PRIVACY POLICY / GDPR
The purpose of this Privacy Policy is to explain the principles on which Velumed sp. z o.o. with its registered office in Tychy (43-100), at ul. Strefowa 22, KRS: 0000804343, NIP: 6452562449, REGON: 384392407, collects, uses and protects the personal data of Website users, as well as to present the rights they have in connection with the processing of their personal data by the Company.
Personal data are processed in accordance with applicable law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: "GDPR").
I. DATA CONTROLLER
- The controller of Users' personal data is Velumed Sp. z o.o. with its registered office in Tychy (43-100), at ul. Strefowa 22, KRS: 0000804343, NIP: 6452562449, REGON: 384392407 (hereinafter: "Controller").
- The Controller selects and applies appropriate technical and organisational measures to protect processed data with due care and proportionate to the risk, including securing data against disclosure to unauthorised persons, as well as other cases of their disclosure or loss, and against destruction or unauthorised modification of the data, as well as against their processing in violation of applicable law.
- The Controller exercises constant control over the data processing process and limits access to data to the greatest possible extent, granting appropriate authorisations only when necessary.
- Personal data may be transferred to the Controller's legal successors.
II. CONTACT WITH THE DATA CONTROLLER
- For matters concerning personal data, the exercise of rights under the GDPR and reports concerning the processing of personal data, please contact the Controller at:
Velumed sp. z o.o.
ul. Strefowa 22, 43-100 Tychy
e-mail: rodo@velumed.eu
tel. +48 512 112 663 - The Controller has not appointed a Data Protection Officer. For matters concerning the processing of personal data, please contact the Controller directly.
III. SCOPE OF DATA PROCESSED
- The Controller collects and processes ordinary data concerning natural persons, in particular:
- identification data (first and last name),
- contact data (e-mail, phone number),
- address data,
- data concerning the entity on whose behalf the user contacts the Controller,
- data contained in correspondence conducted with the Controller, regardless of the form (contact form, e-mail, traditional correspondence or telephone contact),
- technical data related to the use of the website, including IP address, information about the end device, web browser and cookies.
- The Controller collects only necessary data.
IV. PURPOSE AND LEGAL BASIS FOR PROCESSING PERSONAL DATA
- The Controller processes personal data for the following purposes:
- responding to enquiries submitted via the contact form, e-mail, traditional correspondence or telephone contact – on the basis of Art. 6(1)(f) GDPR,
- taking steps prior to entering into a contract and performing the concluded contract – on the basis of Art. 6(1)(b) GDPR,
- fulfilling obligations arising from applicable law, in particular tax, accounting and personal data protection regulations – on the basis of Art. 6(1)(c) GDPR,
- establishing, pursuing or defending claims – on the basis of Art. 6(1)(f) GDPR,
- sending commercial information concerning the Controller's services – solely upon obtaining the separate consent of the data subject, on the basis of Art. 6(1)(a) GDPR.
- The provision of personal data by the User is voluntary, but is required for the fulfilment of the processing purposes described above. Failure to provide personal data will result in the inability to conclude and perform the contract, the inability to receive responses to enquiries submitted via the contact form, e-mail, traditional mail and telephone contact, as well as the inability to receive commercial information.
V. RIGHTS OF DATA SUBJECTS
- Users have the right to:
- where the processing is based on consent – withdraw consent to the processing of personal data at any time, whereby withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal (Art. 7(3) GDPR),
- access their personal data (Art. 15(1) GDPR),
- receive a copy of their personal data (Art. 15(3) GDPR),
- rectify or update their personal data (Art. 16 GDPR),
- erasure of personal data – if the User considers that there are no grounds for the Controller to process their data, they may request the Controller to erase it, except in situations where the obligation to process personal data arises from a legal provision or the processing of data is necessary for the establishment, pursuit or defence of claims (Art. 17 GDPR),
- restriction of the processing of personal data (Art. 18 GDPR),
- portability of their personal data, i.e. to receive from the Controller information about the personal data being processed, in a structured, commonly used, machine-readable format, solely to the extent that personal data are processed on the basis of a contract or the User's consent and are processed by automated means (Art. 20 GDPR),
- lodge a complaint with the President of the Personal Data Protection Office, where the User considers that the processing of their personal data, or the data of other persons by the Controller, violates the provisions of the GDPR.
