Privacy Policy & Cookie Policy
§1 General Provisions
This document defines the Privacy Policy of the CO.BRICK service operating at https://cobrick.com/, run by CO.BRICK spółka z ograniczoną odpowiedzialnością with its registered office in Gliwice (44-100), Kaczyniec 9, registered in the entrepreneurs' register kept by the District Court in Gliwice, 10th Commercial Division of the National Court Register under KRS no. 0000546609, NIP: 6312656512, REGON: 360916970, share capital: PLN 4,486,250.00. It includes, in particular, regulations on the protection of personal data and the security of other data submitted to the Service by the User.
This Privacy Policy constitutes an integral appendix to the Terms of Service of the above-mentioned website.
§2 Definitions
Terms used in this document have the following meaning:
- Personal Data Controller (also referred to as the Controller) – CO.BRICK spółka z ograniczoną odpowiedzialnością with its registered office in Gliwice (44-100), Kaczyniec 9, registered in the entrepreneurs' register kept by the District Court in Gliwice, 10th Commercial Division of the National Court Register under KRS no. 0000546609, NIP: 6312656512, REGON: 360916970, share capital: PLN 4,486,250.00.
- Service – the website at https://cobrick.com/ and all its subpages.
- User – a natural person who uses the Service and provides personal data within it.
- Personal Data – information about an identified or identifiable natural person, identifiable by one or more specific factors determining their physical, physiological, genetic, mental, economic, cultural or social identity, including image, voice recording, contact details, location data, information contained in correspondence, information collected through recording equipment or other similar technology.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
- Terms of Service – the terms of service of the website.
§3 Personal Data Protection
- The Controller is the personal data controller within the meaning of the GDPR.
- The Controller collects and processes personal data in accordance with applicable laws, in particular the GDPR, and in line with the principles set out therein.
- The Controller informs about data processing at the time of collection. The Controller processes data within the scope, for the time and for the purposes specified each time in the content available beneath the forms used to collect personal data from the User.
- The Controller transfers Personal Data only to trusted subcontractors, i.e. providers responsible for the operation of IT systems, entities such as banks and payment operators, providers of accounting and legal services, marketing agencies (within the scope of marketing services), and other entities providing IT and software services.
- The Controller has the right to transfer selected User Personal Data to competent authorities and third parties if such necessity arises from applicable legal provisions and where these entities request such disclosure on an appropriate legal basis.
- The Controller ensures the security and confidentiality of the processed personal data and gives the User access to information about data processing. Should a Personal Data breach occur despite the security measures in place (e.g. a data "leak" or loss) and such breach could result in a high risk to the User's rights or freedoms, the Controller will inform the User of such event in accordance with applicable regulations.
- The User may contact the Controller. The contact details are as follows:
- Postal address: Kaczyniec 9, 44-100 Gliwice, Poland.
- Email address: office@cobrick.com.
§4 Personal Data Security
- The Controller uses all available technical and organisational measures to ensure the security of the User's personal data and protect it against accidental or intentional destruction, accidental loss, modification, unauthorised disclosure of, or access to it. Users' personal data is stored and processed on highly secured servers, with appropriate security measures meeting the requirements of Polish law.
- The entrusted data is stored on top-class equipment and servers in appropriately secured data centres, accessible only to authorised persons.
- The Controller carries out activities related to the processing of personal data in compliance with all legal and technical requirements imposed by personal data protection regulations. The Controller continuously analyses the risks associated with its processing of personal data and ensures that data is accessible only to authorised persons and only to the extent necessary to perform their duties.
- The Controller takes all necessary actions to ensure that its subcontractors and other cooperating entities also guarantee the application of appropriate security measures whenever they process Personal Data on the Controller's behalf.
- The Controller undertakes to keep backup copies containing the User's personal data.
§5 User Rights
The User has the following rights:
- the right to be informed about the processing of Personal Data;
- the right to obtain a copy of the Personal Data processed by the Controller;
- the right to rectification of Personal Data;
- the right to erasure of Personal Data (on this basis the User may request deletion of data the processing of which is no longer necessary to fulfil any of the purposes for which it was collected);
- the right to restriction of processing of Personal Data;
- the right to data portability of Personal Data;
- the right to object to the processing of Personal Data for marketing purposes (the User may at any time object to the processing of Personal Data for marketing purposes without having to justify such objection);
- the right to object to other purposes of data processing (the User may at any time – on grounds relating to their particular situation – object to the processing of Personal Data carried out on the basis of the Controller's legitimate interest; such objection requires justification);
- the right to withdraw consent if Personal Data is processed on the basis of consent (withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal);
- the right to lodge a complaint with the supervisory authority responsible for personal data protection competent for the User's habitual residence, place of work or place of the alleged infringement. In Poland, the supervisory authority is the President of the Personal Data Protection Office (PUODO).
