PRIVACY AND COOKIE POLICY

sowosz.com online store

Version 2.0 · effective from 5 August 2026

We want you to know what happens to your data when you visit our website, ask us for a quotation for a staircase, or place an order. We have written this in plain language, without unnecessary legal jargon.

  1. Which laws apply to you

We are established in Poland and have no establishment outside Poland. This means:

  • All of our processing of personal data is governed by Regulation (EU) 2016/679 (the “EU GDPR”), together with Polish national law — in particular the Act of 10 May 2018 on the Protection of Personal Data and the Act of 12 July 2024 (Electronic Communications Law), which governs cookies and electronic marketing.
  • If you are located in the United Kingdom, our processing of your personal data is additionally governed by the UK GDPR (as defined in section 3(10) of the Data Protection Act 2018), by virtue of Article 3(2)(a) UK GDPR, together with the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (“PECR”).
  • If you are located in another country outside the European Economic Area, we still apply the standards described in this policy to your data. Local law in your country may give you additional rights, which we will honour where they apply to us.

Wherever this policy refers simply to “the GDPR”, the statement applies equally under the EU GDPR and the UK GDPR, because the two are substantially identical on that point. Where the two diverge, we say so explicitly.

If you are a consumer in the EEA, please also note that under Article 6 of the Rome I Regulation you keep the protection of the mandatory consumer-law provisions of the country where you habitually reside, regardless of the law we apply to the contract itself.

  1. Who is the controller of your data

The controller of your personal data is:

Name

Przedsiębiorstwo Produkcyjno-Usługowo-Handlowe „SOWOSZ” Sp. z o.o.

(a limited liability company incorporated under Polish law)

Address

ul. Wadowicka 86, 32-551 Jankowice, Poland

Registration

KRS 0000182999 · VAT ID PL6280001480 · REGON 003445122

E-mail

biuro@sowosz.pl

Telephone

Staircases: +48 33 841 08 18, +48 602 668 242

Sawmill / timber products: +48 33 841 25 59

We have not appointed a Data Protection Officer — we are not required to do so under Article 37 GDPR. For any matter concerning personal data, please write to biuro@sowosz.pl marking your message “GDPR”, or to our registered address above.

  1. Who this policy covers and where we get your data

This policy applies to people who:

  • visit sowosz.com;
  • submit an enquiry through the “Enter your own dimensions” form or the contact form;
  • write to us directly by e-mail or call us;
  • create an account and place an order in our online store;
  • receive a quotation from us prepared in our ERP system;
  • submit a complaint, take part in a competition, or leave us a review;
  • act as a contact person for our business partners, suppliers, or fitters.

In the vast majority of cases we receive data directly from you. Occasionally we may receive it from your employer or business partner (if you are a contact person on the company side) or from public registers.

If you buy our products through a marketplace — currently Allegro, Erli, Castorama or Leroy Merlin, among others — we receive the data needed to fulfil the order from the operator of that marketplace. This is typically your name, delivery address, contact details, the order number and its contents, and, if you request an invoice, your billing details. We process this data in order to fulfil the order, account for it, and handle any complaint, on the terms set out in section 4. The list of marketplaces may change over time.

  1. Why we process your data and on what legal basis

The table below is the most important part of this policy. It sets out why we process data, on what legal basis, and how long we keep it.

Purpose

Legal basis

Retention period

Answering an enquiry from the “Enter your own dimensions” form, the contact form, an e-mail or a phone call — including preparing a free quotation

Art. 6(1)(b) GDPR — steps taken at your request prior to entering into a contract;

Art. 6(1)(f) GDPR (our legitimate interest) — if you write on behalf of a company

12 months from the last contact in the matter. If an order follows — as set out in the rows below

Preparing and sending you a quotation from our ERP system (system.sowosz.pl) in response to your enquiry

Art. 6(1)(b) GDPR — pre-contractual steps taken at your request

Validity period of the quotation plus 12 months

Checking whether the message containing the quotation was accepted by your mail server and whether we received a delivery failure notice (Elastic Email service)

Art. 6(1)(f) GDPR — our legitimate interest in confirming that the quotation was sent correctly

Available only in the Elastic Email administration panel for 7 days after the message is sent. We do not copy it to any other system

Checking whether the message was opened and whether links in it were clicked (tracking pixel and tracking links provided by Elastic Email)

Art. 6(1)(f) GDPR — our legitimate interest in technically verifying that a quotation sent at your request displayed correctly and that its links work. You may object to this processing at any time (Art. 21(1) GDPR)

Available only in the Elastic Email administration panel for 7 days after the message is sent. We do not copy it to any other system and we do not build a customer profile from it

Maintaining a suppression list: addresses that returned a permanent delivery failure (non-existent address or non-existent mailbox), addresses reported as unsolicited mail, and addresses of people who have opted out of our messages

Art. 6(1)(c) GDPR in conjunction with Art. 21(3) and Art. 5(2) GDPR — our obligation to respect your objection and to demonstrate that we have done so; Art. 6(1)(f) GDPR — our legitimate interest in maintaining an accurate address database

For as long as we send messages at all — we must keep the address precisely so that we do not write to you again. We use it for no other purpose

