Privacy Policy – Contact Form

The Controller of your personal data is Storware sp. z o.o., ul. Bakalarska 15A U2, 02-212 Warsaw. 

Your personal data shall be processed for the following purpose: 

  • to respond to your inquiries and to maintain contact with you – on the basis of Article 6(1)(f) of the GDPR, i.e. the Controller’s legitimate interest consisting in handling enquiries and communications; 
  • to take steps at your request prior to entering into a contract, where the inquiry concerns an offer or services – on the basis of Article 6(1)(b) of the GDPR. 

Provision of data is voluntary; however, providing data marked as required is necessary to respond to the inquiry. 

The data shall be processed for the period necessary to handle the inquiry, and thereafter for the period necessary to secure or pursue any potential claims, in accordance with applicable law. 

Recipients of the data may include entities that support the Controller in operating the website, handling inquiries, and providing IT infrastructure, under appropriate agreements and in accordance with applicable law. 

To the extent provided for by the GDPR, you have the right to access your data, to have it rectified or erased, to restrict processing, and to object to the processing. In cases set out in the GDPR, you also have the right to data portability. 

If you believe that the processing of your personal data infringes the provisions of the GDPR, you have the right to lodge a complaint with the President of the Personal Data Protection Office. 

For matters related to the processing of personal data, you can contact the Controller at compliance@storware.eu

Detailed information on the processing of personal data can be found in the Privacy Policy. 

Privacy Policy

§1 DEFINITIONS 

  1. Controller – Storware sp. z o.o. with its registered office in Warsaw, ul. Bakalarska 15A U2, 02-212 Warsaw, which determines the purposes and means of the processing of personal data. 
  1. Personal data – any information related to an identified or identifiable natural person, in accordance with Article 4(1) of the GDPR. 
  1. Policy – this Privacy Policy. 
  1. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data. 
  1. User – each natural person using the Controller’s website, including persons using the contact form, registering an account or downloading materials, documents or licences. 
  1. Web Platform – the website or websites operated by the Controller, through which the User may use the functionalities offered, including registering an account and downloading materials or licences. 

§2 DATA CONTROLLER AND CONTACT 

The Controller of personal data is: 

Storware limited liability company 

ul. Bakalarska 15A U2 

02-212 Warsaw 

Poland 

For matters related to the processing of personal data, please contact us at the e-mail address: compliance@storware.eu

§3 HOW AND FOR WHAT PURPOSE WE COLLECT PERSONAL DATA 

Each User may provide their personal data to the Controller, in particular via forms available on the Web Platform, during account registration, when downloading materials or licences, as well as when contacting the Controller. 

Personal data may be processed in particular for the purpose of: 

  1. handling the contact form and responding to the inquiry – pursuant to Article 6(1)(f) of the GDPR, i.e. the Controller’s legitimate interest in handling inquiries and maintaining communication; 
  1. taking steps aimed at concluding a contract or performing a contract – under Article 6(1)(b) of the GDPR; 
  1. for the creation and administration of User Account – under Article 6(1)(b) of the GDPR, where necessary for the provision of the Web Platform’s functionality; 
  1. enabling the downloading of materials, documents, software or licences – under Article 6(1)(b) of the GDPR; 
  1. compliance with the legal obligations to which the Controller is subject – under Article 6(1)(c) of the GDPR; 
  1. ensuring the security of the Service, IT systems and data, and preventing abuse – on the basis of Article 6(1)(f) GDPR; 
  1. establishing, pursuing, or defending against claims – on the basis of Article 6(1)(f) of the GDPR; 
  1. conducting analyses regarding the use of the Web Platform and improvements thereof, if the solutions used require an appropriate legal basis or consent – in accordance with applicable law; 
  1. the conduct of marketing activities, where undertaken – on an appropriate legal basis, including consent where required. 

The Controller processes data in accordance with the principles of lawfulness, fairness, transparency, data minimisation, purpose limitation, accuracy, storage limitation, and integrity and confidentiality. 

The provision of data is, as a general rule, voluntary; however, providing data marked as required may be necessary to use specific functionality of the Web Platform, in particular to create an account, download materials or respond to inquiries 

§4 WHAT DATA WE PROCESS 

Depending on how the Web Platform is used, the Controller may process, in particular: 

  • First name and surname; 
  • email address; 
  • data concerning User’s account; 
  • company or organisation details, if provided; 
  • data concerning downloaded materials, documents or licences; 
  • information provided in contact forms; 
  • IP address; 
  • device and web browser data; 
  • data concerning activity on the Web Platform; 
  • technical information related to the use of the Web Platform;. 

The Controller limits the scope of the data processed to that which is adequate, relevant and necessary to achieve the specified purposes. 

§5 SECURITY OF PERSONAL DATA 

The Controller implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration, disclosure, or other unlawful processing. 

As part of the security measures in place, the Controller may, in particular, use: 

  • access control and permissions management; 
  • data transmission encryption using SSL/TLS protocols; 
  • authentication mechanisms and account security measures; 
  • monitoring and logging of security-related events; 
  • security incident management; 
  • regular analysis and risk assessment; 
  • measures ensuring business continuity and data availability. 

Access to personal data is granted solely to authorised persons or entities that possess an appropriate legal basis for the processing thereof. 

The Controller carries out periodic assessments of the security measures in place and adjusts them to the level of risk. 

