Privacy Policy

1) Information Regarding the Collection of Personal Data and Contact Details of the Controller

1.1 We are delighted that you are visiting our website and thank you for your interest. Below, we inform you about how we process your personal data while using our website. Personal data refers to any information that can identify you as an individual.

1.2 The data controller for this website, within the meaning of the General Data Protection Regulation (GDPR), is:

WINMED PIOTROWSKA SPÓŁKA JAWNA
Address: Elektryczna 2/60, 00-346 Warsaw, Poland
Phone: +48 15 816 40 49
Email: info@winmedal.eu

The controller is the natural or legal person who decides, alone or jointly with others, on the purposes and means of processing personal data.

1.3 This website uses SSL or TLS encryption for security purposes and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries sent to the controller). You can recognise an encrypted connection by the string “https://” and the lock icon in your browser’s address bar.

2) Data Collection When Visiting Our Website

When you use our website for informational purposes only (i.e., without registering or providing information in any other way), we collect only the data that your browser transmits to our server (so-called “server log files”). This includes the following data, which is technically necessary for us to display the website:

  • The website visited
  • Date and time of access
  • Amount of data transmitted (in bytes)
  • Referring source/URL
  • Browser used
  • Operating system used
  • Your IP address (potentially anonymised)

Data processing is carried out in accordance with Article 6(1)(f) GDPR, based on our legitimate interest in improving the stability and functionality of our website. These data are not passed on or used in any other way. However, we reserve the right to retrospectively review the server log files if specific evidence suggests unlawful use.

3) Cookies

To make your visit to our website more attractive and to enable the use of certain functions, we use “cookies.” These are small text files stored on your device. Some cookies are deleted after the browser session ends (session cookies), while others remain on your device to recognise your browser during subsequent visits (persistent cookies).

Persistent cookies may collect various user data, such as browser and location data or IP addresses. These cookies are automatically deleted after a specified period, which may vary depending on the cookie.

Cookie Consent

During your first visit to our website, a cookie banner appears, allowing you to consent to the use of cookies in compliance with the ePrivacy Directive. You can accept all cookies, customise your preferences (e.g., accept only essential cookies), or reject them. Cookie consent is entirely voluntary and can be changed at any time through your browser settings or by clicking the relevant link in our website footer.

Your Cookie Choices

You can configure your browser to:

  • Inform you about cookie usage
  • Allow cookies on a case-by-case basis
  • Disable the acceptance of cookies entirely

Each browser manages cookie settings differently. Below are links to instructions for popular browsers:

Please note that disabling cookies may affect the functionality of our website.

4) Contacting Us

When you contact us (e.g., via a contact form, quotation form, or email), personal data is collected. The scope of data collected in the contact or quotation form depends on its content. This data is processed solely for the purpose of responding to your inquiry and administering related technical processes. The legal basis for this processing is our legitimate interest in responding to your inquiry in accordance with Article 6(1)(f) GDPR. If the purpose of your contact is to enter into a contract, an additional legal basis for processing is Article 6(1)(b) GDPR.

If you consent to the processing of your personal data for marketing purposes, this data will also be stored to send you information about our products, services, or special promotions. The legal basis for such processing is your consent under Article 6(1)(a) GDPR. You can withdraw your consent at any time by sending an email to info@winmedal.eu. Withdrawal of consent does not affect the lawfulness of processing conducted before its withdrawal.

This data will be deleted once your inquiry has been fully resolved, provided there are no statutory retention obligations or unless you have consented to its further use for marketing purposes. Deletion occurs when it is evident from the circumstances that the matter has been conclusively clarified and no further correspondence is required.

5) Data Processing for Contract Fulfilment and Marketing Purposes

In accordance with Article 6(1)(b) GDPR, personal data is collected and processed if it is provided to us for the purpose of fulfilling a contract. The scope of the data collected is determined by the relevant input forms, such as a quotation or enquiry form. We store and use the data you provide solely for the purpose of fulfilling the contract.

If you consent to the processing of your personal data for marketing purposes, this data may also be stored to send you information about our products, services, or special promotions. The legal basis for such processing is your consent under Article 6(1)(a) GDPR. You can withdraw your consent at any time by sending an email to info@winmedal.eu. Withdrawal of consent does not affect the lawfulness of processing conducted before its withdrawal.

After the contract has been fully fulfilled, this data is blocked in compliance with statutory retention obligations arising from tax and commercial regulations, and deleted after these periods expire, unless you have expressly consented to further use of your data or if further processing is legally permissible.

