Privacy Policy of ML MEBLE Sp. z o.o.
Table of Contents
I. About us
II. General Provisions
III. How we use your personal data
IV. The principles and legal basis for processing your data
V. Your rights
VI. How we will contact you
VII. The timeframe for fulfilling your request
VIII. Subcontractors/Data processors
IX. How we ensure the protection of your data
X. Data retention
XI. Authorizations
XII. Cookies
I. About Us
As a responsible organization aware that information has a certain value and constitutes a resource requiring proper protection, we are committed to informing you appropriately about matters related to the processing of personal data, especially in light of the new personal data protection regulations, including the General Data Protection Regulation (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”). Therefore, in this document, we present key information on the legal grounds for processing personal data, the ways in which we collect and use it, as well as the rights of individuals to whom the data pertains.
ML Meble Spółka z o.o., Liw, ul. Zawadzka 14, 07-100 Węgrów, registered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, XIV Commercial Division of the National Court Register, under KRS number: 0000934667, NIP: 8241810213. Personal data is collected and processed in the manner and on the principles set forth in this Policy.
II. General Provisions
At ML Meble Sp. z o.o., we place particular emphasis on protecting the privacy of our clients, contractors, employees, and collaborators. One of the key aspects of this protection is safeguarding the rights and freedoms of individuals in connection with the processing of their personal data.
We ensure that the processing of your data complies with the provisions of the General Data Protection Regulation 2016/679/EU (hereinafter referred to as "GDPR"), the Personal Data Protection Act, as well as specific regulations (including those in labor law or accounting law).
ML Meble Sp. z o.o. is the administrator of personal data within the meaning of Article 4(7) of the GDPR, and we also use the services of data processors referred to in Article 4(8) of the GDPR – these entities process personal data on behalf of the administrator (such as accounting, IT, and security companies).
ML Meble Sp. z o.o. implements appropriate technical and organizational measures to ensure a level of security that matches the risk of violations of the rights or freedoms of natural persons, with varying probabilities and severities of the threat. Our actions related to the protection of personal data are based on adopted policies and procedures, as well as regular training programs aimed at enhancing the knowledge and competencies of our employees and collaborators.
III. How We Use Your Personal Data
As an employer, we process personal data of employees and individuals collaborating with us under other than employment agreements. Contact data obtained from contractors (e.g., their employees) are used for entering into and effectively executing contracts. We use our clients' data to fulfill agreements and provide our services. We also conduct marketing activities and, in this regard, strive to reach as wide an audience as possible to ensure they receive current information about our products and services.
We share your data with third parties based on your consent or when required by law.
IV. The Principles and Legal Basis for Processing Your Data
We take care to protect the interests of individuals whose data is processed, ensuring that personal data is:
Processed lawfully, fairly, and transparently for the data subject;
Collected for specified, legitimate purposes and not processed further in ways incompatible with those purposes;
Adequate, relevant, and limited to what is necessary for the purposes for which it is processed;
Accurate and, where necessary, kept up to date. We take steps to ensure that inaccurate personal data is erased or rectified without delay;
Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes of processing;
Processed in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage.
We typically process your data based on consent, which can be withdrawn at any time. Another basis for processing is when processing is necessary for the performance of a contract to which you are a party, or for taking steps at your request before entering into a contract.
In certain situations, processing is necessary to fulfill a legal obligation that we, as the administrator, are subject to (such as labor law or accounting obligations).
Processing may also be necessary for the purposes of our legitimate interests, such as pursuing claims related to our business operations.
V. Your Rights
We take appropriate measures to provide you with concise, transparent, intelligible, and easily accessible information and communication regarding the processing of your personal data. You have the right to:
Information provided at the time of data collection;
Information provided upon request – whether your data is being processed and other matters specified in Article 15 of the GDPR, including the right to a copy of your data;
Rectification of data;
Erasure (right to be forgotten);
Restriction of processing;
Data portability;
Objection to processing;
Not being subject to decisions based solely on automated processing (including profiling);
Information about data breaches.
Additionally, if your personal data is processed based on your consent, you have the right to withdraw it at any time. Withdrawal of consent does not affect the legality of processing carried out before its withdrawal.
To exercise any of your rights, please contact us via:
Email: lod@mlmeble.pl
Correspondence address: Liw, ul. Zawadzka 14, 07-100 Węgrów.
Your data security is our priority. If you believe that we are violating the provisions of the GDPR in processing your personal data, you have the right to file a complaint with the President of the Personal Data Protection Office.
