Privacy Policy

Effective date: from 9 May 2026

1. General provisions

  1. This Privacy Policy explains the rules for processing personal data and using cookies and similar technologies in connection with the use of the website available at https://fortistechnology.pl (the "Website").
  2. This Policy is for information purposes only. It is not an agreement or terms of service, but fulfills the information obligations arising from Articles 13 and 14 of the GDPR.
  3. The Website may be used in particular to present Fortis Technology's business, contact the Controller, submit quote requests, manage business relationships, and present products or services.

2. Data Controller and contact

  1. The controller of personal data is Fortis Technology Rydzińska Sp. k., with its registered office at:
    9 Cisowa Street,
    64-320 Niepruszewo,
    Tax ID: 7811875724
  2. For matters related to personal data protection, you may contact the Controller:
    email: [email protected]
    phone: +48 61 820 94 29
    by mail: Fortis Technology Rydzińska Sp. k., ul. Cisowa 9, 64-320 Niepruszewo
  3. The Controller has not appointed a Data Protection Officer. If one is appointed, the information in this Policy will be updated.

3. Basic definitions

  1. Personal data – information about an identified or identifiable natural person, e.g. full name, email address, phone number, address details, device IP address, cookie identifiers, or data contained in correspondence.
  2. User – any natural person using the Website or contacting the Controller.
  3. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
  4. Website – the website available at https://fortistechnology.pl.

4. Purposes, legal bases and data processing period

Below we present the main purposes of data processing by the Controller. In each case, we indicate the scope of data, purpose, legal basis and expected processing period.

4.1. Contact by email, telephone and contact forms

Scope of data: first and last name, company name, email address, phone number, message content, data contained in correspondence and other data voluntarily provided by the User.

Purpose: responding to an inquiry, preparing an offer, handling business contact, conducting correspondence and contact regarding matters related to the Controller's business.

Legal basis: Art. 6(1)(b) GDPR, if the contact concerns taking steps prior to entering into a contract or performing a contract; Art. 6(1)(f) GDPR, i.e. the Controller's legitimate interest in conducting correspondence and handling inquiries.

Processing period: for the duration of the correspondence, and then for up to 3 years after its end for evidentiary purposes, unless longer retention is justified by the pursuit or defense of claims.

4.2. Preparation of offers, handling inquiries and B2B business relations

Scope of data: identification and contact details of the person submitting the inquiry, company details, job title, phone number, email address, Tax Identification Number, address details, information regarding demand, product, service, project or order.

Purpose: preparing an offer, handling commercial inquiries, conducting negotiations, contact with contractors and potential contractors, and managing business relations.

Legal basis: Art. 6(1)(b) GDPR, if processing is necessary to take steps prior to entering into a contract or to perform a contract; Art. 6(1)(f) GDPR, i.e. the Controller's legitimate interest in conducting business activity and maintaining business relations.

Processing period: for the time necessary to handle the inquiry or business relationship, and then until the limitation period for potential claims expires or until an effective objection is raised, if the legal basis for processing is the Controller's legitimate interest.

4.3. Performance of contracts, orders and deliveries

Scope of data: identification data, contact details, address details, company details, Tax Identification Number, invoice details, data regarding the order, delivery, payment and correspondence related to contract performance.

Purpose: conclusion and performance of the contract, order fulfillment, delivery of products or services, contact regarding contract performance, payment handling, settlements and after-sales service.

Legal basis: Art. 6(1)(b) GDPR, i.e. necessity for the performance of a contract or taking steps prior to its conclusion; Art. 6(1)(c) GDPR, i.e. compliance with legal obligations, in particular tax and accounting obligations; Art. 6(1)(f) GDPR, i.e. the Controller's legitimate interest in pursuing or defending against claims.

Processing period: for the duration of the contract, and then until the limitation period for claims expires. Accounting and tax documents are retained for the period required by law, as a rule 5 years from the end of the year in which the tax payment deadline expired.

4.4. Complaints, service requests and after-sales service

Scope of data: identification data, contact details, data regarding the order, product or service, the content of the complaint or request, photographic documentation, correspondence and information necessary to examine the case.

Purpose: receiving and handling the complaint, processing the request, contact regarding the request, fulfilling obligations arising from legal provisions and possible defense against claims.

Legal basis: Art. 6(1)(c) GDPR, if processing results from legal obligations; Art. 6(1)(b) GDPR, if the request is related to contract performance; Art. 6(1)(f) GDPR, i.e. the Controller's legitimate interest in handling requests and defending against claims.

Processing period: for the duration of handling the complaint or request, and then until the limitation period for potential claims expires.

4.5. Newsletter and marketing communication

Scope of data: email address, first name, company name, marketing preferences, consent information, information about message opens and link clicks, if such statistics are used.

Purpose: przesyłanie informacji handlowych i marketingowych, w tym informacji o produktach, usługach, promocjach, nowościach, wydarzeniach lub treściach branżowych.

Legal basis: Art. 6(1)(a) GDPR, i.e. the consent of the data subject; Art. 6(1)(f) GDPR, i.e. the Controller's legitimate interest in demonstrating that consent was given, its scope, and the moment it was withdrawn. Marketing communication is carried out in compliance with the requirements of the Electronic Communications Law.

Processing period: until consent is withdrawn or marketing communication is unsubscribed from. After consent is withdrawn, the data may be stored for up to 3 years in order to demonstrate that consent was given, its scope and the moment of withdrawal, and to defend against claims.

Subscribing to the newsletter or consenting to marketing communication is voluntary. Lack of consent does not affect the ability to use the Service in other respects.

4.6. Direct marketing of own products and services

Scope of data: contact details, company details, cooperation history, information about interest in the offer, data on activity in the Service or newsletter, if the User has given the relevant consents.

Purpose: conducting direct marketing of the Controller's products and services, including sending offers, invitations, and information about products, services, or industry events.

Legal basis: Art. 6(1)(f) GDPR, i.e. the Controller's legitimate interest in promoting its own products and services to customers or business partners; Art. 6(1)(a) GDPR, if a given form of contact or tool requires consent, in particular under the Electronic Communications Law.

Processing period: until an objection to direct marketing is raised or consent is withdrawn, if the processing is based on consent.

4.7. Fulfilment of tax and accounting obligations

Scope of data: identification data, address data, company data, tax ID, transaction data, invoice data, payment data, and accounting documentation.

Purpose: fulfilment by the Controller of obligations arising from tax law, accounting regulations, and other provisions concerning the maintenance of company records.

Legal basis: Art. 6(1)(c) GDPR, i.e. a legal obligation incumbent on the Controller.

Processing period: for the period required by law, as a rule 5 years from the end of the year in which the tax payment deadline expired.

4.8. Service traffic analysis and statistics

Scope of data: IP address, cookie identifiers, data on activity in the Service, visited subpages, time spent on the site, clicks, device type, operating system, browser, and approximate location data.

Purpose: analysis of the use of the Service, preparation of statistics, optimisation of the website's operation, and improvement of usability and content quality.

Legal basis: Art. 6(1)(f) GDPR, i.e. the Controller's legitimate interest in analysing and developing the Service; Art. 6(1)(a) GDPR, if the data is processed using cookies or similar technologies requiring consent.

Processing period: until consent is withdrawn in the case of cookies requiring consent, or for the period resulting from the settings of the given analytics tool, no longer than necessary to achieve the purpose.

4.9. Service operation and security, including server logs

Scope of data: IP address, date and time of connection, request URL, information about the browser, operating system, technical errors, and data concerning technical activity in the Service.

Purpose: ensuring the security of the Service, protection against abuse and attacks, technical diagnostics, maintaining the continuity of the Service's operation, and preparing technical statistics.

Legal basis: Article 6(1)(f) GDPR, i.e. the Controller's legitimate interest in ensuring the security, stability, and proper functioning of the Service.

Processing period: for up to 12 months from the date the data is recorded in logs, unless longer retention is necessary in connection with a security incident, pursuing claims, or defending against claims.

4.10. Video surveillance on the Controller's premises

Scope of data: image, date and time of the recording, area covered by surveillance.

Purpose: ensuring the safety of persons and property, access control to facilities, protection of trade secrets, prevention of theft and abuse, and possible pursuit or defense of claims.

Legal basis: Article 6(1)(f) GDPR, i.e. the Controller's legitimate interest in ensuring the safety of persons, property, and work organization.

Processing period: as a rule, up to 90 days from the date of recording, unless the recording constitutes evidence in proceedings or the Controller becomes aware that it may constitute evidence. In such a case, the retention period may be extended until the final conclusion of the proceedings or clarification of the matter.

Areas covered by surveillance may include, in particular, entrances and exits, parking lots, loading and unloading zones, passageways, halls, warehouses, and the external area of the facility. Surveillance does not cover places where it would disproportionately infringe the dignity or privacy of individuals.

4.11. Fulfillment of obligations arising from personal data protection regulations

Scope of data: identification data, contact data, the content of the request, correspondence, information regarding the exercise of the data subject's rights, and documentation related to personal data protection.

Purpose: fulfillment of obligations arising from the GDPR, in particular handling data subject requests, maintaining documentation and records, and demonstrating compliance with regulations.

Legal basis: Art. 6(1)(c) GDPR, i.e. a legal obligation incumbent on the Controller.

Processing period: for the period necessary to demonstrate the proper performance of obligations arising from the GDPR and until the limitation period for potential claims expires.