6) Newsletter Registration and Communication

6.1 Registration for Our Email Newsletter

If you subscribe to our newsletter, we will regularly send you information about our products and services. The only required fields for registration are your email address and country of residence. We use a double opt-in procedure for newsletter registration. This means you will receive an email asking you to confirm your subscription by clicking a confirmation link. Only after your confirmation will you begin receiving our newsletter.

By activating the confirmation link, you consent to the processing of your personal data in accordance with Article 6(1)(a) GDPR. During registration, we also store the IP address of your internet service provider (ISP) as well as the date and time of registration to prevent misuse of your email address. Data collected during newsletter registration is used exclusively for newsletter distribution. You can unsubscribe at any time by clicking the unsubscribe link in each email or by sending a relevant message to the administrator’s email address provided at the beginning of this privacy policy. After unsubscribing, your email address will be promptly removed from our mailing list unless you have consented to further use of your data or other legally permissible grounds for processing exist, as outlined in this privacy policy.

6.2 Sending Newsletters to Existing Customers

If you have provided us with your email address when purchasing our products or services, we reserve the right to regularly send you offers for similar products or services from our range. Data processing for this purpose is based on our legitimate interest in direct marketing in accordance with Article 6(1)(f) GDPR.

If you have not consented to the use of your email address for marketing purposes or if you withdraw this consent at any time, emails will not be sent. You have the right to object to the use of your email address for marketing purposes at any time with effect for the future. You can do this by sending a message to info@winmedal.eu or by clicking the unsubscribe link available in every email. Upon receiving an objection, we will no longer use your email address for marketing purposes.

6.3 Postal Advertising

Based on our legitimate interest in personalised direct advertising, we reserve the right to store and use your name, postal address, country of origin, and additional data provided in the course of our business relationship – such as industry or company name – in accordance with Article 6(1)(f) GDPR to send you interesting offers and information about our products by traditional mail.

You may object to the storage and use of your data for this purpose at any time by sending a message to the administrator’s email address provided at the beginning of this privacy policy.

7) Data Processing for Order Fulfilment

7.1 Collaboration with Logistics and Payment Service Providers

To fulfil your order, we collaborate with selected logistics and payment service providers who assist us in fully or partially executing the contracts concluded. In the course of this cooperation, certain personal data is shared with these entities under the following conditions:

  • Personal data collected by us during the order process is shared with the courier or transport company responsible for delivering the order, as necessary for the delivery of the goods.
  • Payment-related data is shared with the selected bank or payment service provider as necessary to process the transaction. If you use third-party payment services, detailed information regarding such services is provided below.
  • The legal basis for such data transfer is Article 6(1)(b) GDPR (contract performance).

7.2 Collaboration with External Logistics Partners

To fulfil our contractual obligations to customers, we collaborate with external logistics partners. Your name, surname, and delivery address are shared solely for the purpose of delivering your order, in accordance with Article 6(1)(b) GDPR.

7.3 Use of Payment Services

When processing payments for orders, we only support payment via traditional bank transfer. To process the payment, we handle personal data as necessary to complete the transaction, in accordance with Article 6(1)(b) GDPR. The data shared may include:

  • Your name or company name,
  • Billing address,
  • Payment amount,
  • Transfer title (e.g., order number).

This data is used solely for processing payment transactions and is not shared with any other parties, except for our bank, which processes the transfer. After the transaction is completed, payment-related data is stored in our systems in compliance with legal obligations arising from tax and accounting regulations. Once these retention periods expire, the data is deleted unless other legal grounds for further processing exist.

8) Contact for Feedback Requests

To ensure the quality of our services and products, we reserve the right to use your email address, provided during the purchase of our goods or services, to send you a feedback request. Such a message may be sent after your order has been completed. Data processing for this purpose is based on our legitimate interest in accordance with Article 6(1)(f) GDPR.

You may object to the use of your email address for this purpose at any time by sending a relevant message to info@winmedal.eu. Such an objection will not result in any costs beyond standard transmission charges.

9) Use of Social Media: Videos

Use of YouTube Videos

This website utilises video embedding features provided by the “YouTube” platform, which is operated by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).

We use YouTube’s enhanced privacy mode, which, according to YouTube, prevents data from being stored about users until the video is played. Once a video embedded on our website is played, YouTube may set cookies to collect user behaviour data. According to YouTube, these cookies are used, among other things, to compile video statistics, improve user-friendliness, and prevent abuse.

If you are logged into your Google account, your data may be directly associated with your account when you click on a video. If you do not want your data to be linked to your YouTube account, please log out before playing a video. Even if you are not logged in, Google may store your data as a user profile and analyse it for advertising purposes, market research, or tailoring its services, as permitted under Article 6(1)(f) GDPR.

