We value your privacy, and we conduct our daily operations in full compliance with personal data protection regulations. This document explains why we collect personal data, the scope of the data we process, the legal basis for doing so, how long we store it and who may receive it. You will also learn about the rights you have in relation to the processing of your personal data.
This document has been prepared in accordance with the EU General Data Protection Regulation 2016/679 (“GDPR”).
Its purpose is to bring clarity to the way personal data is managed and, above all, to ensure the protection and safeguarding of your personal data.
For all matters — including those related to personal data — you can contact us via our website, email, telephone, chat, collaboration platforms or traditional mail. Our contact details are as follows:
FAKRO Sp. z o.o.
ul. Węgierska 144a
33-300 Nowy Sącz
email: fakro@fakro.pl
tel.: +48 18 444 0 444
When working with your personal data, we follow the following principles:
We have appointed a Data Protection Officer (DPO) whom you can contact with any questions or requests regarding personal data. You can do so in the following ways:
a) by post, at the following address:
Data Protection Officer - Kinga Nowobilska
ul. Węgierska 144a
33-300 Nowy Sącz
b) email: iod@fakro.pl
c) tel.: +48 18 444 03 06
| When we process personal data? | What data we process? | Purpose of processing | Legal basis | Retention period |
|---|---|---|---|---|
| Analytical and statistical activities on websites | IP address, cookie-derived data, information about activity on the website | We monitor activity in the online store to understand customer purchasing preferences. The data is collected, among others, through cookies – their processing requires the customer’s consent. | Art. 6(1)(a) and (f) GDPR | Until consent is withdrawn or an effective objection is submitted. |
| Activities related to concluding and performing a contract / Product-related claims | First name, last name, residential address, email address, telephone number | Personal data is processed for the purpose of concluding and performing a contract, providing customer service and warranty support, as well as for the establishment, exercise or defence of legal claims. | Art. 6(1)(b), Art. 6(1)(c) – e.g. the Civil Code, Art. 6(1)(f) GDPR | Until the completion of the service, provision, support, complaint handling or warranty process. In the case of establishing, exercising or defending legal claims – until the last day of the calendar year following a period of three years from the completion of the service. |
| Business activities | First name, last name, residential address, email address, telephone number | We process personal data of individuals, customers, suppliers and other stakeholders in order to carry out business activities. | Art. 6(1)(b), Art. 6(1)(c) – e.g. the Anti-Money Laundering Act, Art. 6(1)(f) | Until the termination of cooperation. |
| Newsletter | Email address | Personal data is used to send a newsletter containing information about price changes, company news and promotions. | Art. 6(1)(a) GDPR | Until consent is withdrawn. |
| Whistleblower protection | First name, last name, email address, nature of the relationship with the company and any other categories of data that may be included in the report to describe the irregularity correctly. | Personal data is processed as part of the whistleblower protection procedure exclusively by authorised persons and solely for the purpose of handling reports of violations of law or internal regulations. | Art.6(1)(c) – e.g. the Whistleblower Protection Act, Art.6 (1)(f) | Until the expiry of claims arising from applicable legal provisions, including the Civil Code, or until the expiry of the limitation period for criminal offences under the Criminal Code. |
| Responding to enquiries | Contact, communication, technical and location data processed for the purpose of providing services, performing analysis and integrating with external platforms. | We collect and process personal data in order to handle customer contact (via email, telephone) and fulfil orders. | Art. 6(1)(b) and (f) GDPR | Until the completion of the service or until we provide an answer / fulfil the subject of the enquiry or request. |
| Training activities | First name, last name, telephone number, email address, company/institution name, company registered address, image (likeness). | Educational activities related to our product offering. | Art. (6)(1)(a), (b) and (f) GDPR | 5 years or for the duration of cooperation including the applicable claims period. |
| Recruitment | First name and last name, date of birth, contact details, education, professional qualifications, employment history. | We require personal data to conduct the recruitment process and, if applicable, to conclude an employment contract, a B2B contract, or to accept a candidate for an internship or traineeship. If you provide consent, your personal data may also be processed for the purposes of future recruitment processes. | Art. 6(1)(a), (b) and (f) GDPR, the Labour Code | Until the expiry of employee-related claims or until consent is withdrawn (if you have provided consent for future recruitment). |
| Use of artificial intelligence | First name and last name, email address, photos or video recordings, information from platform accounts, answers provided during the recruitment process. | Personal data may be processed using AI technologies to streamline processes and improve services, including cooperation with external technology providers. | Art. 6(1)(f) GDPR | Personal data is stored and processed for the period necessary to fulfil the stated purposes, unless the user submits an effective written objection. |
