Privacy Policy

Privacy Policy

The purpose of this Privacy Policy is to explain the principles on which BLUEBOAT company collects, uses, and protects your personal data, as well as to present your rights in connection with the processing of personal data by the Data Administrator. Please familiarize yourself with the following information.

Data Administrator

The administrator of personal data obtained through the website available at https://blueboat.pl/ is BLUEBOAT Jacek Bulik with registered office at ul. Pawia 7/135, 05-500 Piaseczno, VAT ID: PL5751743023, REGON: 140669105, BDO: 000014853, email: office@blueboat.pl, tel.: 29 777 00 20.
The Administrator carefully selects and implements appropriate technical and organizational measures to ensure the protection of processed data, including securing data against unauthorized access, as well as other cases of disclosure or loss, and against destruction or unauthorized modification of the specified data, as well as against processing them in violation of applicable law. The Administrator exercises constant control over the data processing process and limits access to the data to the greatest extent possible, granting appropriate authorizations only when necessary.

For questions regarding the processing of personal data, please contact us at: office@blueboat.pl.

What personal data do we process and for what purposes do we process it?

To provide services in accordance with the business profile, BLUEBOAT processes personal data for various purposes, always in accordance with the law. Below you will find the specified purposes of processing personal data along with the legal bases:

a) To register in the online store, we process personal data such as:

Name and surname / email address / phone number

The legal basis for such processing of data is art. 6 sec. 1 lit. a GDPR and art. 6 sec. 1 lit. b GDPR, which allows processing personal data based on voluntarily given consent, if they are necessary for the performance of a contract or the initiation of actions leading to the conclusion of a contract;

b) To send email notifications about messages in the customer panel, we process personal data such as:

Email address / name and surname / order number

The legal basis for such processing of data is art. 6 sec. 1 lit. f GDPR, which allows processing personal data, if in this way the Data Administrator realizes his legitimate interest (in this case, the Company's interest is to inform the customer about activities related to the order fulfillment to improve the convenience of using the store);

c) For telephone contact regarding order fulfillment, we process personal data such as:

Phone number / order number

The legal basis for such processing of data is art. 6 sec. 1 lit. a GDPR, which allows processing personal data based on voluntarily given consent;

d) For issuing invoices and fulfilling other obligations arising from tax law, such as storing accounting documentation for 5 years, we process personal data such as:

Name and surname / company / address of residence or registered office / tax identification number (NIP) / order number

The legal basis for such processing of data is art. 6 sec. 1 lit. c GDPR, which allows processing personal data if such processing is necessary to fulfill the obligations of the Data Administrator arising from the law;

e) To store unpaid (credited) orders, we process personal data such as:

Name and surname / email address / order number / address of residence or registered office / tax identification number (NIP)

The legal basis for such processing of data is art. 6 sec. 1 lit. f GDPR, which allows processing personal data if in this way the Data Administrator realizes his legitimate interest (obtaining payment for goods and fulfilling the contract);

f) For the purpose of creating records and registers related to GDPR, such as the register of customers who have objected in accordance with GDPR, we process personal data such as email address because, firstly, GDPR regulations impose certain documentary obligations on us to demonstrate compliance and accountability, secondly, if you object to the processing of your personal data for marketing purposes, for example, we need to know who not to apply direct marketing to because they do not wish it.

The legal basis for such processing of data is, firstly, art. 6 sec. 1 lit. c GDPR, which allows processing personal data if such processing is necessary to fulfill the obligations of the Data Administrator arising from the law; secondly, art. 6 sec. 1 lit. f GDPR, which allows processing personal data if in this way the Data Administrator realizes his legitimate interest (knowledge about persons who exercise their rights arising from GDPR);

g) For the purpose of establishing, investigating, or defending against claims, we process personal data such as:

Name and surname or company / address of residence / PESEL or tax identification number (NIP) / email address / IP / order number

The legal basis for such processing of data is art. 6 sec. 1 lit. f GDPR, which allows processing personal data if in this way the Data Administrator realizes his legitimate interest (having personal data that will allow to establish, assert or defend against claims, including those of customers and third parties);

h) For archival and evidential purposes, we process personal data such as:

