PRIVACY POLICY
§ 1. General Provisions
1. This Privacy Policy is addressed to users of the website available at: Strumber.eu, owned by The True Green Joint-Stock Company with its registered office in Tarnawatka-Tartak, ul. Tomaszowska 19, 22-604 Tarnawatka.
2. The Policy defines the principles, methods of processing, and use by the Controller of personal data obtained by the Controller from Users during their use of the Website and obtained as a result of any correspondence directed by Users to the Controller, including via electronic mail or forms available on the Website.
3. Personal data obtained by the Controller are processed on the principles set out in data protection legislation, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: GDPR) and in Polish legislation issued in connection with the GDPR. The Controller keeps personal data confidential and protects them against unauthorised access by third parties on the principles set out in the aforementioned legal acts.
§ 2. Definitions
- Controller - The True Green Joint-Stock Company with its registered office in Tarnawatka-Tartak, ul. Tomaszowska 19, 22-604 Tarnawatka, REGON: 526307850, NIP: 7133126991, registered by the District Court Lublin-Wschód in Lublin with its seat in Świdnik, VI Commercial Division of the National Court Register, under number KRS 0001056603, with a share capital of PLN 139,935.60 (fully paid), which determines the purposes and methods of processing Personal Data;
- Personal Data - any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- Cookies Policy – a policy defining the purposes and principles of the Controller's use of cookies or other similar technologies and solutions, which constitute IT data, in particular text files, which are stored on the Website User's terminal device and are intended for using the Website; the Controller's Cookies Policy is available on the Website at: Strumber.eu
- Newsletter Terms and Conditions - the terms and conditions established by the Controller, which define the detailed rules for the provision of the free Newsletter service available on the Controller's Website; the Newsletter Terms and Conditions are available on the Website at: Strumber.eu
- GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation);
- Website – the website available at: Strumber.eu, owned by the Controller;
- User - a person who uses the Website or directs any correspondence to the Controller, including through forms available on the Website or via electronic mail;
§ 3. Personal Data Controller Details
Personal Data Controller:
The True Green SA with its registered office in Tarnawatka-Tartak, ul. Tomaszowska 19, 22-604 Tarnawatka, REGON: 526307850, NIP: 7133126991, registered by the District Court Lublin-Wschód in Lublin with its seat in Świdnik, VI Commercial Division of the National Court Register, under number KRS 0001056603, with a share capital of PLN 139,935.60 (fully paid)..
Any User may contact the Controller in the following ways:
§ 4. Purposes and Legal Bases for Processing Personal Data
1. The purposes and legal bases for processing Users' Personal Data by the Controller depend on the way the User uses the Website, including the use of available Website functionalities, as well as on the method by which the User directs correspondence to the Controller, including via electronic mail or contact forms available on the Website. The Controller processes Users' personal data, among other things:
- for the purpose of the Controller providing services by electronic means in the scope of making Website content available to Users (e.g., the Newsletter service), including for the conclusion and performance of a contract or taking steps at the User's request prior to entering into a contract - the legal basis is Article 6(1)(b) GDPR or based on Article 6(1)(f) GDPR, i.e., the Controller's legitimate interest in providing these services,
- for the purpose of establishing and pursuing claims or defending against claims that may arise in connection with the User's use of the Website or directing and conducting correspondence with the User, as well as the User placing orders - based on Article 6(1)(f) GDPR, i.e., the Controller's legitimate interest in establishing and pursuing these claims or defending against these claims,
- for the purpose of marketing the Controller's services and products, including informing about events or the Controller's activities, in particular via the Newsletter available on the Website - based on Article 6(1)(f) GDPR, i.e., the Controller's legitimate interest in informing about its activities and marketing the Controller's services and products,
- for analytical, statistical purposes (e.g., use of analytical cookies), as well as ensuring IT security related to the Website - based on Article 6(1)(f) GDPR, i.e., the Controller's legitimate interest in performing these activities,
- for the purpose of responding to inquiries directed by the User via the contact form or via electronic mail and conducting correspondence with the User – based on Article 6(1)(f) GDPR, i.e., the Controller's legitimate interest in providing responses and conducting correspondence with the User,
- for the purpose of fulfilling orders, including the conclusion and performance of a contract or taking steps at the User's request prior to entering into a contract - the legal basis is Article 6(1)(b) GDPR or based on Article 6(1)(f) GDPR, i.e., the Controller's legitimate interest in providing these services,
- for the purpose of fulfilling quotation requests, including the conclusion and performance of a contract or taking steps at the User's request prior to entering into a contract - the legal basis is Article 6(1)(b) GDPR or based on Article 6(1)(f) GDPR, i.e., the Controller's legitimate interest in providing these services,
- for the purpose of establishing cooperation - including the conclusion and performance of a contract or taking steps at the User's request prior to entering into a contract - the legal basis is Article 6(1)(b) GDPR or based on Article 6(1)(f) GDPR, i.e., the Controller's legitimate interest in providing these servicesg,
- for the purpose of the Controller fulfilling legal obligations incumbent upon the Controller – based on Article 6(1)(c) GDPR,
- for purposes resulting from the User's consent to the processing of their personal data – based on Article 6(1)(a) GDPR.
