PRIVACY AND COOKIE POLICY
OF THE ONLINE STORE sklep.bmtg.eu
Chapter I
1. General Information
This Privacy and Cookie Policy sets out the rules governing the processing of personal data and the use of cookies in the online store sklep.bmtg.eu.
This document has been prepared in accordance with:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR),
- the Polish Act of 10 May 2018 on the Protection of Personal Data,
- the Polish Act of 18 July 2002 on the Provision of Electronic Services,
- the Polish Act of 12 July 2024 – Electronic Communications Law (with regard to cookies and similar technologies).
The Controller makes every effort to ensure that personal data is processed in accordance with applicable law and with appropriate technical and organisational measures ensuring its security.
Use of the online store is voluntary. Providing personal data is voluntary; however, when placing an order or using selected functionalities of the store, providing certain personal data may be necessary for the provision of the relevant services.
2. Data Controller
The controller of personal data is:
Marek Gelbert “BMTG”
GÄ…sawy RzÄ…dowe 133F
26-502 JastrzÄ…b
Poland
Tax Identification Number (NIP): 7991030223
Contact with the Controller:
E-mail:
The Controller is responsible for the lawful processing of personal data and for enabling data subjects to exercise their rights.
3. Scope of Application
This Policy applies to all persons using the online store sklep.bmtg.eu, in particular:
- persons browsing the store’s offer,
- customers making purchases as guests,
- customers with a user account,
- persons contacting BMTG via the contact form,
- persons subscribing to the newsletter.
4. Data Security
The online store uses an encrypted SSL (HTTPS) connection, which ensures secure transmission of data between the user’s device and the store’s server.
The Controller applies appropriate technical and organisational measures to protect personal data against loss, destruction, unauthorised access, disclosure or modification.
Access to personal data is limited to authorised persons and entities cooperating with the Controller to the extent necessary for the provision of services.
Chapter II – Scope, Purposes and Legal Bases for the Processing of Personal Data
5. Personal Data We Process
Depending on how the online store is used, the Controller may process the following personal data:
a) When placing an order
For the purpose of processing an order, the following data may be processed in particular:
- first name and surname,
- company name (if applicable),
- delivery address,
- billing address,
- Tax Identification Number (NIP) in the case of businesses,
- e-mail address,
- telephone number,
- information about the products ordered,
- selected delivery method,
- selected payment method.
Providing the above data is voluntary but necessary for the conclusion and performance of the sales contract.
b) Customer account
If a user account is created, data necessary for its creation and administration is processed, in particular:
- first name and surname,
- e-mail address,
- address details,
- order history,
- password (stored in encrypted form and inaccessible to the Controller).
c) Contact form
When contacting BMTG via the contact form or e-mail, the following data may be processed:
- first name,
- e-mail address,
- telephone number (if provided),
- content of the message,
- other data voluntarily provided by the user.
d) Newsletter
When subscribing to the newsletter, the following is processed:
as well as information relating to the consent given to receive commercial communications.
Consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to its withdrawal.
e) Technical data
When using the store, technical data may be automatically recorded, such as:
- IP address,
- date and time of connection,
- information about the web browser,
- operating system,
- device identifiers,
- information stored in cookies,
- server logs.
This data is used primarily to ensure security, proper operation of the store and diagnosis of potential technical issues.
6. Purposes of Data Processing
Personal data is processed for the following purposes:
- conclusion and performance of the sales contract,
- processing orders,
- processing payments,
- arranging delivery of ordered products,
- issuing sales documents,
- managing customer accounts,
- responding to enquiries,
- handling complaints and returns,
- complying with legal obligations,
- ensuring the security of the online store,
- compiling statistics relating to the operation of the store,
- sending newsletters – only after obtaining the user’s separate consent.
7. Legal Bases for Data Processing
The Controller processes personal data pursuant to Article 6(1) of the GDPR, in particular:
a) Article 6(1)(b) GDPR – where processing is necessary for the conclusion or performance of a sales contract;
b) Article 6(1)(c) GDPR – where processing is necessary for compliance with legal obligations, in particular tax and accounting obligations;
c) Article 6(1)(a) GDPR – where consent has been given, e.g. to receive a newsletter;
d) Article 6(1)(f) GDPR – where processing is necessary for the purposes of the legitimate interests pursued by the Controller, such as:
- ensuring the security of the store,
- establishing, pursuing or defending claims,
- preventing fraud and abuse,
- conducting internal analyses concerning the operation of the store.
