Pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the “GDPR”, we hereby inform you that:
The controller of your personal data provided via the contact form available on the website is C.M.C. sp. z o.o., with its registered office in Andrychów at ul. Przemysłowa 54, entered into the Register of Entrepreneurs of the National Court Register by the District Court for Kraków-Śródmieście in Kraków, 12th Commercial Division of the National Court Register, under KRS number 0000197403, NIP: 9451559352, REGON: 351097803, share capital: PLN 240,000.00, hereinafter referred to as the “Controller”. Contact with the Controller regarding personal data protection matters is possible via e-mail at: rodo@cmc.net.pl
Your personal data is processed within the scope provided in the contact form and may include in particular: full name, e-mail address, phone number, company name, message content, and other data voluntarily provided in the inquiry. The Controller may also process technical data related to the use of the website or submission of the form, such as IP address, date and time of form submission, and information stored in system logs.
Personal data will be processed for the following purposes:
handling the inquiry submitted via the contact form, including providing a response, conducting correspondence, and taking actions at your request prior to the potential conclusion of a contract — pursuant to Article 6(1)(b) GDPR, if the inquiry concerns the possibility of concluding or performing a contract;
ongoing communication, handling correspondence, and responding to inquiries where the contact is made outside the direct intention of concluding a contract or when you act as a representative, employee, associate, or contact person of a third party — pursuant to Article 6(1)(f) GDPR, i.e. the legitimate interest of the Controller consisting in maintaining communication with persons contacting the Controller;
pursuing claims or defending against claims if such claims arise in connection with the correspondence or matter to which the inquiry relates — pursuant to Article 6(1)(f) GDPR, i.e. the legitimate interest of the Controller;
fulfilling obligations arising from generally applicable laws, if such obligations arise in connection with the submitted inquiry, in particular under civil law, tax law, or accounting regulations — pursuant to Article 6(1)(c) GDPR.
Personal data will be processed for the period necessary to handle the inquiry and conduct correspondence, and thereafter:
for the period necessary to secure or pursue potential claims or defend against claims — generally no longer than the limitation period for such claims;
for the period required by law, if an obligation to retain specific data or documents arises in connection with the matter;
with regard to technical data and system logs — for the period resulting from website security and administration rules, no longer than necessary for those purposes.
Providing personal data is voluntary; however, failure to provide data marked as required in the form may prevent the submission of the form or receiving a response to the inquiry.
Please do not provide special categories of personal data referred to in Article 9 GDPR in the contact form, in particular data concerning health, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, or data concerning sexuality, unless it is necessary for handling the matter and such data is provided on your own initiative.
Your personal data may be disclosed to third parties only where permitted by law. Recipients of the data may include in particular: hosting service providers, IT service providers, entities supporting the Controller’s website or e-mail systems, subcontractors, legal, tax, or accounting advisors, auditors, as well as entities authorized to obtain data under applicable laws.
As a rule, your personal data will not be transferred outside the European Economic Area. However, if, in connection with the Controller’s use of specific IT tools or technical services, data is transferred outside the European Economic Area, such transfer will take place exclusively with the safeguards required by the GDPR, in particular standard contractual clauses or other appropriate data protection mechanisms.
Your personal data will not be used by the Controller for automated decision-making, including profiling.
You have the right to request from the Controller access to your personal data, rectification, erasure, restriction of processing, and — where provided by law — the right to data portability.
To the extent that data is processed on the basis of the Controller’s legitimate interest, you have the right to object to the processing of your personal data.
If you believe that the processing of your personal data violates the law, you have the right to lodge a complaint with the President of the Personal Data Protection Office. Contact details of the supervisory authority are available on the website of the Personal Data Protection Office.