| Marketing activities | Contact data and technical data (e.g. browsing history, cookie data) collected while using our services and communication channels, as well as those belonging to third party providers, for the purpose of service provision and interaction analysis. | We use this data for marketing activities, including the creation of personalised offers. Processing for this purpose is based on the customer’s consent, which may be withdrawn at any time. | Art. 6(1)(a) and (f) GDPR | Until consent is withdrawn or an effective objection is submitted. |
| Digital platforms and mobile apps | Personal data collected on digital platforms and mobile apps. | Personal data is collected through our platforms and apps to improve customer communication and to support the development of our products and services. | Art. 6(1)(b) and (f) GDPR | Personal data is processed for the duration of the contract and, based on legitimate interest, until the expiry of the limitation period or until an effective objection is submitted. |
| Social media accounts/profiles | First name, last name, username, profile picture, other images containing likeness, statistical data. | We process personal data through our social media accounts for the purposes of communication, promotion, activity analysis and event organisation. Processing occurs, among others, when you subscribe, leave a comment or complete a form. In certain cases, we act as joint controllers of these platforms. | Art. 6(1)(f) GDPR | Until the subscription is withdrawn or for as long as the social media accounts remain active. |
| Video monitoring | Image | Image (likeness) is processed as part of video monitoring for the purposes of ensuring safety, protecting property, controlling production processes and safeguarding confidential information. | Art. 6(1)(b), (c) and (f) GDPR | Recordings are stored for a maximum of 3 months from the date they are made. If recordings constitute evidence in proceedings conducted under applicable law, the retention period may be extended until the final conclusion of the proceedings. |
| Promotional activities | First name, last name, residential address, email address, telephone number, identity document number, bank account number, National ID (PESEL) number, tax ID. | Personal data is collected for the organisation of promotional activities, registration of participants, delivery of prizes and verification of the winners’ identity. | Art. 6(1)(b) and (f) GDPR | Until the expiry of the period resulting from tax regulations or until an effective objection is submitted. |
| Participation in photos, videos and campaigns | Image | The image may be processed on the basis of consent or under the provisions of a contract. In certain cases — for example, when the image appears only as an element of a larger photograph — additional consent is not required. | Art. 6(1)(a) and (b) GDPR | Until consent is withdrawn or for the period specified in the contract |
| Registration and purchases in the online store | First name, last name, delivery address, email address, purchase history, contact details, bank account number. | We process personal data for the purpose of fulfilling an order, enabling login to the store through external services, analysing purchase history and handling payments and deliveries. | Art. 6(1)(b), (c) and (f) GDPR | Until the completion of the service, until an effective objection is submitted, and for the periods specified by applicable law. |
We may process your data when:
We obtain data from, for example:
You have the following rights related to the processing of your personal data:
We exercise these rights after successfully verifying the identity of the person submitting the request. A request may be submitted by telephone, email or in person at our registered office, as well as by post. You can also send your request directly to our Data Protection Officer. We will provide a written response without undue delay.
The personal data we collect may be shared with other companies within the FAKRO Group and with companies cooperating with us – our business partners – so that we can assist you in resolving your issue, preparing an offer or organising the provision of a service.
In accordance with the law, we may also share your data with other entities in order to fulfil statutory obligations or to conclude and perform a contract.
We may share your data in particular with:
Your personal data may be transferred to so called “third countries”, meaning countries outside the European Economic Area.
In such cases, to ensure the security of your personal data, we make sure that the transfer to a given third country is safe. This is done through mechanisms such as: a European Commission adequacy decision confirming an adequate level of data protection in that country; the use of Standard Contractual Clauses approved by the European Commission; Binding Corporate Rules; codes of conduct; certification mechanisms; or standard data protection clauses adopted by the supervisory authority.
Based on your consent, we may use your data for profiling. However, decisions will not be made in an automated manner and will not produce any legal effects concerning you.
Profiling of personal data means processing your data (including automated processing) in order to evaluate certain information about you — in particular to analyse or predict your personal preferences and interests.
A personal data breach occurs when personal data is accidentally or unlawfully destroyed, lost, altered, disclosed or made available to unauthorised persons. In the event a personal data breach is identified, we take the following steps:
Due to ongoing changes in the functioning of our company and regularly evolving legal regulations, we may introduce periodic updates to this document. The latest version of the Data Protection Policy will always be available on our website.
Date of GDPR implementation: 25.05.2018
Date of last update to this document: 15.01.2026
Copyright © 2026 FAKRO. All rights reserved.