Privacy Policy

§ 1. Definitions
  1. Administrator - the entity operating the Website and processing personal data; its exact identification and contact details are indicated in § 2.
  2. Digital Services Act - Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on the digital single market for services and amending Directive 2000/31/EC (DSA).
  3. Personal Data - information about an identified or identifiable natural person through one or more specific factors including, but not limited to, physical, psychological identity, including device IP, internet identifier and information collected through cookies or other similar technologies.
  4. Policy Privacy Commissioner - this privacy policy.
  5. Regulations - Terms and conditions of the Service available at: [...].
  6. RODO - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU. L. 2016 No. 119, p. 1 as amended).
  7. Service - website available at https://rulity.pl.
  8. User - an entity that uses the Website and/or the services provided electronically (within the meaning of the Act on Provision of Services by Electronic Means) by the Administrator as part of the Website.
  9. The terms (with the exception of the Administrator) referred to above, which are used in the body of the Terms and Conditions, in the plural, shall also apply accordingly to the singular and vice versa.
  10. In the case of the use in the Rules and Regulations of proper names with a capital letter and not indicated in this paragraph of the Rules and Regulations, their definition indicated in the applicable provisions of Polish law shall be adopted.
§ 2. Data of the Administrator
  1. RULITY CONSULTING SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ is the administrator of the personal data with its registered office at ul. Chełmońskiego 22/1, 60-756 Poznań, entered in the register of entrepreneurs kept by the District Court Nowe Miasto and Wilda in Poznań, VIII Economic Division of the National Court Register, under KRS number: 0000893846, holding NIP: 7812019625, with the share capital of PLN 5,000.00.
  2. Address for correspondence: ul. Chełmońskiego 22/1, 60-756 Poznań.
  3. Contact e-mail address: biuro@rulity.pl
  4. Contact phone: +48 609 555 023, the cost of the call corresponds to the rate of the user's operator.
§ 3. General provisions
  1. In connection with the User's use of the Website, the Administrator collects, processes and stores personal data in accordance with this privacy policy.
  2. The personal data collected by the Administrator through the website is processed in accordance with the RODO and other applicable data protection legislation.
  3. Provision of Personal Data is voluntary, however, it is necessary, inter alia, in order to exercise rights resulting from applicable laws, to use services provided electronically (including, inter alia, the contact form from the „Contact” tab), to use the Website correctly and safely, to contact the Administrator.
  4. Users who provide the Administrator with personal data of third parties are also bound by the applicable legal provisions on the protection of Personal Data.
  5. In matters relating to the Administrator's processing of Personal Data, you can contact the Administrator using the Administrator's contact details set out in § 2 of the Privacy Policy.
  6. The controller has not appointed a Data Protection Officer (IODO/IOD).
  7. The Administrator shall, taking into account the technology available, make reasonable efforts to verify that the person with parental responsibility or custody of a child under 16 years of age who uses the Service has given or consented, in accordance with Article 8(2) of the RODO.
  8. For further information relating to the Service, please refer to the Terms and Conditions..
§ 4. Type of Personal Data processed
  1. Personal Data is processed by the Controller or recipients of Personal Data through:
    • Order Form, available on the Website: name, email address.
    • contact the Administrator at the Administrator's data indicated on the Website: e-mail address.
    • obtained through cookies or similar technologies within the Service: IP address, information about the web browser you are using.
§ 5. Aims and legal bases of the processing
  1. Users' Personal Data is processed for:
    • to send and reply to messages sent to the Administrator within the contact form from the „Contact Us” tab on the Website - legitimate business interest (Article 6(1)(f) RODO),
    • archiving documents, ensuring security within the Shop, fulfilling User requests under data protection legislation - on the basis of the necessity of the processing for the fulfilment of the Administrator's legal obligation (Article 6(1)(c) of the DPA),
    • in order to establish and pursue the Administrator's claims (if needed), on the basis of the Administrator's legitimate interest (Article 6(1)(f) of the DPA).
§ 6. Period of processing of Personal Data
  1. The period of processing of Personal Data by the Administrator depends on the type of service provided and the purpose of the processing. As a general rule, data are processed for the time necessary to fulfil the relevant purposes indicated in § 5 of the Privacy Policy or to fulfil other legal obligations. After the expiry of the processing period, the data are irreversibly deleted or anonymised.
  2. In addition to the above paragraph, Personal Data:
    • processed on the basis of separate consent, for the purposes of marketing the Administrator's products or services, sending surveys and forms, importing opinions from the Administrator's profiles on other websites - until you withdraw your consent or express your objection,
    • related to the analysis of network traffic, including identification of Users as currently logged in, maintenance of the User's session, remembering the User's choices, assessment and analysis of the User's activity (including information about links and references they decide to click on or other activities undertaken on the Website) - until cookies or similar technologies are deleted from the User's device; some Personal Data is not deleted when cookies are deleted from the device - in this situation the data will be processed until an objection is made to the Administrator,
    • to assert the Administrator's claims - unless otherwise provided by a specific provision, the period of limitation is six years, and three years for claims for periodic performance and claims relating to the conduct of business.
§ 7. Entitlements of personal data subjects
  1. The user has the right to:
    • request from the Administrator to inspect (access) your Personal Data stored by the Administrator, as well as to receive a copy thereof (Article 15 RODO) - You have the right to obtain the information contained in the Privacy Policy, including but not limited to. about the source and purposes of processing, the categories of data processed, the period of processing, the recipients of the Personal Data, as well as your rights under the RODO, the right to object, the Administrator's safeguards regarding Personal Data when transferred outside the European Union, the technologies used by the Administrator to collect and process Personal Data,
    • request the Administrator to rectify or correct their Personal Data (Article 16 of the RODO) - with regard to the request for rectification of data, when the User notices that the data is incorrect or incomplete,
    • request the Administrator to erase his/her Personal Data (Art. 17 RODO) - in the cases indicated in Article 17 of the Regulation, in particular when personal data are no longer necessary for the purposes for which they were collected or an effective objection to the processing of personal data has been lodged,
    • request the Administrator to restrict the processing (Article 18 RODO) of their Personal Data - in case: the Service User has reservations as to the accuracy of his/her data; he/she considers that the Administrator should not process his/her data, but at the same time does not want him/her to delete it; such Personal Data is no longer needed by the Administrator, while the Service User needs it in connection with the assertion of claims; the Service User has objected to the processing of his/her data, and it is the Administrator's duty to verify whether he/she should continue to process it,
    • object to the processing of his/her Personal Data - in exercising this right, the Service User is entitled to object, on grounds related to his/her particular situation, to the processing of his/her Personal Data by the Service User on the basis of legitimate interests pursued by the Seller; despite the objection, the Administrator is entitled to continue to process the Personal Data if he/she can demonstrate the existence of valid, legitimate grounds for the processing, overriding the interests, rights and freedoms of the Data Subject, or grounds for the establishment, investigation or defence of claims,
    • withdraw consent to the processing of your Personal Data at any time - withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of consent before its withdrawal,
    • request the transfer of your Personal Data to another organisation,
    • lodge a complaint in relation to the Administrator's processing of the User's Personal Data with the President of the Personal Data Protection Authority.
  1. In order to exercise the rights referred to above, you can send an appropriate email to the Administrator's contact details as indicated in § 2 of the Privacy Policy.
  2. The Administrator will deal promptly (up to 30 days) with the requests indicated in the previous paragraph regarding operations and activities on Personal Data.
§ 8. Recipients of Personal Data
  1. Users' Personal Data may be transferred:
    • to processors of Personal Data where the obligation to provide such data arises from applicable legislation, including but not limited to government authorities,
    • entities processing Personal Data on behalf of the Controller or in accordance with the Controller's instructions (including employees, associates and representatives, however subject to their confidentiality and responsibility for the Personal Data provided),
    • providers of IT, financial and accounting, legal, marketing services.
§ 9. Transfers of Personal Data outside the European Economic Area
  1. The controller may communicate Personal Data to the competent authorities or to third parties who request such information on a specific and sufficient legal basis.
  2. The Administrator transfers Personal Data outside the European Economic Area, however, only if this is necessary for the proper functioning of all the functionalities of the Service and with the assurance of an adequate degree of protection by these recipients, primarily by means of:
    • to have a place of establishment for these entities in countries for which a relevant decision of the European Commission has been issued concerning the determination of an adequate level of protection for Personal Data,
    • the use by these entities of standard contractual clauses issued by the European Commission,
    • the application by these entities of binding corporate rules approved by the competent supervisory authority.
§ 10. Security of Personal Data
  1. The Administrator conducts ongoing and appropriate risk analysis to ensure that Personal Data is processed by him in a secure manner - ensuring, in particular, that only authorised persons have access to the data and only to the extent necessary for the performance of the tasks. The Controller shall ensure that all operations on Personal Data are recorded and carried out only by authorised persons.
  2. The Administrator emphasises that no method of transferring data via the Internet or storing them electronically is fully secure. Therefore, the Administrator does not guarantee absolute protection of data, including Personal Data, from unauthorised disclosure.
§ 11. Cookies and similar technologies
  1. Within the scope of the Service, the Administrator collects and processes Personal Data contained in cookies and similar technologies.
  2. Cookies are small pieces of text that the Administrator or other cookie providers send to the User's browser, which the browser sends back the next time the User visits the Website or third party websites. These tools are used, among other things, to collect information about the User's device and his/her visit for security purposes. For more information, please visit https://pl.wikipedia.org/wiki/HTTP_cookie.
  3. In many cases, the web browsing software (web browser) allows cookies to be stored on the User's terminal device by default. The User may change their cookie settings at any time. These settings can be changed in particular in such a way as to block the automatic handling of cookies in the web browser settings or inform on their placement in the User's device each time. Detailed information on the possibility and methods of using cookies is available in the settings of your software (web browser) - usually in the „Help” section: Chrome, Firefox, Opera, Microsoft Edge, Safari, Safari (iPhone).
  4. The information obtained through cookies and similar technologies is not combined with the personal data of users provided through other channels, nor is it used to identify them by the Administrator.
  5. The Service uses the following types of cookies for the purposes set out below:
    • permanent cookies - these are stored on the User's device and remain there until they are deleted; they provide optimisation and selected settings for the Website,
    • session cookies - temporarily stored until the end of the browser session; they are necessary for the correct functioning of the Website.
  1. The Service uses:
    • essential cookies - necessary for the functioning of the Website, which cannot be switched off in order to use the Website,
    • analytical cookies - allow measuring the number of visits and gathering information about traffic on the Website, the data from them are used to improve the quality and operation of the Website; they may be used by the Administrator or provided by external cookie providers,
    • Functional cookies - allow marketing activities to be tailored to the User's needs and preferences; may be used by the Administrator or provided by third party cookie providers,
    • advertising cookies - used to promote products, also on other websites of third-party cookie providers, according to the relevance and preferences of the User, and prevent the duplication of advertising; may be used by the Administrator or provided by third-party cookie providers.
  1. The Service User consents to the cookies used within the Service, in particular in the window (banner) of the cookies. Consent to cookies is divided into consent to all cookies or consent to specific types of cookies, as indicated in the previous paragraph of the Privacy Policy, with the exception of essential cookies. The User may change the scope of consent to cookies at any time on the Website or remove them himself from his own terminal device. By using the Website with consent to all cookies, you consent to their use for the purposes set out in the Privacy Policy. Disabling or restricting the use of necessary cookies may result in the prevention of, or difficulty in using, some of the functionalities available on the Website and on the websites of third-party cookie providers used within the Website.
  2. In addition to cookies, the Administrator may also collect data customarily collected by web system administrators as part of so-called logs or log files.
  3. Some subpages within the Service and other means of communication made available by the Administrator may contain so-called „web beacons” (so-called electronic images). Web beacons make it possible to obtain information such as e.g. the IP address of the computer to which the page on which the web beacon has been posted has been loaded, the URL number of the page, the time the page was loaded, the type of browser, as well as information contained in cookies. This data will not be combined with the Personal Data provided by the User.
§ 12. Cookies and similar technologies from external providers

