inaccurate;

c) request restriction of processing;

d) request erasure of personal data;

e) object to the processing of personal data in cases described in Article 21 GDPR (including processing based on legitimate interests of the Controller — such objection is binding on the Controller);

f) request data portability in a structured, commonly used and machine-readable format, where technically feasible (applies to data processed for contract performance or based on consent)

g) withdraw consent to the processing of personal data at any time, without affecting the lawfulness of processing carried out before withdrawal.

2. Exercising these rights requires submitting a written request by e-mail to poldent@poldent.pl or by traditional mail to the Controller’s registered office.

3. Users also have the right to lodge a complaint with the supervisory authority:
President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.

7. COOKIES

1. The Website uses text files known as cookies.

2. Cookies do not contain information enabling the identification of individual Users and are not used to collect personal data.

3. Cookies are placed on the User’s device and accessed by the Controller.

4. Blocking cookies may impair or prevent the use of the Website.

5. Cookies do not modify the User’s device, install software or affect the integrity of system data.

6. The Controller may use third-party services to prepare anonymous usage statistics, without providing them with personal data.

7. Cookies are used to:

a) tailor Website content to Users’ preferences and optimise its operation;

b) compile anonymised Website usage statistics;

c) maintain User sessions (after login), eliminating the need to log in again.

8. The Website uses, or may use, the following types of cookies:

a) “necessary” cookies,

b) “security cookies,

c) “performance” cookies,

d) “functional” cookies.

9. Under the Polish Telecommunications Law of 16 July 2004, Users may manage cookie settings via their browser. Browsers often allow cookies by default. Users may block or limit cookies at any time.

10. Limiting cookies may affect certain functionalities of the Website.

8. CHANGES TO THIS PRIVACY POLICY

1. The Controller reserves the right to amend this Privacy Policy if required by law or due to changes introduced on the Website. The Controller shall inform the User of any planned amendment and the date on which it enters into force via the Website, and, in the case of registered Users, such information shall also be provided through the User’s account.

2. The User using the Website is bound by the Privacy Policy currently in effect and made available by the Controller.