4.12. Establishment, pursuit, or defense of claims

Scope of data: data necessary to establish, pursue, or defend against claims, including identification, contact, and transaction data, correspondence, documents, evidence, and information related to the dispute.

Purpose: protection of the Controller's rights, debt collection, defense against claims, and conducting complaint, judicial, administrative, or debt recovery proceedings.

Legal basis: Article 6(1)(f) GDPR, i.e. the Controller's legitimate interest in protecting its rights.

Processing period: until the limitation period for potential claims expires or until the final conclusion of the relevant proceedings.

5. Data recipients

Personal data may be disclosed to the following categories of recipients:

  1. entities authorized to receive them under the law, including public authorities, courts, law enforcement authorities, or administrative bodies, if they submit a request based on an appropriate legal basis;
  2. providers of IT, hosting, email, domain, security system, and technical infrastructure maintenance services;
  3. providers of analytics, marketing, advertising, and communication tools, if the Controller uses such tools;
  4. providers of systems for sending newsletters, marketing automation, or customer communication support;
  5. courier companies, carriers, postal operators, and entities supporting delivery fulfillment;
  6. accounting firms, law firms, tax advisors, auditors, and entities providing advisory services;
  7. to banks, payment operators, or other entities involved in payment processing, where applicable;
  8. to subcontractors and business partners supporting the Controller in the delivery of products, services, projects, or customer service.

Entities processing data on behalf of the Controller act under appropriate agreements, including personal data processing agreements, and process data only to the extent necessary to perform the tasks entrusted to them.

6. Transfer of data outside the European Economic Area

  1. Some tools used by the Controller, in particular analytics, advertising, marketing, or social media tools provided by Google, Meta, LinkedIn, YouTube, or similar providers, may involve the transfer of data outside the European Economic Area.
  2. In such cases, data is transferred only using mechanisms provided for under the GDPR, in particular:
    • on the basis of a European Commission decision confirming an adequate level of protection for the relevant country or entity,
    • on the basis of standard contractual clauses approved by the European Commission,
    • with additional security measures applied, if required.
  3. Detailed information on data processing by external providers can be found in their privacy policies.

7. Social media

  1. The Controller may maintain profiles on social media platforms such as Facebook, Instagram, LinkedIn, YouTube, or other similar platforms.
  2. In connection with maintaining social media profiles, the Controller may process the data of الأشخاص visiting the profiles, following them, reacting to published content, commenting on posts, or contacting the Controller via private messages.
  3. The scope of data may include in particular: profile name, first and last name, profile picture, comment content, reactions, private messages, statistical data on activity, and other publicly available information within the relevant platform.
  4. The purposes of processing include:
    • maintaining social media profiles,
    • communication with Users,
    • responding to messages and comments,
    • publishing informational, promotional, and industry-related content,
    • building relationships with audiences,
    • keeping statistics on profile activity.
  5. The legal basis for processing is Article 6(1)(f) GDPR, i.e. the Controller's legitimate interest in conducting communication, promotion, and building relationships with audiences.
  6. With regard to statistics made available by social media platforms, the Controller may be a joint controller of data together with the operator of the relevant platform, in accordance with the rules set by that platform.
  7. Data is processed for the duration of maintaining the profile, until a comment or message is deleted, until unfollowing the profile, submitting an effective objection, or in accordance with the retention rules set by the operator of the relevant platform.

8. Cookies and similar technologies

8.1. What are cookies?

Cookies are small text files stored on the User's device, such as a computer, tablet, or smartphone, while using the Service. Cookies may be read during subsequent visits to the Service.

8.2. Types of cookies used in the Service

The following categories of cookies may be used in the Service:

  1. Necessary cookies – necessary for the proper functioning of the Service, e.g. to ensure security, maintain the session, remember privacy settings, or display the page correctly. Without these files, the Service may function improperly. The legal basis for processing is Art. 6(1)(f) GDPR.
  2. Analytical or statistical cookies – help analyze traffic in the Service and how the website is used, e.g. the number of visits, the popularity of subpages, or traffic sources. The legal basis for processing is the User's consent, i.e. Art. 6(1)(a) GDPR, if consent is required.
  3. Marketing or advertising cookies – enable advertising activities, measuring campaign effectiveness, or displaying content tailored to the User's interests. The legal basis for processing is the User's consent, i.e. Art. 6(1)(a) GDPR.
  4. Functional cookies – allow selected User settings to be remembered or additional Service features to be used. The legal basis for processing may be the User's consent or the Controller's legitimate interest, depending on the nature of the given file.

A detailed list of cookies, including the file name, provider, purpose, and storage period, may be available in the cookie banner or in the cookie settings in the Service.

