Privacy Policy

Privacy and cookies policy.

Principles of processing your personal data and the use of cookies in connection with the use of the website https://besteon.pl

General Information

This document sets forth the Privacy Policy of the Website (hereinafter referred to as the “Website”). The administrator of the Website is Besteon sp. z o.o., NIP 8971922798, Regon 525408683, place of business: Marsz. Józefa Piłsudskiego 74 / 320, 50-020 Wrocław.

Words used with a capital letter have the meaning given to them in the regulations of this Website.

Personal data collected by the Website Administrator are processed in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27.04.2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (Official Journal of the EU L 119, p. 1), hereinafter referred to as: RODO.

The Administrator of the Website makes special efforts to protect the privacy and information provided to him and concerning the Website’s Customers. The Administrator shall exercise due diligence in the selection and application of appropriate technical measures, including those of a programmatic and organizational nature, ensuring the protection of the processed data, in particular securing the data against their access to unauthorized persons, disclosure, loss and destruction, unauthorized modification, as well as against their processing in violation of applicable laws.

  1. By creating a user account, placing an order, filing a complaint, withdrawing from a contract, subscribing to a newsletter or contacting us, you provide us with your personal data, and we guarantee that your data will remain confidential and will not be shared with third parties without your consent.
  2. We entrust the processing of personal data only to verified and trusted partners providing personal data processing services.
  3. We use Google Analytics analytical tools that collect information about your visit to the site, such as sub-pages viewed, time spent on the site or transitions between sub-pages. Google LLC’s Google Analytics cookies are used for this purpose. As part of Google Analytics, we collect demographic and interest data. As part of your cookie settings, you can choose whether you consent to the collection of such data about you.
  4. We use the Google AdWords tool to run remarketing campaigns. Google LLC’s cookies for the Google AdWords service are used for this purpose. As part of your cookie settings, you can choose whether you consent to the use of such cookies for you.
  5. We use the Google Tag Manager tool to control advertising campaigns and the use of our sites. Google LLC cookies associated with the Google Tag Manager service are used for this purpose. As part of your cookie settings, you can choose whether you consent to the use of such cookies for you.
  6. We use marketing tools such as Facebook Pixel to target you with personalized Facebook ads. This involves the use of cookies from Facebook. As part of your cookie settings, you can choose whether you consent to our use of the Facebook Pixel for you.
  7. We provide you with the ability to use social features, such as sharing content on social networks and subscribing to a social profile. The use of these functions may involve the use of cookies of social network administrators such as Facebook, Instagram, Twitter.
  8. We use the Disqus comment system, which uses cookies.
  9. We use proprietary cookies for the proper operation of the site, in particular the operation of the user account, the ordering process.
  10. If the above information is not enough for you, below you will find more far-reaching details.

Personal Data.

The administrator of your personal data is:

Besteon sp. z o.o., place of business: Marsz. Józefa Piłsudskiego 74 / 320, 50-020 Wrocław, NIP 8971922798, Regon 525408683.

You can contact the Personal Data Administrator regarding your personal data through:

e-mail: biuro@besteon.pl
snail mail: Besteon Wojciech Musiał, Długołęka 55-095, South 3 Street

The purposes, legal basis and period of personal data processing are indicated separately for each purpose of data processing.

Entitlements. The RODO grants you the following potential rights related to the processing of your personal data:

  • the right to access your personal data;
  • the right to erasure of your personal data;
  • the right to rectify your personal data;
  • the right to restrict the processing of your personal data;
  • the right to object to the processing of your personal data;
  • the right to data portability;
  • the right to lodge a complaint with a supervisory authority,
  • the right to withdraw consent to the processing of your personal data, if you have given such consent.

The rules related to the exercise of the indicated rights are described in detail in Articles 16 – 21 of the RODO. The rights indicated above are not absolute and you will not be entitled to them in relation to all processing of your personal data. We have made an effort to indicate your rights within the description of individual personal data processing operations.

