Terms and documents
Privacy and cookies policy
Pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR), OMNIRES Spółka z ograniczoną odpowiedzialnością hereby introduces its Privacy and Cookies Policy. This Policy is for information purposes only. It is not a source of rights and obligations for customers of OMNIRES sp. z o.o. or Users of the website www.omnires.com.
1. Who is the Data Controller?
The controller of your personal data is OMNIRES Spółka z ograniczoną odpowiedzialnością, with its registered office in Warsaw at ul. Solec 18, 00-410 Warsaw, entered in the Register of Entrepreneurs under KRS number: 0000088578 and Tax Identification Number (NIP): 5222626866, hereinafter referred to as the Controller.
The Controller has appointed a Data Protection Officer, who can be contacted by email at: [email protected] or by post at the Controller’s address given above, marked “Data Protection Officer.”
2. Data processing principles
The Controller attaches great importance to respecting Users’ rights, with particular regard to the right to privacy. The privacy policy set out below explains the principles applied by the Controller in the collection and processing of personal data. When collecting and processing personal data, the Controller adheres to all the following data processing principles and meets at least one of the conditions for the processing of personal data.
- Lawfulness, fairness and transparency;
- Purpose limitation;
- Data minimisation;
- Accuracy;
- Storage limitation;
- Integrity and confidentiality.
3. What data is collected by the Controller?
- Data collected during registration on the website and when using contact or complaint forms: first name and surname or company name, town/city, street, phone number and email address (and full address when registering in the professionals’ panel and when submitting a complaint), nature of the matter, internal complaint reference number, and data contained in attachments.
- Data collected automatically (relating to Users’ visits), in particular:
- IP address and approximate location determined on the basis thereof,
b) session identifiers,
c) type and version of the web browser,
d) operating system and language settings,
e) information about the device and its technical specifications,
f) date and time of the visit,
g) information about the subpages visited and the time spent on the website,
h) the source from which the User accessed the website,
i) information about clicks and other interactions with elements of the website.
4. For what purpose and on what legal basis will the data be processed?
Users’ personal data collected in connection with the use of the website by the Controller will be processed for the following purposes:
- To handle enquiries sent via the contact form – pursuant to Article 6(1)(f) of the GDPR, i.e. our legitimate interest in establishing and maintaining contact with you and responding to requests and enquiries,
- To register and manage an online store User account – pursuant to Article 6(1)(a) of the GDPR, i.e. on the basis of your freely given consent. Through your account, you can manage your personal data, view your order history and statuses, create a list of favourite products, manage delivery addresses and billing details, and use other features available via your account.
- Handling the sales process – pursuant to Article 6(1)(b) of the GDPR, i.e. to the extent necessary for the performance of a contract or to take steps at the User’s request prior to entering into a contract,
- Handling of complaints – on the basis of Article 6(1)(f) of the GDPR, i.e. our legitimate interest in processing the complaint and ensuring the high quality of our service, or Article 6(1)(c) of the GDPR, i.e. on the basis of legal provisions applicable to us (the Polish Civil Code),
- Marketing – pursuant to Article 6(1)(a) of the GDPR, i.e. your consent,
- Activities related to ensuring the security and functionality of the website – pursuant to Article 6(1)(f) of the GDPR, i.e. our legitimate interest, which is to ensure the security and reliability of the website,
- Statistical and archiving purposes – pursuant to Article 6(1)(a) of the GDPR, i.e. your consent,
- Managing services and planning meetings and events, including booking showroom visits – pursuant to Article 6(1)(f) of the GDPR, i.e. our legitimate interest, which is to provide the best possible customer service,
- Improving the quality of our services – pursuant to Article 6(1)(f) of the GDPR, i.e. our legitimate interest in monitoring the quality and evaluating our work,
- Establishing, exercising or defending against legal claims – pursuant to Article 6(1)(f) of the GDPR, i.e. our legitimate interest in defending our legal interests.
5. Who will be the recipients of the data and where will it be transferred?
The list of recipients of personal data processed by the Controller depends in each case on the scope of services used by the User. The list of recipients of personal data may also result from the User’s consent or legal provisions.
The recipients of your data may include the Controller’s Partners, maintenance service providers, IT and hosting service providers, as well as accounting, legal, courier, consultancy and marketing service providers. Architects registered on the website may also be recipients of your data.
