Data protection
The security and protection of personal data are of particular importance to us. In this section, you will find information regarding the principles governing the processing of personal data and the data protection measures implemented by BODEX in accordance with applicable legislation.
Information notice on the processing of personal data
Information clause regarding the processing of personal data
Pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR), we hereby inform you that:
- The controller of your personal data is BODEX Sp. z ograniczoną odpowiedzialnością, Spółka Komandytowa, 53-149 Wrocław, ul. Racławicka 13, Registry Court: District Court for Wrocław-Fabryczna in Wrocław, VI Commercial Division of the National Court Register, KRS No. 0000287275, Tax Identification Number (NIP) 8992615274, (hereinafter referred to as the "Controller").
- Your personal data are processed for the following purposes:
- execution of contracts concluded with the Controller,
- fulfilment of the Controller's legal obligations (in particular: issuing and storing invoices/sales documents and other accounting documents, processing complaints),
- establishing, defending, and pursuing claims,
- verifying payment credibility.
- The legal basis for the processing of your personal data is:
- within the scope of the purpose indicated in point 2.1. – performance of a contract to which the data subject is a party, or taking action at the request of the data subject before entering into a contract – Article 6 paragraph 1 point b) of the GDPR,
- within the scope of the purpose indicated in point 2.2. – compliance with a legal obligation to which the Controller is subject – Article 6 paragraph 1 point c) of the GDPR,
- within the scope of the purpose indicated in point 2.3. – legitimate interests pursued by the Controller, consisting in conducting business activities and expanding the market for the offered goods – Article 6 paragraph 1 point f) of the GDPR. Article 6, paragraph 1, point f) of the GDPR,
- within the scope of the purpose indicated in point 2.4 – the legitimate interest pursued by the Controller, consisting in conducting business activities and expanding the market for the offered goods (Article 6, paragraph 1, point f) of the GDPR).
- Your personal data will be stored for the period necessary to perform the Controller's tasks and comply with the archiving obligations arising from legal provisions, including accounting regulations. In the event of claims, your personal data will be processed until the statute of limitations expires, as defined by the Civil Code. After the aforementioned periods, your data will be deleted or anonymized.
- The recipients of your personal data may be/will be: postal companies, courier/transport companies, companies providing IT support to the Controller, the Controller's business partners, and companies providing consulting services.
- The categories of recipients to whom your personal data have been or will be disclosed include:
- authorized employees of the Controller,
- entities conducting postal or courier activities,
- business partners,
- banks,
- state authorities or other entities authorized under law,
- entities operating our IT systems.
- You have the right to:
- access your personal data,
- correct your personal data,
- delete your personal data,
- restrict the processing of your personal data,
- transfer your personal data to another controller,
- object to the processing of your personal data.
- Providing your personal data is voluntary, but necessary for the performance of the contract. You are obligated to provide it, and failure to provide your personal data will result in the inability to conclude or perform the contract.
- Your data will not be subject to automated decision-making (profiling).