2. Providing by the User the Personal Data required for a given service available on the Website (e.g., email address for the Newsletter service) is voluntary; however, refusal to provide these data will prevent the User from using that Website service.
3. Providing other Personal Data than those mandatory for a specific functionality available on the Website is voluntary. The Website User may at any time withdraw consent to the processing of Personal Data for which they have given consent. Withdrawal of consent to the processing of Personal Data does not affect the lawfulness of processing based on consent before its withdrawal.
§ 5. Contact Forms
1. The Controller provides the possibility to contact it using electronic contact forms available on the Website.
2. Using the contact forms requires providing the relevant Personal Data specified in point 2.3 below, in order to enable the Controller to respond to the inquiry or order directed by the User using one of the contact forms available on the Website.
3. The Controller provides the following contact forms on the Website:
- general contact form, which requires providing at least the following User data:
- first and last name,
- email address,
- message content.
- form for those interested in cooperation/recipients, which requires providing at least the following User data:
- first and last name,
- email address,
- country
- message content.
- form for the agricultural sector, which requires providing at least the following User data:
- first and last name,
- email address,
- country
- message content.
- form for sample orders, which requires providing at least the following User data:
- first and last name,
- email address,
- country
- message content.
- form for quotation requests, which requires providing at least the following User data:
- first and last name,
- email address,
- country
- message content.
(hereinafter: "Mandatory Data").
4. Providing Mandatory Data is voluntary, but failure to provide them results in the inability for the Controller to handle the inquiry or order directed via one of the above-mentioned contact forms. Providing other data in a given form than the Mandatory Data is voluntary.
5. In the case of providing by the User other Personal Data than the Mandatory Data, the legal basis for their processing is the User's consent (Article 6(1)(a) GDPR). The Website User may at any time withdraw consent to the processing of Personal Data for which they have given consent. Withdrawal of consent to the processing of Personal Data does not affect the lawfulness of processing based on consent before its withdrawal.
§ 6. Newsletter
1. The Controller provides the so-called Newsletter service on the Website.
2. Using the newsletter requires providing Personal Data in the form of the User's email address.
3. The Controller provides the newsletter service in accordance with the applicable Newsletter Terms and Conditions available on the Website.
§ 7. Cookies
1. The Controller uses cookies on the Website.
2. The purposes and principles of using cookies by the Controller are defined in the Cookies Policy available on the Website.
§ 8. Users' Rights
Users have the following rights:
- the right to withdraw consent to the processing of Personal Data (to the extent that Personal Data are processed on the basis of consent) at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
- the right of access to their Personal Data and to receive a copy thereof – the right to obtain information as to whether the Controller processes Personal Data, and in the case of such processing – the right of access to these data and to obtain the information referred to in Article 15(1)(a) – (h) GDPR, as well as the right to obtain a copy of the Personal Data.
- the right to rectification of Personal Data – the right to request the correction of any incomplete or incorrect Personal Data;
- the right to erasure of Personal Data – the right to request the erasure of Personal Data in certain situations; the Controller may refuse to erase Personal Data, e.g., due to the necessity to retain data for the purpose of compliance with legal obligations or for the purpose of establishing, exercising or defending claims.
- the right to restriction of processing of Personal Data – the right to request restriction of processing of the User's Personal Data.