- Where the processing of personal data is based on the Controller's legitimate interest, the right to object to the processing of personal data is available (Art. 21 GDPR).
- To exercise the rights available, please contact the Controller at e-mail: rodo@velumed.eu, by phone at +48 512 112 663 or by post to the Controller's registered office address.
VI. WITHDRAWAL OF CONSENT
- The User's consent may be withdrawn at any time. Consent may be withdrawn by contacting the Controller.
- Withdrawal of consent:
- does not affect the lawfulness of prior processing,
- results in the cessation of processing of data for marketing purposes for which consent was previously given,
- results in the deletion of data from marketing databases.
VII. SOURCE OF DATA
Data are obtained directly from the person whose data are concerned, in particular via the contact form, e-mail, traditional mail, telephone contact or in connection with ongoing cooperation.
VIII. DATA RETENTION PERIOD
- Users' personal data may be retained for the period necessary to fulfil the purpose for which they were collected.
- In particular, data are retained:
- for the period necessary to conduct correspondence and carry out cooperation,
- until consent is withdrawn,
- for the period required by law (e.g. tax, accounting),
- for the time necessary to pursue claims or defend against claims – as a rule from 2 to 6 years,
- in the case of ongoing proceedings – until the proceedings become final and binding.
- After the indicated periods have elapsed, the data will be deleted.
- In some cases, the retention period may be counted until the end of the calendar year in which the limitation period for claims expires.
IX. RECIPIENTS OF DATA
- Users' data will be processed by authorised employees and associates of the Controller. Recipients of Users' data may include entities that are subcontractors of services with whom the Controller has concluded service agreements, external IT service providers and external accounting and bookkeeping service providers on the basis of a data processing agreement. Data processing entities act exclusively in accordance with the Controller's instructions. Furthermore, data may be disclosed to public authorities and entities performing public tasks or acting on behalf of public authorities, to the extent and for the purposes arising from applicable law.
- The Controller does not transfer e-mail addresses, phone numbers and other contact details of Users to marketing partners without obtaining the User's separate, explicit consent to such disclosure of personal data.
- Consent to receive marketing information from partners does not automatically mean the transfer of contact details to partners.
X. TRANSFER OF DATA OUTSIDE THE EEA
- As a rule, personal data are processed within the European Economic Area (EEA).
- The Controller may use the services of providers of IT, analytical or e-mail tools whose servers or technical infrastructure are located outside the EEA, in particular in the United States of America.
- Where data are transferred outside the EEA, the Controller ensures an adequate level of protection of personal data as required by the GDPR, in particular by applying standard contractual clauses or other mechanisms provided for by law.
- The data subject may obtain additional information regarding the safeguards applied by contacting the Controller.
- Where there is no need to use the services of entities based outside the EEA, personal data are not transferred outside the EEA.
XI. COOKIES
- Cookies are IT data, in particular text files, which are stored on the User's end device and are used to browse the website.
- The Controller uses cookies necessary for the proper functioning of the website.
- With the User's consent, analytical, functional, marketing and other cookies serving to improve the quality of services provided and to analyse the manner of using the website may also be used.
- Cookies are used in particular for the purpose of:
- ensuring the proper functioning of the website,
- adapting the content of the website to the User's preferences,
- conducting analyses and statistics on the use of the website,
- ensuring the security of using the website.
- During the first visit to the website, the User is informed about the use of cookies by means of an appropriate message and has the option to manage their preferences regarding the use of cookies.
- The User may at any time change the settings regarding cookies via their web browser settings or the consent management tool available on the website.
- Limiting the use of cookies may affect some functionalities of the website.
XII. CHANGES TO THE PRIVACY POLICY
The Controller reserves the right to amend the Privacy Policy if required by applicable law, technological changes or changes relating to the functioning of the website.
The current version of the Privacy Policy is published on the Controller's website.
Last modified: 11 June 2026