§6 TO WHOM WE MAY DISCLOSE DATA 

Personal data may be transferred to entities supporting the Controller in the operation of its business and the Web Platform, in particular: 

  • to providers of IT services, hosting and cloud infrastructure; 
  • to providers of SaaS systems and tools used for the operation of the Web Platform; 
  • to providers of customer service and communication systems; 
  • to entities supporting the distribution of materials, documents or licences; 
  • to entities providing accounting, legal, audit and advisory services; 
  • to entities supporting the operation and maintenance of the website ; 
  • to providers of analytics or marketing services, if used; 
  • public authorities or other entities authorised by law. 

Entities processing data on behalf of the Controller process the data under appropriate agreements and solely to the extent necessary to perform the tasks entrusted to them. 

In the event of a reorganisation of the Controller’s operations, a merger, transformation, sale of part of the business, or other similar processes, data may be transferred to entities participating in such a process, to the extent permitted by applicable law. 

§7 TRANSFER OF DATA OUTSIDE THE EEA 

Personal data may be transferred outside the European Economic Area (EEA) where this is necessary in connection with the Controller’s use of services from providers that are based outside the EEA or that utilise infrastructure outside the EEA. 

In such a case, the Controller ensures the use of an appropriate GDPR-compliant data transfer mechanism, in particular: 

  • a decision of the European Commission establishing an adequate level of protection; 
  • standard contractual clauses (SCC); 
  • other mechanisms provided for in Chapter V of the GDPR. 

§8 DATA RETENTION PERIOD 

Personal data is stored for the period necessary to achieve the purpose for which it was collected. 

In particular: 

  1. The data provided via the contact form is retained for the period necessary to handle the enquiry, and thereafter for the period necessary to secure or pursue any potential claims; 
  1. data related to the User’s account is stored for the duration of the account’s existence, and after deletion thereof, for the period necessary to fulfil legal obligations and to secure or pursue potential claims; 
  1. data related to the performance of contracts is retained for the period required by law and for the period necessary to secure or pursue any potential claims; 
  1. Data processed on the basis of consent is retained until that consent is withdrawn, unless further processing has another legal basis. 

After the appropriate period has elapsed, the data ia deleted or anonymised, unless further retention is required by law. 

§9 USER RIGHTS 

Each user is entitled, within the scope provided by the GDPR, to: 

  • obtain information on the processing of their personal data 
  • access their personal data; 
  • rectify inaccurate or incomplete data; 
  • request data deletion; 
  • request restriction of processing; 
  • lodge an objection to the processing of data; 
  • data portability – in cases specified in the GDPR; 
  • withdraw their consent to the processing of data, if such consent is the basis for processing  
  • lodge a complaint with the President of the Personal Data Protection Office. 

The right to object to processing based on the Controller’s legitimate interests may be exercised on the terms set out in Article 21 of the GDPR. 

§10 EXERCISE OF RIGHTS 

A request to exercise rights may be submitted: 

  • electronically, to the address [email address]; 
  • in writing, to the Controller’s registered office address. 

The Controller takes appropriate steps to verify the identity of ech person submitting a request, where this is necessary for data security. 

The Controller responds to requests within the time limits set out in the GDPR 

§11 DATA OF WEBSITE VISITORS 

When using the Web Platform, technical information relating to the device and how the website is used may be collected automatically, in particular: 

  • IP address; 
  • browser type and version; 
  • operating system; 
  • device type; 
  • language settings; 
  • screen resolution; 
  • date and time of the visit; 
  • information about the subpages visited; 
  • information about the source from which the website was accessed; 
  • data relating to activity on the Web Platform 

The scope of the automatically collected data depends on the technologies used and the configuration of the Web Platform. 

These data may constitute personal data if it allows the user to be identified. 

Technical data may be processed, in particular, for the purpose of: 

  • ensuring the proper functioning of the Web Platform; 
  • ensuring the security of the Web Platform and IT infrastructure; 
  • detection and prevention of abuse; 
  • conducting statistical analyses; 
  • improving the functionality and performance of the Web Platform 

§12 COOKIES AND SIMILAR TECHNOLOGIES 

The Web Platform may use cookies and similar technologies. 

Depending on their function, the following may be used: 

  • necessary cookies – required for the proper functioning of the Web Platform, including maintaining sessions and using certain features; 
  • analytical cookies – used to analyse how the Service is used and to improve it; 
  • marketing cookies – used for marketing purposes, if used and if the User has given the consent required by law. 

To the extent that the use of certain cookies requires the User’s consent, such consent is obtained through an appropriate consent management mechanism. 

Users  can also manage cookie settings via their browser settings. 

Detailed information on the cookies used, their providers, purposes, and retention periods may be set out in a separate Cookie Policy or in the consent management panel. 

§13 AUTOMATED DECISION-MAKING AND PROFILING 

The Controller does not make decisions concerning Users that are based solely on automated processing, including profiling, which produce legal effects concerning them or otherwise significantly affect them, unless the User is separately informed thereof in accordance with applicable law. 

If, in the future, the Controller implements such solutions, this Policy will be updated accordingly. 

§14 FINAL PROVISIONS 

The Controller reserves the right to update this Privacy Policy, in particular in the event of: 

  • changes to the legislation in force; 
  • changes in the manner or scope of data processing; 
  • changes to the functionality of the Web Platform; 
  • changes in the suppliers or technologies used. 

The current version of the Privacy Policy is published on the Web Platform. 

Date of last update: 20/08/2026 

Ready to protect your data?