PRIVACY POLICY

The Privacy Policy below sets forth the rules for storing and accessing data on the Devices of Users who use the Website for the purpose of providing electronic services by the Administrator, as well as the rules for collecting and processing Users’ personal data, which they have provided personally and voluntarily through the tools available on the Website.

The Privacy Policy below is an integral part of the Website Terms of Use, which set forth the rules, rights, and obligations of Users of the Website.

§1 Definitions

  • Website – the “Mushrooms Borowczyk” website, available at https://www.mushroomsborowczyk.com/wp-content/uploads/2025/01/mushrooms_borowczyk_kuchnia_0028.jpg
  • External services – websites of partners, service providers, or service recipients that collaborate with the Administrator
  • Website Administrator / Data Controller – The Website Administrator and Data Controller (hereinafter referred to as the “Administrator”) is the company “U BORÓWEK,” operating at the following address: 63-830 Pępowo, ul. Szkolna 26, with tax identification number (NIP): 618 138 79 38, providing services electronically via the Website
  • User – a natural person to whom the Administrator provides services electronically through the Website.
  • Device – an electronic device, including its software, through which the User accesses the Website
  • Cookies – text data collected in the form of files stored on the User’s Device
  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
  • Personal data – means information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more specific factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of a natural person
  • Processing—means any operation or set of operations performed on personal data or sets of personal data, whether by automated or non-automated means, such as collection, recording, organization, structuring, storage, adapting or modifying, retrieving, consulting, using, disclosing by transmission, dissemination, or otherwise making available, aligning or combining, restricting, erasing, or destroying;
  • Restriction of processing – means marking stored personal data to restrict its future processing
  • Profiling—means any form of automated processing of personal data that involves the use of personal data to evaluate certain personal aspects of a natural person, in particular to analyze or predict aspects concerning that natural person’s work performance, their economic situation, health, personal preferences, interests, credibility, behavior, location, or movements
  • Consent – the consent of the data subject means a voluntary, specific, informed, and unambiguous expression of will by which the data subject, through a statement or a clear affirmative action, consents to the processing of their personal data
  • Personal Data Breach – means a security breach resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to personal data that is transmitted, stored, or otherwise processed
  • Pseudonymization—means processing personal data in such a way that it can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is stored separately and is subject to technical and organizational measures that prevent it from being attributed to an identified or identifiable natural person
  • Anonymization – Data anonymization is an irreversible data processing operation that destroys or overwrites “personal data,” thereby preventing the identification of, or the linking of, a given record to a specific user or natural person.

§2 Data Protection Officer

Pursuant to Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer.
For matters related to data processing, including the processing of personal data, please contact the Controller directly.

§3 Types of Cookies

  • First-party cookies – files stored on and retrieved from the User’s Device by the Website’s IT system
  • Third-party cookies – files placed on and read from the User’s Device by the information and communication systems of third-party websites. Scripts from third-party services that may place cookies on the User’s Device have been intentionally included on the Website through scripts and services made available and installed on the Website
  • Session cookies – files placed on and read from the User’s Device by the Website during a single session on that Device. Once the session ends, the files are deleted from the User’s Device.
  • Persistent cookies – files placed on and read from the User’s Device by the Website until they are manually deleted. These files are not automatically deleted at the end of the Device session unless the User’s Device is configured to delete cookies at the end of the Device session.

§4 Data Storage Security

  • Mechanisms for Storing and Reading Cookies – The mechanisms for storing, reading, and exchanging data between cookies stored on the User’s Device and the Website are carried out through the built-in mechanisms of web browsers and do not allow for the retrieval of other data from the User’s Device or data from other websites that the User has visited, including personal data or confidential information. The transfer of viruses, Trojan horses, and other worms to the User’s Device is also practically impossible.
  • First-party cookies – The cookies used by the Administrator are safe for Users’ Devices and do not contain scripts, content, or information that could compromise the security of personal data or the security of the Device the User is using.
  • Third-party cookies – The Administrator takes all possible measures to verify and select the website’s partners with a view to ensuring User security. The Administrator selects well-known, large partners with global public trust for collaboration. However, the Administrator does not have full control over the content of cookies originating from third-party partners. To the extent permitted by law, the Administrator is not liable for the security of cookies, their content, or their license-compliant use by scripts installed on the website that originate from third-party websites. A list of partners is provided later in this Privacy Policy.
  • Cookie Management
    • Users can change the settings for saving, deleting, and accessing data stored in cookies by any website at any time on their own
    • The User may delete any cookies stored to date at any time using the tools available on the User’s device through which the User accesses the Website’s services.
  • Risks on the User’s Part – The Administrator takes all possible technical measures to ensure the security of data stored in cookies. However, it should be noted that ensuring the security of this data depends on both parties, including the User’s actions. The Administrator assumes no liability for the interception of this data, impersonation of the User’s session, or the deletion of such data resulting from the User’s intentional or unintentional actions, viruses, Trojan horses, or other spyware with which the User’s Device may be or may have been infected. To protect themselves against these threats, Users should follow general internet safety guidelines.
  • Storage of Personal Data – The Controller ensures that it makes every effort to ensure that the personal data processed—which is voluntarily provided by Users—is secure, that access to it is restricted, and that it is used in accordance with its intended purpose and the purposes of processing. The Controller also ensures that it makes every effort to protect the data in its possession against loss by implementing appropriate physical and organizational security measures.