Operating your account in the online store

Art. 6(1)(b) GDPR — performance of the account agreement

Until the account is deleted by you, or by us at your request

Concluding and performing the sales contract: accepting the order, manufacturing, payment, delivery and any installation

Art. 6(1)(b) GDPR — performance of a contract

Until the order is completed, and then for the limitation period for claims (see below)

Issuing invoices, tax settlements and bookkeeping

Art. 6(1)(c) GDPR in conjunction with Polish accounting and tax legislation, which applies to us as a Polish company

5 years from the end of the calendar year in which the tax payment deadline fell

Handling complaints, notifications that goods do not conform to the contract, withdrawals from the contract, and warranty claims

Art. 6(1)(c) GDPR in conjunction with applicable consumer protection legislation — Polish law and, where they apply to you, the mandatory consumer rules of your country of residence

Until the complaint procedure is concluded, and then for the limitation period for claims

Establishing, exercising or defending legal claims

Art. 6(1)(f) GDPR — our legitimate interest

Until the limitation period expires: as a rule 6 years for consumers and 3 years in business-to-business relations under Polish law, unless a longer or shorter period applies under the law of your country

Sending our customers messages asking for a review of a completed order, and invitations to competitions

Art. 6(1)(a) GDPR — your consent, together with the national rules implementing the ePrivacy Directive 2002/58/EC — in Poland Art. 398(1) of the Electronic Communications Law, and in the United Kingdom regulation 22 PECR

Until you withdraw consent or object. We keep proof of consent and of its withdrawal for as long as we need it to demonstrate compliance

Running competitions: selecting the winner, awarding the prize, tax obligations

Art. 6(1)(b) GDPR (competition rules) and Art. 6(1)(c) GDPR (tax obligations)

Until the competition is settled; tax records as set out in the bookkeeping row

Cookies and similar technologies used for analytics, personalisation and marketing (Google, Meta, Pinterest, CallTracker, YouTube)

Art. 6(1)(a) GDPR — your consent, together with Art. 399(1) of the Polish Electronic Communications Law and, for users in the United Kingdom, regulation 6 PECR

As set out in the cookie declaration (most often up to 13 months) or until you withdraw consent

Cookies strictly necessary for the website, the shopping basket, logging in, and remembering your choice in the consent banner

Art. 6(1)(f) GDPR — our legitimate interest. These are exempt from the consent requirement under Art. 399(3) of the Polish Electronic Communications Law and under Schedule A1 PECR

Browser session or up to 12 months

Keeping the website secure, preventing abuse and spam, server logs

Art. 6(1)(f) GDPR — our legitimate interest

Up to 12 months

Demonstrating that we comply with the GDPR (accountability), including maintaining records of consents and requests

Art. 6(1)(c) GDPR in conjunction with Art. 5(2) GDPR

For as long as we need it to demonstrate that we acted lawfully — as a rule until the limitation period for related claims expires

  1. What data we collect

We collect only the data we genuinely need:

  • identification and contact details: name and surname (or company name), e-mail address, telephone number;
  • technical details of the staircase you are planning: opening dimensions, height, type and direction of the flight, and the content of your message;
  • data needed to fulfil an order: delivery address, installation address, billing details (including VAT number), and bank account number for refunds;
  • records of orders, quotations, complaints and correspondence history;
  • account data: username, password stored only as an irreversible cryptographic hash, settings, list of favourite products;
  • technical data: IP address, cookie identifier, browser and device type, approximate location at city level, referral source, pages visited;
  • data about your interaction with our e-mails: delivery, opening, link clicks, and opt-outs.

We do not collect, and do not want to collect, special categories of personal data (Art. 9 GDPR), such as data about health, opinions or beliefs. Please do not include such information in messages you send us.

  1. Do you have to provide your data

Providing data is voluntary, but in some situations it is necessary:

  • without an e-mail address or telephone number we cannot answer your enquiry or prepare a quotation;
  • without the data required for delivery, installation and payment we cannot fulfil an order — some of it is needed to perform the contract, and some is required of us by tax and accounting law;
  • consent to marketing cookies and to review-request messages is entirely optional — withholding it does not affect your ability to buy from us or the price you pay.
  1. Who we share data with

We do not sell your data. We share it only with parties we need in order to run our business, and only to the extent necessary. These are:

Category of recipient

Examples and role

IT and hosting providers

The company hosting sowosz.com and our e-mail, the supplier and maintainer of our ERP system (system.sowosz.pl), and Cloudflare (site protection and acceleration) — acting as processors under data processing agreements

E-mail delivery provider

Elastic Email — sends and tracks delivery of the quotation messages generated in our ERP system

Cookie consent management

Cookiebot (Usercentrics A/S, Denmark) — operates the consent banner and the consent record

Analytics and advertising providers

Google Ireland Ltd. (Google Analytics, Google Ads, Google Tag Manager, Google Maps, YouTube), Meta Platforms Ireland Ltd. (Facebook pixel, Instagram), Pinterest, and the provider of the CallTracker service (measuring the effectiveness of telephone campaigns)

Carriers and installation firms

Courier and transport companies and the fitters we work with — they receive the data needed for delivery or installation

