Privacy Policy
1. Data Controller
The data controller is Kopalnie Kruszyw Naturalnych spółka z ograniczoną odpowiedzialnością, with its registered office at ul. Rolna 195, 02-729 Warszawa, entered in the National Court Register under KRS no. 0000577099, NIP 9482604645, REGON 36258731200000, with register files maintained by Sąd Rejonowy Lublin-Wschód w Lublinie z siedzibą w Świdniku, VI Wydział Gospodarczy Krajowego Rejestru Sądowego, and share capital of 5 000,00 PLN. Contact: radka@kknkruszywa.pl, phone +48 530 315 961.
2. Scope and purpose of processing
We process data shared during direct contact by phone, email, or WhatsApp, as well as technical data related to website operation, security, and cookie settings, including:
- name or company name,
- email address, phone number, or identifier used in the selected contact channel,
- message content and any product, quantity, delivery, or other inquiry details you provide,
- technical and performance events, if you consent to optional analytics cookies.
The purpose is to respond to contact requests, handle commercial arrangements, maintain website security and reliability, and, if consent is given, analyze website performance and usage.
3. Legal basis
For contact related to an offer or cooperation, the legal basis is Article 6(1)(b) GDPR (steps taken prior to entering into a contract). For optional analytics cookies and related telemetry events, the legal basis is Article 6(1)(a) GDPR (consent).
4. Data recipients
Data may be shared with providers supporting website hosting, email and technical infrastructure, and, if consent is given, optional analytics mechanisms, only to the extent necessary for service delivery.
5. Retention period
- records of commercial contact and inquiries handled in internal systems: up to 365 days,
- synthetic monitoring probes for contact handling: up to 180 days,
- telemetry events: up to 180 days,
- failed notification queue entries: up to 30 days.
Retention is enforced automatically by backend maintenance jobs.
6. Your rights
You have the right to access, rectify, erase, restrict processing, object and withdraw consent.
8. Security controls
We apply technical and organizational safeguards including encryption at rest, pseudonymization of client metadata (IP/UA hashing), restricted operational API access, and no-store API response headers.