Last updated: 2 September 2026
This document describes the rules governing the processing of personal data and the use of cookies on the Frezpol-Serwis website.
1. Data controller
The controller of personal data is FREZPOL-SERWIS Spółka z ograniczoną odpowiedzialnością, ul. Sokołowska 159B, 08-110 Siedlce, Poland, NIP: 8212647331, REGON: 364941373, KRS: 0000627415.
For privacy matters, contact us at druty@frezpol-serwis.pl or by post at our registered office address.
2. Data that may be processed
The website is informational and does not include a contact form. Browsing its public pages does not require users to provide personal data.
If a user contacts us by telephone or through their own email application, we may process the data included in the message, particularly their email address, first and last name, telephone number, company name and correspondence content.
For persons authorized to use the “Stock availability” page, we process the email address, telephone number, account identifier, user name or surname and company name, depending on the information assigned to the account. The email address is used to initiate sign-in and the telephone number to send a one-time authentication code.
The server may store technical connection logs including the IP address, request date and time, requested URL, browser information and response status. These data are used to ensure security and diagnose website operation.
The stock module also stores a security event log containing the event time and type, user identifier and a cryptographic hash of the IP address. The log does not contain SMS codes, telephone numbers, access tokens or email addresses.
3. Purposes and legal bases for processing
- handling enquiries and correspondence to take action at the data subject’s request before entering into a contract or on the basis of the controller’s legitimate interest in communicating with customers and business partners;
- establishing, pursuing or defending claims on the basis of the controller’s legitimate interest;
- ensuring the security, availability and proper operation of the website on the basis of the controller’s legitimate interest;
- providing authorized customers with stock information and authenticating users by SMS code for the performance of a contract or actions connected with its performance, and on the basis of the controller’s legitimate interest in protecting commercial data against unauthorized access;
- recording sign-in attempts, successful sign-ins and sign-outs on the basis of the controller’s legitimate interest in preventing abuse, detecting incidents and ensuring accountability for access.
4. Data recipients and retention periods
Data may be entrusted to entities providing hosting, email, IT or legal services, solely to the extent required to provide those services. Data may also be disclosed to authorized public authorities where required by law.
To send and verify a one-time code, the telephone number is transferred to the SMSAPI service provider, LINK Mobility Poland sp. z o.o., with its registered office in Gliwice. The provider receives the data necessary to deliver the message and may process related transmission data under its service terms. Information about its processing rules is available in the SMSAPI privacy policy.
We retain correspondence for the time needed to handle the matter and subsequently until the applicable limitation periods for potential claims expire, or for the period required by law. Authorized user account data are retained for the duration of cooperation or until access is revoked, and subsequently for the period required to account for access and defend potential claims.
Sign-in event logs are normally retained for no longer than 90 days. Selected entries may be retained longer where necessary to investigate a security incident, comply with a legal obligation, or establish, pursue or defend claims. Other technical logs are retained according to the server’s configuration and security rules.
5. Data subject rights
Where provided for by law, data subjects have the right to access, rectify or erase their data, restrict processing, receive portable data and object to processing. Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.
A person who believes their data are processed unlawfully may lodge a complaint with the President of the Polish Personal Data Protection Office.
6. Cookies
The public part of the website does not use first-party analytics or marketing cookies and does not load tracking tools when a page is opened. Therefore, the website does not display a cookie consent banner.
The protected “Stock availability” page uses the necessary session cookie FRS_STOCK_V2. It is used solely to maintain a secure signed-in session, has settings that restrict script access and cross-site transmission, and is not used for analytics or advertising. The session expires when the browser is closed, the user signs out, or after the inactivity period set by the administrator.
Blocking this necessary cookie prevents signing in to the stock page. The browser may also retain technical data such as cached files according to its settings.
7. Google Maps
The map on the “Contact” page is not loaded automatically. A connection to Google Maps is established only after the user selects “Display map”. Google may then receive technical data such as the IP address and device information and may store or read its own cookies under its policies.
Before loading the map, users can read the Google Privacy Policy and information about how Google uses cookies.
8. Changes to this policy
This policy may be updated following changes to the website’s functionality, services used or applicable law. The current version is always published on this page.