Payment providers and banks

Processing payments for orders and refunds

Accounting and legal advisers

Our accounting office, tax adviser and law firm — in relation to settlements and any disputes

Marketplace operators

Marketplaces and stores where we offer our products — currently Allegro, Erli, Castorama and Leroy Merlin, among others. If you buy through them, the marketplace operator is a separate controller in respect of running its own platform and your account there, and applies its own privacy policy. The list may change

Public authorities

Only where the law requires us to disclose data (for example tax authorities, courts, or the police)

Joint controllership. In respect of the statistics for our Facebook, Instagram and Pinterest profiles, and in respect of data collected by those services’ pixels, we act as joint controllers together with the operators of those platforms. The essence of those arrangements is published by the platforms themselves — please refer to their privacy policies. You may exercise your rights both against us and against the platform operator.

  1. Transfers outside the EEA and the UK

Some of our providers — in particular Google, Meta, Pinterest and Elastic Email — are established in, or process data in, countries outside the European Economic Area, principally the United States.

Where this happens, the transfer takes place:

  • on the basis of European Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection under the EU–US Data Privacy Framework — provided the recipient concerned appears on the list of certified organisations maintained by the U.S. Department of Commerce (dataprivacyframework.gov); or
  • in all other cases, and should that decision cease to have effect — on the basis of the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (Art. 46(2)(c) GDPR), supplemented by additional safeguards. For personal data subject to the UK GDPR we use the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

You can obtain a copy of the safeguards we rely on by writing to biuro@sowosz.pl.

  1. Your rights

In connection with the processing of your data you have the following rights:

  • the right of access to your data and to obtain a copy of it (Art. 15 GDPR);
  • the right to rectification and completion of your data (Art. 16 GDPR);
  • the right to erasure, the “right to be forgotten” (Art. 17 GDPR);
  • the right to restriction of processing (Art. 18 GDPR);
  • the right to data portability, where we process data by automated means on the basis of consent or a contract (Art. 20 GDPR);
  • the right to object to processing based on our legitimate interest (Art. 21(1) GDPR);
  • an absolute right to object to direct marketing — once you exercise it we stop processing your data for that purpose immediately (Art. 21(2) GDPR);
  • the right to withdraw consent at any time — withdrawal does not affect the lawfulness of processing carried out before it (Art. 7(3) GDPR);
  • the right to lodge a complaint with a supervisory authority (see section 9.1 below).

How to exercise these rights: write to biuro@sowosz.pl or to our registered address. We respond without undue delay and no later than one month. In particularly complex cases we may extend that period by a further two months, and we will tell you if we do. Exercising your rights is free of charge. If you are not satisfied with how we have handled your request, you may complain to us first, and we will acknowledge your complaint and tell you the outcome.

9.1. Which supervisory authority you can complain to

This depends on where you are located.

If you are in the European Economic Area: under Art. 77 GDPR you may lodge a complaint with the supervisory authority of the Member State where you habitually reside, where you work, or where the alleged infringement took place. Because our only establishment is in Poland, the lead supervisory authority for us under the one-stop-shop mechanism (Art. 56 GDPR) is:

Authority

Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office)

Address

ul. Stawki 2, 00-193 Warsaw, Poland

Website

uodo.gov.pl

If you are in the United Kingdom: you may complain to the Information Commissioner’s Office under section 165 of the Data Protection Act 2018. (Please note that Article 77 of the UK GDPR was repealed by the Data (Use and Access) Act 2025, so the right to complain now arises under the Data Protection Act 2018.)

Authority

Information Commissioner’s Office (ICO)

Address

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom

Website

ico.org.uk

Helpline

0303 123 1113

If you are outside the EEA and the UK, you may still raise any concern with us directly using the contact details in section 2, and we will deal with it under the standards described in this policy.

  1. Cookies and tracking technologies

10.1. What cookies are

Cookies are small text files stored on your device. Similar technologies work in comparable ways: tracking pixels, tags, markers in e-mail messages, browser local storage, and device identifiers.

Under the European Data Protection Board Guidelines 2/2023, these technologies may be subject to the same rules as cookies — in particular where they store information on your device or gain access to information already stored there. This does not apply where the law permits the technology to be used without consent, for example where it is strictly necessary to provide a service you have specifically requested.

10.2. The consent banner — Cookiebot

When you first visit sowosz.com we display a consent banner operated by Cookiebot (Usercentrics A/S, Denmark). Its role is to block cookies and scripts other than strictly necessary ones until you make a choice. You can:

  • accept all categories;
  • reject all optional categories — in a single click, just as easily as accepting;
  • select individual categories in the detailed settings.

You can change your decision at any time by clicking the cookie consent icon in the corner of the page. An up-to-date, automatically maintained list of every cookie, together with its provider, purpose and storage duration, is available in the cookie declaration shown in the same panel.

We ask for consent to all non-essential cookies for every visitor, wherever you are located. In the United Kingdom, PECR (as amended by the Data (Use and Access) Act 2025) permits certain statistical and appearance-related storage on an objection basis rather than a consent basis; we have chosen to apply the stricter consent standard to everyone, so you always keep full control.