- the right to data portability – the right to request assistance in transferring the User's Personal Data to another entity.
- the right to object to the processing of Personal Data based on the Controller's legitimate interest – an objection may be raised at any time – for reasons relating to the User's particular situation; also the right to object to processing for direct marketing purposes (including the provision of the Newsletter service) - an objection may be raised at any time to the extent that the processing is related to such direct marketing.
- the right to lodge a complaint with a supervisory authority - the right to lodge a complaint to the President of the Personal Data Protection Office (PUODO) in Warsaw (ul. Stanisława Moniuszki 1A, 00-014 Warsaw) or via email: kancelaria@uodo.gov.pl.
§ 9. Period of Processing Personal Data
1. Users' Personal Data are processed by the Controller for a period which depends on the purpose and legal basis for processing, and in particular on the following principles:
- for the duration of the provision of the service or performance of the contract to which the processing of Personal Data is related (e.g., for the period from the moment the User subscribes to the Newsletter until the cancellation of the subscription by the User).
- until the relevant legitimate interests pursued by the Controller are fulfilled.
- until the User lodges an effective objection to the processing of Personal Data.
- when processing is based on consent, data will be processed until that consent is withdrawn.
- for the period necessary for processing data arising from legal provisions, when they constitute the basis for processing.
- for the period of fulfilment by the Controller of its legal obligations arising from legal provisions.
2. The period of processing Personal Data mentioned above may be extended if the processing is necessary for the establishment, exercise or defence of claims, and after this period – only in the case and to the extent required by applicable law.
§ 10. Recipients of Personal Data
1. Users' Personal Data are disclosed only to entities authorised under the provisions of law, an agreement on entrusting Personal Data concluded with the Controller or having another legal basis for processing Personal Data.
2. The Controller may disclose Users' Personal Data (on the principles resulting from the provisions of law), in particular to the following entities:
- entities directly or indirectly affiliated with the Controller, in particular in an organisational or personal manner, having their registered office in one of the member states of the European Union.
- state authorities and services, as well as judicial and law enforcement authorities, if required by law.
- external entities providing and supporting IT systems or other technological solutions used by the Controller (including IT services, Website maintenance, database management, tools for managing the Newsletter and electronic communication).
- external entities providing accounting and bookkeeping services (including accounting, auditors and reviewers) to the extent that the disclosure of data is necessary for the provision of these services to the Controller.
- legal advisors and consultants serving the Controller to the extent that the disclosure of data is necessary to use their services.
- entities handling shipments, providing scanning, printing, correspondence handling, document archiving and destruction services, etc.
- financial institutions – in the case of conducting financial settlements.
- partners assisting the Controller in data analysis by providing analytical tools.
3. Due to the use of cookies on the Website, as mentioned in the Controller's Cookies Policy, to the extent they constitute Users' Personal Data, the data are disclosed to the entities indicated in the Cookies Policy.
§ 11. Transfer of Personal Data outside the EEA
1. The Controller may transfer Personal Data outside the European Economic Area (hereinafter: "EEA") when necessary and only to the necessary extent, related e.g., to the provision of services to the Controller by entities outside the EEA, especially IT services (e.g., data storage) and marketing services (e.g., Newsletter handling). When transferring Personal Data outside the EEA, the Controller takes all measures aimed at ensuring the security of these data and in compliance with appropriate data protection standards, in particular through:
- applying standard contractual clauses approved by the European Commission.
- cooperation with entities processing personal data in countries in respect of which the European Commission has issued an adequate decision on ensuring an adequate level of protection of personal data.
2. The Controller will inform the User about the intention to transfer Personal Data outside the EEA.
§ 12. No Profiling
Users' Personal Data are not subject to profiling, nor any other form of automated decision-making.
§ 13. Final Provisions
1. The Policy is regularly reviewed and updated as necessary.
2. The Controller has the right to make changes to the Privacy Policy at any time, in particular to update its content and adapt it to the requirements imposed by law.
3. Any changes made by the Controller to the Privacy Policy will be published on the Website and marked with the effective date.
4. The current version of the Privacy Policy is effective from 8 December 2025.
5. Archival versions of the Privacy Policy are available at the following address: Strumber.eu