We emphasize that one of the rights indicated above is always available to you – if you consider that we have violated data protection regulations in the processing of your personal data, you have the opportunity to file a complaint with the supervisory authority (President of the Office for Personal Data Protection).
You can also always request information from us about what data we have about you and for what purposes we process it. Just send an email to biuro@besteon.pl. You can also use the email address provided above if you have any questions about the processing of your personal data.

Security. We guarantee the confidentiality of any personal information you provide to us. We assure you that we have taken all security and data protection measures required by data protection regulations. Personal data is collected with due diligence and properly protected from unauthorized access.

Recipients of data. Your data may be processed by our subcontractors, i.e., entities we use to process your data and provide you with services or fulfill orders on the online store.
All entities to which we entrust the processing of personal data guarantee the application of appropriate measures for the protection and security of personal data required by law.

Purposes and legal basis for processing personal data

Email contact. When you contact us by e-mail, including sending an inquiry through the contact form, you naturally provide us with your e-mail address as the sender of the message. In addition, you may include other personal data in the body of the message. Provision of data is voluntary, but necessary to establish contact.

Your data is processed in this case for the purpose of establishing contact, and the basis for processing is Article 6(1)(a) of the RODO, i.e. your consent resulting from initiating contact with us. The legal basis for processing after contact is the legitimate purpose of archiving correspondence for internal purposes (Article 6(1)(c) RODO).

The content of your correspondence may be subject to archiving and we are not able to clearly determine when it will be deleted. You have the right to request a history of correspondence you have had with us (if it was subject to archiving), and to request its deletion, unless its archiving is justified by our overriding interests, such as defense against potential claims on your part.

Newsletter. If you wish to subscribe to the newsletter, you must provide us with your email address via the newsletter sign-up form. Providing your data is voluntary, but necessary to sign up for the newsletter.

The data you give us when you sign up for the newsletter is used for the purpose of sending you the newsletter, and the legal basis for its processing is your consent (Article 6(1)(a) of the DPA) given when you sign up for the newsletter.

The data will be processed for the duration of the newsletter, unless you unsubscribe earlier, which will result in the deletion of your data from the database.

You can correct your data stored in the newsletter database at any time, as well as request its deletion by unsubscribing from the newsletter. You also have the right to data portability, in accordance with Article 20 of the RODO.

User account. When setting up a user account, you must provide the data necessary to set up the account, such as e-mail address, name, address data, telephone number. Providing data is voluntary, but necessary to create an account. As part of editing your account data, you can provide further data.

The data provided to us in connection with the creation of an account, is processed for the purpose of creating and maintaining an account on the basis of the contract for the provision of electronic services concluded through account registration (Article 6(1)(b) RODO).

The account data will be processed for the duration of the account’s operation. When you decide to delete your account, we will also delete the data contained in it. Deletion of your account does not delete information about orders placed by you using your account.

You have options to correct the data contained in your account, and you can also delete your account. You also have the right to data portability as stated in Article 20 of the RODO.

Orders. When placing an order, you must provide the data necessary to process the order, such as your name, billing address, email address, phone number. Providing data is voluntary, but necessary to place an order.

The data provided to us in connection with your order is processed for the purpose of processing your order (Article 6(1)(b) RODO), issuing an invoice (Article 6(1)(c) RODO), including the invoice in our accounting records (Article 6(1)(c) RODO), and for archival and statistical purposes (Article 6(1)(f) RODO).

Order data will be processed for the time necessary to process the order, and then until the expiration of the statute of limitations for claims under the contract. In addition, after this period, the data may continue to be processed by us for statistical purposes. Remember also that we are obliged to keep invoices with your personal data for a period of 5 years from the end of the fiscal year in which the tax liability arose.

In the case of order data, you do not have the opportunity to rectify this data once your order has been processed. You also cannot object to the processing of your data and demand its deletion until the expiration of the statute of limitations for contractual claims. Similarly, you cannot object to the processing of data and demand the deletion of data contained in invoices. After the expiration of the statute of limitations for contractual claims, you may unanimously object to our processing of your data for statistical purposes, as well as demand the deletion of your data from our database.
With regard to your order data, you also have the right to data portability in accordance with Article 20 of the RODO.