- The Controller may refuse to delete the User's personal data if its retention is required due to an obligation imposed on the Controller by law.
- The User has the right to submit a request regarding the exercise of the rights listed above by post or electronically (email). The Controller's contact details are indicated in §3.7.
- If, on the basis of the request referred to in clause 3, the Controller is unable to identify the natural person concerned, the Controller will request additional information from the requester. Failure to provide additional information will result in refusal to fulfil the request.
- The Controller responds to a request within one month of its receipt. Should it be necessary to extend this period, the Controller will inform the requester of the reasons and the expected response time.
§6 Basis, Purpose and Retention Period of Personal Data
Personal data is processed for the following purposes and on the following bases:
Use of the Service
Personal data of all persons using the Service (including IP address or other identifiers and information collected via cookies or similar technologies) is processed by the Controller for the purpose of:
- providing services by electronic means (legal basis: necessity of processing for the performance of a contract – Art. 6(1)(b) GDPR);
- analytical, statistical and User-preference research purposes (legal basis: consent – Art. 6(1)(a) GDPR);
- establishing and pursuing claims or defending against claims (legal basis: legitimate interest of the Controller – Art. 6(1)(f) GDPR, namely the protection of the Controller's rights).
Newsletter
Users who have notified the Controller of such intention receive emails with promotional content. Subscribing to the Newsletter requires providing the Controller with the User's Personal Data. Providing the data is not mandatory, but refusal to provide it makes it impossible to provide the Newsletter service. The Personal Data indicated by the User is processed by the Controller for the purpose of:
- providing services by electronic means (legal basis: necessity of processing for the performance of a contract – Art. 6(1)(b) GDPR – with respect to the data necessary to send the Newsletter; with respect to optional data, the legal basis is consent – Art. 6(1)(a) GDPR);
- analytical and statistical purposes (legal basis: consent – Art. 6(1)(a) GDPR);
- establishing and pursuing claims or defending against claims (legal basis: legitimate interest of the Controller – Art. 6(1)(f) GDPR, namely the protection of the Controller's rights);
- the Controller's marketing purposes – sending marketing content via the Newsletter (legal basis: legitimate interest of the Controller – Art. 6(1)(f) GDPR – grounded in the User's consent to the Newsletter service).
Marketing
The Controller processes Users' Personal Data in order to carry out marketing activities, which may consist in particular of displaying marketing content matching the User's interests or sending commercial information by electronic means for purposes related to the direct marketing of goods and services. In this case, the User's Personal Data is processed by the Controller on the basis of the User's consent (Art. 6(1)(a) GDPR), which may be withdrawn. The Controller's marketing purposes may be pursued through profiling, consisting of the automated processing of Personal Data and its evaluation to analyse User behaviour and create future predictions, allowing the User to be shown content matching their individual preferences and interests.
Contact form, traditional and electronic correspondence (email)
The User may send messages to the Controller using email and the Controller's contact details available in the Service, the Terms of Service or this Privacy Policy, as well as via the contact form available in the Service. The Controller uses the personal data contained in such correspondence solely to communicate and handle the matter to which the correspondence relates. The basis for processing is the legitimate interest of the Controller – Art. 6(1)(f) GDPR – consisting in maintaining correspondence addressed to it in connection with its business activity, and in the case of contact related to the services provided or a contract – the necessity of processing for the performance of the contract – Art. 6(1)(b) GDPR.
Telephone contact
The User may contact the Controller by telephone in matters related to the services provided or a contract concluded, as well as in other matters. If telephone contact is initiated in matters not related to a concluded contract or service, the Controller may request Personal Data only when this is necessary to handle the matter. The legal basis for processing is the legitimate interest of the Controller – Art. 6(1)(f) GDPR – consisting in the need to resolve the reported matter related to its business activity, and in the case of contact related to services or a contract – the necessity of processing for the performance of the contract – Art. 6(1)(b) GDPR.
Social media profiles
The Controller maintains profiles on social media (including Facebook). The Controller processes Personal Data left by persons interacting with these profiles, e.g. comments or online identifiers. The Controller uses such data to effectively run its profiles, enable activity on these profiles, and for analytical and statistical purposes. The legal basis for processing is the legitimate interest of the Controller – Art. 6(1)(f) GDPR – consisting in promoting its activity and the services provided, and where applicable for asserting claims or defending against claims of third parties. The above does not apply to the processing of personal data by the social media platforms themselves. To learn about how social media platforms process data, please refer to their personal data processing policies.