Name and surname / email address / order number

For the purpose of securing information that may serve to prove facts of legal significance. The legal basis for such processing of data is art. 6 sec. 1 lit. f GDPR, which allows processing personal data if in this way the Data Administrator realizes his legitimate interest (in this case, the Company's interest is to have personal data that will allow to prove certain facts related to order fulfillment, e.g. when a state authority demands it);

i) For analytical purposes, i.e. researching and analyzing activity on the Blueboat company website, we process personal data such as:

Date and time of website visits / type of operating system / approximate location / type of web browser used to browse the website / time spent on the website / visited subpages

The legal basis for such processing of data is art. 6 sec. 1 lit. f GDPR, which allows processing personal data if in this way the Data Administrator realizes his legitimate interest (understanding the activity of customers on the website);

j) For website administration purposes, we process personal data such as:

IP address / date and time of the server / information about the web browser / information about the operating system

This data is automatically recorded in server logs each time the blueboat.pl website is used. Administering the website without using a server and without this automatic recording would not be possible. The legal basis for such processing of data is art. 6 sec. 1 lit. f GDPR, which allows processing personal data if in this way the Data Administrator realizes his legitimate interest (website administration).

Cookies Policy

a) Cookies are small text information in the form of text files sent by the server and stored on the visitor's side of the Internet Store website (e.g., on the hard drive of a computer, laptop, or on the memory card of a smartphone - depending on the device used by the visitor of the Internet Store). Detailed information about cookies, as well as the history of their creation, can be found, among others, here: http://en.wikipedia.org/wiki/HTTP_cookie

b) The collected information concerns the IP address, type of browser used, language, type of operating system, internet service provider, information about time and date, location, and information sent to the website through the contact form.

c) The Administrator may process data contained in cookies when visitors use the Internet Store website for the following purposes:

- identifying Service Recipients as logged in to the Internet Store and showing that they are logged in;
- remembering Products added to the cart to place an Order;
- remembering data from filled Order Forms, surveys, or login data for the Internet Store;
- adapting the content of the Internet Store website to the individual preferences of the Service Recipient (e.g., concerning colors, font size, page layout) and optimizing the use of the Internet Store website;
- conducting anonymous statistics showing how the Internet Store website is used.
- researching the characteristics of visitors' behavior on the Internet Store website by analyzing their actions (repeated visits to pages, keywords, etc.) to create their profile and provide them with personalized promotions.

d) Most internet browsers available on the market by default accept the storage of cookies. Everyone has the possibility to determine the conditions of using cookies using the settings of their internet browser. This means that, for example, it is possible to partially limit (e.g., temporarily) or completely disable the possibility of saving cookies - in the latter case, however, it may affect some functionalities of the Internet Store (for example, it may be impossible to go through the Order path via the Order Form due to not remembering Products in the cart during subsequent Order steps).

e) The settings of the internet browser regarding cookies are essential from the point of view of consent to the use of cookies by our Internet Store - according to the regulations, such consent can also be expressed through the settings of the internet browser. In the absence of such consent, it is necessary to appropriately change the settings of the internet browser regarding cookies.

f) Detailed information on changing settings regarding cookies and their self-deletion in the most popular internet browsers is available in the help section of the internet browser.

g) The Administrator also processes anonymized operational data related to the use of the Internet Store (IP address, domain) to generate statistics helpful in administering the Internet Store. These data are aggregate and anonymous, i.e., they do not contain characteristics identifying persons visiting the Internet Store website. These data are not disclosed to third parties.

Voluntariness of providing personal data

Providing any personal data is voluntary and depends on your decision.

To place an order in the store, it is necessary to provide an email address and company data - without this, we are unable to conclude and execute the contract.

To receive an invoice for the order, it is necessary to provide all data required by tax law, i.e., the company name, registered office address, and tax identification number (NIP) - without this, we are unable to properly issue the invoice.

To be able to contact you by phone regarding matters related to the execution of the order, it is necessary to provide a phone number - without this, we are unable to establish telephone contact.

What rights do you have regarding the processing of your personal data?

Based on GDPR, you have the right to:

- request access to your personal data,
- request correction of your personal data,
- request deletion of your personal data,
- request restriction of processing of personal data,
- object to processing of personal data,
- request data portability.

If you submit any of the above requests to us without undue delay (within one month from receiving the request), we will provide you with information about the actions taken in connection with your request.