Complaints and withdrawal. If you make a complaint or withdraw from the contract, you provide us with personal data contained in the content of the complaint or withdrawal statement, which includes your name, address, telephone number, e-mail address, bank account number. Providing the data is voluntary, but necessary to make a complaint or withdraw from the contract.

The data provided to us in connection with the submission of a complaint or withdrawal from the contract are used for the purpose of the complaint procedure or withdrawal from the contract (Article 6(1)(c) RODO).

Data will be processed for the time necessary to carry out the complaint procedure or withdrawal procedure. Complaints and withdrawal statements may also be archived for statistical purposes.

In the case of data contained in complaints and withdrawal declarations, you do not have the opportunity to correct this data. You also cannot object to the processing of your data and request their deletion until the expiration of the statute of limitations for contractual claims. On the other hand, after the expiration of the limitation period for contractual claims, you may object to our processing of your data for statistical purposes, as well as demand the deletion of your data from our database.

Voluntariness of providing personal data

The provision of the required personal data by you is voluntary and is a condition for the provision of services by the Personal Data Administrator through the Website.

Duration of data processing

Personal data will be processed for the period necessary for the fulfillment of orders, services, marketing activities and other services performed for the benefit of the Customer. Personal data will be deleted in the following cases:

  • when the data subject requests erasure or withdraws the consent given;
  • when the data subject does not take action for more than 10 years (inactive contact);
  • upon learning that the stored data is outdated or inaccurate.

Some data in the following areas: e-mail address, first and last name, may be stored for a further period of 3 years for evidential purposes, processing of complaints, claims and claims related to services provided by the Online Store – this data will not be used for marketing purposes.

Data on orders of Goods and paid services, contests and loyalty programs will be stored for a period of 5 years from the date of delivery of the order.

We store data on non-logged-in Customers for a period corresponding to the life cycle of cookies stored on devices or until they are deleted on the Customer’s device by the Customer.

Your personal data regarding your preferences, behaviors and choice of marketing content may be the basis for automated decisions to determine the sales opportunities of the Website.

Recipients of personal data

We provide your personal data to the following categories of recipients:

  • state authorities, e.g. the Prosecutor’s Office, the Police, GIODO, the President of the OCCP, if they ask us to do so,
  • service providers we use to operate the Website, e.g. to process orders. Depending on contractual arrangements and circumstances, these entities either act on our instructions or determine the purposes and means of processing themselves.

List of suppliers:

  • Inpost SA, 130 Malborska St., 30-624 Krakow
  • DPD Polska Sp. z o.o., ul. Mineralna 15, 02-274 Warsaw
  • Poczta Polska SA, ul. Rodziny Hiszpańskich 8, 00-940 Warsaw

Rights of the data subject

Under the RODO, you have the right to:

  • request access to your personal data;
  • to request the rectification of your personal data;
  • to request the deletion of your personal data;
  • request the restriction of the processing of your personal data;
  • to object to the processing of your personal data;
  • to request the transfer of your personal data.

The personal data controller will, without undue delay – and in any case within one month of receiving your request – provide you with information about the action taken on your request. If necessary, the one-month period may be extended by another two months due to the complexity of the request or the number of requests.

In any case, the Data Controller will inform you of such extension within one month of receiving the request, stating the reasons for the delay.

Right of access to your personal data (Article 15 of the RODO)

You have the right to obtain from the Data Controller information about whether your personal data is being processed.

If the Administrator processes your personal data you have the right to:

  • access your personal data;
  • obtain information about the purposes of the processing, the categories of personal data processed, the recipients or categories of recipients of that data, the intended period of storage of your data or the criteria for determining that period, your rights under the RODO and your right to lodge a complaint with a supervisory authority, the source of that data, automated decision-making, including profiling, and the safeguards applied in connection with the transfer of that data outside the European Union;
  • obtain a copy of your personal data.

If you wish to request access to your personal data, submit your request to: biuro@besteon.pl

Right to rectify your personal data (Article 16 of the RODO)

If your personal data is inaccurate you have the right to request the Administrator to rectify your personal data immediately.

You also have the right to request that the Administrator complete your personal data.

If you wish to request that your personal data be rectified or supplemented, please submit your request to: biuro@besteon.pl

If you have registered with the Website, your personal data can be corrected and supplemented by yourself after logging in to the Website.

The right to erasure of personal data, the so-called “right to be forgotten” (Article 17 RODO)

You have the right to request the Data Controller to delete your personal data when:

  • Your personal data are no longer needed for the purposes for which they were collected or otherwise processed;
  • you have withdrawn specific consent, to the extent that your personal data were processed on the basis of consent;
  • Your personal data was processed unlawfully;
  • you have objected to the processing of your personal data for direct marketing purposes, including profiling, to the extent that the processing of your personal data is related to direct marketing;
  • you have objected to the processing of your personal data in connection with processing necessary for the performance of a task carried out in the public interest or processing necessary for the purposes of legitimate interests pursued by the Personal Data Controller or a third party.

Despite your request for erasure, the Personal Data Controller may continue to process your data for the purpose of establishing, asserting or defending claims, of which you will be informed.

If you wish to request deletion of your personal data submit your request to: biuro@besteon.pl

Right to request restriction of processing of your personal data (Article 18 RODO)

You have the right to request the restriction of the processing of your personal data when:

  • you question the correctness of your personal data – the Personal Data Administrator will restrict the processing of your personal data for a period of time that allows you to verify the correctness of your data;
  • when the processing of your data is unlawful and instead of deleting your personal data, you request that the processing of your personal data be restricted;
  • Your personal data are no longer needed for the purposes of processing, but are needed to establish, assert or defend claims;
  • when you have objected to the processing of your personal data – until it is determined whether the legitimate interests on the part of the Personal Data Controller override the grounds stated in the objection.

If you wish to request a restriction of the processing of your personal data, submit your request to: biuro@besteon.pl

Right to object to the processing of your personal data (Article 21 RODO)

You have the right to object at any time to the processing of your personal data, including profiling, in connection with:

  • processing necessary for the performance of a task carried out in the public interest, or processing necessary for the purposes of legitimate interests pursued by the Personal Data Controller or a third party;
  • processing for direct marketing purposes.

If you wish to object to the processing of your personal data, please submit your request to: biuro@besteon.pl

The right to request the transfer of personal data (Article 20 RODO)

You have the right to receive your personal data from the Personal Data Controller in a structured, commonly used machine-readable format and send it to another data controller.

You may also request that the Personal Data Controller send your personal data directly to another data controller (if technically possible).

If you wish to request the transfer of your personal data, submit your request to: biuro@besteon.pl

Right to withdraw consent

You may withdraw your consent to the processing of your personal data at any time.

Withdrawal of consent to process personal data does not affect the lawfulness of processing that was carried out on the basis of consent before its withdrawal.

If you wish to withdraw your consent to the processing of your personal data, please submit your request to: biuro@besteon.pl

Complaint to the supervisory authority

If you believe that the processing of your personal data violates the RODO, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place where the alleged violation occurred.

In Poland, the supervisory authority under RODO is the General Inspector for Personal Data Protection (GIODO).

Cookies and other tracking technologies

Our Website, like almost all other websites, uses cookies.

Cookies are small textual information stored on your terminal device (e.g. computer, tablet, smartphone), which can be read by our ICT system (our own cookies) or a third party’s ICT system (third party cookies).

Some cookies we use are deleted when your browser session ends, i.e. when you close your browser (so-called session cookies). Other cookies are retained on your terminal device and allow us to recognize your browser the next time you visit the site (persistent cookies).

More details can be found below.

Consent to cookies. When you visit the site for the first time, you will see information about the use of cookies. Thanks to a special tool, you have the ability to manage cookies from the site. In addition, you can always change the settings of cookies from the level of your browser or delete them completely.

