Privacy policy

This Privacy Policy sets out the rules for storing and accessing data on Users’ Devices used to access the Website for the purpose of providing electronic services by the Controller, as well as the rules for collecting and processing Users’ personal data provided by them personally and voluntarily through the tools available on the Website.

§1 Definitions

  • Website – the website “Procabi – forklift cabin manufacturer” operating at www.procabi.pl.
  • External Website – websites of partners, service providers or customers cooperating with the Controller.
  • Website / Data Controller – the Website Controller and Data Controller (hereinafter referred to as the Controller) is “Procabi Arkadiusz Nitecki”, operating at ul. Karoliny 45, 42-260 Wanaty, Poland, Tax Identification Number (NIP): 5732934785, providing electronic services through the Website.
  • User – a natural person to whom the Controller provides electronic services through the Website.
  • Device – an electronic device together with software through which the User accesses the Website.
  • Cookies – text data collected in the form of files stored on the User’s Device.
  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation).
  • Personal Data – information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name and surname, identification number, location data, online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Processing – any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • Restriction of Processing – the marking of stored personal data with the aim of limiting their processing in the future.
  • Profiling – any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
  • Consent – consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or clear affirmative action, agree to the processing of personal data relating to them.
  • Personal Data Breach – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.
  • Pseudonymisation – processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and subject to technical and organisational measures preventing attribution to an identified or identifiable natural person.
  • Anonymisation – the irreversible process of modifying data in a way that destroys or overwrites personal data so that identification of, or connection with, a specific user or natural person is no longer possible.

§2 Data Protection Officer

Pursuant to Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer.

For matters concerning data processing, including personal data, please contact the Controller directly.

§3 Types of Cookies

  • First-party Cookies – files placed on and read from the User’s Device by the Website’s IT system.
  • Third-party Cookies – files placed on and read from the User’s Device by IT systems of External Websites. Scripts of External Websites that may place Cookies on Users’ Devices have been deliberately implemented on the Website through scripts and services made available and installed on the Website.
  • Session Cookies – files placed on and read from the User’s Device by the Website during a single session of a given Device. After the session ends, the files are deleted from the User’s Device.
  • Persistent Cookies – files placed on and read from the User’s Device by the Website until they are manually deleted. They are not automatically removed when the Device session ends unless the User’s Device is configured to delete Cookies after each session.

§4 Data Storage Security

  • Cookie storage and retrieval mechanisms – the mechanisms for storing, reading and exchanging data between Cookies stored on the User’s Device and the Website are provided by built-in web browser functions and do not allow other data to be retrieved from the User’s Device or from other websites visited by the User, including personal or confidential information. Transmission of viruses, Trojan horses or other malicious software to the User’s Device through these mechanisms is also practically impossible.
  • First-party Cookies – Cookies used by the Controller are safe for Users’ Devices and do not contain scripts, content or information that could threaten the security of personal data or the security of the Device used by the User.
  • Third-party Cookies – the Controller takes all reasonable steps to verify and select Website partners with regard to User security. The Controller cooperates with well-known and reputable global partners. However, the Controller does not have full control over the content of Cookies originating from external partners. To the extent permitted by law, the Controller is not responsible for the security, content or use of Cookies originating from third-party scripts installed on the Website. A list of partners is provided later in this Privacy Policy.
  • Cookie Control
  • Risks on the User’s side – the Controller applies reasonable technical measures to ensure the security of data stored in Cookies. However, the security of such data also depends on the User’s actions. The Controller is not responsible for interception, session impersonation or deletion of such data resulting from intentional or unintentional activity of the User, viruses, Trojan horses or other spyware with which the User’s Device may be or may have been infected. Users should follow safe Internet usage recommendations to protect themselves against these risks.
  • Storage of personal data – the Controller makes every effort to ensure that personal data voluntarily provided by Users are secure, access to them is restricted and they are used only for their intended purposes and processing objectives. The Controller also makes every effort to protect the data against loss by applying appropriate physical and organisational safeguards.