Right of access to personal data (Article 15 of the GDPR)

You have the right to know whether we process your personal data. If we process your personal data, you have the right to:

- access to personal data,
- obtain information about the purposes of processing, the categories of personal data processed, recipients or categories of recipients of this data, the planned period of storage of your data or the criteria for determining this period, the rights granted to you under the GDPR, and the right to lodge a complaint with the President of the Office for Personal Data Protection, the source of this data, automated decision-making, including profiling, and the security measures applied in connection with the transfer of this data outside the European Union;
- obtain a copy of your personal data.

If you wish to request access to your personal data, please submit your request to: office@blueboat.pl.

Right to rectification of personal data (Article 16 of the GDPR)

If your personal data is incorrect, you have the right to request immediate rectification of your personal data from us. You also have the right to request supplementation of your personal data by us. If you wish to request rectification or supplementation of your personal data, please submit your request to: office@blueboat.pl.

Right to erasure of personal data, the "right to be forgotten" (Article 17 of the GDPR)

You have the right to request the erasure of your personal data when:

- your personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- you have withdrawn specific consent, to the extent that personal data has been processed based on your consent;
- your personal data has been processed unlawfully;
- you have objected to the processing of your personal data for direct marketing purposes, including profiling, to the extent that the processing of personal data is related to direct marketing;
- you have objected to the processing of your personal data in connection with processing necessary for the performance of a task carried out in the public interest or processing necessary for purposes arising from the legitimate interests pursued by us or a third party.

Despite submitting a request for the erasure of personal data, we may continue to process your data in order to establish, assert, or defend claims, of which you will be informed.

If you wish to request the erasure of your personal data, please submit your request to: office@blueboat.pl.

Right to request restriction of processing of personal data (Article 18 of the GDPR)

You have the right to request the restriction of processing of your personal data when:

- you contest the accuracy of your personal data – in this case, we will restrict the processing of your personal data for a period enabling us to verify the accuracy of this data;
- the processing of your data is unlawful, and instead of deleting personal data, you request the restriction of processing of your personal data;
- your personal data is no longer needed for the purposes of processing, but is necessary for the establishment, exercise, or defense of your claims;
- you have objected to the processing of your personal data – until it is determined whether our legitimate interests prevail over the grounds indicated in your objection.

If you wish to request the restriction of processing of your personal data, please submit your request to: office@blueboat.pl.

Right to object to processing of personal data (Article 21 of the GDPR)

You have the right to object at any time to the processing of your personal data, including profiling, in connection with:

- processing necessary for the performance of a task carried out in the public interest or processing necessary for purposes arising from the legitimate interests pursued by the Data Controller or a third party;
- processing for direct marketing purposes.

If you wish to object to the processing of your personal data, please submit your request to: office@blueboat.pl.

Right to data portability (Article 20 of the GDPR)

You have the right to receive your personal data from us in a structured, commonly used, machine-readable format and to transmit it to another data controller.

We will provide you with your personal data in CSV format by default. If you prefer your data to be provided in a different format, please specify the preferred format in your request. We will endeavor to provide you with the data in your preferred format, to the extent possible.

You may also request that we transmit your personal data directly to another data controller (if technically feasible).

If you wish to request the transfer of your personal data, please submit your request to: office@blueboat.pl.

Can you withdraw your consent to process personal data?

You can withdraw your consent to process your personal data at any time. Withdrawing consent to process personal data does not affect the lawfulness of processing based on your consent before its withdrawal.

If you wish to withdraw your consent to process your personal data, please submit your request to: office@blueboat.pl.

If you want to withdraw consent to process your personal data for the "Newsletter" service, you can unsubscribe by sending your request to: office@blueboat.pl.

Automated decision-making and profiling

Please note that we do not make automated decisions, including profiling. The proposed price of goods is not in any way the result of an assessment made by any computer system.

Recipients of personal data

Like most businesses, we use the assistance of other entities in our operations, which often involves the need to disclose personal data. Therefore, if necessary, we disclose your personal data to companies cooperating with us in handling fast payments, accounting firms, debt collection agencies, and hosting companies.

