REIMAHellCold
/

PRIVACY POLICY OF REIMA-POLSKA.PL

1. General Provisions

This Privacy Policy defines the rules for processing personal data and the use of cookies and similar technologies in connection with the use of the website available at:

https://reima-polska.pl/

This Policy has been prepared taking into account, in particular:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 ("GDPR");
  • Act of 10 May 2018 on the Protection of Personal Data;
  • Act of 12 July 2024 – Electronic Communications Law;
  • regulations regarding the provision of services by electronic means and marketing communication, to the extent applicable to the Controller's business activities.

The Controller applies appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

2. Personal Data Controller

The Controller of personal data processed in connection with the use of the Website is:

HellCold Sp. z o.o.
ul. Zofii Kossak 98
43-436 Górki Wielkie, Poland
KRS: 0001002959
VAT ID: PL5482672515
REGON: 363784210

E-mail address for contact regarding the Website and data protection:

kontakt@reima-polska.pl

Contact with the Controller is also possible by phone at:

+48 33 85 13 795

The contact details provided above should also be used to exercise the rights of data subjects.

If the Controller has appointed a Data Protection Officer (DPO), contact with the DPO is possible at the address provided by the Controller on the Website.

3. What Personal Data We May Process

Depending on how you use the Website, the Controller may process, in particular:

  • first and last name;
  • e-mail address;
  • phone number;
  • company name;
  • position or job function;
  • address or other data related to the location of service delivery;
  • content of the message sent to the Controller;
  • data provided in the contact form or request for quotation form;
  • data regarding ongoing correspondence;
  • technical information regarding the use of the Website, such as IP address, device identifiers, browser and operating system information;
  • information stored via cookies and similar technologies – to the extent such technologies are used.

The Controller does not require the provision of personal data that are not necessary to achieve a specific purpose.

4. Purposes and Legal Bases for Data Processing

Personal data may be processed for the following purposes:

4.1. Handling Inquiries and Contact

If a person contacts the Controller via a form, e-mail, telephone, or other available channels, their data may be processed to:

  • answer the inquiry;
  • conduct correspondence;
  • prepare an offer;
  • establish details of cooperation;
  • take steps at the request of the data subject prior to entering into a contract.

The legal basis for processing is Art. 6(1)(b) GDPR, if the contact aims to take steps prior to entering into a contract, or Art. 6(1)(f) GDPR – the legitimate interest of the Controller consisting in handling inquiries and communication with individuals contacting the Controller.

4.2. Conclusion and Execution of a Contract

If a contract is concluded as a result of contact, data will be processed for the purpose of its conclusion, execution, service, and settlement.

The legal basis is Art. 6(1)(b) GDPR.

4.3. Compliance with Legal Obligations

Data may be processed to fulfill obligations resulting from legal provisions, in particular tax law, accounting regulations, and documentation retention requirements.

The legal basis is Art. 6(1)(c) GDPR.

4.4. Establishment, Exercise, or Defense of Claims

The Controller may process data to establish, pursue, or defend against legal claims.

The legal basis is Art. 6(1)(f) GDPR, i.e., the legitimate interest of the Controller.

4.5. Ensuring Website Security

Technical data, including IP address and device information, may be processed to ensure Website security, detect abuse, prevent attacks, and diagnose technical issues.

The legal basis is Art. 6(1)(f) GDPR.

4.6. Statistics and Analysis of Website Usage

If analytical tools are used on the Website, information about the use of the Website may be processed to compile statistics and improve its functionality.

In the case of technologies requiring user consent, the legal basis for processing personal data is Art. 6(1)(a) GDPR, upon obtaining the relevant consent.

4.7. Direct Marketing

The Controller may process data to conduct its own direct marketing, to the extent permitted by applicable laws.

The legal basis may be Art. 6(1)(f) GDPR, if marketing is carried out based on the Controller's legitimate interest, taking into account regulations governing the possibility of sending specific marketing communications.

In the case of communication channels requiring prior consent, the Controller obtains such consent prior to initiating marketing communication.

5. Consent to Data Processing

If the legal basis for processing is consent, the data subject has the right to withdraw it at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal.

Consent is voluntary and is not required if data processing can take place on another legal basis provided for by the GDPR.

6. Data Provided in Forms

Providing data marked as required is necessary to process a given form or achieve the specific purpose for which the form was provided.

Providing other data is voluntary.

Before submitting a form, the user should receive information about the Controller, the purpose and legal basis for processing data, and other information required under Art. 13 GDPR.

7. Data Recipients

Personal data may be transferred to entities cooperating with the Controller strictly to the extent necessary to fulfill specific purposes.

These may include, in particular:

  • hosting and IT infrastructure providers;
  • e-mail service providers;
  • form management software providers;
  • IT and maintenance service providers;
  • analytical or marketing tool providers, if utilized;
  • accounting, legal, or consulting service providers;
  • courier or logistics service providers, if necessary for contract performance;
  • law firms, debt collection agencies, or other entities supporting the Controller in pursuing claims;
  • public authorities and other entities authorized by law.

Entities entrusted with data processing by the Controller receive access to data exclusively to the extent necessary to perform the tasks assigned to them.

8. Data Transfers Outside the European Economic Area

If personal data is transferred outside the European Economic Area in connection with using external service providers, the Controller ensures that such transfer takes place in accordance with Chapter V of the GDPR.

Depending on the specific provider, the basis for transfer may include, in particular:

  • an adequacy decision adopted by the European Commission;
  • standard contractual clauses adopted by the European Commission;
  • other mechanisms provided for in the GDPR.

The list of services used by the Controller should be periodically reviewed regarding the location of data processing and the transfer mechanisms applied.