Your personal data may also be collected and processed using cookies and similar technologies by our external providers of analytics, marketing, advertising and marketing automation services. As we use the services of providers based outside the European Economic Area, in particular in the United States, your personal data may be transferred to third countries. Such data transfers are carried out in accordance with the appropriate safeguards set out in Chapter V of the GDPR, in particular on the basis of a European Commission decision recognising an adequate level of protection (including under the EU–US Data Privacy Framework, provided the recipient holds the relevant certification) or – in the absence of such a decision – on the basis of standard contractual clauses adopted by the European Commission.
An up-to-date list of the service providers we use, along with information on the rules governing data transfers outside the European Economic Area, can be obtained by contacting the Data Protection Officer.
The website contains links to other websites and social media platforms, whose providers are separate controllers of your data. You can find information about how they process your data in the privacy policy on each of these sites.
6. For how long will the data be processed?
The period for which personal data is processed depends on the purpose for which the data is processed. The period for which the personal data will be stored is as follows:
- Data processed for the purposes of: handling enquiries sent via the contact form, managing services and scheduling meetings and events, improving the quality of services, and carrying out activities related to ensuring the security and functionality of the website – we will process this data for the period necessary to fulfil the purpose, but no longer than until the limitation period for claims expires,
- Data processed for the purpose of handling the sales process – we will process it for the period specified by law or until the limitation period for claims expires,
- Data processed for the purposes of: marketing, statistical and archiving activities – we will process this for the period necessary to fulfil the purpose of processing or until you withdraw your consent,
- Data processed for the purpose of establishing, pursuing or defending against claims – we will process this data until the limitation period for claims expires.
7. User Rights
Users have the right to:
- Request access to their personal data;
- Rectify their data;
- Request that incomplete personal data be completed, including by providing a supplementary statement;
- Have their data erased or restrict its processing;
- Object to the further processing of personal data;
- To have personal data transferred.
Users have the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of data processing carried out on the basis of the consent given prior to its withdrawal.
In the event of any doubts regarding the lawfulness of the Controller’s processing of personal data, the User has the right to lodge a complaint with the supervisory authority.
8. What are the consequences of not providing data?
Providing data is voluntary; however, without it, some features of the www.omnires.com website may not function correctly, or we may be unable to fulfil your request or respond to your enquiry.
9. How can I obtain information about data processing?
All correspondence regarding the processing of personal data should be addressed to the Controller at the address given in point 1 of this Policy, marked “Personal data”, via email to the Controller’s email addresses: [email protected], or to the Data Protection Officer’s email addresses: [email protected].
10. Use of cookies
When browsing the website www.omnires.com, depending on your browser settings, one or more cookies may be stored on your computer (end device). Cookies may be set by the Controller as well as by third parties with whom the Controller cooperates. It is advisable to familiarise yourself with the information below regarding cookies and how they are used.
Cookies and the User’s IP address may also be used to automatically determine the country from which the connection to the website is made. This information is used to tailor the website’s functionality to the User’s location, in particular to display the appropriate language version, the correct currency and the range of products and services available for that market. Selected or automatically assigned settings may be stored using cookies, enabling the website to retain the User’s preferences during subsequent visits.
The website www.omnires.com uses cookies to identify the User’s browser whilst they are using the site. Cookies contain small amounts of text that can only be read by the website that sends them. Thanks to the information collected, the Controller can obtain details on how often the User visits the website and which elements of it are of most interest to the User. The Administrator uses the data obtained to ensure the security and proper functioning of the website, to better tailor the website to Users’ needs, and for statistical and advertising purposes. These cookies cannot be used to infect a device with viruses or other malicious software (malware).
The Administrator uses two types of cookies:
- Session cookies: these are stored on the User’s device and remain there until the end of the session in that particular browser. The recorded information is then permanently deleted from the device’s memory. The mechanism of session cookies does not allow for the collection of any personal data or confidential information from the User’s device.
- Persistent cookies: these are stored on the User’s device and remain there until deleted. Closing a browser session or switching off the device does not remove persistent cookies from the User’s device. The way persistent cookies work does not allow for the collection of any personal data or confidential information from the User’s device.
The Website uses the following types of cookies:
- “essential" cookies, which enable the use of the services available as part of the Service; for example, authentication cookies used for services that require authentication as part of the Service;
- cookies used to ensure security, for example, to detect fraud in authentication procedures as part of the Service;
- “performance” cookies, which enable the collection of information about the use of the Service’s website;
- “functional” cookies, which ‘remember’ settings chosen by the User and personalise the User’s interface, e.g. in terms of the language or region from which the User originates, the font size, the appearance of the website, etc.
