Effective Date: May 2026
1. PERSONAL DATA ADMINISTRATOR
The administrator of personal data collected via the bolglass.pl website is: PROFICHEM24.PL MAGDALENA STELMASZYK, ul. Witkowska 82A, 62-200 Gniezno, Poland, NIP: 7842515599, REGON: 381749524.
Contact e-mail: biuro@bolglass.pl
Contact phone: +48 606 103 746
2. PURPOSES AND LEGAL BASIS FOR DATA PROCESSING
We process your personal data in accordance with the GDPR for the following purposes:
- Execution of sales and booking contracts: Processing orders for ready-made and personalized products (3D Configurator) and booking workshops and Manufactory visits (Art. 6 sec. 1 lit. b GDPR).
- Loyalty Program: Calculating points, managing membership levels, and issuing rewards (Art. 6 sec. 1 lit. b GDPR).
- User Account: Handling the registration and login process (E-mail, Magic Link, Apple Login) and storing activity history (Art. 6 sec. 1 lit. b GDPR).
- Legal and tax obligations: Issuing invoices and maintaining accounting documentation (Art. 6 sec. 1 lit. c GDPR).
- Analytics and Marketing: Optimizing website performance and displaying tailored advertising content (Art. 6 sec. 1 lit. f GDPR - legitimate interest, carried out only with your consent).
- Security: Monitoring system errors and breach attempts to ensure website stability (Art. 6 sec. 1 lit. f GDPR).
3. SCOPE OF COLLECTED DATA
- Order data: Name, surname, e-mail address, phone number, delivery address, possibly company VAT number (NIP).
- Personalization data: Content entered by the User in the 3D Configurator (names, dedications, dates).
- System data: IP address (anonymized), cookie identifiers, device and browser data.
- Loyalty data: Transaction history assigned to the e-mail address to calculate points.
4. DATA RECIPIENTS (THIRD PARTIES)
In order to properly provide services, data may be transferred to:
- Payment operators: Stripe Payments Europe Ltd. - for the secure processing of online payments.
- ERP Systems and Logistics Integrators: Sellasist (e-script sp. z o.o.) - an order management system to which data is sent to generate courier labels and handle logistics.
- Logistics companies: InPost, DPD, DHL - directly from the integrator to deliver ordered products.
- Analytics tool providers: Google Ireland Ltd. (Google Analytics 4, Google Tag Manager) and Meta Platforms Ireland Ltd. (Facebook Pixel).
- Technology partners: VPS server providers (PostgreSQL database) and internal technical notification systems.
5. COOKIES AND GOOGLE CONSENT MODE V2
The bolglass.pl website uses cookies transparently:
- Consent Management: We have implemented Google Consent Mode v2. This means that no analytical or marketing cookies are triggered without your explicit, active consent expressed in the privacy settings module.
- Types of Cookies:
- - Essential: Guarantee cart operation, login, and security. Always active.
- - Analytical: Allow us to understand how users use the site and which products are most popular.
- - Marketing: Used to display ads tailored to your interests.
You can change your preferences at any time by clicking the privacy settings link on the website.
6. DATA RETENTION PERIOD
- Accounting data: 5 years from the end of the calendar year in which the tax payment deadline expired.
- User Account: Until the account is deleted by the User.
- Loyalty points: 730 days from the moment they are awarded.
- Inquiries: Until communication is completed.
7. YOUR RIGHTS AND SUPERVISORY AUTHORITY
Under the GDPR, you have the following rights:
- Right to access your data and receive a copy.
- Right to rectify (correct) your data.
- Right to erasure (right to be forgotten) - provided we have no legal obligation to keep it.
- Right to data portability - download order history in a structured format.
- Right to withdraw consent at any time (does not affect lawfulness of processing before withdrawal).
- RIGHT TO LODGE A COMPLAINT: If you believe we process data unlawfully, you can complain to the supervisory authority in Poland: Prezes Urzędu Ochrony Danych Osobowych (PUODO), ul. Stawki 2, 00-193 Warsaw (www.uodo.gov.pl).
8. FINAL PROVISIONS
The Administrator makes every effort to ensure data security through SSL certificates, database encryption, and regular monitoring of security logs. This policy may change along with the development of the website's functionality.