Protecting your data
Information about the processing of personal data under GDPR by ABC Zabezpieczeń Sp. z o.o.
General provisions
1.1. This privacy policy is informational only, meaning it does not create obligations for Service Recipients or Customers of the Company.
1.2. The controller of personal data collected via employees is ABC ZABEZPIECZEŃ SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, seated in Warsaw (registered address: Al. Jerozolimskie 214, 02-486 Warsaw); entered in the Register of Entrepreneurs of the National Court Register under KRS number 0000527109; registration court: District Court for the Capital City of Warsaw, 13th Commercial Division of the National Court Register; NIP: 5223017810; REGON: 147366477; e-mail: info@smart-lock.pl – hereinafter the „Controller", acting also as Service Provider and Seller.
1.3. Personal data of Service Recipients and Customers are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (the regulation commonly known as GDPR).
1.4. The Controller takes particular care to protect the interests of data subjects, ensuring that collected data are processed lawfully; collected for specified, legitimate purposes and not further processed in ways incompatible with those purposes; substantively correct and relevant to the purposes for which they are processed, and stored in a form that allows identification of data subjects for no longer than necessary to achieve the processing purpose.
Purpose and scope of data collection and data recipients
2.1. Each time, the purpose, scope and recipients of data processed by the Controller result from actions taken by the Service Recipient or Customer. For example, if a Customer chooses in-person pickup instead of a courier shipment when placing an Order, their personal data will be processed to conclude and perform the Sales Agreement but will not be shared with a carrier delivering shipments on the Controller's behalf.
2.2. Possible purposes of collecting personal data of Service Recipients or Customers by the Controller:
- •2.2.1. conclusion and performance of a Sales Agreement or an agreement for the provision of a Service
- •2.2.2. direct marketing of the Controller's own products or services.
2.3. Possible recipients of Customers' personal data:
- •2.3.1. Where the Customer uses postal or courier delivery, the Controller discloses the collected personal data to the selected carrier or intermediary performing shipments on the Controller's behalf.
- •2.3.2. Where the Customer uses electronic or card payment, the Controller discloses the collected personal data to the selected entity handling such payments.
2.4. The Controller may process the following personal data of Service Recipients or Customers: first and last name; e-mail address; contact phone number; delivery address (street, house number, unit number, postal code, city, country), address of residence/business/registered office (if different from the delivery address). For Service Recipients or Customers who are not consumers, the Controller may additionally process the company name and tax identification number (NIP).
2.5. Providing the personal data referred to above may be necessary to conclude and perform a Sales Agreement or a Service Agreement.
Legal basis for data processing
3.1. Providing personal data by the Service Recipient or Customer is voluntary; however, failure to provide the personal data necessary to conclude and perform a Sales Agreement or a Service Agreement makes it impossible to conclude such an agreement.
3.2. The legal basis for processing personal data of the Service Recipient or Customer is the necessity to perform the agreement to which they are a party or to take actions at their request before entering into it. Where data are processed for direct marketing of the Controller's own products or services, the basis is (1) prior consent of the Service Recipient or Customer or (2) fulfilment of legitimate purposes pursued by the Controller.
Right to control, access and correct your data
4.1. At any time the Service Recipient or Customer has the right to access and correct their personal data.
4.2. Every person has the right to control the processing of data that concern them and are held in the Controller's data set, including in particular the right to: request supplementation, updating, correction of personal data, temporary or permanent suspension of processing or their deletion if they are incomplete, out-of-date, untrue or collected in breach of the law or no longer needed for the purpose for which they were collected.
4.3. Where the Service Recipient or Customer has consented to data processing for direct marketing of the Controller's own products or services, the consent may be withdrawn at any time.
4.4. Where the Controller intends to process or processes data of the Service Recipient or Customer for direct marketing of its own products or services, the data subject is entitled to (1) submit a written request to cease processing of their data or (2) object to the processing of their data.
4.5. To exercise the rights referred to above, you may contact the Controller by sending an appropriate message in writing or by e-mail to the Controller's address: info@smart-lock.pl.
Personal data retention period, in line with GDPR
5.1. Personal data processed to conclude or perform a contract and to comply with the Controller's legal obligation will be stored for the term of the contract and, after its expiry, for the period necessary to:
- •5.1.1. post-sale handling (e.g. complaints)
- •5.1.2. securing or pursuing any claims of ABC Zabezpieczeń Sp. z o.o.
- •5.1.3. fulfilling the Controller's legal obligation (e.g. under tax, accounting or other laws)
5.2. Personal data processed for marketing of ABC Zabezpieczeń Sp. z o.o.'s own products or services on the basis of legitimate interest will be processed until the data subject objects.
5.3. Personal data processed based on separate consent will be stored until the consent is withdrawn.
5.4. Personal data recorded in accounting documentation will be stored for the period indicated in applicable laws, including tax and accounting rules.
5.5. Data may be stored for the prevention of abuse and for statistical and archival purposes for 15 years from the end of the contract or the event requiring their processing. After that period, and provided there is no obligation to store them further, personal data will be deleted or anonymised.
Final provisions
6.1. The Controller applies technical and organisational measures ensuring protection of the processed personal data appropriate to the risks and categories of data protected, and in particular protects data against disclosure to unauthorised persons, seizure by an unauthorised person, processing in breach of applicable laws, and against alteration, loss, damage or destruction.
6.2. The Controller provides the following technical measures preventing acquisition and modification of personal data transmitted electronically by unauthorised persons:
- •6.2.1. Protecting the data set against unauthorised access.
Last updated: March 2026