8. Data Retention Period
Personal data will be retained for the period necessary to fulfil the purpose for which it was collected and subsequently for the period required by law or until the expiry of the limitation period for potential claims.
In particular:
- data relating to order processing and accounting documentation – for the period required by tax and accounting regulations and subsequently for the period necessary to protect against or pursue potential claims,
- customer account data – until the account is deleted by the user or the Controller ceases to maintain it,
- data provided via the contact form – for the period necessary to respond to the enquiry and conduct any subsequent correspondence,
- data processed on the basis of consent – until consent is withdrawn.
Chapter III – Recipients of Personal Data
9. Recipients of Personal Data
The Controller transfers personal data only to the extent necessary for the proper operation of the online store and fulfilment of orders.
Data may be transferred to the following categories of recipients:
a) Payment service provider
If electronic payment is selected, the data necessary to process the payment is transferred to the Przelewy24 payment service, operated by PayPro S.A., with its registered office in Poznań.
The scope of the data transferred depends on the selected payment method and is limited to the information necessary to process the transaction.
b) Courier companies and logistics operators
For the purpose of delivering ordered products, the Controller provides the necessary data to carriers responsible for delivery.
Depending on the selected delivery method, these may include in particular:
- InPost,
- DPD,
- other carriers cooperating with the Controller or selected by the Customer.
The data transferred is limited to the information necessary to deliver the shipment.
c) Accounting firm and invoicing system
For the purpose of issuing sales documents and complying with tax obligations, data may be transferred to the Fakturownia.pl system and – if the Controller uses such services – to an accounting firm.
d) Hosting provider
The online store uses hosting services provided by cal.pl.
Consequently, data stored in the store may be stored on the hosting provider’s servers solely to the extent necessary for the provision of the hosting service.
e) IT service providers
The Controller may use the services of entities providing technical support, server administration, online store maintenance or software development services.
Such entities process data solely on the Controller’s instructions and on the basis of appropriate agreements.
f) Newsletter service provider
If the user subscribes to the newsletter, their e-mail address may be transferred to Mailchimp, which is used to manage subscriptions and send e-mail messages.
g) Public authorities
The Controller may disclose data to competent public authorities only where required by applicable law.
10. Data Processing on Behalf of the Controller
The Controller uses only service providers that ensure an appropriate level of security for the processing of personal data.
Where applicable law requires a data processing agreement to be concluded, the Controller enters into such an agreement with the relevant service provider.
11. Transfers of Data Outside the European Economic Area
As a general rule, personal data is processed within the European Economic Area.
Where service providers whose infrastructure is located outside the European Economic Area are used, data may be transferred to third countries only in accordance with the applicable provisions of the GDPR and subject to appropriate safeguards, such as European Commission adequacy decisions or Standard Contractual Clauses.
At present, this applies in particular to the Mailchimp service, whose provider may process data outside the European Economic Area subject to compliance with the requirements of the GDPR.
Chapter IV – Rights of Data Subjects
12. User Rights
Every person whose personal data is processed by the Controller has the rights provided for under the GDPR.
In particular, the user has the right to:
- access their personal data,
- rectify (correct) their personal data,
- erase their data (“right to be forgotten”), where the conditions provided for by law are met,
- restrict the processing of their data,
- data portability,
- object to processing based on the Controller’s legitimate interests,
- withdraw consent at any time where processing is based on consent (e.g. in the case of the newsletter). Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal.
13. Exercising Your Rights
To exercise their rights, the user may contact the Controller by e-mail at:
E-mail:
The Controller shall respond to requests without undue delay and no later than one month after receipt of the request, unless the GDPR permits this period to be extended.
14. Right to Lodge a Complaint
If the user believes that their personal data is being processed in breach of applicable law, they have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO).
Current information on how to lodge a complaint is available on the website of the Personal Data Protection Office.
15. Voluntary Provision of Data
Providing personal data is voluntary.
However, when placing an order, creating a customer account or using the contact form, providing certain data may be necessary for the provision of these services.