Please note that disabling or restricting the use of cookies may cause difficulties in using our site, as well as many other websites that use cookies.

Proprietary cookies. We use our own cookies to ensure the proper operation of the site, in particular the ordering process and account login.

Third-party cookies. Our site, like most modern websites, uses features provided by third parties, which involves the use of cookies from third parties. The use of such cookies is described below.

Google Analytics. We use the Google Analytics tool provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. We perform these activities based on our legitimate interest to create statistics and analyze them in order to optimize our websites.

Google Analytics automatically collects information about your use of our website. The information collected in this way is mostly sent to a Google server in the United States and stored there.

Due to the IP address anonymization activated by us, your IP address is truncated before transmission. Only in exceptional cases is the full IP address transferred to a Google server in the United States and only shortened there. The anonymized IP address transmitted by your browser as part of Google Analytics is generally not combined with other Google data.

Since Google LLC is based in the US and uses a technical infrastructure located in the US, it has joined the EU-US-Privacy Shield program to ensure an adequate level of data protection as required by European regulations. As part of an agreement between the US and the European Commission, the latter has determined an adequate level of data protection for companies certified under Privacy Shield.

You can prevent Google from recording the data collected by cookies about your use of our website, as well as the processing of this data by Google, by installing a browser plug-in located at the following address: https://tools.google.com/dlpage/gaoptout.

We also collect demographic and interest data as part of Google Analytics. You can disable Google Analytics cookies within the cookie settings directly from our website.

If you are interested in the details related to data processing within Google Analytics, we encourage you to read the explanation prepared by Google: https://support.google.com/analytics/answer/6004245.

Google Adwords. We use Google AdWords marketing tools provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. We use Google Adwords to promote our website in search results and on third-party websites. We also use remarketing tools. We conduct activities in this regard based on our legitimate interest in marketing our own products or services.

When you visit our website, a Google remarketing cookie is automatically left on your device, using a pseudonymous identifier (ID) and based on the pages you visit to enable interest-based advertising.

Further data processing only takes place if you have consented to Google linking your browsing and application usage history to your account and using the information from your Google account to personalize ads displayed on websites. If you are subsequently logged in when you visit our website on Google, Google will use your data together with Google Analytics data to create and define target group lists for remarketing purposes on different devices. For this purpose, Google temporarily combines your personal data with Google Analytics data to create targeting groups.

Because Google LLC is based in the United States and uses technical infrastructure located in the United States, it has joined the EU-US-Privacy Shield program to ensure an adequate level of personal data protection as required by European regulations. As part of an agreement between the U.S. and the European Commission, the latter has set an appropriate level of data protection for Privacy Shield-certified companies.

You can disable cookies used for remarketing within your Google account settings: https://adssettings.google.com. In addition, you can disable the use of cookies for remarketing within the cookie settings from our website.

If you are interested in details related to data processing by Google AdWords, we encourage you to read Google’s privacy policy: https://policies.google.com/privacy.

Google Tag Manager. We use the Google Tag Manager tool provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Using Google Tag Manager, we control our advertising campaigns and how you use our sites. We perform these activities based on our legitimate interest in marketing our own products or services and optimizing our websites.

When you visit our website, a Google cookie is automatically left on your device, which, using a pseudonymous identifier (ID) and based on the pages you visit, enables us to display interest-based advertising, control the effectiveness of these ads and other activities related to controlling your behavior on the website.

Further data processing only takes place if you have consented to Google linking your browsing and application usage history to your account and using information from your Google account to personalize the ads displayed on the websites. If you are then logged in when you visit our website on Google, Google will use your data together with Google Analytics data to create and define target group lists for remarketing purposes on different devices. For this purpose, Google temporarily combines your personal data with Google Analytics data to create targeting groups.