You have the right to object to the creation of such user profiles by contacting YouTube directly.

Using YouTube features may involve the transfer of personal data to Google LLC servers in the USA. Google LLC is certified under the “Privacy Shield,” ensuring compliance with EU data protection standards. More information about the certification is available here: https://www.privacyshield.gov/list.

For further information about data protection at YouTube, please refer to YouTube’s privacy policy: https://www.google.com/intl/en/policies/privacy.

10) Online Marketing

10.1 Use of Google Ads Conversion Tracking

Our website uses the “Google Ads” advertising program and its conversion tracking feature, provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). With Google Ads, we can analyse the effectiveness of our advertising campaigns, allowing us to tailor our ads to user needs, optimise our website, and efficiently manage advertising costs.

A conversion tracking cookie is set when a user clicks on a Google Ads advertisement. Cookies are small text files stored on the user’s device that expire after 30 days and are not used to personally identify the user. If the user visits specific pages of our website before the cookie expires, Google and we can determine that the user clicked on the ad and was redirected to our site. Each Google Ads customer receives a unique cookie, preventing tracking across websites of different Google Ads customers.

The collected data allows us to generate conversion statistics, which inform us about the number of users clicking on our ads and visiting specific pages. However, we do not receive information that personally identifies users. If you do not wish to participate in tracking, you can disable the conversion tracking cookie in your browser settings. Tracking will then be disabled, and the data will not be included in conversion statistics.

Data processing is carried out based on our legitimate interest in analysing, optimising, and managing our online advertising, in accordance with Article 6(1)(f) GDPR.

Information generated by cookies may be transmitted to Google servers in the USA. Google LLC is certified under the “Privacy Shield,” ensuring compliance with European data protection standards. More information can be found here:
https://www.privacyshield.gov/list.

Details about Google’s privacy policy can be found here:
https://www.google.com/policies/privacy/.

To permanently disable cookies for personalised advertising, you can download the appropriate browser plugin available here:
https://www.google.com/settings/ads/plugin.

10.2 Google Marketing Platform

Our website uses the “Google Marketing Platform” (GMP) marketing tool, provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). GMP uses cookies to display relevant advertisements to users, improve campaign reports, and prevent users from seeing the same ads multiple times.

GMP cookies enable Google to track user interactions with ads and websites. The collected data, such as the number of clicks or impressions, is used to analyse the effectiveness of advertising campaigns. According to Google, GMP cookies do not contain any personal data.

When using GMP, the user’s browser connects to Google servers, which may result in the transmission of data such as the user’s IP address. If the user is logged into Google services, this data may be associated with their account.

If you wish to opt-out of such tracking, you can disable cookies in your browser settings. More information about data protection by GMP can be found here:
https://www.google.com/policies/privacy/.

11) Web Analytics Services

11.1 Google (Universal) Analytics

Our website uses Google Analytics, an online analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). Google Analytics uses cookies – small text files stored on your device – that allow for the analysis of how you use our website. The information generated by the cookies about your use of our website (including the shortened IP address) may be transferred to Google’s servers, including in the USA, and stored there.

On this site, Google Analytics operates exclusively with the “_anonymizeIp()” extension, which ensures anonymisation of the IP address, preventing it from being directly linked to a user. In exceptional cases, the full IP address may be transferred to Google’s server in the USA and shortened there. This data is processed in accordance with Article 6(1)(f) GDPR based on our legitimate interest in conducting statistical analysis of user behaviour for optimisation and marketing purposes.

Google uses this information on our behalf to analyse website usage, create reports on site activity, and provide other services related to internet usage. The IP address sent by your browser in connection with Google Analytics will not be linked with other Google data.

You can prevent the storing of cookies by appropriately configuring your browser settings. Please note, however, that doing so may limit the functionality of some features on our website. You can also block the transmission of data generated by the cookies related to your usage of the website (including the IP address) to Google and the processing of this data by Google by installing the plugin available at the following link:
https://tools.google.com/dlpage/gaoptout?hl=pl.

Alternatively, you can set an “Opt-Out-Cookie” to block Google Analytics tracking on this website in the future. Click here to set the Opt-Out-Cookie:
Disable Google Analytics.

Google LLC, responsible for data processing in the USA, holds the “Privacy Shield” certification, ensuring compliance with European data protection standards. More information can be found here:
https://www.privacyshield.gov/list.

Additionally, we use the “demographic data and interests” feature in Google Analytics, which allows us to generate reports on the age, gender, and interests of users. These data are derived from interest-based ads in Google and user data provided by third-party providers. You can disable this feature in your Google account settings or fully block Google Analytics by using the options described above.