Failure to provide required data may make it impossible to conclude and perform a sales contract, create a user account or respond to an enquiry.
16. Automated Decision-Making and Profiling
BMTG does not make decisions concerning users based solely on automated processing of personal data that would produce legal effects concerning them or similarly significantly affect them.
The Controller does not use profiling for marketing purposes.
Chapter V – Cookies and Similar Technologies
17. What Are Cookies?
Cookies are small text files stored on the user’s device when using the online store.
Cookies enable the proper operation of the store, remember selected user settings and – depending on the consents given – enable the use of statistical and marketing functions.
Cookies are used primarily to ensure the proper operation of the store and to remember selected user settings.
18. Purposes for Which Cookies Are Used
The store uses cookies for the following purposes:
- ensuring the proper operation of the online store,
- maintaining the user’s session after logging in,
- remembering the contents of the shopping cart,
- remembering selected user preferences,
- ensuring the security of the store,
- compiling statistics relating to the operation of the store,
- operating contact forms.
If the user gives separate consent, cookies may also be used for other purposes in accordance with the scope of the consent given.
19. Types of Cookies Used
The following categories of cookies may be used in the store:
Essential
These cookies are necessary for the proper operation of the store.
Without them, it may not be possible to use basic functions such as logging in, placing orders or remembering the contents of the shopping cart.
These cookies do not require the user’s consent.
Functional
These cookies make it possible to remember user settings, such as preferred language or other selected options, making the store more convenient to use.
Statistical
These cookies enable analysis of how users use the store in order to improve it.
The store currently uses the local WP Statistics analytics system.
If additional analytics tools, such as Google Analytics, are implemented in the future, the Privacy Policy will be updated accordingly.
Marketing
The store does not currently use cookies for behavioural advertising or remarketing.
If marketing tools such as Google Ads, Meta Pixel or similar solutions are implemented in the future, the user will be informed through an updated Privacy Policy and appropriate consent banner settings.
20. Managing Cookie Consent
During the first visit to the store, the user is given the opportunity to manage their consent to the use of cookies via a consent banner.
The user may:
- accept all cookies,
- reject cookies other than essential cookies,
- individually select the scope of consent.
Consent may be changed or withdrawn at any time using the settings available in the store.
21. Managing Cookies Through Your Browser
Regardless of the settings available in the store, the user may also manage cookies through their web browser settings.
Restricting or blocking certain cookies may, however, cause some store functions to operate incorrectly.
Chapter VI – Data Security
22. Personal Data Security
The Controller applies appropriate technical and organisational measures to ensure the security of personal data and to protect it against loss, destruction, unauthorised access, disclosure or modification.
In particular, the online store:
- uses an encrypted SSL (HTTPS) connection,
- uses authentication mechanisms for users and administrators,
- regularly updates the store software and plugins used,
- restricts access to personal data to authorised persons only,
- takes measures to protect IT systems against unauthorised access.
Despite the use of appropriate safeguards, the Controller notes that use of the Internet involves the risk of events beyond its control. Users are therefore advised to observe basic security practices, in particular to protect passwords used to access their customer accounts.
Chapter VII – Final Provisions
23. Changes to the Privacy Policy
BMTG reserves the right to amend this Privacy and Cookie Policy, in particular in the event of:
- changes in applicable law,
- technological changes affecting the operation of the store,
- implementation of new services or functionalities,
- changes in the manner in which personal data is processed.
A new version of the Policy will be published on the online store website together with the date on which it enters into force.
24. Contact Regarding Personal Data Protection
For all matters concerning the processing of personal data, please contact the Controller:
Marek Gelbert “BMTG”
GÄ…sawy RzÄ…dowe 133F
26-502 JastrzÄ…b
Poland
E-mail:
The Controller will respond without undue delay, in accordance with applicable law.
25. Language Versions
This Privacy and Cookie Policy is available in Polish and English.
In the event of any discrepancies in interpretation between the language versions, the Polish version shall prevail, unless mandatory provisions of applicable law provide otherwise.
26. Effective Date
This Privacy and Cookie Policy is effective from the date of its publication in the online store.
đź“„ Download Privacy and Cookie Policy (PDF)