Skip to content Skip to footer

Personal Data Protection

Privacy Policy

Last updated 23.06.2026. Applies to the hurteks.pl website and commercial relations conducted by Hurteks Sp. z o.o.

This Privacy Policy describes the principles of personal data processing by Hurteks Sp. z o.o. in connection with the use of the hurteks.pl website, correspondence, and commercial cooperation. This document fulfils the information obligation arising from Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).

1.Definitions

For the purposes of this document, the following terms shall have the meanings set out below:

  • GDPR. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
  • Controller. Hurteks Sp. z o.o., the entity that determines the purposes and means of personal data processing.
  • Personal data. Any information relating to an identified or identifiable natural person.
  • Processing. Any operation performed on personal data, including collection, storage, modification, disclosure, and erasure.
  • Data subject. The natural person whose personal data are being processed.
  • Processor. An entity processing personal data on behalf of the Controller under a data processing agreement.
  • Website. The website available at hurteks.pl.
  • Supervisory authority. The President of the Personal Data Protection Office (UODO).

2.Data Controller and Contact

The controller of personal data is:

Hurteks Sp. z o.o.
ul. Juliana Smulikowskiego 4A, lok. 21
00-389 Warsaw, Republic of Poland
KRS 0001203396, District Court for the Capital City of Warsaw
NIP 5252961310, VAT-UE PL5252961310

Contact for personal data matters: office@hurteks.pl

The Controller has not appointed a Data Protection Officer, as the prerequisites set out in Article 37 of the GDPR are not met. For all matters relating to the processing of personal data and the exercise of rights, please contact us at the email address indicated above or in writing at our registered address.

3.Sources of Data Collection

The Controller collects personal data:

  • directly from the data subject, for example through the contact form, email correspondence, commercial discussions, and concluded contracts,
  • from a contractor who is the employer or principal of a contact person, regarding the professional data of persons designated to handle the cooperation,
  • from publicly available sources and official registers, in particular the National Court Register (KRS), the Central Register and Information on Economic Activity (CEIDG), and VIES databases, for the purpose of verifying a business entity’s status.

Where data is obtained from sources other than directly from the data subject, the Controller processes identification data, professional contact details, and registration data related to the conducted business activity, in accordance with Article 14 of the GDPR.

4.Purposes, Legal Bases and Retention Periods

Personal data are processed for the following purposes and on the following legal bases:

Purpose of processingLegal basisRetention period
Handling enquiries submitted via the contact form and email correspondenceArt. 6(1)(f) GDPR — legitimate interest in responding to enquiriesUntil the correspondence is concluded, then up to 12 months
Presenting a commercial offer and conducting negotiationsArt. 6(1)(b) GDPR — steps taken prior to entering into a contractUntil negotiations are concluded, then until the limitation period expires
Conclusion and performance of B2B contracts and ordersArt. 6(1)(b) GDPR — performance of a contractDuration of the contract
Issuing and retaining accounting and tax documentsArt. 6(1)(c) GDPR — legal obligation (Accounting Act, Tax Code)5 years from the end of the year in which the tax obligation arose
Pursuing or defending legal claimsArt. 6(1)(f) GDPR — legitimate interestUntil the claims limitation period expires
Direct marketing of own products and servicesArt. 6(1)(f) GDPR — legitimate interest, or Art. 6(1)(a) GDPR — consentUntil an objection is raised or consent is withdrawn
Sending the newsletterArt. 6(1)(a) GDPR — consentUntil consent is withdrawn
Statistics, analytics, and website securityArt. 6(1)(a) GDPR — consent to cookies, and Art. 6(1)(f) GDPRIn accordance with the Cookie Policy
Communication on social mediaArt. 6(1)(f) GDPR — legitimate interestUntil an objection is raised

5.Categories of Data Processed

Depending on the form of contact and the nature of the cooperation, the Controller may process the following categories of data:

  • identification and contact data: first name, last name, company name, job title, telephone number, email address,
  • address and registration data: registered address, NIP (tax identification number), REGON (statistical number), KRS number,
  • payment and settlement data: bank account number, invoicing details,
  • content of correspondence and information provided in the course of the cooperation,
  • technical data related to the use of the website: IP address, browser type, cookie identifiers, website activity data.

As a rule, the Controller does not process special categories of personal data within the meaning of Article 9 of the GDPR.

6.Voluntary Nature of Data Provision

Providing personal data is voluntary, but necessary to make contact, receive an offer, and enter into and perform a contract. In respect of the issuance of accounting documents, providing data is a statutory requirement. Failure to provide data may make it impossible to handle an enquiry or carry out the cooperation.

7.Server Log Files

Using the website involves the automatic recording of technical information in server logs, such as IP address, date and time of the request, browser type, and operating system. This data is used to ensure security, diagnose technical issues, and generate statistics, on the basis of Article 6(1)(f) of the GDPR. Server logs are not linked to data of specific individuals and are stored for the period necessary to fulfil the above purposes.

