Order measurement

Privacy Policy

This is a translation. In case of discrepancies, the Polish version prevails.

Last updated: 20 March 2025  ·  bobiditrade.pl@gmail.com

Part I — Information for the data subject

Personal data controller

BOBIDI TRADE Spółka z ograniczoną odpowiedzialnością
ul. Hoża 86/410, 00-682 Warszawa
KRS: 0000975678  ·  NIP: 7011091688  ·  REGON: 522225373
E-mail: bobiditrade.pl@gmail.com

Legal basis for processing

The Customer's personal data are processed by the Controller:

  • on the basis of Articles 6 and 9 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: GDPR);
  • on the basis of consent and solely for the purpose specified therein.

Purposes of processing personal data

The Customer's personal data are processed in particular for the purpose of:

  • taking steps prior to entering into a contract and performing the contract;
  • enabling Customers to use the grandis-trade.pl website;
  • concluding distance/off-premises sales contracts with Customers;
  • performing the sales contract;
  • handling Customers' complaints;
  • carrying out marketing and promotional activities;
  • the purposes covered by the Customer's declaration of consent to receiving commercial information by electronic means;
  • archiving.

Retention of personal data

Personal data processed in connection with the Customer placing an order for the purchase and delivery of goods and services offered by the Controller will be processed until the limitation period for claims arising from the concluded contract expires.

Data processed by the Controller in connection with pursuing potential claims, as well as for archiving purposes, will be processed for a period of 3 years from the performance of the sales contract.

Furthermore, due to the need to comply with obligations under generally applicable law, including tax law, some personal data will be stored by the Controller for a period of 6 years from the date of conclusion of the sales contract.

Customer's rights regarding personal data

The Customer has:

  • the right of access to their personal data;
  • the right to rectification of their personal data;
  • the right to erasure of their personal data;
  • the right to restriction of processing of their personal data;
  • the right to portability of their personal data;
  • the right to withdraw consent to the processing of personal data at any time;
  • the right to object to the Controller regarding the manner in which personal data are processed;
  • the right to lodge a complaint with a supervisory authority if they consider that the processing of personal data concerning the Customer infringes the GDPR.

If the Customer considers that the Controller processes their data unlawfully, they may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) by sending it to: Urząd Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, or by e-mail to: kancelaria@uodo.gov.pl.

Other information regarding personal data

  • The Controller informs that personal data may be transferred to third countries outside the European Economic Area.
  • Provision of personal data by the Customer is voluntary but necessary to conclude and perform the contract.
  • The Customer's data may be processed by automated means.
  • The personal data controller is not obliged to appoint a Data Protection Officer and no such Officer has been appointed.

Part II — Privacy Policy (full text)

§ 1. Definitions

The terms used in this Privacy Policy have the following meanings:

  • Controller or Company — BOBIDI TRADE Spółka z ograniczoną odpowiedzialnością with its registered office in Warsaw, ul. Hoża 86/410, 00-682 Warszawa, KRS: 0000975678, NIP: 7011091688, REGON: 522225373, e-mail address: bobiditrade.pl@gmail.com.
  • GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
  • Customer — an adult natural person with full legal capacity, entitled to acquire rights and incur obligations in their own name and on their own behalf, who concludes a sales contract with the Company within the scope of their business or professional activity — i.e. acting as a consumer within the meaning of Article 221 of the Polish Civil Code.
  • Business Customer — an adult natural person with full legal capacity, entitled to acquire rights and incur obligations in their own name and on their own behalf, as well as a legal person or an organisational unit without legal personality but capable of acquiring rights and incurring obligations in its own name, who concludes a sales contract with the Company within the scope of their business or professional activity.
  • Online Store — the online store operated by the Company via the Internet at www.grandis-trade.pl, through which the Customer or Business Customer may obtain an offer for the sale of goods and services offered by the Company and conclude with the Company a distance/off-premises sales contract for the goods and services offered by the Company.

The terms Customer or Customers used further in this Privacy Policy refer to both Customers and Business Customers, unless otherwise provided by particular provisions of this Privacy Policy.

§ 2. General provisions and principles of personal data processing

This Privacy Policy sets out the manner of processing personal data provided by Customers, the principles of securing such data and the rights Customers have in this respect.

The controller of Customers' personal data is:

BOBIDI TRADE Spółka z ograniczoną odpowiedzialnością
ul. Hoża 86/410, 00-682 Warszawa
KRS: 0000975678  ·  NIP: 7011091688  ·  REGON: 522225373
E-mail: bobiditrade.pl@gmail.com

The personal data controller may be contacted:

The personal data controller is not obliged to appoint a Data Protection Officer and no such Officer has been appointed.

