Privacy Policy (RODO / GDPR)
How Marine Engine Solutions collects, uses, and protects your personal data.
1. Data Controller
The data controller responsible for processing your personal data is:
- Company Name
- Marine Engine Solutions Sp. z o.o.
- Address
- [YOUR REGISTERED ADDRESS]
[POSTAL CODE] [CITY], Poland - NIP
- PL [YOUR NIP NUMBER]
- info@marineengineservice.pl
- Phone
- +48 123 456 789
If you have any questions about how we process your personal data, please contact our Data Protection Officer at info@marineengineservice.pl.
2. What Data We Collect
We collect and process the following categories of personal data:
2.1 Data You Provide Directly
- Contact Information: Name, email address, phone number, shipping/billing address
- Account Information: Login credentials, account preferences
- Order Information: Purchase history, product inquiries, quote requests
- Communication: Emails, messages, support tickets, chat transcripts
- Payment Data: Bank account details, payment card information (processed securely by our payment providers)
2.2 Data Collected Automatically
- Technical Data: IP address, browser type, device information, operating system
- Usage Data: Pages visited, time spent, clicks, search queries, referral sources
- Cookie Data: Preferences, session identifiers, analytics identifiers (see our Cookie Policy)
- Location Data: Approximate geographic location based on IP address
2.3 Data from Third Parties
- Payment processors (transaction confirmation)
- Shipping carriers (delivery status updates)
- Social media platforms (if you interact with our pages)
3. Legal Basis for Processing
Under RODO/GDPR Article 6, we process your personal data based on the following legal grounds:
| Purpose | Legal Basis |
|---|---|
| Order processing & delivery | Art. 6(1)(b) — Performance of a contract |
| Customer support & communication | Art. 6(1)(b) — Performance of a contract / Art. 6(1)(f) — Legitimate interest |
| Accounting & tax compliance | Art. 6(1)(c) — Legal obligation |
| Marketing & newsletters | Art. 6(1)(a) — Consent (withdrawable at any time) |
| Website analytics & improvement | Art. 6(1)(f) — Legitimate interest |
| Fraud prevention & security | Art. 6(1)(f) — Legitimate interest |
4. How We Use Your Data
We use your personal data for the following purposes:
- To process and fulfill your orders — including payment processing, shipping, delivery, and returns
- To provide customer support — responding to inquiries, troubleshooting, warranty claims
- To manage your account — account creation, login, preference management
- To comply with legal obligations — tax records, invoicing, regulatory reporting
- To improve our website — analytics, user experience optimization, error fixing
- To send marketing communications — only with your explicit consent (newsletters, promotions, product updates)
- To prevent fraud — transaction security, identity verification
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
| Data Category | Retention Period |
|---|---|
| Order & transaction data | 5 years (Polish tax law requirement) |
| Account information | Until account deletion + 1 year |
| Marketing consent records | Until consent withdrawal + 2 years |
| Customer support tickets | 3 years from case closure |
| Website analytics data | 26 months (Google Analytics default) |
| Cookie consent records | 1 year |
After the retention period expires, your data is securely deleted or anonymized.
6. Data Sharing & Recipients
We do not sell your personal data. We may share your data with the following categories of recipients:
- Service Providers: Hosting (e.g., OVH, AWS), email delivery, analytics platforms
- Payment Processors: Stripe, PayPal, Przelewy24 (for secure payment handling)
- Shipping Carriers: DHL, DPD, InPost, FedEx (for order delivery)
- Marketing Platforms: Mailchimp, Klaviyo (only with your consent)
- Legal Authorities: When required by law, court order, or regulatory request
- Professional Advisors: Accountants, lawyers, auditors (bound by confidentiality)
All third-party processors are bound by data processing agreements (DPA) compliant with RODO/GDPR Article 28.
7. International Data Transfers
Your personal data is primarily processed within the European Economic Area (EEA). However, some of our service providers (e.g., Google, Meta, Mailchimp) may transfer data outside the EEA.
When this occurs, we ensure adequate protection through:
- EU Standard Contractual Clauses (SCCs)
- Adequacy decisions by the European Commission
- Certification under the EU-US Data Privacy Framework (where applicable)
8. Your Rights Under RODO/GDPR
As a data subject, you have the following rights:
- Right to Access (Art. 15) — Request a copy of the personal data we hold about you
- Right to Rectification (Art. 16) — Request correction of inaccurate or incomplete data
- Right to Erasure / "Right to be Forgotten" (Art. 17) — Request deletion of your data, subject to legal retention obligations
- Right to Restriction of Processing (Art. 18) — Request limited processing in certain circumstances
- Right to Data Portability (Art. 20) — Receive your data in a structured, machine-readable format
- Right to Object (Art. 21) — Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent (Art. 7) — Withdraw consent at any time without affecting prior lawful processing
- Right to Lodge a Complaint (Art. 77) — File a complaint with the Polish Data Protection Authority (UODO)
To exercise any of these rights, please contact us at info@marineengineservice.pl. We will respond within 30 days of receiving your request.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- SSL/TLS Encryption — All data transmitted between your browser and our servers is encrypted
- Secure Hosting — Servers protected by firewalls, intrusion detection, and regular security audits
- Access Controls — Role-based access limited to authorized personnel only
- Regular Backups — Encrypted backups with restricted access
- PCI-DSS Compliance — Payment data handled exclusively by certified payment processors
- Employee Training — Staff trained on data protection and privacy best practices
10. Children's Privacy
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at info@marineengineservice.pl and we will delete the information promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or technology. When we make significant changes, we will:
- Post the updated policy on this page with a revised "Last Updated" date
- Notify registered users via email if the changes are material
- Display a prominent notice on our website for 30 days
We encourage you to review this policy periodically. Continued use of our website after changes constitutes acceptance of the updated policy.
Contact Our DPO
For any privacy-related questions, data subject requests, or concerns:
Email: info@marineengineservice.pl
Phone: +48 123 456 789
Address: Marine Engine Solutions Sp. z o.o., [YOUR ADDRESS], Poland
We respond to all data subject requests within 30 days as required by RODO/GDPR.
It was last reviewed on 25 August 2026.
Marine Engine Solutions — marineengineservice.pl
All business details marked [YOUR ...] must be completed before publication.