§5 Purposes for Which Cookies Are Used

  • Improving and Facilitating Access to the Website
  • Website Personalization for Users
  • Enabling Login to the Website
  • Marketing, Remarketing on Third-Party Websites
  • Advertising Services
  • Tracking statistics (users, number of visits, device types, internet connection, etc.)
  • Provision of Community Services
  • §6 Purposes of Personal Data Processing

    Personal data voluntarily provided by Users is processed for one of the following purposes:

    • Provision of electronic services:
      • Services related to the registration and maintenance of a User’s account on the Website and related features
    • Communication between the Administrator and Users regarding matters related to the Website and data protection
    • To safeguard the Controller’s legitimate interests

    User data collected anonymously and automatically is processed for one of the following purposes:

    • Statistics, Remarketing
    • Serving ads tailored to users' preferences
    • To safeguard the Controller’s legitimate interests

    §7 Cookies from Third-Party Websites

    The Website Administrator uses JavaScript scripts and web components from partners, who may place their own cookies on the User’s Device. Please note that in your browser settings, you can decide for yourself which cookies are allowed to be used by individual websites. Below is a list of partners or their services implemented on the Website that may place cookies:

    • Advertising services and affiliate networks: Google AdSense
    • Statistics tracking: Google Analytics
    • Other Services: Google Maps
    • Services provided by third parties are beyond the Administrator’s control. These third parties may change their terms of service, privacy policies, purposes of data processing, and methods of using cookies at any time.

      §8 Types of Data Collected

      The Website collects data about Users. Some of this data is collected automatically and anonymously, while other data consists of personal information voluntarily provided by Users when signing up for specific services offered by the Website.

      Anonymous data collected automatically:

      • IP Address
      • Browser type
      • Screen resolution
      • Approximate location
      • Subpages of the website that can be opened
      • Time spent on a specific subpage of the website
      • Type of operating system
      • Address of the previous subpage
      • Referring URL
      • Browser language
      • Internet connection speed
      • Internet service provider

      Data collected during registration:

      • First name / last name / nickname
      • Email address
      • IP address (collected automatically)

      §9 Access to Personal Data by Third Parties

      As a general rule, the only recipient of the personal data provided by Users is the Administrator. The data collected in connection with the services provided is not transferred or resold to third parties.

      Access to the data (most often under a Data Processing Agreement) may be granted to entities responsible for maintaining the infrastructure and services necessary to operate the website, namely:

      • Web hosting companies that provide hosting or related services to the Administrator
      • IT service and support companies that perform maintenance or are responsible for maintaining IT infrastructure
      • Companies that facilitate online payments for goods or services offered through the Website (when making a purchase on the Website)
      • Companies responsible for handling the Administrator’s accounting (in the case of purchase transactions made on the Website)

      Entrusting the Processing of Personal Data – Hosting, VPS, or Dedicated Server Services

      To operate the website, the administrator uses the services of an external hosting provider, VPS, or Dedicated Servers—ZENBOX. All data collected and processed on the website is stored and processed within the service provider’s infrastructure located within the European Union. The service provider’s staff may access the data as part of maintenance work. Access to this data is governed by an agreement between the Administrator and the Service Provider.

      Entrusting the Processing of Personal Data – Website Maintenance Services

      To operate the website, the Administrator uses the services of an external service provider—FHU Kaczmarek Grzegorz. The staff of this entity has access to data entered by users during registration and when editing their user accounts, and/or data related to the Newsletter service. Access to this data is governed by an agreement between the Administrator and the Service Provider.

      Data Processing for Online Payments

      When making an online payment, all payment-related data is provided directly by the User to the payment processor. Selected data necessary to process the transaction is then transmitted by that provider to the Administrator. The transfer of data is governed by an agreement between the Administrator and the Service Provider.

      Transfer of Personal Data – Accounting Services

      When a transaction is concluded, certain personal data of individuals or data of individuals conducting business activities is transferred to the entity providing accounting services to the Controller. The transfer of this data is governed by the Act … and the agreement concluded between the Controller and the Service Provider.