10.3. The categories of cookies we use

Category

What it is for

Consent required

Strictly necessary

Running the site, the shopping basket, the login session, security (Cloudflare), and remembering your choice in the consent banner

No — these are necessary to provide the service you requested

Preferences

Remembering settings, such as the contrast and font size chosen in the accessibility module, and your list of favourite products

Yes

Statistics

Google Analytics — visit statistics that tell us which content is useful

Yes

Marketing

Google Ads, the Meta pixel (Facebook / Instagram), Pinterest Tag, CallTracker, YouTube — tailoring adverts, measuring their effectiveness, and attributing phone calls to campaigns

Yes

10.4. Third parties and embedded content

Our site embeds content supplied by external providers. Loading that content may involve cookies being stored and your IP address being passed to those parties:

  • Google Ireland Ltd. — Google Tag Manager, Google Analytics, Google Ads, Google Maps (the map on the Contact page), YouTube (videos on the site and on the blog);
  • Meta Platforms Ireland Ltd. — the Facebook pixel, social plugins, and buttons linking to our Facebook and Instagram profiles;
  • Pinterest — the Pinterest Tag and “Pin it” buttons;
  • the provider of the CallTracker service — dynamic telephone number replacement and attribution of calls to the source of the visit;
  • Cloudflare — protection against attacks and faster page loading.

The consent banner governs when this content and these scripts run: until you consent to the relevant category, we aim not to load them. Some embedded content — a Google map or a YouTube video, for instance — may nevertheless contact the provider’s server as soon as the page containing it is displayed. If you want to avoid this, reject the optional categories in the banner and use your browser’s privacy settings.

10.5. Browser settings

Independently of our banner, you can manage cookies in your browser settings — block them, delete them, or ask to be notified when one is stored. Please note that blocking strictly necessary cookies may prevent you from using the basket and logging in.

  1. Quotations from our ERP system and how we send messages

We want this process to be completely transparent to you:

  • We prepare quotations in our internal ERP system, available at system.sowosz.pl. It is a platform for our staff only — it is not used to present commercial offers, it is not indexed by search engines, and you have no direct access to it.
  • We only ever send a quotation in response to your enquiry — submitted through a form, by e-mail, by telephone, or in person. We never send quotations to people who have not asked for one.
  • We use the Elastic Email service to send quotation messages. It lets us check whether the message was accepted by your mail server and whether we received a delivery failure notice. We do not need your consent for this, because it does not involve accessing your device.
  • The service also records whether the message was opened and whether links in it were clicked. We use that information for one technical purpose only — to check that the quotation displays correctly and that its links work. We do not assess your interests or behaviour on that basis, and we do not send you any further messages because of it. If you would rather we did not do this, just write to biuro@sowosz.pl and we will turn the feature off for your address.
  • Delivery statuses and information about opens and clicks are visible to us only in the Elastic Email administration panel, and only for 7 days after the message is sent. After that we no longer have access to them. We do not transfer them into our ERP system or any other tool, and we do not build a customer profile from them.
  • The only thing we keep for longer is the suppression list. It contains addresses that returned a permanent delivery error (a non-existent address or a non-existent mailbox), addresses reported as unsolicited mail, and addresses of people who opted out of our messages. This list serves exactly one purpose: to make sure we do not write to you again against your wishes. We use it for nothing else.
  • Marketing messages always include a simple, free way to opt out of further messages of that kind. Opting out of marketing does not affect correspondence necessary to handle your enquiry, quotation, order, complaint, or the performance of a contract — you will continue to receive those. You can also simply write to us at biuro@sowosz.pl about anything.
  • We send review-request messages and competition invitations only to people who have bought from us and consented to receive them. People who only asked for a quotation and did not place an order do not receive such messages from us.
  1. Profiling and automated decision-making

We do not take decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).

Profiling occurs to a limited extent only in advertising tools (Google, Meta, Pinterest). It is based on your consent and has no effect on the price of the product or on the terms of any contract.

We do not, by contrast, profile you on the basis of whether you opened an e-mail or clicked a link in it. That data serves only to check technically that the quotation displayed correctly and that the links work — we do not assess your characteristics or behaviour from it, and we do not create segments or scores.

  1. Data security

We apply technical and organisational measures appropriate to the risk, including:

  • encryption of the connection to the website and to the ERP system using TLS (HTTPS);
  • account passwords stored only as an irreversible cryptographic hash — we do not know your password and cannot recover it;
  • access control — only authorised staff can access the data, and only to the extent needed to do their job;
  • written authorisations to process data and confidentiality undertakings;
  • regular backups and software updates;
  • data processing agreements with the providers who process data on our behalf.

If a personal data breach nevertheless occurs and it is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. If the breach is likely to result in a high risk to your rights and freedoms, we will also inform you, unless one of the exceptions in Art. 34(3) GDPR applies.

  1. Changes to this policy

We may update this policy — most often because the law changes, because we launch a new feature on the site, or because we change a service provider. The current version is always available at sowosz.com. The version number and its effective date appear at the end of this document. We will announce any significant change on the home page as well.