Personal data are processed in compliance with the principles set out in generally applicable law, in particular the GDPR.

In order to meet statutory requirements, the Controller selects and applies appropriate technical and organisational measures ensuring the protection of the processed data and secures the data against disclosure to unauthorised persons, as well as against processing in breach of applicable law.

§ 3. Legal basis for processing personal data

Personal data are collected by the Controller on an entirely voluntary basis. Provision of personal data by Customers is voluntary, but necessary in order to use the Online Store and conclude a sales contract with the Company.

The legal basis for the Controller's processing of data such as:

  • the Customer's first name and surname;
  • the company name in the case of a Business Customer;
  • the Customer's e-mail address;
  • the Customer's contact telephone number;
  • the Customer's address;

provided by the Customer during registration in the Online Store, is Article 6(1)(a) GDPR, i.e. the Customer's explicit consent given by registering in the Online Store and providing their personal data. The Controller reserves the right to request the Customer to provide additional data, not listed in this paragraph, which are necessary for the proper performance of the sales transaction and for pursuing the Controller's legitimate purposes.

The legal basis for the Controller's processing of the data indicated above when an order is placed is Article 6(1)(b) GDPR, i.e. taking steps necessary to conclude the sales contract and the need for the Controller to perform the contract for the given Customer.

In addition, the Controller processes personal data voluntarily provided by Customers and collected automatically regarding the manner of using the Online Store, in accordance with Article 6(1)(f) GDPR, i.e. for the legitimate purposes pursued by the Controller, in particular for the direct marketing of the Controller's products or services, as well as for optimising, improving and personalising the functions of the Online Store.

If the Customer gives separate consent to the processing of their personal data, their data in the form of an e-mail address may be processed by the Controller for the purpose of sending the Customer commercial information about the Company's activities. The Customer is entitled at any time to request the Controller to stop sending them commercial information by electronic means.

Personal data processed for purposes related to the Customer's registration in the Online Store will be processed until the Customer deletes their account in the Online Store, unless generally applicable law obliges the Controller to store personal data for a specified period.

Personal data processed in connection with the Customer placing an order for the purchase and delivery of goods and services offered by the Controller will be processed until the limitation period for claims arising from the concluded contract expires. Data processed by the Controller in connection with pursuing potential claims, as well as for archiving purposes, will be processed for a period of 3 years from the performance of the sales contract. Furthermore, due to the need to comply with obligations under generally applicable law, including tax law, some personal data will be stored by the Controller for a period of 6 years from the date of conclusion of the sales contract.

If the Customer withdraws consent to receiving commercial information by electronic means, the data processed by the Controller for this purpose will be deleted without undue delay.

§ 4. Purpose and scope of data collection

The Controller collects Customers' personal data for the purpose of:

  • enabling Customers to use the Online Store;
  • concluding distance/off-premises sales contracts with Customers;
  • performing the sales contract;
  • handling Customers' complaints;
  • carrying out marketing and promotional activities;
  • the purposes covered by the Customer's declaration of consent to receiving commercial information by electronic means;
  • archiving.

Each purpose of the Controller's processing of personal data results from the consent given by the Customer or from provisions of generally applicable law imposing on the Controller the obligation to process and archive personal data.

Each purpose of the Controller's processing of personal data may be specified in more detail as a result of actions taken by the Customer.

The Controller collects personal data only for a specifically justified purpose and does not process them in a manner incompatible with, or going beyond, such purpose.

§ 5. Principles of data processing

The Controller makes every effort to duly fulfil its obligations under the GDPR and other generally applicable law. In particular, the Controller complies with the principles set out in Article 5 GDPR, i.e.:

  • processes personal data lawfully, fairly and in a transparent manner in relation to the data subject;
  • collects personal data for specified, explicit and legitimate purposes and does not process them in a manner incompatible with those purposes;
  • collects personal data that are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
  • collects accurate personal data and, where necessary, updates or modifies them;
  • takes, where necessary, all necessary steps to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
  • stores data in a form which permits identification of the data subject for no longer than is necessary for the purposes for which the data are processed;
  • processes personal data in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.