Because Google LLC is based in the United States and uses technical infrastructure located in the United States, it has joined the EU-US-Privacy Shield program to ensure an adequate level of personal data protection as required by European regulations. As part of an agreement between the U.S. and the European Commission, the latter has set an appropriate level of data protection for Privacy Shield-certified companies.

You can disable cookies used for remarketing within your Google account settings: https://adssettings.google.com. In addition, you can disable the use of cookies for remarketing within the cookie settings from our website.

If you are interested in details related to Google Tag Manager’s data processing, we encourage you to read Google’s privacy policy: https://policies.google.com/privacy.

Facebook Pixel. We use marketing tools available through Facebook and provided by Facebook Inc, 1601 S. California Ave. Palo Alto, CA 94304, USA. As part of these tools, we target you with Facebook ads. We perform these activities based on our legitimate interest in marketing our own products or services.

In order to target you with ads personalized to your behavior on our site, we have implemented the Facebook Pixel within our pages, which automatically collects information about your use of our site in terms of pages viewed. The information collected in this way is mostly sent to a Facebook server in the United States and stored there.

The information collected by Facebook Pixel is anonymous, i.e. it does not allow us to identify you. We only know what actions you have taken within our site. However, we inform you that Facebook may combine this information with other information about you collected as part of your use of Facebook and use it for its own purposes, including marketing. Such actions by Facebook are no longer up to us, and you can look for information about them directly in Facebook’s privacy policy: https://www.facebook.com/privacy/explanation. You can also manage your privacy settings from within your Facebook account.

Because Facebook Inc. is headquartered in the U.S. and uses technical infrastructure located in the U.S., it has joined the EU-US-Privacy Shield program to ensure an adequate level of personal data protection as required by European regulations. As part of an agreement between the U.S. and the European Commission, the latter has set an appropriate level of data protection for Privacy Shield-certified companies.

As part of the cookie settings available on our website, you can disable the Facebook Pixel.

Social media tools. Our websites use plugins and other social media tools provided by social networks such as Facebook, Twitter, Instagram, Google.

When you view our website containing such a plug-in, your browser establishes a direct connection to the servers of the social network administrators (service providers). The content of the plug-in is transmitted by the respective service provider directly to your browser and integrated into the website. Thanks to this integration, service providers receive information that your browser has viewed our site, even if you do not have a profile with the respective service provider or are not currently logged in with them. This information (along with your IP address) is sent by your browser directly to the service provider’s server (some servers are located in the US) and stored there.

If you have logged into one of the social networks, that service provider will be able to directly attribute your visit to our site to your profile on that social network.

If you use a specific plug-in, such as by pressing the “Like” or “Share” button, the corresponding information will be sent directly to the server of the respective service provider and stored there.

In addition, the information will be published in the respective social network and will appear with people added as your contacts. The purpose and scope of data collection and their further processing and use by service providers, as well as the possibility of contacting you and your rights in this regard and the possibility to make settings to ensure the protection of your privacy are described in the privacy policies of the respective service providers.

  • Facebook – https://www.facebook.com/legal/FB_Work_Privacy,
  • Instagram – https://help.instagram.com/519522125107875?helpref=page_content,
  • Twitter – https://twitter.com/en/privacy,
  • Google – https://policies.google.com/privacy?hl=pl.

If you do not want social networks to attribute data collected during your visit to our Website directly to your profile on a particular service, then you must log out of that service before visiting our Website. You can also completely prevent plug-ins from loading on the site by using appropriate extensions for your browser, such as blocking scripts.

Server logs. Use of the site involves sending requests to the server on which the Website is stored. Each request made to the server is recorded in the server logs.

The logs include, among other things, the user’s IP address, the date and time of the server, information about the web browser and the operating system the user is using. The logs are saved and stored on the server.

The data recorded in the server logs are not associated with specific individuals using the site and are not used by us to identify you.

The server logs are only auxiliary material used to administer the site, and their contents are not disclosed to anyone except those authorized to administer the server.

Security. The “cookies” we use are safe for your devices. In particular, it is not possible for viruses or other unwanted software or malware to enter your devices through cookies.