8.Social Media Profiles

The Controller may maintain profiles on social media platforms. Through these profiles, data of persons who interact with the Controller is processed to the extent made available by the relevant platform, for example account identifier, content of comments and messages. Processing is carried out on the basis of Article 6(1)(f) of the GDPR. The operator of the relevant social media platform remains an independent data controller to the extent resulting from its terms of service and privacy policy.

9.Newsletter and Marketing Communications

Subscribing to the newsletter is voluntary and requires providing an email address and giving consent. Consent may be withdrawn at any time, in particular by clicking the unsubscribe link included in every message or by contacting the Controller. Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal. The sending of commercial information by electronic means is carried out in accordance with the Act on the Provision of Electronic Services and the Telecommunications Law.

10.Recipients and Data Processors

Personal data may be disclosed or entrusted to entities supporting the Controller’s activities, including:

  • providers of hosting, email, and IT services,
  • providers of analytics and marketing tools,
  • accounting firms and tax and legal advisors,
  • financial institutions and payment operators,
  • courier, freight, and logistics companies,
  • public authorities and courts, where the obligation to disclose data arises from legal provisions.

Entities processing data on behalf of the Controller act on the basis of data processing agreements and exclusively in accordance with the Controller’s instructions.

11.Transfers of Data Outside the EEA

As a rule, the Controller processes data within the European Economic Area. If the use of third-party tools results in data being transferred outside the EEA, such transfer will only take place with appropriate safeguards as provided for in Chapter V of the GDPR, in particular on the basis of standard contractual clauses approved by the European Commission or an adequacy decision. Upon request, the Controller will provide information on the safeguards applied.

12.Data Retention Period

Personal data are retained for the period necessary to fulfil the purposes set out in section 4, and thereafter for the period required by law or until the claims limitation period expires. After the retention period has ended, the data are deleted or anonymised.

13.Rights of Data Subjects

Every individual has the following rights:

  • Right of access (Art. 15 GDPR). The right to obtain information about processing and a copy of the data.
  • Right to rectification (Art. 16 GDPR). The right to have inaccurate data corrected and incomplete data completed.
  • Right to erasure (Art. 17 GDPR). The right to request the deletion of data where there is no longer a basis for continued processing.
  • Right to restriction of processing (Art. 18 GDPR). The right to request that operations on data be suspended in certain situations.
  • Right to data portability (Art. 20 GDPR). The right to receive data in a structured format and to have it transferred to another controller.
  • Right to object (Art. 21 GDPR). The right to object to processing based on legitimate interest, including direct marketing.
  • Right to withdraw consent. In respect of processing based on consent, without affecting the lawfulness of processing carried out prior to withdrawal.

To exercise the above rights, please contact the Controller at office@hurteks.pl. The Controller will respond without undue delay, and no later than one month from receipt of the request.

14.Right to Lodge a Complaint

Any data subject who considers that the processing of their data infringes the GDPR has the right to lodge a complaint with the supervisory authority:

President of the Personal Data Protection Office
ul. Stawki 2, 00-193 Warsaw
uodo.gov.pl

15.Automated Decisions and Profiling

The Controller does not make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect data subjects. Should such processing be implemented, the Controller will inform the affected data subjects and explain the principles applicable to it.

16.Data Security

The Controller applies appropriate technical and organisational measures to protect personal data, commensurate with the risk, in accordance with Article 32 of the GDPR. These measures include, in particular, access controls, transmission encryption, regular backups, and incident response procedures. Access to data is restricted to authorised individuals who are bound by a duty of confidentiality.

17.Cookies

The hurteks.pl website uses cookies and similar technologies. The detailed rules governing their use are described in a separate document: Cookie Policy.

18.Changes to the Privacy Policy

The Controller reserves the right to amend this Privacy Policy, in particular in connection with changes in legislation or the scope of business activities. The current version of the document is always available on the hurteks.pl website, and the date of the last update is indicated at the beginning of the document.

Hurteks Sp. z o.o., ul. Juliana Smulikowskiego 4A/21, 00-389 Warsaw. KRS 0001203396, NIP 5252961310, VAT-UE PL5252961310.

We design and craft contemporary textiles

Hurteks is a company that buys, sells, and acts as an intermediary in all types of unregulated products. It primarily buys in Asia and resells in Europe. The products can include textiles, clothing

Address

4a/21 Juliana Smulikowskiego Street,
00-389 Warsaw, Poland

Say Hello
infohurteks@gmail.com

HURTEKS © 2026. All Rights Reserved.

Używamy plików cookie, aby zapewnić Ci najlepsze wrażenia na naszej stronie internetowej. Jeśli nadal będziesz korzystać z naszej strony, założymy, że jesteś z tego zadowolony.