8.3. Consent to cookies and managing them

  1. During the first visit to the Service, a cookie banner may be displayed in which the User may:
    • accept all categories of cookies,
    • refuse consent to cookies other than necessary ones,
    • adjust their preferences by selecting chosen categories of cookies.
  2. Consent to cookies may be withdrawn or changed at any time via the cookie banner settings, if such a function is available, or by changing the web browser settings.
  3. The User may also block or delete cookies through their browser settings. However, restricting the use of cookies may affect the operation of some Service functions.
  4. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

9. Analytical and advertising tools

  1. In the Service, the Controller may use analytical, advertising, or marketing tools such as Google Analytics, Google Ads, Meta Pixel, LinkedIn Insight Tag, or similar tools.
  2. These tools may process in particular: IP address, cookie identifiers, data about the device, browser, activity in the Service, visited subpages, and traffic sources.
  3. The purpose of using these tools is to analyze the operation of the Service, measure the effectiveness of marketing activities, optimize content, and conduct advertising activities.
  4. To the extent that these tools use cookies or similar technologies requiring consent, data is processed only after the User has given consent.
  5. The User may block the use of analytical and advertising cookies through the cookie settings on the Website or through the web browser settings.

10. Server logs

Each use of the Website involves sending requests to the server. Information recorded in the server logs may include, among other things, the IP address, date and time of the visit, request URL, information about the browser, operating system, and technical errors.

Server log data is used for administrative, technical, and security purposes, in particular for diagnostics, protection against attacks, ensuring the stability of the Website, and maintaining technical statistics. This data is not used to identify specific Users, except where necessary, for example in the event of a legal violation, an attack on the Website, or the need to pursue claims.

11. Profiling and automated decision-making

  1. The Controller does not make decisions concerning Users based solely on automated processing, including profiling, that would produce legal effects concerning them or similarly significantly affect them.
  2. The Controller may use limited marketing profiling, for example by analyzing activity on the Website or in the newsletter to tailor marketing content, if the User has given the appropriate consents or if the processing is based on the Controller's legitimate interest.
  3. The User has the right to object to profiling carried out on the basis of the Controller's legitimate interest, and where processing is based on consent, the right to withdraw it.

12. Voluntary provision of data

  1. Providing personal data is generally voluntary, but it may be necessary for:
    • responding to an inquiry,
    • preparing an offer,
    • concluding and performing a contract,
    • processing an order or delivery,
    • issuing an invoice,
    • handling a complaint or request,
    • sending the newsletter or marketing communications, if the User has given consent.
  2. Failure to provide the required data may make it impossible to achieve the given purpose, for example preparing an offer, responding to a message, concluding a contract, processing an order, or sending the newsletter.

13. Rights of data subjects

Data subjects are entitled – within the limits set by the GDPR – to the following rights:

  1. the right of access to data, including obtaining information about data processing and a copy of the data;
  2. the right to rectify data if the data is inaccurate or incomplete;
  3. the right to erasure if the conditions set out in Article 17 GDPR are met;
  4. the right to restriction of data processing;
  5. the right to data portability, to the extent specified in Article 20 of the GDPR;
  6. the right to object to data processing based on the Controller's legitimate interest, on grounds relating to the particular situation of the data subject;
  7. the right to object to the processing of data for direct marketing purposes, including profiling related to such marketing;
  8. the right to withdraw consent at any time if processing is based on consent. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal;
  9. the right to lodge a complaint with the President of the Personal Data Protection Office if the person considers that the processing of their data violates personal data protection regulations.

Requests regarding the exercise of the above rights may be submitted:

  • by email: [email protected]
  • by mail: Fortis Technology Rydzińska Sp. k., ul. Cisowa 9, 64-320 Niepruszewo

For security reasons, the Controller may request additional information to verify the identity of the person submitting the request. The Controller does not process rights under Articles 15–21 of the GDPR by phone if it is not possible to reliably identify the person submitting the request.

14. Security measures

  1. The Controller applies appropriate technical and organizational measures to ensure the protection of personal data adequate to the risk, in particular protecting data against access by unauthorized persons, loss, destruction, unauthorized modification, or disclosure.
  2. Access to personal data is granted only to authorized persons and entities with whom the Controller has concluded appropriate agreements, if required by law.
  3. The Controller regularly reviews the safeguards in place and adjusts them to the nature of the processed data, risks, and technological and organizational changes.

15. Changes to the Privacy Policy

  1. The Privacy Policy is periodically reviewed and may be updated, in particular in the event of changes in legal regulations, technology, tools used in the Service, Service functionalities, or the Controller's data processing activities.
  2. The current version of the Privacy Policy is available in the Service and is effective from the date indicated at the beginning of the document.
© Fortis Technology 2026 All rights reserved.
×
Service Contact To top