Privacy Policy

1. This Privacy Policy sets out the principles for the processing of personal data obtained through the website normotech.pl, hereinafter referred to as the “Website”.

2. The owner of the Website and at the same time the Data Controller is NORMOTECH LIMITED LIABILITY COMPANY, 63-940 Bojanowo, ul. Kopernika 13, NIP (Tax ID): 6991973527, hereinafter referred to as the Controller.

3. Personal data collected by the Controller via the Website is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation), also referred to as GDPR.

4. The Controller exercises particular care to respect the privacy of Customers visiting the Website.

§ 1 Type of processed data, purposes and legal basis

1. The Controller collects information regarding natural persons performing a legal act not directly related to their business activity, natural persons conducting business or professional activity in their own name, as well as natural persons representing legal entities or organizational units without legal personality to which the law grants legal capacity, conducting business or professional activity in their own name, hereinafter collectively referred to as Customers.

2. The Controller processes Customers’ personal data in connection with the use of the contact form service on the Website to the extent necessary to perform a contract or to take steps prior to entering into a contract – legal basis: Article 6(1)(b) GDPR.

3.

When using the contact form service, the Customer provides the following data:

  • e-mail address

  • first name

  • phone number

4. While using the Website, additional information may be collected, in particular: the IP address assigned to the Customer’s computer or the external IP address of the Internet provider, domain name, browser type, access time, operating system type. Navigation data may also be collected from Customers, including information about links and references they decide to click or other activities undertaken on the Website for the purposes related to service provision, as well as technical, administrative, analytical and statistical purposes – in this scope the legal basis for processing is also Article 6(1)(f) GDPR, i.e. the necessity for the purposes of the Controller’s legitimate interests such as ensuring IT security, managing the Website and improving its functionality and services.

§ 2 Data recipients

1. The Customer’s personal data is transferred to service providers used by the Controller in operating the Website. Depending on contractual arrangements and circumstances, service providers either act on the Controller’s instructions regarding the purposes and methods of data processing (processors) or independently determine the purposes and methods of processing (controllers).

  • 1.1.Processors. The Controller uses providers who process personal data solely on the Controller’s instructions, including hosting providers, accounting service providers, marketing system providers, website traffic analytics providers, and marketing campaign effectiveness analysis providers.

  • 1.2.Controllers.The Controller also uses providers who do not act solely on instructions and independently determine the purposes and methods of using Customers’ personal data. These include electronic payment and banking service providers.

2.Location.Service providers are based mainly in Poland and other countries of the European Economic Area (EEA).

3. Upon request, the Controller provides personal data to authorized state authorities, in particular organizational units of the Prosecutor’s Office, the Police, the President of the Personal Data Protection Office, the President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications.

§ 3 Data retention period

1. Customers’ personal data is stored:

  • 1.1. If the legal basis for processing is consent – until the consent is withdrawn, and after withdrawal for a period corresponding to the limitation period of claims that may be raised by or against the Controller. Unless a specific provision states otherwise, the limitation period is six years, and for periodic claims and claims related to business activity – three years.

  • 1.2. If the legal basis for processing is contract performance – for as long as necessary to perform the contract, and thereafter for a period corresponding to the limitation period of claims. Unless a specific provision states otherwise, the limitation period is six years, and for periodic claims and claims related to business activity – three years.

§ 4 Cookies mechanism, IP address

1. The Website uses small files called cookies. They are stored by the Controller on the end device of a person visiting the Website, if the web browser allows it. A cookie file usually contains the domain name it comes from, its “expiry time,” and an individual, randomly selected number identifying the file. Information collected through cookies helps tailor the Controller’s products to individual preferences and actual needs of Website visitors.

2. The Controller uses two types of cookies:

  • 2.1.Session cookies – after the browser session ends or the computer is turned off, stored information is removed from the device memory. Session cookies do not allow the collection of any personal or confidential data from Customers’ computers.
  • 2.2.Persistent cookies – stored in the Customer’s end device memory and remain there until deleted or expired. Persistent cookies do not allow the collection of any personal or confidential data from Customers’ computers.

3. The Controller uses its own cookies for:

  • 3.1. analyses, research and audience audits, in particular to create anonymous statistics that help understand how Customers use the Website, enabling improvements to its structure and content.

4. The Controller uses external cookies for:

  • 4.1. presenting a map showing the location of the Controller’s office on information pages of the Website via maps.google.com (external cookie administrator: Google Inc., USA).

5. The cookie mechanism is safe for Customers’ computers. In particular, it is not possible for viruses or other unwanted or malicious software to enter Customers’ computers through this method. However, Customers can limit or disable cookies in their browsers. If this option is used, the Website can still be used, except for functions that by their nature require cookies.

6. The Controller may collect Customers’ IP addresses. An IP address is a number assigned to the computer of a person visiting the Website by the Internet service provider. The IP number enables Internet access. In most cases, it is assigned dynamically and changes with each Internet connection and is therefore generally treated as non-personal identifying information. The IP address is used by the Controller to diagnose technical server problems, create statistical analyses (e.g., determining regions with the highest number of visits), as information useful in administering and improving the Website, as well as for security purposes and potential identification of unwanted automated programs overloading the server.

§ 5 Rights of data subjects

Persons whose data is processed have the right to:

1. Withdraw consent at any time:

  • 1.1.The Customer has the right to withdraw any consent given.
  • 1.2.Withdrawal takes effect from the moment of withdrawal.
  • 1.3.Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • 1.4.Withdrawal does not entail negative consequences but may prevent further use of services or functionalities that legally require consent.