Version 2.0 · effective date: 5 August 2026

PRIVACY AND COOKIE POLICY

sowosz.com online store

Version 1.0 · effective from 5 August 2026

We want you to know what happens to your data when you visit our website, ask us for a quotation for a staircase, or place an order. We have written this in plain language, without unnecessary legal jargon.

  1. Which laws apply to you

We are established in Poland and have no establishment outside Poland. This means:

  • All of our processing of personal data is governed by Regulation (EU) 2016/679 (the "EU GDPR"), together with Polish national law — in particular the Act of 10 May 2018 on the Protection of Personal Data and the Act of 12 July 2024 (Electronic Communications Law), which governs cookies and electronic marketing.
  • If you are located in the United Kingdom, our processing of your personal data is additionally governed by the UK GDPR (as defined in section 3(10) of the Data Protection Act 2018), by virtue of Article 3(2)(a) UK GDPR, together with the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 ("PECR").
  • If you are located in another country outside the European Economic Area, we still apply the standards described in this policy to your data. Local law in your country may give you additional rights, which we will honour where they apply to us.

Wherever this policy refers simply to "the GDPR", the statement applies equally under the EU GDPR and the UK GDPR, because the two are substantially identical on that point. Where the two diverge, we say so explicitly.

If you are a consumer in the EEA, please also note that under Article 6 of the Rome I Regulation you keep the protection of the mandatory consumer-law provisions of the country where you habitually reside, regardless of the law we apply to the contract itself.

  1. Who is the controller of your data

The controller of your personal data is:

Name

Przedsiębiorstwo Produkcyjno-Usługowo-Handlowe „SOWOSZ" Sp. z o.o.

(a limited liability company incorporated under Polish law)

Address

ul. Wadowicka 86, 32-551 Jankowice, Poland

Registration

KRS 0000182999 · VAT ID PL6280001480 · REGON 003445122

E-mail

biuro@sowosz.pl

Telephone

Staircases: +48 33 841 08 18, +48 602 668 242

Sawmill / timber products: +48 33 841 25 59

 

We have not appointed a Data Protection Officer — we are not required to do so under Article 37 GDPR. For any matter concerning personal data, please write to biuro@sowosz.pl marking your message "GDPR", or to our registered address above.

  1. Who this policy covers and where we get your data

This policy applies to people who:

  • visit sowosz.com;
  • submit an enquiry through the "Enter your own dimensions" form or the contact form;
  • write to us directly by e-mail or call us;
  • create an account and place an order in our online store;
  • receive a quotation from us prepared in our ERP system;
  • submit a complaint, take part in a competition, or leave us a review;
  • act as a contact person for our business partners, suppliers, or fitters.

In the vast majority of cases we receive data directly from you. Occasionally we may receive it from your employer or business partner (if you are a contact person on the company side) or from public registers.

If you buy our products through a marketplace — currently Allegro, Erli, Castorama or Leroy Merlin, among others — we receive the data needed to fulfil the order from the operator of that marketplace. This is typically your name, delivery address, contact details, the order number and its contents, and, if you request an invoice, your billing details. We process this data in order to fulfil the order, account for it, and handle any complaint, on the terms set out in section 4. The list of marketplaces may change over time.

  1. Why we process your data and on what legal basis

The table below is the most important part of this policy. It sets out why we process data, on what legal basis, and how long we keep it.

Purpose

Legal basis

Retention period

Answering an enquiry from the "Enter your own dimensions" form, the contact form, an e-mail or a phone call — including preparing a free quotation

Art. 6(1)(b) GDPR — steps taken at your request prior to entering into a contract;

Art. 6(1)(f) GDPR (our legitimate interest) — if you write on behalf of a company

12 months from the last contact in the matter. If an order follows — as set out in the rows below

Preparing and sending you a quotation from our ERP system (system.sowosz.pl) in response to your enquiry

Art. 6(1)(b) GDPR — pre-contractual steps taken at your request

Validity period of the quotation plus 12 months

Checking whether the message containing the quotation was accepted by your mail server and whether we received a delivery failure notice (Elastic Email service)

Art. 6(1)(f) GDPR — our legitimate interest in confirming that the quotation was sent correctly

Available only in the Elastic Email administration panel for 7 days after the message is sent. We do not copy it to any other system

Checking whether the message was opened and whether links in it were clicked (tracking pixel and tracking links provided by Elastic Email)

Art. 6(1)(f) GDPR — our legitimate interest in technically verifying that a quotation sent at your request displayed correctly and that its links work. You may object to this processing at any time (Art. 21(1) GDPR)

Available only in the Elastic Email administration panel for 7 days after the message is sent. We do not copy it to any other system and we do not build a customer profile from it

Maintaining a suppression list: addresses that returned a permanent delivery failure (non-existent address or non-existent mailbox), addresses reported as unsolicited mail, and addresses of people who have opted out of our messages

Art. 6(1)(c) GDPR in conjunction with Art. 21(3) and Art. 5(2) GDPR — our obligation to respect your objection and to demonstrate that we have done so; Art. 6(1)(f) GDPR — our legitimate interest in maintaining an accurate address database

For as long as we send messages at all — we must keep the address precisely so that we do not write to you again. We use it for no other purpose