9. Data Retention Period

Personal data is stored for no longer than necessary to achieve the purpose for which it was collected.

In particular:

  • data related to inquiry handling – for the period necessary to handle the inquiry and complete correspondence, and thereafter for a period justified by potential claims pursuit or defense;
  • data related to a concluded contract – for the duration of the contract and for the period required by law or necessary for the establishment, exercise, or defense of claims;
  • data contained in accounting documentation – for the period required by applicable regulations;
  • data processed based on consent – until consent is withdrawn, unless there is another legal basis for further processing;
  • data processed for marketing purposes – until an effective objection is lodged or consent is withdrawn, if consent was required.

After the relevant retention period expires, data is erased or anonymized, unless further storage is required by law.

10. Rights of Data Subjects

A data subject has the right, under the rules specified in the GDPR, to:

  1. access their personal data;
  2. obtain a copy of the data;
  3. rectify inaccurate data;
  4. complete incomplete data;
  5. erase data ("right to be forgotten");
  6. restrict processing;
  7. data portability – in cases provided for in the GDPR;
  8. object to data processing – in cases provided for in the GDPR;
  9. withdraw consent at any time, if processing is based on consent;
  10. lodge a complaint with the President of the Personal Data Protection Office (UODO).

The right to erasure, restriction of processing, data portability, and objection are not absolute. The Controller may be obliged to continue processing data if required by law or if another legitimate basis exists.

11. Objection to Marketing

If personal data is processed for direct marketing purposes, the data subject may object to such processing at any time.

Upon lodging an objection, the data will no longer be processed for direct marketing purposes, unless further processing is permissible under law for another purpose.

12. Right to Lodge a Complaint

The data subject has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych - UODO) if they consider that the processing of their personal data violates the provisions of the GDPR or other personal data protection regulations.

13. Cookies

The Website uses cookies and similar technologies, provided they are technically implemented within its framework.

Cookies are small files stored on the user's device or information read from the user's device while using the Website.

13.1. Essential Cookies

Essential cookies may be used to:

  • ensure proper operation of the Website;
  • maintain user sessions;
  • ensure security;
  • remember privacy and cookie preferences;
  • support functions without which the Website could not operate correctly.

To the extent that the use of such technologies is strictly necessary to provide the service or functionality requested by the user, their application may not require separate consent.

13.2. Analytical Cookies

If the Controller uses analytical tools, cookies may serve to determine how the Website is used, compile statistics, and improve its functionality.

Analytical cookies that are not essential for the operation of the Website are activated only after obtaining the required user consent.

13.3. Marketing Cookies

If the Website uses advertising or remarketing technologies, they may serve to:

  • measure ad effectiveness;
  • create target audiences;
  • conduct remarketing;
  • personalize content or ads.

Such technologies are activated only after obtaining the required user consent.

13.4. Consent Management

The user may accept all optional cookies, reject optional cookies, or customize settings for individual categories – provided the Website offers an appropriate consent management mechanism.

Withdrawing consent should be as easy as granting it.

The user can also modify cookie settings directly in their web browser.

Restricting or disabling certain cookies may cause some Website features to function improperly.

14. List of Cookies and External Tools

A detailed list of cookies should be maintained in accordance with the actual technical state of the Website and include at least:

  • cookie name;
  • provider;
  • category;
  • purpose;
  • retention period;
  • information on whether the cookie is first-party or third-party;
  • information on whether its use requires consent.

The Controller should not declare tools or cookies in this Policy that are not actually in use.

This list should be updated following every significant technological change to the Website.

15. Server Logs

Using the Website may involve automatic logging of information in server logs.

Logs may contain, among other things:

  • IP address;
  • date and time of connection;
  • browser details;
  • operating system information;
  • requested resource;
  • error logs.

Logs are primarily used to ensure security, guarantee proper operation of the Website, and diagnose technical problems.

Access to server logs is restricted exclusively to authorized individuals and entities administering the IT infrastructure.

16. External Links

The Website may contain links to third-party websites.

The Controller is not responsible for the data processing principles applicable on third-party websites.

Before using such sites, users are advised to read their respective privacy policies and cookie notices.

17. Automated Decision-Making and Profiling

Personal data of Website users are not used to make decisions producing legal effects or similarly significantly affecting them based solely on automated processing, unless the user is separately informed and relevant GDPR provisions apply.

Should the Controller initiate profiling or automated decision-making under Art. 22 GDPR in the future, appropriate information will be provided to users prior to such processing.

18. Children's Data

The Website is not directed to children, and the Controller generally does not intend to knowingly collect personal data from children without a proper legal basis.

If the Controller learns that a child's data has been collected without the required legal basis, appropriate steps will be taken to erase it, subject to applicable law.

19. Security

The Controller implements technical and organizational measures appropriate to the risk associated with personal data processing.

These measures may include, in particular:

  • data access control;
  • restricting data access strictly to authorized personnel;
  • securing IT infrastructure;
  • enforcing encrypted HTTPS connections;
  • maintaining data backups;
  • protection against unauthorized access;
  • periodic review of security measures in place.

20. Changes to the Privacy Policy

The Controller may update this Privacy Policy, in particular in the event of:

  • changes in legal regulations;
  • operational changes to the Website;
  • implementation of new services or functionalities;
  • changes in third-party providers or tools used;
  • changes in personal data processing methods.

The current version of the Privacy Policy is published directly on the Website.

21. Privacy Contact Details

In case of questions regarding the processing of personal data or exercising rights under the GDPR, you can contact the Controller:

HellCold Sp. z o.o.
ul. Zofii Kossak 98
43-436 Górki Wielkie
Poland

E-mail: kontakt@reima-polska.pl

Phone: +48 33 85 13 795


Last updated: August 18, 2026