Controller
The data controller is ŻARMED SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Ogrodowa 14, 42-311 Żarki-Letnisko, Poland, VAT/NIP 5772007447.
Company registration details: KRS: 0001253899; NIP: 5772007447; share capital: PLN 30,000.00. Registry court: Sąd Rejonowy w Częstochowie, XVII Wydział Gospodarczy Krajowego Rejestru Sądowego.
Data and purposes
The contact form processes the name/company, email address, optional phone number, message content and technical security data. Data is used to answer enquiries, prepare quotations, perform contracts, comply with legal obligations and protect legitimate business and security interests.
Legal grounds
Depending on the context, processing is based on GDPR Article 6(1)(b), 6(1)(c) or 6(1)(f). Consent is used only where a function expressly requires it.
Form security
A necessary PHP session, CSRF protection, mathematical CAPTCHA and rate limiting protect the form. Messages are not stored in the website content database after submission; they are delivered to the configured mail system.
Recipients and external services
Hosting, email, IT and security providers may process data on the controller’s behalf. OpenStreetMap is embedded directly in the location section. Loading the map may send the IP address and standard browser headers to OpenStreetMap infrastructure. Google Fonts supplies Poppins and the footer retrieves a logo from barcoo.pl; these connections may disclose the IP address and standard browser headers to the respective providers.
Retention
Data is retained only as long as needed to handle the enquiry, perform contractual/legal duties and protect against claims. Server logs follow the hosting provider’s operational retention policy.
Your rights
You may request access, rectification, erasure, restriction and, where applicable, portability; you may object to processing based on legitimate interests and complain to the competent supervisory authority.
Cookies and storage
No advertising or analytics cookies are installed by this package. A necessary PHP session supports security. The privacy choice can be stored in browser localStorage.
International transfers
Some external providers may use global infrastructure. Where data is transferred outside the EEA, the relevant provider is responsible for an appropriate GDPR Chapter V transfer mechanism.
Automated decisions
The website does not use marketing profiling or solely automated decisions producing legal or similarly significant effects.
Security and changes
The website uses HTTPS when configured, session protection, CSRF tokens, CAPTCHA, input validation and access controls. This policy may be updated when services, processing or law change.