§5 Purposes for which Cookies are used

  • Improving and facilitating access to the Website
  • Personalising the Website for Users
  • Marketing and remarketing on external websites
  • Keeping statistics (Users, number of visits, types of devices, connection type, etc.)
  • Providing multimedia services
  • Providing social media services

§6 Purposes of Personal Data Processing

Personal data voluntarily provided by Users are processed for one or more of the following purposes:

  • Provision of electronic services:
    • Newsletter service, including sending advertising content with the User’s consent
    • Commenting on / liking Website posts without the need to register
    • Sharing information and Website content on social media platforms or other websites.
  • Communication between the Controller and Users regarding the Website and data protection matters
  • Ensuring the legitimate interests of the Controller

Data concerning Users that are collected anonymously and automatically are processed for one or more of the following purposes:

  • Keeping statistics
  • Remarketing
  • Ensuring the legitimate interests of the Controller

§7 Cookies of External Websites

The Controller uses JavaScript scripts and web components of partners on the Website which may place their own Cookies on the User’s Device. Please remember that you can decide in your browser settings which Cookies may be used by particular websites. Below is a list of partners or services implemented on the Website that may place Cookies:

Services provided by third parties are beyond the Controller’s control. Such entities may change their terms of service, privacy policies, purposes of data processing or methods of using Cookies at any time.

§8 Types of Data Collected

The Website collects data concerning Users. Some data are collected automatically and anonymously, while some constitute personal data voluntarily provided by Users when registering for particular services offered through the Website.

Anonymous data collected automatically:

  • IP address
  • Browser type
  • Screen resolution
  • Approximate location
  • Website pages visited
  • Time spent on individual Website pages
  • Type of operating system
  • Address of the previous page
  • Referring website address
  • Browser language
  • Internet connection speed
  • Internet service provider
  • Demographic data (age, gender)

Data collected during registration:

  • First name / surname / nickname
  • Email address
  • IP address (collected automatically)
  • Other ordinary data

Data collected when subscribing to the Newsletter:

  • First name / surname / nickname
  • Email address
  • IP address (collected automatically)

Data collected when adding a comment:

  • First name and surname / nickname
  • Email address
  • Website address
  • IP address (collected automatically)

Some data that do not identify the User may be stored in Cookies. Some data that do not identify the User may be transferred to the provider of statistical services.

§9 Access to Personal Data by Third Parties

As a general rule, the Controller is the only recipient of personal data provided by Users. Data collected as part of the services provided are not transferred or sold to third parties.

Access to data, most often on the basis of a data processing agreement, may be granted to entities responsible for maintaining the infrastructure and services necessary for operation of the Website, including:

  • Hosting companies providing hosting or related services to the Controller
  • Companies through which the Newsletter service is provided

Entrusting Personal Data Processing – Newsletter

For the purpose of providing the Newsletter service, the Controller uses the services of a third party – Freshmail. Data entered in the newsletter subscription form are transferred to, stored and processed by this external service provider.

Please note that the partner may modify its privacy policy without the Controller’s consent.

Entrusting Personal Data Processing – Hosting, VPS or Dedicated Server Services

For the purpose of operating the Website, the Controller uses the services of an external hosting, VPS or Dedicated Server provider – ADMIN.NET.PL Tomasz Rzepka. All data collected and processed through the Website are stored and processed within the service provider’s infrastructure located in Poland. Access to the data may occur as a result of maintenance work performed by the service provider’s personnel. Access to such data is governed by the agreement concluded between the Controller and the Service Provider.

§10 Method of Personal Data Processing

Personal data voluntarily provided by Users:

  • Personal data will not be transferred outside the European Union unless they have been published as a result of an individual action by the User, for example by posting a comment or entry, making the data available to anyone visiting the Website.
  • Personal data will not be used for automated decision-making (profiling).
  • Personal data will not be sold to third parties.

Anonymous data (without personal data) collected automatically:

  • Anonymous data (without personal data) may be transferred outside the European Union.
  • Anonymous data (without personal data) will not be used for automated decision-making (profiling).
  • Anonymous data (without personal data) will not be sold to third parties.

