This policy applies to the website operating at the URL: www.shk-feuerfestbau.com
The operator of the website and the Controller of personal data is SHK Feuerfestbau company.
The operator's contact email address: office@shk-feuerfestbau.com
The Operator is the Controller of your personal data with regard to data provided voluntarily through the website.
The website uses personal data for the following purposes:
Handling inquiries via the contact form.
Provision of requested services.
Presentation of offers or information.
The website collects information about users and their behaviour in the following ways:
Through data voluntarily entered in forms, which are stored in the Operator's systems.
Through cookies saved on end-user devices.
2. Selected Data Protection Methods Used by the Operator
Areas for logging in and entering personal data are protected at the transmission layer (SSL certificate). This ensures that personal and login data entered on the website is encrypted on the user's computer and can only be read on the target server.
Personal data stored in the database is encrypted in a way that only the Operator possessing the decryption key can read it. This protects the data in case the database is stolen from the server.
User passwords are stored in a hashed form. The hashing function is one-way — it cannot be reversed, which is the current standard in password storage.
Two-factor authentication is used on the website, providing an additional layer of protection for login.
The Operator periodically changes its administrative passwords.
To minimize the risk of unauthorized access, the Operator uses complex passwords containing uppercase and lowercase letters, digits, and special characters, and that are at least 8 characters long.
3. Hosting
The website is hosted (technically maintained) on servers provided by: cyberFolks.pl
The hosting company maintains server-level logs for technical reliability. Logs may include:
Resources specified by URL identifiers (addresses of requested pages or files)
Time the request was received.
Time the response was sent.
Name of the client station – identified via the HTTP protocol.
Information about errors that occurred during HTTP transactions.
URL of the page previously visited by the user (referrer link) – if the user accessed the website via a link.
Information about the user's browser.
IP address information.
Diagnostic information related to the process of ordering services via forms on the website.
Information related to email communications sent to or from the Operator.
4. Your Rights and Additional Information on Data Use
In certain situations, the Controller has the right to transfer your personal data to other recipients, if necessary to perform a contract with you or to fulfil legal obligations. This applies to the following categories of recipients:
Authorized persons – employees and associates who need access to data to perform their duties.
Hosting company.
Email service providers.
SMS communication providers.
Companies cooperating with the Controller in the scope of own marketing.
Courier services.
Insurers.
Law firms and debt collectors.
Banks.
Payment operators.
Public authorities.
Your personal data is processed by the Controller for no longer than necessary to perform related activities defined by separate regulations (e.g., accounting rules). Marketing data will not be processed for more than 3 years.
You have the right to request from the Controller:
Access to your personal data.
Rectification of data.
Erasure of data.
Restriction of processing.
Data portability.
You have the right to object to processing described in point 4.2 concerning the processing of personal data for the purposes of the legitimate interests pursued by the Controller, including profiling, but your objection may not be accepted if there are valid, legally justified grounds for processing, overriding your interests, rights, and freedoms, particularly for the establishment, exercise, or defence of claims.
You have the right to lodge a complaint with the President of the Personal Data Protection Office.
Providing personal data is voluntary but necessary to use the website.
Automated decision-making, including profiling, may apply to you for the purpose of providing services under a concluded contract and for the Controller's direct marketing.
Personal data is not transferred to third countries within the meaning of data protection regulations — this means we do not transfer it outside the European Union.
5. Information in Forms
The website collects information provided voluntarily by the user, including personal data if provided.
The website may store information about connection parameters (timestamp, IP address).
In certain cases, the website may store information that facilitates linking the data in the form with the email address of the user completing the form. In such cases, the user's email address may appear in the URL of the page containing the form.
Data provided in forms is processed for the purpose resulting from the specific function of the form — e.g., to process a service request, establish commercial contact, register services, etc. The context and description of each form clearly indicate its intended purpose.
6. Administrator Logs
Information about users' activity on the website may be logged. Such data is used for website administration purposes.
7. Key Marketing Techniques
The Operator uses statistical analysis of website traffic via Google Analytics (Google Inc., USA). The Operator does not transmit personal data to this service provider, only anonymized information. The service uses cookies stored on the user's end device. Users can view and edit information derived from cookies related to their preferences within the Google advertising network using the following tool: https://www.google.com/ads/preferences/
The Operator uses remarketing techniques to tailor advertising content to user behaviour on the website. This may give the impression that personal data is being used to track the user, but in practice, no personal data is transmitted by the Operator to advertisers. Such actions are technologically dependent on the user's acceptance of cookie usage.
The Operator uses the Facebook pixel. This technology informs Facebook (Facebook Inc., USA) that a registered user has visited the website. Facebook uses its own data, for which it is the controller; the Operator does not provide any additional personal data to Facebook. The service relies on cookies stored on the user's end device.
The Operator uses solutions to analyze user behaviour through heatmaps and session recording. This data is anonymized before being sent to the service provider, meaning it cannot be linked to any specific individual. Notably, recorded data does not include entered passwords or other personal data.
The Operator uses automation tools on the website, such as those that may send emails to users after visiting specific subpages, provided the user has given consent to receive commercial communications from the Operator.
The Operator may apply profiling as defined in data protection legislation.
8. Information About Cookies
The website uses cookies.
Cookies are IT data, in particular text files, stored on the end device of the Website User and intended for use with the Website's pages. Cookies typically contain the name of the website from which they originate, their storage time on the end device, and a unique number.
The entity placing cookies on the User's end device and accessing them is the Website Operator.
Cookies are used for the following purposes:
Maintaining the User's session on the Website (after logging in), so the User does not have to re-enter login and password information on every subpage.
Fulfilling the purposes described above in section "7. Key Marketing Techniques".
The Website uses two basic types of cookies: "session" cookies and "persistent" cookies. Session cookies are temporary files stored on the User's end device until logging out, leaving the website, or closing the browser. Persistent cookies remain on the User's device for the time specified in their parameters or until deleted by the User.
Web browsing software (internet browser) usually allows cookies to be stored on the User's device by default. Website users may change their browser settings to block cookies or delete them. Detailed instructions can be found in the help or documentation section of the internet browser.
Restricting the use of cookies may affect some of the functionalities available on the Website.
Cookies placed on the User's device may also be used by entities cooperating with the Website Operator, in particular companies such as: Google (Google Inc., USA), Facebook (Facebook Inc., USA), and Twitter (Twitter Inc., USA).
9. Cookie Management – How to Grant and Withdraw Consent in Practice
If a user does not wish to receive cookies, they may change their browser settings. Please note that disabling cookies essential for authentication, security, and user preferences may hinder or, in extreme cases, prevent the use of websites.
To manage cookie settings, select your internet browser from the list below and follow the instructions: