Privacy and Cookie Policy

BORNIAK Privacy Policy

Last updated: 12 June 2026

Version: global version for borniak.pl, borniak.de, borniak.com and borniak.co.uk

This Privacy Policy describes how personal data of users, customers, business partners and persons contacting the BORNIAK brand are processed through websites, online stores, forms, electronic communication channels, after-sales services, complaints, warranty and service processes.

This document has been prepared with regard to Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and, for users in the United Kingdom, the UK GDPR and the Data Protection Act 2018.

1. Definitions

For the purposes of this Privacy Policy, the following terms have the meanings set out below:

  • Controller – the entity deciding on the purposes and means of personal data processing, identified in section 2 of this Privacy Policy.
  • BORNIAK – the trade brand used by ZUT BORNIAK Dawid Szurlej and BORNIAK LTD.
  • Websites – websites operated under the domains borniak.pl, borniak.de, borniak.com and borniak.co.uk, including online stores, forms, customer accounts and related electronic services.
  • User – any person visiting the Websites or using BORNIAK electronic services.
  • Customer – a natural person, legal person or organisational unit making a purchase or taking steps to enter into a contract with the Controller.
  • Personal data – any information relating to an identified or identifiable natural person.
  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council.
  • UK GDPR – the United Kingdom data protection rules corresponding to the General Data Protection Regulation.
  • Cookies – text files or similar technologies stored on the user's device or allowing information to be read from the device.
  • Consent Manager – BORNIAK's own consent management module used on the Websites.

2. Controllers of personal data

2.1. Websites borniak.pl, borniak.de and borniak.com

The controller of personal data of users of borniak.pl, borniak.de and borniak.com is:

ZUT BORNIAK Dawid Szurlej
Al. Niepodległości 41
78-449 Borne Sulinowo
Poland
Tax ID (NIP): PL8992343025
REGON: 021138535
GIOŚ No.: E0013994W
E-mail for data protection matters: support@borniak.com

For the German market, the Controller also uses the following identification details:

VAT ID: DE 305403854
Tax number: 111/134/03251
WEEE Reg. No.: DE 31838397
Warehouse and service: Lochau 24, D-95704 Pullenreuth, Germany

2.1.1. Information for customers in Germany

For customers using borniak.de, logistics, warehouse and service support in Germany is also provided by:

BORNIAK Deutschland – Service & Logistik
Lochau 24
95704 Pullenreuth
Germany

This address may be used for service, complaint, warranty, logistics and customer contact purposes on the German market.

2.2. Website borniak.co.uk

The controller of personal data of users of borniak.co.uk is:

BORNIAK LTD
590 Kingston Road
London, SW20 8DN
England, United Kingdom
Company No: 14423007
VAT Number: GB428268280
Warehouse and service: Poole, United Kingdom
E-mail for data protection matters: support@borniak.com

2.3. Common contact point

For matters concerning data protection, exercising data subject rights, questions about processing, withdrawal of consent or objection to processing, please contact:

support@borniak.com

3. Scope of this Privacy Policy

This Privacy Policy applies to the processing of personal data in connection with the following domains and services:

  • borniak.pl – online store and information about BORNIAK products,
  • borniak.de – online store and information about BORNIAK products,
  • borniak.com – information and catalogue website allowing users to view products, prices and distributors, with no direct sales as at the date of publication of this Privacy Policy,
  • borniak.co.uk – online store operated by BORNIAK LTD,
  • contact, complaint, warranty, service and repair forms,
  • newsletter and marketing communication,
  • customer account in the online store,
  • purchase of digital subscriptions, including Borcook Plus, through the online store.

This Privacy Policy does not regulate in detail the operation of BORNIAK or Borcook mobile applications if such applications have their own terms and conditions or privacy policy. The online store account is not a mobile application account and is not automatically linked to it.

4. Categories of personal data processed

The scope of personal data depends on how the Websites and BORNIAK services are used. The Controller may process in particular the following categories of data:

4.1. Identification data

  • first and last name,
  • company name,
  • tax identification number, VAT number or other tax ID,
  • details of a contact person representing a company.

4.2. Contact details

  • e-mail address,
  • telephone number,
  • correspondence address,
  • delivery address,
  • billing address.

4.3. Customer account data

  • login or account identifier,
  • e-mail address,
  • password in encrypted or cryptographic hash form,
  • order history,
  • addresses saved in the account,
  • account settings,
  • account creation date,
  • login history and account security activity.

4.4. Purchase and transaction data

  • order number,
  • order date,
  • ordered products or services,
  • order value,
  • currency,
  • payment status,
  • payment method,
  • order fulfilment status,
  • transaction or order identifier from a marketplace platform, if the order was placed through such a platform,
  • data provided by the marketplace operator to the extent necessary for order fulfilment, settlement, delivery, returns, complaints or after-sales support,
  • invoice data,
  • delivery data,
  • information on returns, complaints and warranties.

4.5. Technical and usage data

  • IP address,
  • device type,
  • browser type and version,
  • operating system,
  • cookie identifiers,
  • session data,
  • date and time of visit,
  • visited pages,
  • traffic source,
  • data concerning consent to cookies and similar technologies.

4.6. Data submitted in forms

  • message content,
  • subject of enquiry,
  • product information,
  • device serial number,
  • information about a defect,
  • information concerning complaints, warranty, returns, spare parts or repair,
  • attached files, including photos of the device, photos of damage, invoices, PDF documents and technical documentation.

4.7. Data related to digital services and Borcook Plus subscription

  • device identifier,
  • device serial number,
  • licence identifier,
  • purchase or order identifier,
  • subscription status,
  • subscription period,
  • data necessary to process payments for digital services,
  • other technical identifiers necessary to activate, maintain or provide digital services.

The online store account and the Borcook mobile application account are separate accounts. The terms and detailed rules for using the Borcook application are set out in the application or in documents applicable to that application. The BORNIAK online store may allow the purchase of a Borcook Plus subscription and its assignment to a specified device. The Controller may also offer additional digital services, licences, subscriptions or premium features connected with BORNIAK products in the future.

5. Sources of data

The Controller obtains personal data primarily directly from the user or customer, in particular when:

  • the user visits the Websites,
  • the user creates a customer account,
  • the customer places an order,
  • the customer places an order through an external sales platform, in particular Allegro, Amazon or another marketplace used by the Controller,
  • the user subscribes to the newsletter,
  • the user completes a contact, service, complaint, warranty or return form,
  • the user contacts the Controller by telephone, e-mail or otherwise,
  • the user consents to cookies or marketing and analytics technologies,
  • the user uses Google or Apple login.

The Controller may also receive data from payment partners, carriers, authorised service partners, distributors, marketplace platform operators, providers of sales, ERP, warehouse, logistics, accounting and customer service systems, analytics and marketing tools, customer review providers and entities maintaining technical infrastructure, to the extent necessary for the relevant purpose.

6. Purposes and legal bases of processing

The Controller processes personal data only where there is an appropriate legal basis. Data may be processed for the following purposes:

6.1. Use of the Websites and ensuring their security

Technical data, including IP address, browser data, session data and server logs, are processed to display the Websites correctly, ensure stability and security, and protect them against misuse, errors, attacks and unauthorised access.

Legal basis: Article 6(1)(f) GDPR – the Controller's legitimate interest in ensuring the security and proper operation of the Websites.

6.2. Creating and maintaining a customer account

Customer account data are processed to enable registration, login, account management, ordering, viewing order history and using customer account functions in the online store.

Legal basis: Article 6(1)(b) GDPR – performance of a contract for the customer account service.

6.3. Order fulfilment

Personal data are processed to accept orders, including orders placed through external sales platforms, confirm purchases, issue sales documents, process payments, prepare shipments, deliver products, handle returns and complaints and communicate with the customer about the order.

To ensure efficient order fulfilment, data may be automatically transferred and synchronised between systems used by the Controller, in particular the e-commerce platform, ERP system, warehouse and logistics systems, accounting systems, payment systems and customer service systems.

Legal basis: Article 6(1)(b) GDPR – performance of a sales contract or taking steps before entering into a contract; Article 6(1)(c) GDPR – compliance with legal obligations, in particular tax and accounting obligations.

6.4. Payment handling

Payment data are processed to enable payment for an order or subscription. The Controller does not store full payment card details. Payments are handled by external payment platforms.

Legal basis: Article 6(1)(b) GDPR – performance of a contract; Article 6(1)(c) GDPR – accounting and tax obligations; Article 6(1)(f) GDPR – establishing and defending claims and preventing abuse.

6.5. Purchase of Borcook Plus subscription

Data are processed to enable the purchase of the Borcook Plus digital subscription in the online store, process payment, confirm the transaction and assign the subscription to the indicated device identifier.

Legal basis: Article 6(1)(b) GDPR – performance of a contract for a digital service; Article 6(1)(c) GDPR – accounting and tax obligations; Article 6(1)(f) GDPR – protection against abuse and establishing or defending claims.

6.6. Contact forms, product enquiries and spare parts

Data submitted through forms are processed to respond, handle the enquiry, prepare an offer, provide information about products, prices, availability, spare parts or distributors.

Legal basis: Article 6(1)(f) GDPR – legitimate interest in handling enquiries; Article 6(1)(b) GDPR – where the enquiry relates to entering into or performing a contract.

6.7. Complaints, warranties, returns, service and repairs

Personal data are processed to handle complaints, warranties, returns, repairs, service requests, device diagnostics, customer communication, collection or shipment of devices, assessment of claims and compliance with legal or contractual obligations.

Legal basis: Article 6(1)(b) GDPR – performance of a contract or exercise of customer rights; Article 6(1)(c) GDPR – legal obligations; Article 6(1)(f) GDPR – establishing, pursuing and defending claims.

6.8. Newsletter

Personal data are processed to send newsletters, commercial information, product information, promotions, news and marketing materials. Newsletter data are collected through the online store and may be exported or synchronised with Brevo.

Legal basis: Article 6(1)(a) GDPR – user consent; rules on electronic communication and direct marketing.

6.9. Marketing, analytics, remarketing and conversion measurement

Data are processed to analyse traffic on the Websites, measure advertising effectiveness, run Google Ads campaigns and remarketing, display interest-based ads, optimise content and create statistics.

Legal basis: Article 6(1)(a) GDPR – consent to cookies and similar technologies where required; Article 6(1)(f) GDPR – legitimate interest in basic statistics not requiring consent, where permitted by law.

6.10. Customer reviews and trust marks

Data may be processed in connection with Trusted Shops and other review systems to send review invitations, display reviews, provide buyer protection or confirm store credibility.

Legal basis: Article 6(1)(a) GDPR – consent where required; Article 6(1)(b) GDPR – performance of buyer protection service; Article 6(1)(f) GDPR – legitimate interest in building store credibility and handling reviews.

6.11. Communication related to product and service safety

The Controller may contact customers regarding product safety, software updates, service actions, technical information, recalls, changes to digital service functionality or other information relevant to safe use of BORNIAK products.

Legal basis: Article 6(1)(c) and (f) GDPR.

6.12. Legal obligations

Personal data may be processed to comply with tax, accounting, consumer, record-keeping, warranty, product safety and manufacturer, importer or seller obligations, including obligations arising from Regulation (EU) 2023/988 on general product safety (GPSR).

Legal basis: Article 6(1)(c) GDPR – legal obligation imposed on the Controller.

6.13. Establishing and defending claims

Data may be processed to establish, pursue or defend claims, handle disputes, complaint procedures, alternative dispute resolution and communication with attorneys, insurers or public authorities.

Legal basis: Article 6(1)(f) GDPR – legitimate interest of the Controller.

7. Voluntary provision of data and consequences of failure to provide data

Providing personal data is voluntary, but in some cases it may be necessary to use specific Website functions, enter into or perform a contract, fulfil an order, process payment, delivery, complaint, warranty, return, service, repair, contact with the Controller or purchase of digital services.

Failure to provide data required for a given purpose may result in the inability to create a customer account, place an order, deliver an order, issue an invoice, process payment, consider a complaint, perform a service, respond to an enquiry or provide a digital service.

Providing data for newsletter, analytics cookies, marketing cookies, remarketing, ad personalisation or other consent-based activities is voluntary. Refusal of consent does not affect the use of basic Website functions but may limit certain additional functions, content personalisation or marketing communications.

8. Customer account in the online store

The user may create a customer account that allows, among other things, placing orders, saving addresses, viewing purchase history and using online store functions.

Creating an account is voluntary unless a particular function requires an account. The user may request account deletion at any time by contacting the Controller at support@borniak.com or using available account functions.

Account deletion does not delete data that the Controller must retain under applicable law, in particular data relating to orders, invoices, complaints, warranties, tax settlements or claims.

The online store customer account is not a Borcook mobile application account and is not automatically linked to it.

9. Google and Apple login

The Websites may allow login or registration through external identity providers, in particular Google Login and Apple Login.

If the user chooses Google or Apple login, the relevant provider may transfer to the Controller data necessary to create or maintain the account, such as name, e-mail address or user identifier with that provider. The scope of transferred data depends on the user's account settings and the rules of the provider.

Using external login is voluntary. The user may also create a store account using an e-mail address and password.

10. Orders, payments and invoices

To fulfil an order, the Controller processes data necessary to enter into and perform a sales contract or a contract for digital services, including identification, contact, address, billing, order and payment data.

The Controller does not store full payment card details. Card data, payment authentication data and other sensitive payment information are processed by external payment providers in accordance with their security rules and terms.

The following payment methods or providers may be available on the Websites:

  • Stripe,
  • Stripe Card,
  • Stripe Klarna,
  • Stripe BLIK,
  • Stripe Revolut,
  • PayPal,
  • PayU,
  • Klarna,
  • Apple Pay,
  • Google Pay.

The list of payment providers may change. The current list is always presented during the order process.

The scope of data transferred to payment providers depends on the payment method selected and may include identification data, contact details, billing address, payment amount, currency, order number and information necessary to authorise and settle the transaction.

10A. Marketplace orders and automatic exchange of data between systems

Orders placed through external sales platforms, in particular Allegro, Amazon and other marketplaces used by the Controller, may be automatically imported into the Controller's IT systems for fulfilment.

In connection with sales handling, Customer data may be automatically transferred, imported, exported or synchronised between systems used by the Controller, in particular the e-commerce platform, ERP system, warehouse and logistics systems, accounting systems, payment systems and customer service systems.

The automatic exchange of data takes place only to the extent necessary for order fulfilment, payment processing, delivery, issuing sales and accounting documents, settlements, handling returns, complaints, warranties, service, after-sales support and complying with the Controller's legal obligations.

For orders fulfilled by BORNIAK LTD in the United Kingdom, data necessary for settlements, issuing accounting documents, tax and accounting services may be transferred to accounting systems and to providers of accounting and tax services.

11. Borcook Plus digital subscription

The BORNIAK online store may allow the purchase of the Borcook Plus digital subscription. This subscription concerns digital services related to the Borcook ecosystem.

When purchasing a subscription, the user may be asked to provide a device identifier, serial number, licence identifier or other technical identifiers necessary to assign the service to a specific device. These data are processed only to fulfil the purchase, assign the right to use the service, handle the subscription, settlements, technical support and possible complaint handling.

The online store account and the Borcook application account are separate accounts. Detailed rules for using the Borcook application, including the application account, may be set out in separate terms and privacy policy available in the application.

If the subscription is renewable or recurring, data may be processed by the payment provider to handle recurring payments in accordance with the provider's rules and the user's consent or payment instruction.

The Controller may in the future offer additional digital services, licences, subscriptions, premium features or other solutions related to BORNIAK devices. In such case, data may be processed to the extent necessary to provide those services.

12. Contact, product, spare parts, complaint, return, warranty, service and repair forms

The Controller provides forms enabling contact, product enquiries, spare parts enquiries, complaints, returns, warranty claims, service or repair requests.

Forms may process identification data, contact data, order data, product data, device serial number, defect description, customer expectations and attachments.

Service and complaint forms may allow attachments to be uploaded, in particular:

  • photos of the device,
  • photos of damage,
  • invoices,
  • PDF documents,
  • other documents needed to handle the request.

The user should ensure that attachments do not contain personal data of third parties or special categories of personal data unless this is necessary to handle the request. In particular, the user should not send health data, political opinions, religion, biometric data, private life data or other sensitive data unless absolutely necessary due to the nature of the request.

13. Transfer of data to authorised partners, distributors and service points

For warranty, complaint, service, repair, diagnostic or after-sales activities, the Controller may transfer customer personal data to selected authorised partners, distributors, service points or repair centres cooperating with the BORNIAK brand.

The scope of transferred data is limited to information necessary to handle the request, in particular:

  • first and last name,
  • company name, if applicable,
  • e-mail address,
  • telephone number,
  • delivery, collection or service address,
  • order number,
  • device serial number,
  • data relating to the service, complaint or warranty request,
  • attached documents and diagnostic materials.

Authorised partners, distributors and service points process data only to the extent necessary to perform the assigned activities and in accordance with applicable data protection laws. Depending on the circumstances, they may act as processors on behalf of the Controller or as separate controllers if they independently decide on the purposes and means of processing under their own legal or organisational obligations.

14. Newsletter, marketing communication and marketing automation

The user may voluntarily subscribe to the BORNIAK newsletter. At least the e-mail address is processed for this purpose and, depending on the form, also name, language preference, country, marketing consents and technical confirmation of subscription.

Newsletter data may be collected in the online store and then exported or synchronised with Brevo, which is used to send newsletters, marketing communications, marketing automation, recipient segmentation and analysis of message effectiveness.

The Controller may also use Brevo for e-mail remarketing, in particular reminder messages, abandoned cart messages, product recommendations, information about promotions, discount codes, special campaigns or communications adapted to the user's previous interactions with the Websites, where the user has given appropriate consent or where another legal basis allows such activity.

The newsletter is sent until the user withdraws consent. The user may unsubscribe at any time using the unsubscribe link in the message or by contacting the Controller at support@borniak.com.

Within newsletter and marketing communication, basic statistics may be measured, such as message opens, link clicks, reactions to messages, campaign effectiveness, use of discount codes or other interactions with marketing content, where the user has given appropriate consent or where applicable law allows this.

15. Cookies and similar technologies

The Websites use cookies and similar technologies to ensure correct operation of the pages, cart, user session, login, saving preferences, statistics, analytics, marketing, remarketing and measuring advertising effectiveness.

The Controller uses its own module for managing consents to cookies and similar technologies. The module allows the user to give or refuse consent to individual cookie categories and to change the decision later.

The following cookie categories may be used on the Websites:

  • Necessary – required for the correct operation of the website, store, cart, customer account, security and basic functions. These cookies usually do not require consent.
  • Preferences – allow remembering user settings such as language, region, display preferences or other convenience settings.
  • Statistics – allow analysis of how the Websites are used, traffic measurement, reporting and improvement of the Websites.
  • Marketing – allow advertising, remarketing, conversion measurement, ad personalisation and audience creation.

The user may manage consents through the consent module available on the Website. Changing consent settings does not affect the lawfulness of processing carried out before consent was withdrawn.

16. Google Consent Mode v2

The Websites use Google Consent Mode v2, which allows Google tags to operate according to the user's decisions on cookies, analytics and marketing.

Consent Mode v2 allows information about the user's consent status to be communicated to Google services, in particular for analytics, ads, ad personalisation and storage of advertising-related data. Depending on the consents granted, Google tags may operate in full or limited mode.

If the user does not consent to certain cookie categories, Google services may operate in a limited mode designed to respect the user's decision while enabling basic, aggregated measurement of Website and campaign effectiveness where permitted by law.

17. Google Analytics 4

The Websites may use Google Analytics 4, an analytics service provided by Google Ireland Limited. Google Analytics 4 enables analysis of Website use, statistical reports, traffic measurement, sources, events and marketing effectiveness.

Google Analytics 4 may process, among other data, IP address, cookie identifiers, device data, browser data, information on visited pages, events, clicks and user interactions.

If the User is signed in, Google Analytics 4 may also receive a pseudonymous user identifier (User-ID), which allows the use of the Services to be analysed across different sessions and devices. The User-ID does not contain directly identifying information such as the User's name, email address or telephone number and is used in accordance with the User's consent settings.

Google Analytics 4 is used on the basis of the user's consent where consent is required. The user may withdraw consent in the consent module.

Additional Google Analytics 4 functions may be used, such as Google Signals, demographic reports, conversion measurement or enhanced measurement, if the user has given appropriate consent and the functions are active on the Website.

18. Microsoft Clarity

The Controller uses or may use Microsoft Clarity, a service provided by Microsoft Corporation, for analysing Website use, identifying usability problems and optimising Website operation.

Microsoft Clarity may collect information about the user's activity on the Website, including mouse movements, scrolling, clicks, form interactions, device data, browser data, IP address and technical Website usage information.

The data are used only to improve functionality, quality, security and user experience of the Websites.

If applicable law requires user consent for Microsoft Clarity, the tool is activated only after the relevant consent is given through the consent module. The user may change consent settings at any time.

19. Google Ads, remarketing, conversion measurement, Google Merchant Center and Google Shopping services

The Controller uses or may use Google Ads, Google Ads Remarketing, Google Tag Manager, Google gtag.js, Google Merchant Center and Google Shopping services, as well as other Google tools for advertising campaigns, conversion measurement, ad optimisation, product presentation in Google services and analysis of marketing effectiveness.

Google Ads and remarketing may enable ads to be shown to users who previously visited the Websites or showed interest in BORNIAK products. Conversion measurement helps assess whether a user performed a specific action after clicking an ad, such as placing an order, sending a form or subscribing to the newsletter.

Google Merchant Center may be used to present information about products, prices, availability and the store in Google services, including search results, product ads and Google Shopping services.

Google marketing tools are used on the basis of user consent where consent is required. The user may withdraw consent in the consent module.

20. Google Tag Manager

The Websites may use Google Tag Manager, a tool provided by Google Ireland Limited for managing tags and scripts used on the Websites.

Google Tag Manager itself does not create user profiles, analyse user behaviour or display ads. However, it may enable the launch of other services described in this Privacy Policy, such as Google Analytics 4, Google Ads, Meta Pixel, Microsoft Clarity or other analytics and marketing tools.

Services launched through Google Tag Manager operate in accordance with the user's consent settings in the consent module.

21. Meta Platforms, Facebook, Instagram, Meta Pixel and Conversion API

The Controller may now or in the future use marketing tools of Meta Platforms Ireland Limited, in particular Meta Pixel, Meta Conversion API (CAPI), Facebook Ads and Instagram Ads.

These tools may be used to measure ad effectiveness, create audiences, run remarketing, optimise campaigns and show ads to persons interested in BORNIAK products.

Meta Pixel and similar technologies are used only in accordance with the user's decisions on cookies and marketing. If the user does not consent, these technologies should not be activated in full.

22. Google Maps

The Websites may use Google Maps to display locations, warehouses, service points, distributors or other places related to BORNIAK activity.

When using Google Maps, Google may process the user's technical data, including IP address, browser data and map interaction information. In some cases, data may be transferred to Google LLC in the United States.

If Google Maps is embedded in a way that requires consent, the map is loaded only after the user gives the relevant consent.

23. YouTube

The Websites may embed YouTube videos. YouTube is provided by Google Ireland Limited. Playing embedded videos may involve transferring technical data to Google, including IP address, device data, browser data and video playback information.

If the user is logged into a Google account, Google may associate the activity with that account according to its own privacy rules. Depending on the Website configuration, YouTube videos may be loaded only after the user has given consent.

24. Trusted Shops and customer reviews

The Websites may use Trusted Shops to display trust marks, customer reviews, review invitations and possible buyer protection.

In connection with Trusted Shops, data such as e-mail address, order number, order value, order information or other data necessary to provide a review, send a review invitation or use buyer protection may be transferred.

Transfer of data to Trusted Shops may include the e-mail address and order data necessary to verify the transaction, send a review invitation, display reviews or use buyer protection.

Transfer takes place in accordance with applicable rules, user consents and the operation of the relevant service.

25. Distributor search

The borniak.com Website may allow users to view BORNIAK distributor data. This function is used only to present distributor data and find the nearest or appropriate trade partner.

If the user only views distributor data, the Controller does not transfer the user's personal data to the distributor within this function. If a distributor contact form or enquiry forwarding function is introduced in the future, the data processing rules will be supplemented or described in the form.

26. Carriers and logistics operators

For delivery, collection of returns, handling complaints, warranty or service cases, the Controller may transfer personal data to carriers and logistics operators.

Depending on the country, selected delivery method and type of shipment, these may include in particular:

  • DHL,
  • DHL Freight,
  • DPD,
  • GLS,
  • UPS,
  • FedEx,
  • Raben,
  • Rhenus,
  • Schenker.

The scope of transferred data includes data necessary for delivery, collection or shipment handling, in particular first and last name, company name, delivery or collection address, telephone number, e-mail address, shipment number and information necessary for the logistics service.

27. Hosting, technical infrastructure and security

The Websites are maintained using technical infrastructure, servers, hosting services, database systems, e-mail, administrative tools, backups and IT security services.

Technical infrastructure providers may process personal data only to the extent necessary to maintain, secure, administer and ensure the proper operation of the Websites and BORNIAK systems.

Data may be stored and processed using cloud, hosting and IT service provider infrastructure used by the Controller to maintain sales, ERP, warehouse, logistics, accounting and customer service systems.

Customer data may be transferred to the ERP system provider and hosting and cloud service providers related to maintaining the ERP system used by the Controller.

For orders fulfilled by BORNIAK LTD, data necessary for accounting and tax services may be processed in the ERP system and by accounting, tax, hosting and cloud service providers supporting BORNIAK LTD's operations.

28. Recipients of personal data

Personal data may be transferred to the following categories of recipients:

  • hosting and IT infrastructure providers,
  • cloud, hosting and maintenance service providers,
  • providers of the store platform, online store maintenance and technical support,
  • marketplace platform operators, in particular Allegro, Amazon and other sales platforms used by the Controller,
  • providers of ERP, warehouse, logistics and order handling systems,
  • providers of accounting, bookkeeping and tax systems,
  • providers of accounting, tax and bookkeeping services,
  • IT service providers maintaining the Controller's systems,
  • providers of e-mail and communication tools,
  • newsletter providers, including Brevo,
  • analytics and marketing providers, including Google, Meta and Microsoft,
  • providers of analytics and user experience optimisation tools, including Microsoft Clarity,
  • consent management tool providers,
  • payment service providers,
  • banks and financial institutions,
  • carriers and logistics operators,
  • authorised partners, distributors, service points and repair centres,
  • entities handling complaints, returns, warranty and service cases,
  • Trusted Shops and other review system providers, if used,
  • accounting firms, tax advisers, auditors, law firms and attorneys,
  • public authorities, courts, offices, law enforcement authorities and supervisory authorities where required by law.

The Controller enters into appropriate data processing agreements with processors where required by law.

29. Transfers outside the European Economic Area and the United Kingdom

Some service providers used by the Controller may process data outside the European Economic Area or outside the United Kingdom, in particular in the United States.

This may apply in particular to some marketplace platform operators such as Amazon, accounting system providers, cloud, hosting, IT, analytics, marketing, payment or other providers supporting sales, settlements, logistics and customer service.

Transfers of personal data outside the European Economic Area or the United Kingdom take place only where there is an appropriate legal basis, in particular:

  • an adequacy decision,
  • the provider's participation in the EU-US Data Privacy Framework, the UK Extension to the EU-US Data Privacy Framework or another appropriate mechanism,
  • Standard Contractual Clauses approved by the European Commission,
  • standard clauses or transfer mechanisms recognised by UK law,
  • other safeguards permitted by the GDPR or UK GDPR.

The Controller applies appropriate organisational and legal measures to protect data transferred to third countries.

Detailed information on the safeguards used, including Standard Contractual Clauses, Data Privacy Framework certifications or other appropriate transfer mechanisms, may be obtained by contacting the Controller.

30. Data retention period

Personal data are stored for the period necessary to fulfil the purpose for which they were collected and then for the period required by law or the limitation period for claims.

  • customer account data are stored until the account is deleted unless further storage is required by law or for claims,
  • order, invoice and settlement data are stored in accordance with applicable local tax and accounting rules,
  • newsletter data are stored until consent is withdrawn,
  • contact form data are stored for 24 months unless the matter requires longer storage due to a contract, legal obligation or claims,
  • complaint and warranty data are stored for the warranty period and 3 years after it ends,
  • service and repair data are stored for the period necessary to perform the service and for the warranty or claims period,
  • Borcook Plus subscription data are stored for the duration of the subscription and for the period required by tax, accounting or claims rules,
  • cookie consent data are stored for the period needed to prove giving, refusing or withdrawing consent, according to consent module settings and applicable law.

31. Data subject rights

Data subjects have rights provided by the GDPR or UK GDPR, depending on the applicable legal system.

  • right of access to personal data,
  • right to receive a copy of data,
  • right to rectify inaccurate data,
  • right to complete incomplete data,
  • right to erase data where legal grounds exist,
  • right to restrict processing,
  • right to data portability,
  • right to object to processing based on legitimate interests,
  • right to object to direct marketing,
  • right to withdraw consent at any time where processing is based on consent,
  • right to lodge a complaint with a supervisory authority.

The right to erasure may be limited and will not be exercised to the extent that further processing is necessary for contract performance, compliance with a legal obligation, establishment, exercise or defence of claims or other reasons provided by applicable law.

To exercise rights, please contact the Controller at support@borniak.com.

The Controller may request additional information to confirm the identity of the person making the request where necessary to protect data from disclosure to an unauthorised person.

32. Right to withdraw consent

Where processing is based on consent, the user has the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Newsletter consent may be withdrawn using the unsubscribe link in the e-mail or by contacting the Controller.

Consent to cookies, analytics and marketing may be changed using the consent management module available on the Website.

33. Right to object

The user has the right to object at any time to the processing of personal data where the processing is based on the Controller's legitimate interest.

If the objection concerns direct marketing, the Controller will stop processing data for that purpose.

If the objection concerns other purposes based on legitimate interest, the Controller will stop processing unless it demonstrates compelling legitimate grounds overriding the user's interests, rights and freedoms, or grounds for establishing, exercising or defending claims.

34. Complaint to a supervisory authority

The user has the right to lodge a complaint with the competent supervisory authority if the user considers that the processing of personal data violates data protection laws.

For users from Poland, the competent authority is:

Prezes Urzędu Ochrony Danych Osobowych
ul. Stawki 2
00-193 Warszawa
Poland
Website: https://uodo.gov.pl

For users from the United Kingdom, the competent authority is:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Website: https://ico.org.uk

35. Data security

The Controller applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration, disclosure or unlawful use.

These measures include in particular:

  • SSL/TLS encryption of data transmission,
  • access control to systems,
  • use of passwords and user permissions,
  • backups,
  • monitoring of system security,
  • limiting access to data to authorised persons only,
  • mechanisms detecting unauthorised login attempts and account abuse,
  • agreements with data processors,
  • procedures for handling data breaches.

Despite security measures, no data transmission over the Internet and no IT system can guarantee full security. The Controller continuously strives to reduce risks related to personal data processing.

36. Automated decision-making and profiling

The Controller does not make decisions based solely on automated processing, including profiling, which produce legal effects concerning the user or similarly significantly affect the user, unless expressly stated in a separate process and supported by an appropriate legal basis.

Marketing, analytics and remarketing activities may include segmentation of recipients or creation of audiences, for example based on interests, purchase history, interactions with the Websites or marketing consents. Such activities are used to tailor content and advertising, where permitted by law and, where required, based on consent.

37. Users from the United Kingdom

For users of borniak.co.uk, BORNIAK LTD is the Controller of personal data processed in connection with that Website and the services offered there.

For users from the United Kingdom, the UK GDPR and the Data Protection Act 2018 may apply. References to the GDPR should be understood accordingly as references to the UK GDPR where necessary for processing by BORNIAK LTD.

38. Children and minors

The BORNIAK Websites and paid services are generally intended for adults. Minors may use the Websites only under the supervision and with the consent of a legal representative, where permitted by applicable law.

39. Special categories of personal data

The Controller does not intend to collect special categories of personal data such as health data, biometric data, political opinions, religious beliefs or data concerning sex life.

Users should not submit such data through forms, attachments, messages or other communication channels unless strictly necessary. If such data are provided voluntarily, they may be processed to the extent necessary to handle the matter, comply with legal obligations or protect claims.

40. Changes to this Privacy Policy

The Controller may amend this Privacy Policy, in particular in the event of changes to the Websites, services, tools used, processing purposes, categories of recipients or legal requirements.

The current version of the Privacy Policy is available on the Websites. Where required by law, users will be informed of material changes in an appropriate manner.

41. Contact

For questions about this Privacy Policy or the processing of personal data, please contact:

support@borniak.com