Respecting the right to privacy of individuals who have entrusted their personal data to Winnica Kazimierskie Wzgórza SP. Z O. O., we wish to assure you that we process the collected data in accordance with national and European laws and under conditions that guarantee its security.
To ensure transparency in data processing, we present the personal data protection policy in effect at Winnica Kazimierskie Wzgórza SP. z o.o., established pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter “GDPR”).
Data Controller
The controller of your personal data—that is, the entity that determines the purposes and means of processing—is WINNICA KAZIMIERSKIE WZGÓRZA SP. Z O. O., REGON 382098589, NIP 9522191587, KRS 0001156514, address: ul. Wylągi 35, 24-120 Kazimierz Dolny, Lubelskie Province, hereinafter referred to as the Controller.
Contact information: Email: winnica@kazimierskiewzgórza.pl Phone: +48 570 789 665.
For all matters regarding the processing of personal data and the exercise of your rights in connection with such processing at
, please contact us at the address or email address provided above.
What are the purposes and legal basis for processing your personal data, and for how long will it be processed?
The legal basis for processing your data for specific purposes is as follows:
| Purpose of data processing | Legal basis | Data processing period |
| Taking action prior to entering into a contract, as well as entering into and performing a contract with a customer or business partner | Article 6(1)(b) (regarding customers); Article 6(1)(f) of the GDPR (regarding individuals working with the Controller on behalf of a customer or business partner) | Until the expiration of the relevant agreement between the Customer and the Administrator, with the proviso that, in some cases, such data may also be processed after the expiration of that agreement, but only if permitted or required by applicable law or for the purpose of asserting claims. |
| Maintaining records, bookkeeping, and financial reporting. | Article 6(1)(c) of the GDPR | For the duration until the expiration of data retention obligations arising from legal provisions, in particular the retention of accounting documents (as a rule, for 5 years following the year in which the legal event occurred that required the issuance of the accounting document). |
| Handling complaints, requests, and claims. | Article 6(1)(b), (c), and (f) of the GDPR: The needto contact employees or associates of customers in connection with the handling of complaints, requests, and claims. | For the duration of the contract or until the expiration of the warranty period or the resolution of the complaint |
| Establishment, pursuit, and defense of claims. | Article 6(1)(f) of the GDPR: Processingof data of customers or business partners and their employees/associates in connection with the establishment, pursuit, and defense of claims. | For the duration until the expiration of the statute of limitations for claims arising from the contract—in accordance with applicable law. |
| Data processing under the Administrator profile on the Facebook social media platform. | Article 6(1)(f) of the GDPR The data is jointly controlled by the Controller and Facebook. The data will be processed until an objection to the processing is raised. | Handling day-to-day correspondence using the tools provided by Facebook, including Messenger, and conducting other marketing activities. |
If the document retention periods specified in the section “Record-keeping, Accounting, and Financial Reporting” are longer than the periods applicable to the pursuit of potential claims, the longer periods shall apply.
To whom will your personal data be disclosed?
Your data may be transferred to entities that process personal data on behalf of the Controller, including providers of external IT systems that support our operations, IT service providers, an entity providing accounting services—whereby such entities process data based on a contract with the Controller and exclusively in accordance with the Controller’s instructions. Your data may also be shared with banks, payment providers, and entities providing postal and courier services.
What are your rights regarding the processing of personal data?
You have the following rights regarding the processing of your personal data by the Controller:
- the right to access your data, including the right to obtain a copy of your data,
- the right to request the correction of data
- the right to erasure (in certain situations),
- the right to lodge a complaint with a data protection supervisory authority,
- the right to restrict data processing,
- the right to object to the processing of your data.
- right to data portability
If your data is processed based on your consent, you may also exercise the following rights:
- the right to withdraw consent to the extent that data is processed on that basis. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal.
To exercise the above rights, please contact the Data Controller.
Automated processing of personal data
Your personal data will not be used for automated decision-making (including profiling).
Do you have to provide the Administrator with your personal information?
Providing your data is necessary for entering into contracts, accounting for business activities, and enabling the Controller to comply with legal requirements. If your employer or another entity has designated you as a contact person in connection with the conclusion or performance of a contract with the Controller, your data will be processed to the extent disclosed by that entity (typically, this includes first name, last name, job title, email address, and phone number). In all other respects, the provision of data is voluntary.