2. Object to data processing

  • 2.1.
  • The Customer has the right to object at any time, for reasons related to their particular situation, to the processing of their personal data based on Article 6(1)(e) or (f) GDPR, including profiling. The Controller may no longer process the data unless it demonstrates compelling legitimate grounds or grounds for establishing, pursuing or defending claims.

  • 2.2.
  • Opting out of marketing communications via e-mail constitutes an objection to processing for marketing purposes, including profiling.

3. Erasure of data (“right to be forgotten”)

  • 3.1.
  • The Customer has the right to request deletion of all or some personal data.

  • Deletion may be requested if data is no longer necessary, consent is withdrawn, an objection is raised, data is processed unlawfully, deletion is required by law, or data was collected in connection with information society services.

    • 3.2.1.
    • Despite a deletion request, the Controller may retain certain data where necessary for legal claims or legal obligations.

    • 3.2.2. has withdrawn a specific consent, to the extent that the personal data were processed on the basis of that consent.
    • 3.2.3. has objected to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or has objected to the processing pursuant to Article 21(2) of the GDPR.
    • 3.2.4. the personal data are being processed unlawfully.
    • 3.2.5. the personal data must be erased in order to comply with a legal obligation laid down in Union law or the law of a Member State to which the Controller is subject.
    • 3.2.6. “the personal data were collected in connection with the offering of information society services.
  • 3.3. “Despite a request for the deletion of personal data, in connection with an objection or withdrawal of consent, the Controller may retain certain personal data to the extent that processing is necessary for the establishment, pursuit or defence of claims, as well as for compliance with a legal obligation requiring processing under Union law or the law of a Member State to which the Controller is subject. This applies in particular to personal data including: first name, last name and e-mail address, which are retained for the purpose of handling complaints and claims related to the use of the Controller’s services, as well as additionally the residential/correspondence address and order number, which are retained for the purpose of handling complaints and claims related to concluded sales contracts or the provision of services.

4. Right to restriction of data processing:

  • 4.1. “The Customer has the right to request the restriction of the processing of their personal data. Submitting such a request, until it is reviewed, prevents the use of certain functionalities or services whose use involves the processing of the data covered by the request. The Controller will also refrain from sending any communications, including marketing communications.
  • 4.2. The Customer has the right to request the restriction of the use of personal data in the following cases:
    • 4.2.1. when the accuracy of their personal data is contested – in this case, the Controller restricts their use for the time necessary to verify the accuracy of the data, but no longer than 7 days.
    • 4.2.2. “when the processing of the data is unlawful, and instead of requesting the deletion of the data, the Customer requests the restriction of its use.
    • 4.2.3. “when the personal data are no longer necessary for the purposes for which they were collected or used, but are still needed by the Customer for the establishment, exercise, or defense of legal claims.
    • 4.2.4. “when the data subject has objected to the processing of their data – until it is determined whether the Controller’s legally justified grounds override the grounds for objection of the data subject.

5. “Right to request from the Controller access to one’s personal data and to receive a copy thereof:

  • 5.1. The Customer has the right to obtain from the Controller confirmation as to whether their personal data is being processed, and if so, the Customer has the right to:
    • 5.1.1. “to access their personal data
    • 5.1.2. to obtain information about the purposes of processing, the categories of personal data being processed, the recipients or categories of recipients of such data, the planned retention period of the Customer’s data or the criteria for determining that period (if it is not possible to specify the planned retention period), the rights of the Customer under the GDPR, and the right to lodge a complaint with a supervisory authority; if the personal data were not collected from the data subject, to obtain any available information about their source; information on automated decision-making, including profiling referred to in Articles 22(1) and 22(4) of the GDPR, and – at least in these cases – essential information about the logic involved, as well as the significance and the expected consequences of such processing for the data subject, and the safeguards applied in connection with the transfer of personal data outside the European Union.
    • 5.1.3. “to obtain a copy of their personal data. The right to obtain a copy must not adversely affect the rights and freedoms of others.

6. “Right to rectification (correction) of data:

  • 6.1. The Customer has the right to request from the Controller the immediate rectification of inaccurate personal data concerning them. Taking into account the purposes of processing, the Customer also has the right to request the completion of incomplete personal data, including by providing an additional statement, by sending a request to the e-mail address indicated in §6 of the Privacy Policy.

7.Right to data portability:

  • 7.1. “The Customer has the right to receive their personal data that they provided to the Controller and to transfer it to another data controller of their choice. The Customer also has the right to request that the data be transmitted directly by the Controller to such a data controller, provided this is technically feasible. In such a case, the Controller will transmit the Customer’s personal data in a file in CSV format, which is a commonly used, machine-readable format that allows the data to be transferred to another data controller.

8. Right to lodge a complaint with a supervisory authority:

  • 8.1. The Customer has the right to lodge a complaint with the President of the Personal Data Protection Office regarding any violation of their rights to the protection of personal data or other rights granted under the GDPR.

9. In the event that the Customer exercises any of the rights described above, the Controller shall comply with or refuse the request without undue delay, and in any case no later than one month from its receipt. However, if – due to the complex nature of the request or the number of requests – the Controller is unable to fulfill the request within one month, it will fulfill it within the following two months, notifying the Customer within one month of receiving the request about the intended extension and the reasons for it.

10. The Customer may submit complaints, inquiries, and requests to the Controller regarding the processing of their personal data and the exercise of their rights.

§ 6 Changes to the Privacy Policy

1

  • The Privacy Policy may be amended, and the Controller is not obliged to notify users of such changes.

  • Questions regarding the Privacy Policy should be sent to the e-mail address: mikolaj.krol@normotech.pl

  • Date of last modification: 22.01.2026