Operating your account in the online store

Art. 6(1)(b) GDPR — performance of the account agreement

Until the account is deleted by you, or by us at your request

Concluding and performing the sales contract: accepting the order, manufacturing, payment, delivery and any installation

Art. 6(1)(b) GDPR — performance of a contract

Until the order is completed, and then for the limitation period for claims (see below)

Issuing invoices, tax settlements and bookkeeping

Art. 6(1)(c) GDPR in conjunction with Polish accounting and tax legislation, which applies to us as a Polish company

5 years from the end of the calendar year in which the tax payment deadline fell

Handling complaints, notifications that goods do not conform to the contract, withdrawals from the contract, and warranty claims

Art. 6(1)(c) GDPR in conjunction with applicable consumer protection legislation — Polish law and, where they apply to you, the mandatory consumer rules of your country of residence

Until the complaint procedure is concluded, and then for the limitation period for claims

Establishing, exercising or defending legal claims

Art. 6(1)(f) GDPR — our legitimate interest

Until the limitation period expires: as a rule 6 years for consumers and 3 years in business-to-business relations under Polish law, unless a longer or shorter period applies under the law of your country

Sending our customers messages asking for a review of a completed order, and invitations to competitions

Art. 6(1)(a) GDPR — your consent, together with the national rules implementing the ePrivacy Directive 2002/58/EC — in Poland Art. 398(1) of the Electronic Communications Law, and in the United Kingdom regulation 22 PECR

Until you withdraw consent or object. We keep proof of consent and of its withdrawal for as long as we need it to demonstrate compliance

Running competitions: selecting the winner, awarding the prize, tax obligations

Art. 6(1)(b) GDPR (competition rules) and Art. 6(1)(c) GDPR (tax obligations)

Until the competition is settled; tax records as set out in the bookkeeping row

Cookies and similar technologies used for analytics, personalisation and marketing (Google, Meta, Pinterest, CallTracker, YouTube)

Art. 6(1)(a) GDPR — your consent, together with Art. 399(1) of the Polish Electronic Communications Law and, for users in the United Kingdom, regulation 6 PECR

As set out in the cookie declaration (most often up to 13 months) or until you withdraw consent

Cookies strictly necessary for the website, the shopping basket, logging in, and remembering your choice in the consent banner

Art. 6(1)(f) GDPR — our legitimate interest. These are exempt from the consent requirement under Art. 399(3) of the Polish Electronic Communications Law and under Schedule A1 PECR

Browser session or up to 12 months

Keeping the website secure, preventing abuse and spam, server logs

Art. 6(1)(f) GDPR — our legitimate interest

Up to 12 months

Demonstrating that we comply with the GDPR (accountability), including maintaining records of consents and requests

Art. 6(1)(c) GDPR in conjunction with Art. 5(2) GDPR

For as long as we need it to demonstrate that we acted lawfully — as a rule until the limitation period for related claims expires

 

  1. What data we collect

We collect only the data we genuinely need:

  • identification and contact details: name and surname (or company name), e-mail address, telephone number;
  • technical details of the staircase you are planning: opening dimensions, height, type and direction of the flight, and the content of your message;
  • data needed to fulfil an order: delivery address, installation address, billing details (including VAT number), and bank account number for refunds;
  • records of orders, quotations, complaints and correspondence history;
  • account data: username, password stored only as an irreversible cryptographic hash, settings, list of favourite products;
  • technical data: IP address, cookie identifier, browser and device type, approximate location at city level, referral source, pages visited;
  • data about your interaction with our e-mails: delivery, opening, link clicks, and opt-outs.

We do not collect, and do not want to collect, special categories of personal data (Art. 9 GDPR), such as data about health, opinions or beliefs. Please do not include such information in messages you send us.

  1. Do you have to provide your data

Providing data is voluntary, but in some situations it is necessary:

  • without an e-mail address or telephone number we cannot answer your enquiry or prepare a quotation;
  • without the data required for delivery, installation and payment we cannot fulfil an order — some of it is needed to perform the contract, and some is required of us by tax and accounting law;
  • consent to marketing cookies and to review-request messages is entirely optional — withholding it does not affect your ability to buy from us or the price you pay.
  1. Who we share data with

We do not sell your data. We share it only with parties we need in order to run our business, and only to the extent necessary. These are:

Category of recipient

Examples and role

IT and hosting providers

The company hosting sowosz.com and our e-mail, the supplier and maintainer of our ERP system (system.sowosz.pl), and Cloudflare (site protection and acceleration) — acting as processors under data processing agreements

E-mail delivery provider

Elastic Email — sends and tracks delivery of the quotation messages generated in our ERP system

Cookie consent management

Cookiebot (Usercentrics A/S, Denmark) — operates the consent banner and the consent record

Analytics and advertising providers

Google Ireland Ltd. (Google Analytics, Google Ads, Google Tag Manager, Google Maps, YouTube), Meta Platforms Ireland Ltd. (Facebook pixel, Instagram), Pinterest, and the provider of the CallTracker service (measuring the effectiveness of telephone campaigns)

Carriers and installation firms

Courier and transport companies and the fitters we work with — they receive the data needed for delivery or installation

