I. General provisions

  1. This Privacy Policy determines the method of collecting, processing and storing personal data necessary to provide electronic services via the website in the domain https://www.krosno.com (hereinafter: the Website).
  2. The Controller of the Users’ personal data is KROSNO GLASS S.A. with its registered office in Krosno, ul. Tysiąclecia 13, 38-400 Krosno (hereinafter: the Controller).
  3. Personal data are processed in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: the GDPR).
  4. The data collected by the Controller will be:
    • processed in accordance with the law,
    • processed for clearly specified purposes and not further processed in a manner that is incompatible with those purposes,
    • factually correct and adequate in relation to the purposes for which they are processed,
    • stored no longer than it is necessary to achieve the purpose of processing.


II. Purpose and legal basis for data processing

  1. The Controller processes personal data necessary for the provision and development of the offered services available via the Website and its individual functionalities.
  2. Personal data will be processed for the following purposes:
    a) account registration, verification of the User’s identity and performance of the contract for the provision of electronic services, including in particular by providing the possibility of using the User’s account – based on the acceptance of the terms of the Regulations (Article 6 (1)(b) of the GDPR);
    b) communication with the User in order to provide him/her with necessary information and to build positive and reliable relationship with him/her, which constitutes the legitimate interest of the Controller (Article 6 (1)(f) of the GDPR);
    c) promoting by the Controller its own products and/or services and those of its Partners by sending marketing information electronically (newsletter), provided that the User has agreed to receive such notifications by e-mail (Article 6(1)(a) of the GDPR);
    d) granting access to information about news in the industry directly related to the Controller’s activity, consisting in conducting verification of Users’ activity and their preferences for the optimization of services and products and the functionalities of the Website (Article 6(1)(f) of the GDPR);
    e) possible determination, pursuit of claims or defence against them on the basis of the Controller’s legitimate interest in protecting its rights (Article 6(1)(f) of the GDPR);
    f) transfer of the User’s personal data to Twisto Polska Sp. z o.o. in connection with the possibility of proposing payment for the purchased goods or services by Twisto Polska Sp. z o.o. under the contract of mandate including the “Buy with Twisto” purchase formula and making this purchase formula available through the Online Shop and for the purpose of verification by Twisto Polska Sp. z o.o. of the proper performance of such mandate contracts (Article 6(1)(f) of the GDPR).
  3. In each of the above-mentioned cases (paragraph 2), the provision of data is voluntary, but necessary to conclude a contract or use other functionalities of the Website.

III. The period of personal data processing

  1. Personal data will be processed for the period in which the person remains an active User of the Website (has a User account), and after that time for the period necessary to comply with the law, pursue or defend against any claims, but not longer than 3 years from the date of termination of the contract for the provision of electronic services.
  2. Data processed on the basis of consent will be processed until the consent is withdrawn, with the proviso that the withdrawal of this consent does not affect the compliance of data processing performed before this withdrawal.

IV. Information on the processing

  1. Personal data may be transferred to the following recipients or categories of recipients:
    a) carriers/ freight forwarders – in the case of a User who uses the online shop on the Website with the method of product delivery by post or courier, the Controller provides the User’s collected personal data to the selected carrier, freight forwarder or intermediary carrying out shipments at the request of the Controller to the extent necessary to complete the delivery of the User’s product;
    b) entities handling electronic or credit card payments – in the case of a User who uses the online shop on the Website with the method of electronic or credit card payments, the Controller provides the User’s collected personal data to the selected entity handling the abovementioned payments on the Website at the request of the Controller to the extent necessary to handle payments made by the User;
    c) opinion poll system providers – in the case of a User who agreed to express an opinion on the purchase made, the Controller provides the User’s collected personal data to the selected entity providing the opinion poll system at the request of the Controller to the extent necessary for the User to express an opinion using the opinion poll system;
    d) service providers supplying the Controller with technical, IT and organizational solutions, enabling the Controller to run its business (in particular, providers of computer software for running the Online Shop, e-mail and hosting providers, and providers of business management and technical assistance software to the Controller) – the Controller provides the User’s collected personal data to a selected provider acting on its behalf only in the case and to the extent necessary to achieve a given purpose of data processing in compliance with this privacy policy;
    e) providers of accounting, legal and advisory services providing the Controller with accounting, legal or advisory support (in particular an accounting office, a law firm or a debt collection company) – the Controller provides the User’s collected personal data to a selected provider acting on its behalf only in the case and to the extent necessary to achieve a given purpose of data processing in compliance with this privacy policy;
    f) in connection with the processing of your data for the purposes set out in paragraph 2 sec. 2 (f) – Twisto Polska sp. z o.o.;
  2. The User’s data will be processed in an automated manner, including in the form of profiling. Automated decision-making will take place on an automated basis, the consequence of such processing will be electronic methods of presenting advertising content or content in the newsletter without human intervention. Profiling will consist in analysing the purchases of specific goods made by the User and, on this basis, adjusting the range of goods presented to the User by the shop. The User has the right not to be subject to profiling, including in particular the right to object.

V. Rights of data subjects

  1. The Website Users have the right to:
    a) access the content of their data;
    b) rectify their data;
    c) delete their data;
    d) restrict data processing;
    e) data portability;
    f) object to processing based on the legitimate interest of the Controller;
    g) withdraw consent at any time without affecting the lawfulness of the processing which was carried out on the basis of consent given before its withdrawal.
  2. The Users have the right to lodge a complaint with the President of the Office for Personal Data Protection in a situation where they considers that the processing violates their rights and freedoms.

VI. Final Provisions

  1. The Controller reserves the right to amend this Privacy Policy and at the same time ensures that the Users’ rights under this document will not be restricted.
  2. The User will be informed about any changes to the Privacy Policy through a message available on the Website.
  3. In matters not covered by this privacy policy, the provisions of the Civil Code and the relevant laws of Poland, as well as of the European Union, in particular the GDPR (Regulation of the European Parliament and of the Council (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC) shall apply.