Polityka Prywatności

Privacy Policy and Cookie Policy

1. Data Controller

The controller of your personal data is SZOP24 Sp. z o.o., Al. Marszałka J. Piłsudskiego 143, 92-332 Łódź, Poland, registered in the National Court Register (KRS) (hereinafter: the “Controller”).

2. Contact for Data Protection Matters

For any questions regarding the processing of your personal data, please contact us at: biuro@szopautomaty.pl.

The Controller has not appointed a Data Protection Officer (DPO). The Controller is not legally required to appoint a DPO given the nature and scope of its activities.

3. Purposes and Legal Basis for Processing

Your personal data is processed on the basis of Article 6(1)(b), (c) and (f) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).

Personal data is processed for the following purposes:

  • entering into and performing contracts (Article 6(1)(b) GDPR),
  • fulfilling legal obligations incumbent on the Controller, including tax and accounting obligations (Article 6(1)(c) GDPR),
  • selling goods and services,
  • processing financial settlements for completed transactions,
  • asserting or defending against legal claims, constituting the Controller’s legitimate interest (Article 6(1)(f) GDPR),
  • sending commercial communications regarding the Controller’s goods and services – only on the basis of prior consent.

4. Data Security

The Controller applies appropriate technical and organisational measures to protect personal data, in particular to prevent unauthorised access, disclosure, loss, destruction or alteration. All employees and associates with access to personal data are required to maintain confidentiality and to comply with internal security procedures.

5. Retention Period

Personal data is retained for the period necessary to fulfil the purposes for which it was collected, in particular:

  • for the duration of the contract and after its termination – until the expiry of the limitation period for claims arising from the contract,
  • for the period required by applicable law, including the retention period for accounting and tax documentation (generally 5 years from the end of the calendar year in which the tax payment deadline falls),
  • for the duration of any warranty or guarantee period,
  • where data is processed on the basis of consent – until that consent is withdrawn.

6. Recipients of Personal Data

In order to perform contracts properly, the Controller may share personal data with the following categories of recipients:

  • authorised employees and associates of the Controller,
  • processors acting on behalf of the Controller (e.g. IT service providers, hosting operators),
  • third parties where the transfer of data is necessary for the performance of the contract (postal operators, courier companies, banks, payment processors).

The Controller does not sell personal data to third parties.

7. Your Rights

Under the GDPR, you have the following rights:

  • right of access to your personal data (Article 15 GDPR),
  • right to rectification of inaccurate data (Article 16 GDPR),
  • right to erasure (“right to be forgotten”) (Article 17 GDPR),
  • right to restriction of processing (Article 18 GDPR),
  • right to data portability (Article 20 GDPR),
  • right to object to processing (Article 21 GDPR),
  • right to withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal (Article 7(3) GDPR).

If you consider that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, www.uodo.gov.pl.

8. International Data Transfers

Personal data collected by SZOP24 Sp. z o.o. is stored exclusively on servers located within the European Economic Area (EEA). The Controller does not transfer personal data to third countries or international organisations.

9. Automated Decision-Making and Profiling

The Controller does not process personal data by automated means, including profiling within the meaning of Article 22 GDPR, in a manner that produces legal effects or similarly significantly affects the individuals concerned.


Cookie Policy

1. What Are Cookies?

Cookies are small text files stored on your device (computer, tablet or smartphone) when you visit a website. A cookie typically contains the name of the website it originates from, its lifetime (expiry date), and a unique randomly generated identifier used to recognise your browser.

2. Types of Cookies We Use

  • Strictly necessary – essential for the website to function properly (e.g. session management). These do not require your consent.
  • Analytical/statistical – collect anonymous data about how the website is used (e.g. Google Analytics) to help us improve its functionality. These require your consent.
  • Marketing/advertising – allow us to tailor advertising content to your interests. These require your consent.
  • Functional – remember your preferences (e.g. language, region) to personalise your experience. These require your consent.

3. Legal Basis

Strictly necessary cookies are used on the basis of the Controller’s legitimate interest (Article 6(1)(f) GDPR). All other cookies are used only after you have given your express and freely given consent, in accordance with Article 6(1)(a) GDPR and applicable telecommunications law.

4. Managing Cookies

You have full control over cookies. You may withdraw your consent at any time by adjusting your preferences in the cookie settings panel available on our website, or by changing your browser settings. Withdrawing consent does not affect the lawfulness of processing that took place before withdrawal.

For guidance on managing cookies in popular browsers, please visit:

Disabling or restricting cookies may affect the availability of certain features of this website.
Last update: 26 May 2026