§ 6. Recipients of data

The recipients of personal data processed by the Controller may be the following entities:

  • the Controller's personnel, understood both as persons employed by the Controller under an employment contract and as persons providing services to the Controller under other civil-law contracts;
  • entities cooperating with the Controller;
  • entities linked to the Controller by personal or capital ties;
  • entities entitled to receive personal data under generally applicable law;
  • entities cooperating with the Controller in providing payment options for services rendered by the Controller;
  • entities providing accounting, legal or administrative services to the Controller;
  • entities authorised to process personal data under a data processing (entrustment) agreement concluded with the Controller.

The entities listed above are obliged to observe the principles of confidentiality and security of personal data, including not disclosing personal data to other unauthorised third parties, and to apply appropriate personal data protection measures adequate to the manner in which they process the data.

Personal data will not be transferred or disclosed to any other third parties not indicated above.

§ 7. Automatic data collection and “Cookies”

When the Customer uses the Online Store, IT data are collected automatically concerning:

  • the IP address;
  • the type of operating system;
  • the type of web browser used.

The Controller automatically collects certain personal data using the tools and technologies specified and described in this paragraph.

“Cookies”

When the Online Store is used, certain personal data of Customers are collected automatically. These data are collected by so-called “Cookies” files, which serve to make the use of the Online Store simpler, more functional and more user-friendly.

“Cookies” are small text files created on the Customer's terminal device — i.e. a desktop computer, laptop, tablet or smartphone. Most “Cookies” are “session files”, which means that they are automatically deleted from the terminal device at the end of the given session. The remaining “Cookies” — persistent ones — remain stored on the Customer's terminal device and make it possible to recognise the terminal device again.

Use of the Online Store by the Customer requires the use of both session and persistent “Cookies”. Restricting the use of “Cookies” by the Customer may affect the functionality of the Online Store.

Analytics tools — Google Analytics

This Website uses the Google Analytics service (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) to analyse anonymous website traffic and user behaviour and to optimise content. Google Analytics uses “Cookies”, which are stored on the Customer's terminal device. All data are transmitted in anonymised form.

Detailed information on Google's data processing principles can be found in the Google Privacy Policy and in the Google Analytics data protection documentation. The Customer may block data processing by Google Analytics by installing the browser add-on: Google Analytics Opt-out.

§ 8. Security and data protection principles

The Controller ensures and guarantees that it applies appropriate technical, technological, IT and organisational measures that ensure due security and protection of the processed personal data.

The Controller secures personal data, among others, against loss, modification, unauthorised access, misuse, unlawful access, unauthorised processing and use of personal data by means of, among others:

  • data encryption;
  • the use of encryption during connection to the Online Store;
  • ensuring appropriate security of the Online Store, its resources and the technologies used;
  • ensuring the ongoing confidentiality, integrity, availability and resilience of systems and technologies;
  • the ability to promptly restore or recover the availability of personal data in the event of an incident;
  • regular assessment, improvement and updating of the security measures applied.

§ 9. Rights of the data subject

The Controller, in compliance with the requirements of the GDPR, informs that every person whose personal data are processed and collected by the Controller in any manner has:

  • the right of access to data;
  • the right to rectification of data;
  • the right to erasure of data or part thereof;
  • the right to restriction of processing, both as to the scope of data and the purpose of processing;
  • the right to object to the processing and collection of data;
  • the right to withdraw consent to the processing and collection of data;
  • the right to information on the scope and purposes of data processing;
  • the right to lodge a complaint with a supervisory authority.

The rights indicated above may be exercised by contacting the Controller directly in the manner specified in § 2 of this Privacy Policy.

If the person whose personal data are processed considers that the Controller processes their data unlawfully, they may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) by sending it to: Urząd Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, or by e-mail to: kancelaria@uodo.gov.pl.

§ 10. Transfer of data to third countries

The Controller, in compliance with the provisions of the GDPR, informs Customers that their personal data may be transferred to third countries outside the European Economic Area.

At the same time, the Controller guarantees that entities located outside the European Economic Area to which personal data may be transferred as part of the Controller's cooperation with such entities, or as a result of capital or personal ties with such entities, ensure a similar level of personal data protection and apply similar protection measures to those indicated in this Privacy Policy and required by the GDPR.

§ 11. Final provisions

The Controller may amend the Privacy Policy at any time for important reasons (such as, among others: a change of address, changes beneficial to Customers, a change in the scope of the Company's activities, changes in applicable law, the introduction of new functionalities in the Online Store).

The Customer will be informed of each amendment to the Privacy Policy before the amendments enter into force by making the new Privacy Policy available in the Online Store.

This Privacy Policy is governed by Polish law.