MEDISEPT sp. z o.o. Privacy Policy
for the website www.medisept.pl
I. GENERAL PROVISIONS
These provisions constitute the privacy policy (hereinafter: “Privacy Policy”), which sets forth the legal basis for the processing of personal data and information regarding the collection and use of personal data by MEDISEPT sp. z o.o., with its registered office in Lublin at ul. L. Spiessa 4 [20-270 Lublin], Tax ID (NIP): 946 00 10 016, National Business Registry Number (REGON): 430566102, National Court Register Number (KRS): 0000020407 (hereinafter: “MEDISEPT”).
MEDISEPT encourages users of the website www.medisept.pl (hereinafter: “the domain”) to review this Privacy Policy.
MEDISEPT uses personal data for the purposes specified in this Privacy Policy, as well as for other purposes; however, these are clearly defined in the Information Clauses available on individual subpages within the domain.
The Controller exercises due diligence to protect the interests of the data subjects whose data it processes. The Controller collects and processes personal data:
- in accordance with generally applicable laws;
- for strictly defined purposes specified in the Privacy Policy and for other purposes, though in each case these are clearly defined in the Information Clauses;
- in a manner appropriate to the purposes and obligations being fulfilled;
- in accordance with applicable retention periods—no longer than is necessary to ensure the fulfillment of specific processes, rights, and obligations, and in accordance with the timeframes specified by law;
- in accordance with applicable data processing security standards, in particular protecting against unauthorized and unlawful data processing, loss, damage, destruction, or distortion—through the application of necessary technical, organizational, and procedural measures.
II. DEFINITIONS
Controller – MEDISEPT sp. z o.o. with its registered office in Lublin at ul. L. Spiessa 4, 20-270 Lublin.
Personal data – information relating to an identified or identifiable natural person (“data subject”); identifiable directly or indirectly, in particular on the basis of a name, online identifier, email address, or telephone number.
Information notice—all information provided when the Controller collects data, pursuant to Articles 13 or 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
Entrepreneur – an adult natural person with full legal capacity, a legal entity, or an organizational unit without legal personality but possessing legal capacity, conducting business or professional activities in its own name and making a purchase from the Seller directly related to its business or professional activities,
Consumer – an adult natural person with full legal capacity, making a purchase from the Seller not directly related to their business or professional activity,
Customer or, alternatively: User – both a Consumer and an Entrepreneur,
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
Processor – a natural or legal person, public authority, or other entity that processes personal data on behalf of the Controller.
Processing—operations or a set of operations performed on Personal Data, such as collection, recording, organization, structuring, storage, adapting or modifying, retrieving, consulting, using, disclosing by transmission, dissemination or otherwise making available, aligning or combining, restricting, erasing, or destroying.
Consent – a specific, informed, and unambiguous expression of will by which the data subject, in the form of a statement or a clear affirmative action, consents to the processing of their Personal Data.
III. LEGAL BASIS
All personal data is processed in accordance with applicable Polish and EU law, in particular the GDPR, the Act of May 10, 2018, on the Protection of Personal Data [i.e., Journal of Laws 2019, item 1781], the Act of July 18, 2002, on the Provision of Electronic Services [i.e., Journal of Laws 2024, item 1513], and the Electronic Communications Law of July 12, 2024 [Journal of Laws 2024, item 1221, as amended].
The controller collects and processes personal data when:
- the data subject has consented to the processing of their data (for a strictly defined purpose, e.g., receiving a newsletter) – in accordance with Article 6(1)(a) of the GDPR;
- the data subject has entered into a contract with MEDISEPT (in particular a purchase and sale agreement, a commercial contract, or a contract for the provision of electronic services), or is seeking to enter into or terminate such a contract, or to fulfill its provisions or perform other activities related to the contract—in accordance with Article 6(1)(b) of the GDPR;
- it is necessary for compliance with a legal obligation to which the Controller is subject—in accordance with Article 6(1)(c) of the GDPR;
- it is necessary for the purposes of the legitimate interests pursued by MEDISEPT (e.g., for the direct marketing of the Controller’s goods and services)—in accordance with Article 6(1)(f) of the GDPR.