VI. How We Will Contact You
We provide information in writing or by other means, including electronically when appropriate. If you request, we can provide the information orally, provided that we verify your identity in another way. If you submit your request electronically, we will, where possible, respond electronically unless you specify a different preferred form of communication.
VII. The Timeframe for Fulfilling Your Request
We strive to provide information promptly, generally within one month of receiving the request. If necessary, this timeframe may be extended by another two months due to the complexity of the request. However, in any case, within one month of receiving the request, we will inform you of the actions taken and, where applicable, of the extended deadline, with the reasons for the delay.
VIII. Subcontractors/Data Processors
If we collaborate with entities that process personal data on our behalf, we use only those data processors that provide sufficient guarantees of implementing appropriate technical and organizational measures to ensure that data processing meets the requirements of the GDPR and protects the rights of data subjects.
We thoroughly check the entities we entrust with processing your data. We enter into detailed contracts with them and regularly audit their compliance with the terms of the contract and legal regulations.
Recipients of your personal data may include:
Entities and authorities authorized to process personal data under applicable law, banks in cases of necessary settlements,
Institutions granting funding for the execution of a contract with the Administrator,
Entities cooperating in marketing campaigns,
Couriers,
Transport and shipping companies,
Accounting service providers,
IT service providers,
Hosting service providers,
Software and system providers,
Providers of automatic client notification systems regarding their order status,
Insurance companies,
Facebook, in accordance with Facebook’s unalterable data handling rules available at https://www.facebook.com/about/privacy.
IX. How We Ensure the Protection of Your Data
To comply with legal requirements, we have developed detailed procedures covering issues such as:
Data protection by design and by default;
Data protection impact assessments;
Notification of data breaches;
Keeping a register of data processing activities;
Data retention;
Exercising the rights of data subjects;
We regularly review and update our documentation to demonstrate compliance with legal requirements as per the GDPR’s accountability principle and incorporate best industry practices in the interest of the data subjects.
X. Data Retention
We store personal data in a form that allows the identification of the data subject for no longer than is necessary for the purposes for which the data is processed. After such a period, the data is anonymized (deprived of identifying features) or deleted. In the retention procedure, we ensure that the period for storing personal data is minimized.
The data processing period is primarily determined based on legal regulations (e.g., the time for storing employee documentation, accounting documents), as well as the justified interest of the administrator (e.g., marketing activities). The retention policy covers both paper and electronic data.
XI. Authorizations
We ensure that any person acting on our behalf and having access to your personal data processes it only on our instruction, unless other requirements arise from EU law or the law of a member state.
XII. Cookies
The policy of using cookies (small data files) on the service.
a) Cookies are text files stored on the User’s device and intended for use on the service’s website. Cookies typically contain the name of the website from which they come, the time they are stored on the device, and a unique number.
b) The entity placing cookies on the User's device and accessing them is the owner of the service.
c) The cookie mechanism is not used to collect any information about users of the service or to track their navigation. Cookies used on the service do not store any personal data or other information gathered from users and are used for statistical purposes.
d) By default, web browsing software (browser) allows cookies to be handled on the User’s device. In most cases, the software can be configured to block cookies automatically. The configuration of cookie handling can be adjusted in the browser’s settings. Please note that restricting cookie handling may affect the functioning of certain website features.
e) Cookies are used for:
Adjusting website content to the User's preferences and optimizing the use of the website, including recognizing the User’s device and displaying the website accordingly,
Creating statistics to understand how Users use the website, improving its structure and content,
Maintaining the User session (after logging in), so the User does not need to re-enter their login and password on every page of the service.
f) The service uses two main types of cookies: “session” cookies (temporary files) and “persistent” cookies (stored for a specified period).
g) The service uses the following types of cookies:
“Essential” cookies, allowing the use of services available within the service, such as authentication cookies,
Security cookies, used to detect authentication abuse,
“Performance” cookies, for collecting information about how users interact with the service,
“Functional” cookies, remembering selected settings by the User and customizing the interface, such as language or region.
Links to Other Websites on the Service's Page
The service owner informs that the service contains links to other websites. The service owner recommends reviewing the privacy policies in effect on those sites, as they are not responsible for them.
User Data Protection in the Service
A description of the technical and organizational measures for data protection is contained in the Service Owner's Security Policy (personal data protection). In particular, the following security measures are implemented:
a) Data automatically collected by the server is protected through an access authentication mechanism to the service.
b) Data collected from users during the registration process is protected by the SSL protocol and through an access authentication mechanism to the service.
c) Access to the administration of the service is secured by an authentication mechanism.

