Privacy Policy

1. General Information

  1. This policy applies to the website operating at the following URL: pareo-polska.com
  2. The website operator and personal data controller is: PAREO POLSKA Borowa 465, 39-305 Borowa
  3. The operator’s email address: info@pareo-polska.com
  4. The operator is the controller of your personal data in relation to the data provided voluntarily on the website.
  5. The website uses personal data for the following purposes:
    • Maintaining the newsletter
    • Preparing, packaging, and shipping goods
    • Handling inquiries via forms
    • Providing ordered services
    • Presenting offers or information
  6. The website performs the functions of collecting information about users and their behavior in the following manner:
    • Through data voluntarily entered in forms, which are entered into the Operator’s systems.
    • By storing cookies on end devices.

2. Selected data protection methods used by the Operator

  1. The login and personal data entry points are protected at the transmission layer (SSL certificate). This encrypts the personal data and login details entered on the website on the user’s computer and can only be read on the target server.
  2. The personal data stored in the database is encrypted in such a way that only the Operator possesses the key to read it. This protects the data in the event the database is stolen from the server.
  3. User passwords are stored in hashed form. The hashing function is unidirectional – it cannot be reversed, which is currently the modern standard for storing user passwords.
  4. The Operator periodically changes its administrative passwords.
  5. To minimize the risk of unauthorized access to data, the Operator uses complex passwords, containing lowercase and uppercase letters, numbers, and special characters, no shorter than 8 characters.
  6. An important element of data protection is the regular updating of all software used by the Operator to process personal data, which in particular means regular updates of programming components.
  7. To protect data, the Operator regularly performs backups.

3. Hosting

  1. The website is hosted (technically maintained) on the Operator’s server: cyberFolks.pl.
  2. To ensure technical reliability, the hosting company maintains logs at the server level. The following may be recorded:
    • resources identified by the URL identifier (addresses of requested resources – pages, files),
    • request arrival time,
    • response sending time,
    • client station name – identification performed via the HTTP protocol,
    • information about errors that occurred during the execution of an HTTP transaction,
    • URL address of the page previously visited by the user (referrer link) – if the Website was accessed via a link,
    • information about the user’s browser,
    • IP address information,
    • diagnostic information related to the process of self-ordering services via the website’s registrars,
    • information related to the handling of emails addressed to the Operator and sent by the Operator.

4. Your rights and additional information on the use of data

  1. Your personal data are processed by the Controller for no longer than is necessary to perform the related activities specified in separate regulations (e.g., accounting). With respect to marketing data, data will not be processed for more than 3 years.
  2. You have the right to request from the Controller:
    • access to personal data concerning you,
    • rectification,
    • erasure,
    • restriction of processing,
    • and data portability.
  3. You have the right to object to the processing of personal data for the purpose of pursuing legitimate interests pursued by the Controller, including profiling. However, the right to object cannot be exercised if there are compelling legitimate grounds for processing, overriding interests, rights and freedoms, in particular the establishment, exercise, or defense of claims.
  4. You may file a complaint against the Controller’s actions to the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw.
  5. Providing personal data is voluntary, but necessary to operate the Website.
  6. You may be subject to automated decision-making, including profiling, for the purpose of providing services under the concluded contract and for the Controller’s direct marketing.
  7. Personal data is transferred from third countries within the meaning of personal data protection regulations. This means that we transfer it outside the European Union.

5. Information in Forms

  1. The website collects information voluntarily provided by the user, including personal data, if provided.
  2. The website may save information about connection parameters (time stamp, IP address).
  3. In some cases, the website may save information to facilitate linking the data in the form with the email address of the user completing the form. In such cases, the user’s email address appears within the URL of the page containing the form.
  4. The data provided in the form is processed for the purpose resulting from the function of the specific form, e.g., to process a service request or sales contact, register services, etc. Each time, the context and description of the form clearly indicate its purpose.

6. Administrator Logs

  1. Information about user behavior on the website may be subject to logging. This data is used for website administration purposes.

7. Important Marketing Techniques

  1. The operator uses statistical analysis of website traffic through Google Analytics (Google Inc., based in the USA). The Operator does not transfer personal data to the operator of this service, only anonymized information. The service relies on the use of cookies on the user’s end device. In terms of information about user preferences collected by the Google advertising network, users can view and edit information derived from cookies using the tool: https://www.google.com/ads/preferences/
  2. The Operator uses the Facebook pixel. This technology allows Facebook (Facebook Inc., headquartered in the USA) to know that a given registered user is using the Service. In this case, it relies on data for which it is the administrator. The Operator does not transfer any additional personal data to Facebook. The service relies on the use of cookies on the user’s end device.
  3. The Operator uses remarketing techniques that allow advertising messages to be tailored to user behavior on the website, which may create the illusion that user personal data is being used for tracking purposes. However, in practice, no personal data is transferred from the Operator to advertising operators. The technological requirement for such activities is that cookies are enabled.
  4. The Operator uses a solution that analyzes user behavior by creating heat maps and recording behavior on the website. This information is anonymized before being sent to the service operator, so that the operator doesn’t know which individual it pertains to. In particular, entered passwords and other personal data are not recorded.
  5. The Operator uses a solution that automates the operation of the Service with respect to users, for example, by sending an email to the user after visiting a specific subpage, provided they have consented to receiving commercial communications from the Operator.
  6. The Operator may use profiling within the meaning of personal data protection regulations.

8. Information about Cookies

  1. The Website uses cookies.
  2. Cookies are computer data, specifically text files, stored on the Website User’s end device and intended for use with the Website’s web pages. Cookies typically contain the name of the website from which they originate, their storage time on the device, and a unique number.
  3. The Website operator is the entity that places cookies on the Website User’s end device and obtains access to them.
  4. Cookies are used for the following purposes:
    1. maintaining the Website User’s session (after logging in), so that the User does not have to re-enter their login and password on each subpage of the Website;
    2. achieving the purposes specified above in the „Important Marketing Techniques” section;
  5. The Website uses two basic types of cookies: „session cookies” and „persistent cookies.” „Session” cookies are temporary files that are stored on the User’s end device until logging out, leaving the website, or disabling the software (web browser). „Persistent” cookies are stored on the User’s end device for the time specified in the cookie parameters or until they are deleted by the User.
  6. Web browsing software (web browser) usually allows cookies to be stored on the User’s end device by default. Users of the Website can change their settings in this regard. The web browser allows cookies to be deleted. It is also possible to automatically block cookies. Detailed information on this topic can be found in the help or documentation for the web browser.
  7. Restricting the use of cookies may affect some functionalities available on the Website’s pages.
  8. Cookies placed on the User’s end device may also be used by entities cooperating with the Website operator, in particular: Google (Google Inc., based in the USA), Facebook (Facebook Inc., based in the USA), Twitter (Twitter Inc., based in the USA).

9. Managing cookies – how to express and withdraw consent in practice?

    1. If you do not wish to receive cookies, you can change your browser settings. Please note that disabling cookies required for authentication, security, and maintaining user preferences may make it difficult, and in extreme cases, impossible, to use websites.
    2. To manage cookie settings, select your web browser from the list below and follow the instructions:
      • Edge
      • Internet Explorer
      • Chrome
      • Safari
      • Firefox
      • Opera

Mobile devices:

    • Android
    • Safari (iOS)
    • Windows Phone