- The data processing period depends on the service provided, the purpose and the basis of processing. As a rule, data is processed for the duration of the service or order fulfilment. Where the basis of processing is consent, data is processed until consent is effectively withdrawn. Where the basis of processing is the Controller's legitimate interest, data is processed until an effective objection is filed.
- The processing period referred to in clause 2 may be extended where data processing is necessary to establish, pursue or defend any claims. After this period, Personal Data may be processed only insofar as required by applicable law.
- Once the processing period has expired, Personal Data is deleted or irreversibly anonymised.
§7 Cookie Policy
- The Controller uses cookies. Cookies are small text files sent (saved) by the Service to the User's terminal device (e.g. computer, smartphone).
- The Controller uses cookies to provide services by electronic means, improve and enhance them, as well as for analytical and statistical purposes and to adjust the Service to the needs of its Users. By using cookies, the Controller personalises content and ads. Information about how the User uses the Service is shared with trusted social, advertising and analytics partners to provide the highest quality of service in the operation of the Service, analytics, matching and personalisation.
- Two types of cookies are used in the Service: "session cookies" and "persistent cookies". "Session" cookies are temporary files stored on the User's terminal device until logout, leaving the website or closing the software (web browser). "Persistent" cookies are stored on the User's terminal device for the period specified in the cookie parameters or until they are removed by the User.
- The Service uses the following types of cookies:
- strictly necessary – enable the use of the services and functionalities available within the Service;
- functional – enable remembering and adjusting the User's choices in the Service, e.g. language preferences, font size, appearance of the Service, etc.;
- analytical – allow the collection of information such as the number of visits and traffic sources in the Service. This data is used to determine which pages are visited most often and to compile statistics on traffic in the Service. This data is used by the Controller to improve the performance of the Service. The collected data is processed in anonymised form. This type includes Google Analytics cookies;
- marketing/advertising – allow the matching of displayed ads to the User's interests. The advertising content referred to may be displayed both on our website and outside it;
- unclassified – this group includes cookies that could not be classified into the previous categories.
- Marketing/advertising, functional, analytical and unclassified cookies may be installed by the Controller and its trusted partners via the Service. The Controller's trusted partners include:
- Google LLC – Google Analytics – privacy policy: https://policies.google.com/privacy.
- The legal basis for data processing in connection with the use of strictly necessary cookies is the necessity of processing Personal Data for the performance of a contract (Art. 6(1)(b) GDPR). For other cookies, the legal basis is the legitimate interest of the Controller or the User's consent (Art. 6(1)(a) and (f) GDPR). To use functional, analytical, marketing/advertising and unclassified cookies, the Controller must obtain the User's consent.
- The consent referred to in clause 6 is granted via the relevant form displayed during the first visit to the Service. Consent granted may be withdrawn or adjusted at any time. To change or withdraw consent, please contact the Controller.
- The User may change cookie settings from the level of the web browser.
- Changing cookie settings and similar technologies may affect the operation of the Service and the services it provides.
§8 Logs
- In line with the practice of most websites, the Controller stores HTTP requests directed to its server (server logs). Accordingly, the Controller stores the following information:
- the IP addresses from which users browse the informational content of our service;
- the time of arrival of the request;
- the time the response was sent;
- the name of the client station – identification carried out via the HTTP protocol;
- information about errors that occurred during HTTP transactions;
- the URL of the page previously visited by the user (referer link);
- information about the user's browser.
- The collected logs are stored indefinitely as auxiliary material used to administer the Service. The information they contain is not disclosed to anyone other than persons authorised to administer the Service. Statistics that assist in administering the Service may be generated based on the log files. Aggregated summaries in the form of such statistics do not contain any features identifying visitors to the Service.
- The information contained in the logs is processed by the Controller for technical and administrative purposes, for ensuring the security of the IT system and managing it, as well as for analytical and statistical purposes – in this respect, the legal basis for processing Personal Data is the legitimate interest of the Controller (Art. 6(1)(f) GDPR).
§9 Transfers Outside the EEA
In connection with the Controller's use of tools supporting its day-to-day activities provided, for example, by Google, Users' Personal Data may be transferred to a country outside the European Economic Area (EEA), in particular to the United States of America (USA) or another country in which the cooperating entity maintains tools used to process Personal Data in cooperation with the Controller. The Controller transfers Personal Data outside the EEA only when necessary, ensuring an adequate level of protection, primarily through the use of standard contractual clauses issued by the European Commission.
§10 Final Provisions
- This Privacy Policy is subject to updates in connection with the ongoing analysis of the technical and legal conditions related to the processing of personal data.
- This Privacy Policy is effective as of January 1, 2026.