Payment providers and banks

Processing payments for orders and refunds

Accounting and legal advisers

Our accounting office, tax adviser and law firm — in relation to settlements and any disputes

Marketplace operators

Marketplaces and stores where we offer our products — currently Allegro, Erli, Castorama and Leroy Merlin, among others. If you buy through them, the marketplace operator is a separate controller in respect of running its own platform and your account there, and applies its own privacy policy. The list may change

Public authorities

Only where the law requires us to disclose data (for example tax authorities, courts, or the police)

 

Joint controllership. In respect of the statistics for our Facebook, Instagram and Pinterest profiles, and in respect of data collected by those services' pixels, we act as joint controllers together with the operators of those platforms. The essence of those arrangements is published by the platforms themselves — please refer to their privacy policies. You may exercise your rights both against us and against the platform operator.

  1. Transfers outside the EEA and the UK

Some of our providers — in particular Google, Meta, Pinterest and Elastic Email — are established in, or process data in, countries outside the European Economic Area, principally the United States.

Where this happens, the transfer takes place:

  • on the basis of European Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection under the EU–US Data Privacy Framework — provided the recipient concerned appears on the list of certified organisations maintained by the U.S. Department of Commerce (dataprivacyframework.gov); or
  • in all other cases, and should that decision cease to have effect — on the basis of the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (Art. 46(2)(c) GDPR), supplemented by additional safeguards. For personal data subject to the UK GDPR we use the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

You can obtain a copy of the safeguards we rely on by writing to biuro@sowosz.pl.

  1. Your rights

In connection with the processing of your data you have the following rights:

  • the right of access to your data and to obtain a copy of it (Art. 15 GDPR);
  • the right to rectification and completion of your data (Art. 16 GDPR);
  • the right to erasure, the "right to be forgotten" (Art. 17 GDPR);
  • the right to restriction of processing (Art. 18 GDPR);
  • the right to data portability, where we process data by automated means on the basis of consent or a contract (Art. 20 GDPR);
  • the right to object to processing based on our legitimate interest (Art. 21(1) GDPR);
  • an absolute right to object to direct marketing — once you exercise it we stop processing your data for that purpose immediately (Art. 21(2) GDPR);
  • the right to withdraw consent at any time — withdrawal does not affect the lawfulness of processing carried out before it (Art. 7(3) GDPR);
  • the right to lodge a complaint with a supervisory authority (see section 9.1 below).

How to exercise these rights: write to biuro@sowosz.pl or to our registered address. We respond without undue delay and no later than one month. In particularly complex cases we may extend that period by a further two months, and we will tell you if we do. Exercising your rights is free of charge. If you are not satisfied with how we have handled your request, you may complain to us first, and we will acknowledge your complaint and tell you the outcome.

9.1. Which supervisory authority you can complain to

This depends on where you are located.

If you are in the European Economic Area: under Art. 77 GDPR you may lodge a complaint with the supervisory authority of the Member State where you habitually reside, where you work, or where the alleged infringement took place. Because our only establishment is in Poland, the lead supervisory authority for us under the one-stop-shop mechanism (Art. 56 GDPR) is:

Authority

Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office)

Address

ul. Stawki 2, 00-193 Warsaw, Poland

Website

uodo.gov.pl

 

If you are in the United Kingdom: you may complain to the Information Commissioner's Office under section 165 of the Data Protection Act 2018. (Please note that Article 77 of the UK GDPR was repealed by the Data (Use and Access) Act 2025, so the right to complain now arises under the Data Protection Act 2018.)

Authority

Information Commissioner's Office (ICO)

Address

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom

Website

ico.org.uk

Helpline

0303 123 1113

 

If you are outside the EEA and the UK, you may still raise any concern with us directly using the contact details in section 2, and we will deal with it under the standards described in this policy.

  1. Cookies and tracking technologies

10.1. What cookies are

Cookies are small text files stored on your device. Similar technologies work in comparable ways: tracking pixels, tags, markers in e-mail messages, browser local storage, and device identifiers.

Under the European Data Protection Board Guidelines 2/2023, these technologies may be subject to the same rules as cookies — in particular where they store information on your device or gain access to information already stored there. This does not apply where the law permits the technology to be used without consent, for example where it is strictly necessary to provide a service you have specifically requested.

10.2. The consent banner — Cookiebot

When you first visit sowosz.com we display a consent banner operated by Cookiebot (Usercentrics A/S, Denmark). Its role is to block cookies and scripts other than strictly necessary ones until you make a choice. You can:

  • accept all categories;
  • reject all optional categories — in a single click, just as easily as accepting;
  • select individual categories in the detailed settings.

You can change your decision at any time by clicking the cookie consent icon in the corner of the page. An up-to-date, automatically maintained list of every cookie, together with its provider, purpose and storage duration, is available in the cookie declaration shown in the same panel.

We ask for consent to all non-essential cookies for every visitor, wherever you are located. In the United Kingdom, PECR (as amended by the Data (Use and Access) Act 2025) permits certain statistical and appearance-related storage on an objection basis rather than a consent basis; we have chosen to apply the stricter consent standard to everyone, so you always keep full control.

