1. Data Controller
The controller of your personal data under the General Data Protection Regulation (GDPR — EU 2016/679) is:
Osowa 12, 98-405 Galewice, Poland
VAT-ID (NIP): 6191418511
E-mail: biuro@enmeble.pl
Phone: 607 733 501
2. What data we collect
We collect the following personal data only when you provide it to us:
- Contact form data: full name, e-mail address, phone number (optional), message content.
- Technical data: IP address, device and browser information (server logs) — stored for the period necessary for security.
3. Purposes and legal basis
- Handling your inquiry (Art. 6(1)(b) GDPR) — responding to messages, preparing custom furniture quotes, steps prior to entering into a contract.
- Order fulfilment (Art. 6(1)(b) GDPR) — communication during production and delivery.
- Legitimate interests (Art. 6(1)(f) GDPR) — protection against abuse (honeypot, rate limiting), website statistics.
- Legal obligations (Art. 6(1)(c) GDPR) — invoicing, accounting records.
4. Data retention period
- Contact form messages — for the duration of correspondence and 12 months after its completion.
- Order fulfilment data — for the period required by Polish tax law (min. 5 years from the end of the accounting year).
- Server logs — up to 90 days.
5. Data recipients
Your data is not sold or transferred to third countries. It may be shared only with:
- Hosting provider (e-mail and website storage) — within the EU.
- Courier company (for furniture delivery — only name, address, phone).
- Accounting office (invoice issuance).
- State authorities only based on applicable law.
6. Your rights
Under GDPR you have the following rights:
- Right of access to your data and to receive a copy.
- Right to rectification (correction) of data.
- Right to erasure ("right to be forgotten").
- Right to restriction of processing.
- Right to data portability.
- Right to object to processing.
- Right to withdraw consent at any time (where consent is the basis).
- Right to lodge a complaint with the President of the Polish Data Protection Authority (UODO).
To exercise any of these rights, contact us at biuro@enmeble.pl.
7. Cookies
enmeble.pl uses only cookies strictly necessary for the website to function:
PHPSESSID— session cookie for the admin panel (only for logged-in administrators).cookies_accepted— remembers your acceptance of the cookie banner (localStorage, 1 year).
We do not currently use analytical (Google Analytics) or marketing cookies. If this changes, we will update this policy and ask for your informed consent.
You can disable cookies at any time in your browser settings, but this may affect website functionality (e.g. admin panel login).
8. Data security
The website uses HTTPS protocol, CSRF protection on all forms, password hashing with bcrypt, and Content-Security-Policy headers protecting against XSS attacks. Data sent through the contact form is encrypted in transit.
9. Changes to this policy
We reserve the right to modify this policy. We will notify you of significant changes in advance. The latest version is always available at enmeble.pl/en/privacy-policy/.
10. GDPR contact
For all questions regarding personal data processing, please contact:
📧 biuro@enmeble.pl
📞 607 733 501
📍 Osowa 12, 98-405 Galewice, Poland
This privacy policy is a GDPR-compliant template. For legal matters we recommend consulting a lawyer specializing in personal data protection.