Additionally, it may happen that, for example, based on the relevant legal provision or decision of the competent authority, we will have to disclose your personal data to other entities, whether public or private. Therefore, it is extremely difficult for us to predict who may request the disclosure of personal data. Nevertheless, we assure you that each case of a request for the disclosure of personal data is analyzed very carefully and thoroughly to avoid unintentionally disclosing information to an unauthorized person.

Will we transfer your personal data outside the EEA or to an international organization?

In order to use Google tools, YouTube, your personal data may be transferred to the United States, where Google LLC servers are located.

Google LLC is listed in the Data Privacy Framework program (link: https://www.dataprivacyframework.gov/s/participant-search), therefore, the protection of personal data is adequate in relation to the regulations applicable in the European Union, in accordance with Commission Implementing Decision (EU) C(2023) 4745 of 10 July 2023 on the adequate level of protection of personal data according to the EU-USA Data Privacy Framework (link: https://ec.europa.eu/commission/presscorner/detail/en/FS_22_2100).

In order to use Facebook tools, your personal data may be transferred to the United States, where Meta Platforms Inc. servers are located.

Meta Platforms Inc. is listed in the Data Privacy Framework program (link: https://www.dataprivacyframework.gov/s/participant-search), therefore, the protection of personal data is adequate in relation to the regulations applicable in the European Union, in accordance with Commission Implementing Decision (EU) C(2023) 4745 of 10 July 2023 on the adequate level of protection of personal data according to the EU-USA Data Privacy Framework (link: https://ec.europa.eu/commission/presscorner/detail/en/FS_22_2100).

Period of personal data processing

In accordance with applicable law, we do not process your personal data "indefinitely", but for the time necessary to achieve the specified purpose. After this period, your personal data will be irreversibly deleted or destroyed.

Regarding the specific periods of processing personal data, please be informed that we process personal data for the following periods:

a) the duration of the contract — regarding personal data processed for the purpose of concluding and performing the contract;
b) 3 years — regarding personal data processed for the purpose of establishing, investigating, or defending claims (the length of the period depends on whether both parties are entrepreneurs or not);
c) 5 years — regarding personal data related to fulfilling tax obligations;
d) until the withdrawal of consent or achieving the purpose of processing, but not longer than 5 years — regarding personal data processed based on consent;
e) until the effective objection or achieving the purpose of processing, but not longer than 5 years — regarding personal data processed based on the legitimate interests of the Data Controller or for marketing purposes;
f) until becoming outdated or obsolete, but not longer than 3 years — regarding personal data processed mainly for analytical purposes, use of cookies, and website administration.

We count the periods in years from the end of the year in which we started processing personal data to facilitate the process of deleting or destroying personal data. Separate counting of the deadline for each concluded contract would entail significant organizational and technical difficulties, as well as significant financial costs, therefore, setting a single date for deleting or destroying personal data allows us to manage this process more efficiently. Of course, in the case of exercising your right to be forgotten, such situations are considered individually.

The additional year associated with processing personal data collected for the purpose of executing the contract is dictated by the fact that hypothetically you may submit a claim just before the expiration of the limitation period, the demand may be delivered with a significant delay, or you may incorrectly determine the limitation period for your claim.

Security of the blueboat.pl website

Blueboat company makes every effort to secure your data and protect it from unauthorized actions by third parties. We implement all necessary server, connection, and website security measures to protect your data. In particular, we use SSL technology (encrypted data transmission) to ensure secure data transmission during registration, login, and placing orders through the www.blueboat.pl website. You can recognize whether a connection is secure by checking if the address of the www.blueboat.pl website when filling out registration data, logging in, or managing the shopping cart starts with https:// and by the closed padlock symbol appearing in the browser. All connections related to making electronic payments by you, if you choose this option, will also be made through a secure encrypted connection.

However, the actions taken by the Data Controller may prove to be insufficient if you do not follow security rules yourselves. In particular, you must keep your login and password to the website confidential and not disclose them to third parties. Blueboat company will not ask you to provide them, except for providing them during login to the www.blueboat.pl website. To prevent unauthorized access to your account, please log out after each use of the website.

Complaint to the supervisory authority

If you believe that the processing of your personal data violates data protection regulations, you have the right to lodge a complaint with the supervisory authority, especially in the Member State of your habitual residence, your place of work, or the place of the alleged infringement.

In Poland, the supervisory authority within the meaning of the GDPR is the President of the Office for Personal Data Protection.

Back to Top