Privacy policy
PRIVACY POLICY
Rules for the Processing of Personal Data and Use of Cookies
Updated: 19 August 2026
1. Data Controller
The controller of your personal data is MONTRESOR sp. z o.o., ul. Mokotowska 71/101, 00-530 Warsaw, Poland, KRS 0001137877, NIP 7011232568, e-mail: info@montresor.pl, tel. +48 730 071 271 (the “Controller”). For privacy-related matters, please contact us at info@montresor.pl.
2. Scope of Data
Depending on how you use the Website, we may process: your first and last name, contact details, delivery address, billing details, tax identification number (NIP), order and payment information, purchase and complaint history, account details, the content of correspondence and forms, newsletter preferences, device and browser information, IP address, online identifiers, logs and information stored in cookies. We do not receive your full payment card details where these are processed by a payment service provider.
3. Purposes, Legal Bases and Retention Periods
Orders and Contracts
We process personal data in order to enter into and perform a contract, process payments and deliveries, communicate with you, and handle returns and complaints, on the basis of Article 6(1)(b) of the GDPR. We retain the data for the duration of the transaction and subsequently until the applicable limitation periods for claims have expired.
Accounting and Legal Obligations
Tax and accounting documents are processed on the basis of Article 6(1)(c) of the GDPR for the period required under applicable tax and accounting regulations, usually 5 years calculated in accordance with the relevant provisions of law.
Contact and Forms
Data submitted through enquiries is processed in order to respond to your request and to take steps at your request prior to entering into a contract (Article 6(1)(b) of the GDPR), or on the basis of our legitimate interest in handling correspondence (Article 6(1)(f) of the GDPR). We retain such data until the matter has been concluded and subsequently for the period necessary to establish, exercise or defend legal claims.
Customer Account
We process account data in order to provide the customer account service (Article 6(1)(b) of the GDPR) until the account is deleted, and subsequently to the extent necessary to establish, exercise or defend legal claims and comply with legal obligations.
Newsletter and Electronic Marketing
We send newsletters and electronic marketing communications on the basis of your voluntary consent (Article 6(1)(a) of the GDPR and the applicable provisions of the Polish Electronic Communications Law). You may withdraw your consent at any time. Information concerning consent is retained for the period necessary to demonstrate that consent was obtained and that any withdrawal or opt-out request has been respected.
Security, Internal Analytics and Legal Claims
We may process logs, event information, fraud-prevention data and statistics that do not require consent on the basis of the Controller’s legitimate interests (Article 6(1)(f) of the GDPR). The data is retained for a period appropriate to the relevant risk and purpose and, as a general rule, no longer than 12 months in the case of operational logs, unless an incident or legal claim justifies a longer retention period.
Analytics and Advertising Based on Cookies
Data collected through analytical, functional and marketing cookies is processed only after obtaining your consent (Article 6(1)(a) of the GDPR in conjunction with the Polish Electronic Communications Law). The retention period of individual cookies is indicated in the cookie settings panel.
4. Recipients of Personal Data
Personal data may be disclosed to entities supporting the Controller, including in particular providers of hosting and e-commerce platforms, payment service providers, banks, carriers and pickup-point operators, e-mail and newsletter providers, invoicing and accounting systems, IT support and security providers, analytics providers – where consent has been given – as well as law firms and public authorities where required by law. Each recipient receives only the data necessary to perform its role.
5. Transfers Outside the EEA
Some technology providers may process personal data outside the European Economic Area. In such cases, we use the safeguards required under the GDPR, in particular an adequacy decision issued by the European Commission, including the EU-U.S. Data Privacy Framework in relation to certified entities, or Standard Contractual Clauses together with additional safeguards where necessary. Information regarding the applicable transfer mechanism may be obtained by contacting info@montresor.pl.
6. Your Rights
You have the right to request access to your personal data, rectification, erasure, restriction of processing and data portability, as well as the right to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out before its withdrawal. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland.
7. Voluntary Provision of Data and Automated Decision-Making
Providing personal data is voluntary; however, data marked as required is necessary for the relevant purpose, for example to process an order or respond to an enquiry. We do not make decisions concerning customers that produce legal effects solely by automated means, unless, prior to implementing such a solution, we provide the information required by law and ensure the appropriate rights and safeguards.
8. Cookies and Similar Technologies
Cookies are small pieces of information stored on your device. The Website may use the following categories:
Necessary – enable the shopping cart, session management, security, storage of privacy settings and the basic operation of the Website. They cannot be disabled through the cookie settings panel because the Website may not function properly without them.
Preferences – remember selected settings and functionality. They are used with your consent where they are not strictly necessary.
Analytics – help us measure visits and understand how the Website is used. They are activated only after obtaining your consent.
Marketing – are used to measure campaigns, personalise advertising or link activity across different websites and services. They are activated only after obtaining your consent.
When you first visit the Website, you may accept all optional cookies, reject them just as easily, or manage your preferences individually. Failure to take any action does not constitute consent. You may change or withdraw your consent at any time using the permanent “Cookie Settings” link in the Website footer. Withdrawing consent is as easy as giving it.
The cookie settings panel should indicate the name of each cookie or technology, its provider, purpose, category and duration. You may also delete or block cookies through your browser settings, although doing so may limit certain Website functionalities.
9. Security and Changes to this Privacy Policy
We use technical and organisational measures appropriate to the level of risk, including encrypted connections, access controls, backups and regular updates. This Privacy Policy may be updated due to changes in law, technology or the services we provide. The date of the latest update will be indicated at the beginning of this Policy, and we will provide appropriate notice of material changes affecting active services.