In many cases, the software used to browse the web (the browser) is set by default to allow cookies to be stored on the User’s device. Users of the website can change their cookie settings at any time. In particular, these settings can be adjusted to block the automatic handling of cookies in your web browser configuration or to be notified about them each time the User accesses the Service using the device. Detailed information on the options and methods for managing cookies can be found in the settings of the software (web browser).
Each individual cookie consists of four basic parts:
- Website name: the name of the domain or subdomain that set the cookie;
- Cookie name: the cookie has a name that is unique to the website that set it;
- Expiry date: some cookies expire when the browser is closed (session cookies), whilst others are automatically deleted only once the set expiry date has been reached (persistent cookies);
- Value: this is the information contained in the cookie that the website uses to ‘remember’ your previous visit.
Cookies store basic information required to display the content on the web pages correctly. Website Users may, at any time, stop providing this information to the website by deleting the cookies stored on their devices by the Administrator’s website. In this case, you should change the settings of the web browser you are currently using.
You have the right to refuse the storage and reading of cookies on your devices (computer, laptop, mobile phone). To do this, you must select the appropriate settings in your web browser’s options or withhold your consent if the application on the website asks for it. Configuring your browser to block the installation of cookies for specific websites selected by you, or for all websites, may result in the loss of certain functionalities that require the installation of cookies.
In accordance with the requirements of the Electronic Communications Law of 12 July 2024 and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), configuring your browser to allow the installation of cookies on your computer is deemed to constitute consent to the use of cookies (see links below). Information on managing cookies can be found at ( http://www.allaboutcookies.org/manage-cookies/ ) or ( http://wszystkoociasteczkach.pl/ ). You can manage cookies by selecting the appropriate sliders in the cookie banner (cookie settings) on our website.
The data controller uses the following cookies on the website:
| Cookie name | Duration | Cookie description |
| __utma | 2 years from creation/update | Used to distinguish between Users and sessions. The cookie is created when the JavaScript library is loaded, and no existing __utma cookies are present. The cookie is updated every time data is sent to Google Analytics. |
| __utmb | 30 minutes from creation/update | Used to identify new sessions / visits. The cookie is created when the JavaScript library is loaded, and no existing __utmb cookies are present. The cookie is updated every time data is sent to Google Analytics. |
| __utmc | session | Not used in ga.js. Set for interoperability with urchin.js. Historically, this cookie worked in conjunction with the __utmb cookie to determine whether the User was in a new session / visit. |
| __utmt | session | Used to throttle request rates. |
| __utmz | 10 minutes | Stores the source of visits or the campaign explaining how the User arrived at your website. The cookie is created when the JavaScript library is loaded and is updated every time data is sent to Google Analytics. |
| _ga | 6 months from creation / update | Used to distinguish between Users. |
| _gat | 1 minute | Used to throttle request rates. If Google Analytics is implemented using Google Tag Manager, this cookie will be named _dc_gtm_<property-id>. |
| _gid | 24 hours | Used to distinguish between Users. |
| counter[*] | 24 hours | Visit counter. |
| page_* | session | For pagination purposes. |
| cookiesPolicyDismissed | 30 years | Information on the cookie policy. |
| sid | session | Session identifier. |
§ 11. How is personal data protected?
The Controller’s databases are protected against unauthorised access by third parties employing appropriate technical or organisational measures.
12. Automated processing
Personal data may be used for marketing profiling, in particular to tailor marketing content, the products displayed, recommendations and communications to the User’s interests and activities. Such profiling does not result in decisions being made regarding an individual based solely on automated processing of data, which would produce legal effects concerning that individual or similarly significantly affect them within the meaning of Article 22 of the GDPR.
13. CHANGES TO THE PRIVACY POLICY
The Data Controller reserves the right to amend this Privacy Policy by publishing a new version on the website. Once amended, the Privacy Policy will be published on the website with a new date.
This version of the Policy is effective from 1 September 2019.
Below you will find detailed information regarding the processing of your personal data, depending on your relationship with the Controller:
- Information clause for job applicants,
- Information clause for website customers (customer service),
- Information clause for customers (telephone support),
- Information clause for business partners,
- Information notice for marketing purposes,
- Information clause regarding CCTV surveillance,
- Information notice regarding the sending of the newsletter.
- Information notice regarding showroom appointments