PRIVACY POLICY OF THE ONLINE STORE WWW.BOROVITA.COM
Effective date: 16 July 2026
This is an English translation of the Polish-language Privacy Policy of www.borovita.com. The Polish version is the governing and legally binding version; in case of discrepancy, the Polish version prevails.
This Privacy Policy sets out the rules for the processing and protection of personal data of Users and Customers of the online store at www.borovita.com, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and the Polish Act of 10 May 2018 on the Protection of Personal Data.
§ 1. Data Controller
The controller of personal data is:
Borovita Sp. z o.o. Borowina Sitaniecka 78E, 22-400 Zamość, Poland Tax ID (NIP) 9223087592, REGON 542534041, KRS 0001190677 e-mail: kontakt@borovita.com phone: +48 501 403 022
For all matters relating to the processing of personal data, please contact the Controller in writing at the registered office address or by e-mail at the above address.
§ 2. Scope and Purposes of Processing, and Legal Bases
| Purpose of processing | Scope of data | Legal basis |
|---|---|---|
| Conclusion and performance of the sales contract (order handling, payment, delivery, including palletised transport of tunnels) | first and last name, delivery address, e-mail, phone; for companies: name, tax ID, registered address | Art. 6(1)(b) GDPR (performance of a contract) |
| Handling complaints and withdrawal | order data, content of the complaint, photographic evidence of defect | Art. 6(1)(b) and (c) GDPR (obligations under statutory warranty and consumer rights law) |
| Issuing invoices and fulfilling tax/accounting obligations | identification and address data, tax ID | Art. 6(1)(c) GDPR (legal obligation – Accounting Act, tax regulations) |
| Creating and maintaining a Store Account | login, password (encrypted), order history | Art. 6(1)(b) GDPR |
| Direct marketing of own products (newsletter, offers) | e-mail address, purchase history (for offer personalisation) | Art. 6(1)(a) GDPR (consent) and Art. 6(1)(f) GDPR (legitimate interest – direct marketing of own products to existing customers) |
| Traffic analysis, statistics, improvement of Store functionality (cookies, analytics tools) | device data, IP address, cookie identifiers | Art. 6(1)(f) GDPR (legitimate interest) and consent given via the cookie banner, where required |
| Establishment, exercise or defence of legal claims | data necessary to demonstrate the course of the business relationship | Art. 6(1)(f) GDPR (legitimate interest of the Controller) |
§ 3. Recipients of Personal Data
Personal data may be disclosed to the following categories of recipients, to the extent necessary for the purposes indicated in § 2:
- courier, freight-forwarding and palletised-transport companies delivering Goods (including oversized tunnels) to the Customer;
- online payment operators (e.g. Przelewy24/PayU) processing online payments and BLIK;
- hosting and IT service providers operating the Store's infrastructure;
- the accounting office servicing the Company and providers of accounting and legal services;
- providers of analytics and marketing tools (e.g. Google Analytics, Meta), where the User has given the required consent for analytics/marketing cookies;
- the tunnel supplier/manufacturer in China – only to the extent of data strictly necessary to organise the import and customs clearance of a given shipment (generally aggregate order data rather than individual Customer personal data), where necessary to fulfil a specific custom order;
- public authorities entitled to obtain data under applicable law (e.g. tax and customs authorities).
The Controller does not sell Customers' personal data to third parties for marketing purposes other than as indicated in this Policy.
§ 4. Transfers of Data Outside the European Economic Area
- As a rule, Customers' personal data is processed within the European Economic Area (EEA).
- In connection with the import of Goods from China, in limited, exceptional cases (e.g. where recipient details must be shown on customs/shipping documents for an order fulfilled to individual specification), a limited scope of data (e.g. name and delivery address) may be transferred outside the EEA.
- In such cases, the Controller ensures an adequate level of data protection in accordance with Art. 46 GDPR, in particular through Standard Contractual Clauses approved by the European Commission or another mechanism provided for by the GDPR. Information on the safeguards applied can be obtained by contacting the Controller.
- Use of certain analytics/marketing tools (e.g. Google, Meta) may involve transferring data to the USA under transfer mechanisms used by those providers (including the EU-U.S. Data Privacy Framework adequacy decision or Standard Contractual Clauses).
§ 5. Data Retention Periods
- Data related to performance of the sales contract – for the duration of the contract, then for the limitation period of claims related to the contract (generally 6 years, and 3 years in relations with Consumers, counted from the end of the relevant calendar year) and for the period required by tax and accounting regulations (generally 5 years from the end of the year in which the tax payment deadline fell).
- Data processed on the basis of consent (e.g. newsletter) – until consent is withdrawn.
- Account data – until the Account is deleted by the Customer or the Controller.
- Data processed on the basis of the Controller's legitimate interest – until an effective objection is raised or the purpose of processing ceases.
§ 6. Rights of Data Subjects
Every person whose personal data is processed by the Controller has the right to:
- access their personal data (Art. 15 GDPR);
- rectification of data (Art. 16 GDPR);
- erasure of data ("right to be forgotten", Art. 17 GDPR), to the extent this does not conflict with the Controller's legal obligations;
- restriction of processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR) – for data processed by automated means on the basis of consent or contract;
- object to processing based on Art. 6(1)(f) GDPR, including profiling and direct marketing (Art. 21 GDPR);
- withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal;
- lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, PUODO), ul. Stawki 2, 00-193 Warsaw, Poland, if the person considers that the processing of their data violates GDPR.
To exercise the above rights, please contact the Controller using the details in § 1.
§ 7. Voluntary Provision of Data
Providing personal data is voluntary but necessary to conclude and perform the sales contract, handle complaints, issue an invoice, and create an Account. Refusal to provide the data necessary to fulfil an order will prevent the order from being placed and processed.
§ 8. Automated Decision-Making
The Controller does not make decisions concerning Customers based solely on automated processing, including profiling, which would produce legal effects concerning the Customer or similarly significantly affect them.
§ 9. Cookies
- The Store uses cookies and similar technologies to: ensure proper functioning of the Store (necessary cookies); remember User preferences (cart, login session); compile visit statistics; and, subject to User consent, for analytics and marketing purposes (remarketing).
- Users may manage cookie settings at any time via the consent banner displayed on first visit and via their browser settings, including blocking or restricting cookies – this may, however, affect the Store's functionality.
- Detailed information on the types of cookies used, their purposes and retention periods is provided in the cookie consent banner/panel available in the Store.
§ 10. Data Security
The Controller applies appropriate technical and organisational measures to protect processed personal data, including encryption of data transmission (SSL/TLS), access controls to IT systems, regular software updates, and data-processing agreements with processors in accordance with Art. 28 GDPR.
§ 11. Final Provisions
- The Controller reserves the right to amend this Privacy Policy, in particular in connection with changes in law, technology, market practice or the scope of services provided. Material changes will be communicated by publishing the updated version on the Store's website.
- This Privacy Policy forms an integral supplement to the Terms and Conditions of the online store www.borovita.com.