The Controller processes Personal Data only if the conditions of the aforementioned legal bases are met.
IV. CONTACTING THE DATA CONTROLLER
To contact the Data Controller to exercise your rights related to personal data protection, as well as to obtain other information regarding data processing by MEDISEPT, please submit your requests: in writing to the address: MEDISEPT sp. z o.o., ul. L. Spiessa 4, 20-270 Lublin, with the note (“regarding GDPR”) or electronically to the address: rodo@medisept.pl
V. DISPLAYING THE WWW.MEDISEPT.PL WEBSITE
Please be advised that when you view the website at the provided address using available web browsers, information is exchanged between your mobile device, computer, or other device and MEDISEPT’s servers. All information collected in connection with viewing the website is used to ensure the smooth operation of IT processes on the MEDISEPT website or other processes occurring in your browser. While viewing the www.medisept.pl website, your browser may transmit the following information: your IP address, the time of entry and exit, the name and URL of the file being viewed, and the website or application from which you entered. This data is transmitted to ensure security and stability, as well as a comfortable and uninterrupted experience while using the Website. The above data is processed in accordance with Article 6(1)(f) of the GDPR—in line with the aforementioned purposes.
The above data is stored only for the duration of your visit to the domain www.medisept.pl and is automatically deleted when you close the website.
VI. PURPOSES OF DATA PROCESSING, RETENTION
Your Personal Data is processed each time for a strictly defined purpose, in accordance with a specific legal basis. Below, we present a description of selected processes related to the processing of Personal Data:
| Purpose of data processing | Legal basis for processing and data retention period | Scope of data processing |
| Conclusion, performance, and administration of contracts (e.g., purchase and sale agreements, commercial contracts, contracts for the provision of electronic services) or taking action at the request of the data subject prior to the conclusion of such contracts. | Article 6(1)(b) of the GDPR (performance of a contract) Data is retained for the period necessary to perform, terminate, or otherwise allow the contract to expire. Data related to invoices for billing purposes will be processed until the expiration of the tax liability period and until the statute of limitations for potential claims expires or the warranty period ends. | Maximum scope: first and last name; email address; contact phone number; mailing address (street, house number, apartment number, ZIP code, city, country), residential address/business address/registered office (if different from the mailing address). In the case of business entities that are not consumers, the Controller may additionally process the company name and tax identification number (NIP). |
| Direct marketing of the Controller’s goods and services – Contact form | Article 6(1)(f) of the GDPR (legitimate interest of the Controller) The data will be stored for the duration of the legitimate interest pursued by the Controller, but no longer than the statute of limitations for claims against the data subject. | Maximum scope: first and last name; email address; contact phone number. Additionally, this may include: mailing/residential address (street, house number, apartment number, ZIP code, city, country). For Customers who are not consumers, the Controller may additionally process the Customer’s company name and tax identification number (NIP). |
| Newsletter | Article 6(1)(a) of the GDPR (consent) Data is stored until the data subject withdraws consent. | First name, email address |
| Maintenance of tax/accounting records | Article 6(1)(c) The data is stored for the period required by law mandating the Controller to maintain accounting records (In the case of MEDISEPT sp. z o.o., this period is 10 years [business is conducted in a Special Economic Zone], counting from the beginning of the year following the fiscal year to which the data relates). | First and last name; residential address/business address/registered office (if different from the address for service), company name, and the Customer’s tax identification number (NIP) |
| Other – any other data may be processed by the Controller in connection with other legal activities and other specifically indicated, legitimate purposes; however, in each case, such purposes are communicated to the data subject via information notices. | ||
VII. DATA RECIPIENTS
The recipients of the data are our employees, associates, and other authorized entities (public authorities and entities cooperating with the Company on the basis of separate agreements). Details can be found in the Information Clauses available on the respective subpages of the domain.
VIII. CONTACT FORM
The Controller provides technical solutions enabling contact via an electronic form. The personal data of individuals using the contact form (including, among others: first name, last name, phone number, email address) will be processed by the Controller for the purpose of identifying, transmitting, and handling the inquiry submitted by the user via the provided form—the legal basis for processing is the Controller’s legitimate interest.