      §10 Methods of Processing Personal Data

      Personal data voluntarily provided by Users:

      • Personal data will not be transferred outside the European Union, unless it has been published as a result of the User’s individual actions (e.g., posting a comment or entry), which will make the data available to anyone visiting the website.
      • Personal data will not be used for automated decision-making (profiling).
      • Personal information will not be sold to third parties.

      Anonymous data (without personal information) collected automatically:

      • Anonymized data (without personal information) will be transferred outside the European Union.
      • Anonymous data (without personal information) may be used for automated decision-making (profiling).
        The profiling of anonymous data (without personal data) does not produce legal effects or similarly significantly affect the individual whose data is subject to automated decision-making.
      • Anonymous data (without personal information) will not be sold to third parties.

      §11 Legal Basis for the Processing of Personal Data

      The website collects and processes User data based on:

      • Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
        • Article 6(1)(a
          ): the data subject has given consent to the processing of his or her personal data for one or more specific purposes
        • Article 6(1)(b):
          Processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract
        • Article 6(1)(f
          ): Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party
      • Act of May 10, 2018, on the Protection of Personal Data (Journal of Laws 2018, Item 1000)
      • Act of July 16, 2004—Telecommunications Law (Journal of Laws 2004, No. 171, Item 1800)
      • Act of February 4, 1994, on Copyright and Related Rights (Journal of Laws 1994, No. 24, Item 83)

      §12 Retention Period for Personal Data

      Personal data voluntarily provided by Users:

      As a general rule, the personal data in question is stored solely for the duration of the Service provided by the Administrator through the Website. It is deleted or anonymized within 30 days of the termination of service provision (e.g., deletion of a registered user account, unsubscription from the newsletter, etc.).

      An exception applies in situations where it is necessary to safeguard the Controller’s legitimate interests in the further processing of such data. In such a situation, the Administrator will retain the specified data, from the time the User requests its deletion, for no longer than 3 years in the event of a violation or suspected violation of the website’s terms of service by the User

      §13 Users' Rights Regarding the Processing of Personal Data

      The website collects and processes User data based on:

      • Right of Access to Personal
        Data: Users have the right to access their personal data, which is granted upon request submitted to the Data Controller
      • Right to Rectify Personal
        Data: Users have the right to request that the Controller immediately rectify any personal data that is inaccurate and/or complete any personal data that is incomplete, upon request submitted to the Controller
      • Right to Erase Personal
        Data: Users have the right to request that the Controller immediately erase their personal data, which is carried out upon a request submitted to the Controller. In the case of user accounts, the deletion of data consists of anonymizing the data that allows the User to be identified. The Administrator reserves the right to suspend the processing of a request to delete data in order to protect the Administrator’s legitimate interests (e.g., if the User has violated the Terms of Service or if the data was obtained as a result of ongoing correspondence).
        In the case of the Newsletter service, the User may delete their personal data independently by using the link included in every email sent.
      • Right to Restrict the Processing of Personal
        Data Users have the right to restrict the processing of their personal data in the cases specified in Article 18 of the GDPR, including when they contest the accuracy of their personal data; this right is exercised by submitting a request to the Controller
      • Right to Data Portability:
        Users have the right to obtain from the Controller their personal data in a structured, commonly used, machine-readable format, upon request submitted to the Controller.
      • Right to Object to the Processing of Personal
        Data Users have the right to object to the processing of their personal data in the cases specified in Article 21 of the GDPR, which may be exercised by submitting a request to the Controller
      • Right to File a Complaint
        Users have the right to file a complaint with the supervisory authority responsible for the protection of personal data.

      §14 Contact Information for the Administrator

      You can contact the Administrator using one of the following methods

      • Mailing address – “U BORÓWEK,” 63-830 Pępowo, 26 Szkolna St.
      • Email address – info@mushroomsborowczyk.com
      • Phone number – +48 605 247 315
      • Contact form – available at: https://www.mushroomsborowczyk.com/en/contact-2/

      §15 Website Requirements

      • Restricting the storage of and access to cookies on the User's Device may cause certain features of the Website to function improperly.
      • The Administrator assumes no liability for any malfunctioning features of the Website if the User restricts the ability to save and read cookies in any way.

      §16 Changes to the Privacy Policy

      • The Administrator reserves the right to modify this Privacy Policy at any time without notifying Users regarding the use and processing of anonymous data or the use of cookies.
      • The Administrator reserves the right to modify this Privacy Policy at its discretion with regard to the processing of Personal Data, and will notify Users who have user accounts or are subscribed to the newsletter via email within 7 days of the changes taking effect. Continued use of the services constitutes acknowledgment and acceptance of the changes made to the Privacy Policy. If a User does not agree with the changes, they are required to delete their account from the Website or unsubscribe from the newsletter service.
      • Any changes made to the Privacy Policy will be posted on this page of the Website.
      • The amendments take effect upon their publication.
      Zaufaj naszemu doświadczeniu i ciesz się najwyższej jakości produktami.