Profiling and Automated Decision-Making

Please note that any profiling (e.g., through analytics or marketing tools) carried out on our website does not result in any legal effects or similarly significant impacts on users.

Detailed information about Google Analytics can be found here:
https://support.google.com/analytics/answer/2838718?hl=en&sjid=14004666734384891624-EU.

12) Rights of the Data Subjects

12.1 Your Rights

In accordance with the applicable data protection regulations, you have a number of rights in relation to the processing of your personal data. Below are your rights:

  • Right of Access (Article 15 GDPR)
    You have the right to obtain information about the personal data we process, the purposes of processing, the categories of personal data being processed, the recipients or categories of recipients to whom your data has been disclosed, the planned retention period or the criteria for determining that period, the existence of the right to rectification, erasure or restriction of processing, the right to object to processing, the right to lodge a complaint with a supervisory authority, the source of the data (if not collected directly from you), as well as information about automated decision-making, including profiling, and relevant details regarding the processing rules.
  • Right to Rectification (Article 16 GDPR)
    You have the right to request the immediate correction of inaccurate personal data concerning you and the completion of incomplete data.
  • Right to Erasure (Article 17 GDPR)
    You have the right to request the deletion of your personal data if there are grounds specified in Article 17(1) GDPR. However, this right does not apply where the processing of data is necessary, for example, to exercise the right to freedom of expression, to comply with a legal obligation, for public interest reasons, or to establish, exercise or defend legal claims.
  • Right to Restriction of Processing (Article 18 GDPR)
    You have the right to request the restriction of the processing of your personal data in situations where:
    • you contest the accuracy of the data – for the period of verification;
    • the processing is unlawful, but you oppose its erasure;
    • the data are necessary for the establishment, exercise or defence of legal claims, even though they are no longer required for processing purposes;
    • you have objected to the processing – until it is determined whether our legitimate grounds override your rights.
  • Right to Notification (Article 19 GDPR)
    If you exercise the right to rectification, erasure or restriction of processing, we are obliged to inform the recipients of your data, unless this proves impossible or requires excessive effort. Upon your request, we will inform you about these recipients.
  • Right to Data Portability (Article 20 GDPR)
    You have the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format, and to request that it be transferred to another controller, where technically feasible.
  • Right to Withdraw Consent (Article 7(3) GDPR)
    You have the right to withdraw your consent to the processing of your personal data at any time, where the processing was based on consent. The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
  • Right to Lodge a Complaint (Article 77 GDPR)
    If you believe that the processing of your personal data violates the provisions of the GDPR, you have the right to lodge a complaint with a supervisory authority in the EU member state of your residence, place of work, or the location where the alleged violation occurred. A list of supervisory authorities in EU countries is available here: https://edpb.europa.eu/about-edpb/board/members_en.

12.2 Right to Object

If we process your personal data based on our legitimate interests under Article 6(1)(f) GDPR, you have the right to object to this processing at any time, on grounds relating to your particular situation, with effect for the future.

If you exercise your right to object, we will cease processing your personal data, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.

If your personal data is processed for direct marketing purposes, you have the right to object to such processing at any time. You can exercise this right by following the instructions in this privacy policy.

In the case of lodging an objection to the processing of your personal data for direct marketing purposes, we will cease processing your data for these purposes.

13) Retention Period for Personal Data

The retention period for personal data depends on the legal basis for processing, the purpose of processing, and, if necessary, applicable data retention regulations (e.g. arising from tax or commercial laws).

Processing Data Based on Consent (Article 6(1)(a) GDPR)

Personal data processed based on your consent will be stored until the consent is withdrawn, unless further processing is permitted under another legal basis.

Processing Data in Connection with a Contract (Article 6(1)(b) GDPR)

If personal data is processed as part of the performance of a contract, it will be stored for the period required by tax and commercial regulations. After this period, the data will be routinely deleted, unless they are no longer needed for the performance of the contract or its preparation, or if there are legitimate interests for further retention.

Processing Data Based on Legitimate Interests (Article 6(1)(f) GDPR)

Personal data processed on this basis will be stored until you exercise your right to object, in accordance with Article 21(1) GDPR, unless we can demonstrate significant and legitimate reasons for further processing that outweigh your interests, rights, and freedoms, or where processing serves the establishment, exercise, or defence of legal claims.

Processing Data for Direct Marketing Purposes (Article 6(1)(f) GDPR)

Personal data processed for direct marketing purposes will be stored until you object, in accordance with Article 21(2) GDPR.

Unless otherwise specified in this privacy policy, personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.