Providing data marked as mandatory is required by the Administrator to accept and process the user’s inquiry. Failure to provide this data prevents the inquiry from being processed. Providing other types of data is voluntary. However, the user may provide them to facilitate contact with the Administrator or to process their inquiry.
IX. NEWSLETTER
The Administrator processes users’ personal data for the purpose of providing the newsletter service. This may involve sending emails about offers or content, which in some cases may contain commercial information (newsletter service). The newsletter service is provided by the Administrator to individuals who have provided their email address for this purpose.
The legal basis for processing is the consent expressed by the user by checking the appropriate checkbox to receive newsletters.
Providing the above data is required by the Administrator in order to provide the service and the newsletter. Failure to provide this data prevents us from providing this service.
X. MEDISEPT ONLINE STORE
To provide you with up-to-date access to information regarding new products and promotions, MEDISEPT sp. z o.o. grants you access to its online store via the domain www.dezynfekcja.pl.
XI. CATEGORIES OF EXTERNAL DATA RECIPIENTS
Personal data may be transferred to, among others, the following recipients or categories of recipients:
- entities providing legal advice, participating in court proceedings, mediation, enforcement, and other proceedings on behalf of and for the benefit of the Controller, as well as notary offices or tax advisors;
- entities operating information technology (IT) systems;
- authorities authorized by law, in particular: Government Agencies (e.g., the Tax Office in the case of a tax audit), the Police, Courts, and others, when required by law;
XII. TRANSFER OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA
Please be advised that your data processed by MEDISEPT is not transferred outside the European Economic Area (EEA).
XIII. YOUR RIGHTS AT A GLANCE (RIGHTS OF DATA SUBJECTS)
Every Customer is entitled to the following rights:
- right of access to data – you have the right to access information regarding which data we process (in accordance with Article 15 of the GDPR);
- the right to request rectification of data – you have the right to update the data provided to MEDISEPT (in accordance with Article 16 of the GDPR);
- the right to erasure (the right to be forgotten) – you have the right to have your data erased if it was processed unlawfully or if the data is no longer necessary for the purposes for which it was collected (in accordance with Article 17 of the GDPR);
- the right to restrict data processing – you have the right to restrict data processing if the controller no longer needs the data for the purposes for which it was processed, the data is inaccurate, or it is being processed unlawfully (in accordance with Article 18 of the GDPR);
- the right to data portability – you have the right to have your data transmitted to another data controller and to receive your data in a structured, commonly used, machine-readable format (in accordance with Article 20 of the GDPR);
- right to withdraw consent – you have the right to withdraw any consent you have voluntarily given at any time, provided that the withdrawal of consent does not affect the processing carried out by the Controller lawfully prior to its withdrawal (in accordance with Article 7(3) of the GDPR);
- the right to object – you have the right to object where data processing is carried out for the purposes of the legitimate interests of the Controller or a third party, including in particular processing for marketing purposes (in accordance with Article 21 of the GDPR);
- the right to lodge a complaint with a supervisory authority – a data subject whose data is processed by the Controller has the right to lodge a complaint with a supervisory authority in the manner and under the procedure set forth in the provisions of the GDPR and Polish law, in particular the Personal Data Protection Act. The supervisory authority in Poland is the President of the Personal Data Protection Office.
To exercise the rights referred to above, please contact the Controller by sending a written message or via email to the address indicated in Section IV of the Privacy Policy.
The Controller does not use automated decision-making, including profiling, as referred to in Article 22(1) and (4) of the GDPR.
XIV. VOLUNTARY PROVISION OF DATA
Providing your data is voluntary at all times. If you have given consent to the processing of your data, you may withdraw that consent at any time by contacting us via the contact information provided in Section IV of the Privacy Policy; however, the withdrawal of consent does not affect the lawfulness of data processing prior to its withdrawal.
XV. COOKIES
XVI. CHANGES TO THE PRIVACY POLICY
Please be advised that in order to ensure the security of your personal data and to maintain up-to-date and transparent procedures and policies at MEDISEPT sp. z o.o., this document will be regularly reviewed and amended in light of changes in generally applicable laws and regulations, as well as any measures taken to ensure the proper protection of your Personal Data.
This Policy is effective as of July 9, 2025.