Category

Name

Supplier

Description

Plug-in (tool)

Google Analytics 4

Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Google Analytics is an analytical tool that allows the Administrator to analyse User activity on the Website, such as the number of visits, traffic sources, time spent on the website, sub-pages visited or device type. As part of providing this service, Google may collect information such as the User's IP address, cookie identifiers, browser and operating system data, as well as approximate geolocation data. This data may be processed on servers located outside the European Economic Area (EEA), with appropriate protection mechanisms (e.g. standard contractual clauses). The processing of personal data takes place on the basis of Article 6(1)(a) of the RODO, i.e. the voluntary consent of the User. Detailed information on the processing of personal data by Google Analytics is available at:
https://policies.google.com/privacy.

Plug-in (tool)

Google Ads

Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Google Ads is a tool that allows the Administrator to manage marketing activities, track conversions and conduct remarketing activities. Google Tag Manager allows various scripts (including Google Ads, Analytics, Facebook Pixel) to be dynamically loaded, while Google Ads enables the analysis of the effectiveness of advertising campaigns and the personalisation of ads. As part of the operation of these tools, Google may process data such as your IP address, device and browser identifiers, data on interactions with ads and data from cookies. This information may be transferred and processed outside the EEA with appropriate legal safeguards. The processing takes place on the basis of the User's consent (Article 6(1)(a) RODO). Detailed information on the processing of personal data by Google Ads and Tag Manager can be found at:
https://policies.google.com/privacy.

Plug-in (tool)

Google Translate

Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Google Translate is a translation tool that allows website owners, including e-commerce shops, to offer content in multiple languages by automatically translating the site. The service can be integrated through a built-in Google Translate widget (Google Website Translator), which allows users to select their preferred language for displaying content. When a user selects a translation language, Google Translate downloads the page, processes the content and displays the translated version while changing the source URL. The widget also allows the user's language preferences to be automatically remembered when navigating the site. As part of the tool's operation, the following data is collected: information on the selected language of translation, the user's language preferences, session identifiers, data on activity on the site (content viewed, forms submitted), browser and device information, IP address, identifiers for cookies used to remember language choices and settings (for example, cookies that store information on the selected language and prevent unnecessary re-translation on subsequent visits to the site). The system uses functional cookies to remember the user's choices and preferences (such as the language selected), to store session-related information (for example, the contents of a shopping cart in a translated version of an online shop), to enable translation functions or perform tasks requested by the user, and to optimise to maintain and improve the performance of the service. Google may also use cookies to analyse the effectiveness of the translations and improve the quality of the Google Translate service. Cookies associated with Google Translate typically last from a few months to 13 months, depending on the type of cookie and the location of the user. For the European Economic Area (EEA), Switzerland and the United Kingdom, the validity period for some cookies can be 13 months, while in other countries it can be up to 24 months. The processing of personal data is based on the user's consent (Article 6(1)(a) of the DPA) and the controller's legitimate interest (Article 6(1)(f) of the DPA) in providing translation functions and improving the user experience. Data may be processed by Google in data centres around the world, including outside the European Economic Area, in accordance with Google's privacy policy on cross-border data transfers. Google ensures compliance with international data protection laws, including the RODO. Users have the right to manage their cookie settings via g.co/privacytools and in their browser settings. Detailed information on Google's data processing is available at: https://policies.google.com/privacy and https://policies.google.com/technologies/cookies.

Plug-in (tool)

Meta Pixel

Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA

The Meta Pixel (formerly Facebook Pixel) is a marketing tool that allows the Administrator to monitor the effectiveness of ads displayed on platforms belonging to Meta (Facebook, Instagram) and to carry out remarketing activities. This tool allows to analyse the behaviour of Users after clicking on an advertisement and their interactions with the Website. For this purpose, data such as IP address, cookie identifiers, browser data, operating system and actions taken on the Website (e.g. filling in a form, clicking on a button) are collected. The data may be transferred outside the EEA and processed in accordance with Meta's data protection conditions. The processing of personal data takes place on the basis of the User's consent (Article 6(1)(a) RODO). Detailed information on Meta's data processing is available at:
https://www.facebook.com/privacy/policy.

 
§ 13. Changes to the Privacy Policy
  1. The Privacy Policy is regularly reviewed and updated as necessary due to the development of the Service or changes in legislation.
  2. The current version of the Privacy Policy has been adopted and is effective as of 29 January 2026.