§11 Legal Basis for Personal Data Processing

The Website collects and processes Users’ data on the basis of:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation)
    • Article 6(1)(a)
      the data subject has given consent to the processing of their personal data for one or more specific purposes
    • Article 6(1)(b)
      processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract
    • Article 6(1)(f)
      processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party
  • Act of 10 May 2018 on the Protection of Personal Data (Journal of Laws 2018, item 1000)
  • Act of 16 July 2004 – Telecommunications Law (Journal of Laws 2004 No. 171, item 1800)
  • Act of 4 February 1994 on Copyright and Related Rights (Journal of Laws 1994 No. 24, item 83)

§12 Personal Data Processing Period

Personal data voluntarily provided by Users:

As a general rule, the indicated personal data are stored only for the period during which the Controller provides services through the Website. They are deleted or anonymised within 30 days from the end of the service provision, for example after deletion of a registered User account or unsubscribing from the Newsletter.

An exception applies where it is necessary to safeguard the Controller’s legitimate interests requiring further processing of such data. In such cases, the Controller will retain the indicated data from the moment the User requests their deletion for no longer than 3 years where there has been an infringement or suspected infringement of the Website’s terms and conditions by the User.

Anonymous data (without personal data) collected automatically:

Anonymous statistical data that do not constitute personal data are stored by the Controller for statistical purposes for an indefinite period.

§13 Users’ Rights Related to Personal Data Processing

The Website collects and processes Users’ data on the basis described above. Users are entitled to the following rights:

  • Right of access to personal data
    Users have the right to obtain access to their personal data by submitting a request to the Controller.
  • Right to rectification of personal data
    Users have the right to request that the Controller promptly rectify inaccurate personal data and/or complete incomplete personal data by submitting a request to the Controller.
  • Right to erasure of personal data
    Users have the right to request that the Controller promptly erase their personal data by submitting a request to the Controller. In the case of User accounts, data deletion consists of anonymising information that enables identification of the User. The Controller reserves the right to suspend execution of a data deletion request in order to protect the Controller’s legitimate interests, for example where the User has breached the Terms and Conditions or where the data were obtained through correspondence.
  • In the case of the Newsletter service, the User may independently delete their personal data using the unsubscribe link included in every email message.
  • Right to restriction of processing
    Users have the right to restrict the processing of personal data in the cases specified in Article 18 of the GDPR, including where the accuracy of personal data is contested, by submitting a request to the Controller.
  • Right to data portability
    Users have the right to obtain from the Controller personal data concerning them in a structured, commonly used and machine-readable format by submitting a request to the Controller.
  • Right to object to the processing of personal data
    Users have the right to object to the processing of their personal data in the cases specified in Article 21 of the GDPR by submitting a request to the Controller.
  • Right to lodge a complaint
    Users have the right to lodge a complaint with the supervisory authority responsible for personal data protection.

§14 Contact Details of the Controller

The Controller can be contacted in one of the following ways:

§15 Website Requirements

  • Restricting the storage of and access to Cookies on the User’s Device may result in certain Website functions operating incorrectly.
  • The Controller accepts no responsibility for incorrectly functioning Website features where the User has restricted the ability to store or read Cookies in any way.

§16 External Links

The Website – including articles, posts, entries or Users’ comments – may contain links to external websites with which the Website owner does not cooperate. Such links and the websites or files to which they lead may be unsafe for your Device or may pose a risk to the security of your data. The Controller is not responsible for content located outside the Website.

§17 Changes to the Privacy Policy

  • The Controller reserves the right to make any changes to this Privacy Policy without the need to inform Users with regard to the use and processing of anonymous data or the use of Cookies.
  • The Controller reserves the right to make any changes to this Privacy Policy with regard to the processing of Personal Data. Users who have registered accounts or subscribed to the Newsletter will be informed by email within 7 days of any such change. Continued use of the services means that the User has read and accepted the changes to the Privacy Policy. If the User does not agree with the changes, they are required to delete their Website account or unsubscribe from the Newsletter service.
  • Changes to this Privacy Policy will be published on this Website page.
  • Changes enter into force at the moment they are published.