Privacy Policy and GDPR
Rules for processing personal data, cookies and your rights under the GDPR.
📅 Last updated: 28 August 2026
1. General provisions
This Privacy Policy sets out the rules for processing personal data of users of the website www.scafo.pl (hereinafter referred to as the “Website”). This Policy has been prepared to fulfil obligations arising from:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR),
- the Polish Act of 10 May 2018 on the Protection of Personal Data,
- the Polish Telecommunications Law Act of 16 July 2004,
- the Polish Act of 18 July 2002 on the Provision of Electronic Services.
The Controller takes measures intended to protect users' privacy and the security of processed data.
2. Data Controller
The controller of personal data is:
SCAFO Sp. z o.o.
ul. S. B. Lindego 1C, 30-148 Kraków, Poland
NIP: 8172188821 | REGON: 380662933 | KRS: 0000738933
Email: biuro@scafo.pl
Telephone: +48 668 150 437
3. What data we process
Depending on the purpose of your contact, we may process the following personal data:
| Data category | Scope of data |
|---|---|
| Identification data | First name, surname |
| Contact details | Email address, telephone number, correspondence address |
| Activity data | History of enquiries, orders and submissions |
| Technical data | IP address, browser type, operating system, cookies |
4. Purposes and legal bases for processing
4.1. Contact via the form
Data provided through the contact form is processed in order to respond to the submitted enquiry. The legal basis is:
- Article 6(1)(a) GDPR – the user's consent to the processing of data for the purpose of providing a response,
- Article 6(1)(f) GDPR – the Controller's legitimate interest in handling enquiries and communicating with users.
4.2. Performance of orders and services
Data is processed for the purpose of fulfilling orders, preparing quotations and providing services. The legal basis is:
- Article 6(1)(b) GDPR – processing necessary for the performance of a contract or to take steps prior to entering into a contract.
4.3. Marketing and newsletter
Where separate consent has been given, data may be used for marketing purposes, including sending a newsletter. The legal basis is:
- Article 6(1)(a) GDPR – the user's voluntary consent.
4.4. Statistical and analytical purposes
Technical data (for example, an IP address) is processed to analyse website traffic and improve the operation of the Website. The legal basis is:
- Article 6(1)(f) GDPR – the Controller's legitimate interest in analysing and optimising the Website.
5. Data retention periods
Personal data is stored for the period necessary to fulfil the purpose for which it was collected and subsequently for the period required by applicable law:
| Purpose of processing | Retention period |
|---|---|
| Performance of a contract / order | 5 years from completion |
| Correspondence and enquiries | Until consent is withdrawn or claims become time-barred |
| Marketing purposes (consent) | Until consent is withdrawn |
| Analytical purposes (cookies) | In accordance with the cookie policy (maximum 12 months) |
| Accounting data | 5 years from the end of the tax year |
6. Your rights under the GDPR
Each user has the following rights:
- Right of access – you may obtain information about personal data being processed.
- Right to rectification – you may request correction of inaccurate data.
- Right to erasure (“right to be forgotten”) – you may request erasure where the data is no longer necessary.
- Right to restriction of processing – you may request that processing be restricted.
- Right to data portability – you may receive your data in a machine-readable format.
- Right to object – you may object to processing for marketing purposes.
- Right to withdraw consent – at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint – with the President of the Personal Data Protection Office (UODO) in Poland.
To exercise your rights, please contact us at: biuro@scafo.pl
7. Recipients of personal data
Personal data may be disclosed to the following categories of recipients:
- Processors – companies providing hosting, IT, accounting, courier and postal services,
- Entities authorised by law – public administration authorities, courts and law-enforcement authorities,
- Business partners – only to the extent necessary to provide services (for example, material suppliers).
All recipients of personal data are required to maintain confidentiality and process data in accordance with applicable law.
8. Cookies
The Website uses cookies to ensure proper operation, analyse traffic and personalise content.
8.1. What are cookies?
Cookies are small text files stored on a user's device while using the Website. They allow the device to be recognised and the Website to be adapted to the user's preferences.
8.2. Types of cookies
| Type | Description | Retention period |
|---|---|---|
| Necessary | Enable the Website to function correctly (for example, remembering a session). | Until the browser is closed |
| Functional | Remember user preferences (for example, language and settings). | Up to 12 months |
| Analytics | Used to analyse website traffic (for example, Google Analytics). | Up to 12 months |
| Marketing | Used for advertising targeting and marketing. | Up to 12 months |
8.3. Managing cookies
You can change cookie settings in your browser at any time. You may block all or selected cookies, although doing so may affect some Website functions.
Instructions for common browsers:
- Google Chrome: Settings → Privacy and security → Cookies and other site data
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
- Microsoft Edge: Settings → Cookies and site permissions
- Safari: Preferences → Privacy → Manage Website Data
9. Data security
The Controller applies technical and organisational measures intended to protect personal data against unauthorised access, loss, destruction or damage. These include:
- Encrypted connection (SSL certificate),
- Regular software updates,
- Access controls,
- Staff training in data protection.
10. Transfers outside the EEA
Personal data is not transferred outside the European Economic Area (EEA) unless this is necessary to provide a service (for example, when using Google Analytics tools, data may be transferred to the United States on the basis of standard contractual clauses).
11. Changes to this Privacy Policy
The Controller reserves the right to amend this Privacy Policy. Changes will be communicated by publishing an updated version on the Website. The date of the latest update is shown at the top of this document.
12. Contact regarding personal data
For matters relating to personal data protection, please contact:
SCAFO Sp. z o.o.
ul. S. B. Lindego 1C, 30-148 Kraków, Poland
Email: biuro@scafo.pl
Telephone: +48 668 150 437
Every user has the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).
Back to home page