The Owner of this website considers the protection of Users’ personal data a matter of utmost importance. Great care is taken to ensure that Users feel secure when entrusting their personal data during their use of the website.
A User is a natural person, legal entity, or organizational unit without legal personality, granted legal capacity by law, who uses the electronic services available through the website.
This privacy policy explains the principles and scope of User data processing, the User’s rights, the data controller’s obligations, and provides information on the use of cookies. The Controller employs state-of-the-art technical measures and organizational solutions to provide a high level of protection for processed personal data and to safeguard it from unauthorized access.
The data controller is DF Express sp. z o.o., located at Annopol 4A, registered in the commercial register by the District Court in Warsaw, Economic Department, under KRS number: 190567, NIP: 5321677826 (hereinafter referred to as “Owner”).
The Controller processes User data for the following purposes:
– To prepare offers for spare parts that may be of interest to the User.
– Additionally, the User may consent to receiving information about new products and promotions, allowing the Controller to process personal data to send commercial information, such as new products or services, promotions, or sales.
– Personal data is also processed to fulfill legal obligations on the data controller and in the public interest, including tasks related to security and defense or the storage of tax documentation.
– Personal data may also be processed for direct product marketing, to secure and pursue claims or protect against User or third-party claims, as well as for third-party product and service marketing or non-direct self-marketing.
The Controller processes the following personal data, which is necessary for handling the inquiry form:
– Email address, phone number.
Personal data is processed in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation), OJ L 119, 4.5.2016, pp. 1–88, hereinafter referred to as “GDPR”.
The Controller processes personal data only after obtaining the User’s consent.
Providing consent for data processing is entirely voluntary.
The User may request information from the Controller at any time regarding the scope of personal data processing.
The User may request that their personal data be corrected or amended at any time.
The User may withdraw their consent to the processing of their personal data at any time, without providing a reason. The request to cease processing may refer to a specific processing purpose indicated by the User, such as withdrawal of consent to receive commercial information, or it may apply to all purposes of data processing. Withdrawal of consent for all processing purposes will result in the deletion of the User’s account on the website, along with all personal data previously processed by the Controller. Withdrawal of consent will not affect any actions already taken.
The User may request, without providing a reason, that the Controller delete their data at any time. Deleting the data will also delete the User’s account, along with all data recorded and processed to date by the Controller.
The User may object to the processing of their personal data at any time, either regarding all data processed by the Controller or limited to a specific purpose. The objection will not affect any actions already taken. Submitting an objection will result in the deletion of the User’s account, along with all data recorded and processed by the Controller to date.
The User may request that the processing of their personal data be restricted, either for a specified period or indefinitely, but within a specified scope, which the Controller is obliged to fulfill. This request will not affect any actions already taken.
The User may request that the Controller transfer the processed personal data to another entity. To do so, the User must submit a request to the Controller, specifying the entity (name, address) to which the data should be transferred and identifying which specific data should be transferred. After confirming the User’s request, the Controller will electronically transfer the User’s data to the indicated entity. Confirmation of the User’s request is necessary to ensure the User’s data security and to verify that the request comes from an authorized individual.
The Controller informs the User of actions taken within one month of receiving any of the requests mentioned in the preceding points.
In principle, personal data is stored only as long as necessary to fulfill the contractual or legal obligations for which it was collected. This data will be deleted immediately when storage is no longer required for evidentiary purposes, under civil law, or for fulfilling statutory retention obligations.
Contract-related information is stored for evidentiary purposes for three years from the end of the year in which the business relationship with the User ended. Data deletion will occur after the statutory limitation period for asserting contractual claims has expired.
Furthermore, the Controller may retain archival information regarding completed transactions, as its storage is associated with the User’s claims, such as those under warranty.
If no contract is concluded between the User and the Owner, the User’s personal data is stored until the User’s account is deleted on the website. Account deletion may occur as a result of a User’s request, withdrawal of consent for data processing, or an objection to data processing.
The Controller may delegate personal data processing to entities cooperating with the Controller, to the extent necessary for transaction execution, such as preparing ordered goods and delivering shipments or providing commercial information from the Controller (the latter applies to Users who have consented to receive commercial information).
Apart from the purposes specified in this Privacy Policy, User data will not be disclosed to third parties or transferred to other entities for the purpose of sending third-party marketing materials.
User data is not transferred outside the European Union.
This Privacy Policy complies with the provisions of Article 13(1) and Article 13(2) of the GDPR.