10.3. The categories of cookies we use

Category

What it is for

Consent required

Strictly necessary

Running the site, the shopping basket, the login session, security (Cloudflare), and remembering your choice in the consent banner

No — these are necessary to provide the service you requested

Preferences

Remembering settings, such as the contrast and font size chosen in the accessibility module, and your list of favourite products

Yes

Statistics

Google Analytics — visit statistics that tell us which content is useful

Yes

Marketing

Google Ads, the Meta pixel (Facebook / Instagram), Pinterest Tag, CallTracker, YouTube — tailoring adverts, measuring their effectiveness, and attributing phone calls to campaigns

Yes

 

10.4. Third parties and embedded content

Our site embeds content supplied by external providers. Loading that content may involve cookies being stored and your IP address being passed to those parties:

  • Google Ireland Ltd. — Google Tag Manager, Google Analytics, Google Ads, Google Maps (the map on the Contact page), YouTube (videos on the site and on the blog);
  • Meta Platforms Ireland Ltd. — the Facebook pixel, social plugins, and buttons linking to our Facebook and Instagram profiles;
  • Pinterest — the Pinterest Tag and "Pin it" buttons;
  • the provider of the CallTracker service — dynamic telephone number replacement and attribution of calls to the source of the visit;
  • Cloudflare — protection against attacks and faster page loading.

The consent banner governs when this content and these scripts run: until you consent to the relevant category, we aim not to load them. Some embedded content — a Google map or a YouTube video, for instance — may nevertheless contact the provider's server as soon as the page containing it is displayed. If you want to avoid this, reject the optional categories in the banner and use your browser's privacy settings.

10.5. Browser settings

Independently of our banner, you can manage cookies in your browser settings — block them, delete them, or ask to be notified when one is stored. Please note that blocking strictly necessary cookies may prevent you from using the basket and logging in.

  1. Quotations from our ERP system and how we send messages

We want this process to be completely transparent to you:

  • We prepare quotations in our internal ERP system, available at system.sowosz.pl. It is a platform for our staff only — it is not used to present commercial offers, it is not indexed by search engines, and you have no direct access to it.
  • We only ever send a quotation in response to your enquiry — submitted through a form, by e-mail, by telephone, or in person. We never send quotations to people who have not asked for one.
  • We use the Elastic Email service to send quotation messages. It lets us check whether the message was accepted by your mail server and whether we received a delivery failure notice. We do not need your consent for this, because it does not involve accessing your device.
  • The service also records whether the message was opened and whether links in it were clicked. We use that information for one technical purpose only — to check that the quotation displays correctly and that its links work. We do not assess your interests or behaviour on that basis, and we do not send you any further messages because of it. If you would rather we did not do this, just write to biuro@sowosz.pl and we will turn the feature off for your address.
  • Delivery statuses and information about opens and clicks are visible to us only in the Elastic Email administration panel, and only for 7 days after the message is sent. After that we no longer have access to them. We do not transfer them into our ERP system or any other tool, and we do not build a customer profile from them.
  • The only thing we keep for longer is the suppression list. It contains addresses that returned a permanent delivery error (a non-existent address or a non-existent mailbox), addresses reported as unsolicited mail, and addresses of people who opted out of our messages. This list serves exactly one purpose: to make sure we do not write to you again against your wishes. We use it for nothing else.
  • Marketing messages always include a simple, free way to opt out of further messages of that kind. Opting out of marketing does not affect correspondence necessary to handle your enquiry, quotation, order, complaint, or the performance of a contract — you will continue to receive those. You can also simply write to us at biuro@sowosz.pl about anything.
  • We send review-request messages and competition invitations only to people who have bought from us and consented to receive them. People who only asked for a quotation and did not place an order do not receive such messages from us.
  1. Profiling and automated decision-making

We do not take decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).

Profiling occurs to a limited extent only in advertising tools (Google, Meta, Pinterest). It is based on your consent and has no effect on the price of the product or on the terms of any contract.

We do not, by contrast, profile you on the basis of whether you opened an e-mail or clicked a link in it. That data serves only to check technically that the quotation displayed correctly and that the links work — we do not assess your characteristics or behaviour from it, and we do not create segments or scores.

  1. Data security

We apply technical and organisational measures appropriate to the risk, including:

  • encryption of the connection to the website and to the ERP system using TLS (HTTPS);
  • account passwords stored only as an irreversible cryptographic hash — we do not know your password and cannot recover it;
  • access control — only authorised staff can access the data, and only to the extent needed to do their job;
  • written authorisations to process data and confidentiality undertakings;
  • regular backups and software updates;
  • data processing agreements with the providers who process data on our behalf.

If a personal data breach nevertheless occurs and it is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. If the breach is likely to result in a high risk to your rights and freedoms, we will also inform you, unless one of the exceptions in Art. 34(3) GDPR applies.

  1. Changes to this policy

We may update this policy — most often because the law changes, because we launch a new feature on the site, or because we change a service provider. The current version is always available at sowosz.com. The version number and its effective date appear at the end of this document. We will announce any significant change on the home page as well.

Version 1.0 · effective date: 5 August 2026