Orders are shipped every Monday. Delivery times vary depending on the destination and typically take 2-4 business days.
Orders are shipped every Monday. Delivery times vary depending on the destination and typically take 2-4 business days.
Orders are shipped every Monday. Delivery times vary depending on the destination and typically take 2-4 business days.
Orders are shipped every Monday. Delivery times vary depending on the destination and typically take 2-4 business days.
Orders are shipped every Monday. Delivery times vary depending on the destination and typically take 2-4 business days.
Orders are shipped every Monday. Delivery times vary depending on the destination and typically take 2-4 business days.
Orders are shipped every Monday. Delivery times vary depending on the destination and typically take 2-4 business days.
Orders are shipped every Monday. Delivery times vary depending on the destination and typically take 2-4 business days.
Orders are shipped every Monday. Delivery times vary depending on the destination and typically take 2-4 business days.
Orders are shipped every Monday. Delivery times vary depending on the destination and typically take 2-4 business days.
Orders are shipped every Monday. Delivery times vary depending on the destination and typically take 2-4 business days.
Privacy Policy


PRIVACY PROTECTION POLICY

crazy-box.eu


§ 1 General Provisions 

 

1. The administrator of the personal data of the users of the website located under the domain www.crazy-box.eu is Andrii Kudrin, conducting business activity under the name CRAZYBOX ANDRII KUDRIN, entered in the Central Registration and Information on Business (CEIDG) of the Republic of Poland, maintained by the minister competent for economic affairs, with its registered office at: ul. Sienna 75, 00-833 Warsaw, Tax Identification Number (NIP): 5223224259, REGON: 521863031 (hereinafter: the “Administrator”).   
2. The Administrator has designated an electronic point of contact intended for direct communication with the authorities of the Member States, the Commission, and the Digital Services Board: support@crazy-box. eu. The same point of contact may be used by every Customer for direct and rapid communication with the Administrator. The Administrator may also be contacted in writing at its address: ul. Sienna 75, 00-833 Warsaw, via the contact form available on the website, or by telephone at: +48 692 362 377 (Service operating hours 8 a.m.–4 p.m. on business days; the call is charged as a standard telephone connection, in accordance with the tariff package of the service provider used by the Customer). Communication may be conducted in Polish, Ukrainian, or English.   
3. The purpose of the Policy is to specify the actions taken with regard to personal data collected via the Administrator's website and the related services and tools used by its users, as well as within the activity of concluding and performing contracts in contact outside the website.
4. If necessary, the provisions of this Policy may change. The change will be communicated to users by announcing the new content of the Policy, and in the case of the database of persons who have consented to the processing of data by e-mail or who provided e-mail data when performing contracts, they will also be notified of the change by e-mail.

 

§ 2 Bases for Processing, Purposes, and Storage of Personal Data 

 

1.     Users' personal data are processed in accordance with the General Data Protection Regulation, the Act on the Protection of Personal Data, the Act on the protection of personal data of 10 May 2018, and the Act on the provision of services by electronic means of 18 July 2002, together with their subsequent amendments, and for the purpose of making a report under Article 16(1) of Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L 2022.277.1, as amended; “DSA”), also under Article 3(h) of the DSA.

2.     The Administrator may collect the following data for the following purposes:

Purpose of data processing

Legal basis

for processing and the data retention period

Data retention period

Scope of the processed data

Performance of the contract with the Customer or taking action at the request of the data subject prior to concluding the above-mentioned contracts

Article 6(1)(b) of the GDPR (performance of a contract).

·  for the duration of the above-mentioned contract until the expiry of the legal obligation related to accounting 

·  the data will be processed until the expiry of the period during which claims may be pursued

·    first name and surname;

·    e-mail address;

·    telephone number;

·    address (street, house number, apartment number, postal code, town/city, country),

·    company name,

·    Tax Identification Number (NIP)

Direct

marketing

Article 6(1)(f) of the GDPR (the legitimate interest of the administrator).

 

The Administrator may process data for direct marketing purposes only after obtaining consent and in the absence of objection from the data subject.

·  until consent is withdrawn – remember, you can withdraw your consent at any time. The processing of data until you withdraw your consent remains lawful.

·  the data will be processed until the expiry of the period during which claims may be pursued

·    e-mail address;

·    telephone number;

Marketing

Article 6(1)(a) of the GDPR (consent)

·  until consent is withdrawn – remember, you can withdraw your consent at any time. The processing of data until you withdraw your consent remains lawful.

·  the data will be processed until the expiry of the period during which claims may be pursued

·  until unsubscribing from the newsletter. 

·    first name and surname;

·    e-mail address;

·    telephone number;

·    address (street, house number, apartment number, postal code, town/city, country),

Keeping

accounting books

Article 6(1)(c) of the GDPR in conjunction with Article 86 § 1 of the Tax Ordinance, i.e.of 17 January 2017 (Journal of Laws of 2017, item 201), or Article 74(2) of the Accounting Act, i.e. of 30 January 2018 (Journal of Laws of 2018, item 395).  

·    the data will be processed until the expiry of the period during which claims may be pursued

·    the data are stored for the period required by the legal provisions requiring the keeping of tax books (until the expiry of the limitation period for the tax liability, unless tax laws provide otherwise) or accounting books (5 years, counting from the beginning of the year following the financial year to which the data relate).

·    first name and surname;

·    e-mail address;

·    telephone number;

·    address (street, house number, apartment number, postal code, town/city, country),

·    Tax Identification Number (NIP);

·    company name;

Making a refund

Performance of the Agreement or taking action at the request of the data subject prior to concluding the Agreement (Article 6(1)(b) of the GDPR).

·    5 years after the end of business relations with the Customer

·    first name and surname;

·    e-mail address;

·    telephone number;

·    address (street, house number, apartment number, postal code, town/city, country),

·    business entity data.

Establishment, exercise, or defence of claims that the Administrator may raise or that may be raised against the Administrator

Article 6(1)(f) of the GDPR

·    the data are stored for the period of existence of our legitimate interest, but no longer than the limitation period for claims against the data subject arising from the conducted business activity.

·    first name and surname;

·    e-mail address;

·    telephone number;

·    address (street, house number, apartment number, postal code, town/city, country),

·    Tax Identification Number (NIP);

·    company name;

Conducting research and analyses to improve the operation of the available services

Article 6(1)(f) of the GDPR

·    the data will be processed until the expiry of the period during which claims may be pursued

·    until the expiry of the validity or deletion of the cookies used for analytical purposes

·    company name;

·    e-mail address;

·    telephone number;

·    address (street, house number, apartment number, postal code, town/city, country),

·    computer components,

·    settings,

·    installed software.

Collecting telemetry data

Article 6(1)(f) of the GDPR

·    until the expiry of the validity or deletion of the cookies used for analytical purposes

·    IP address,

·    approximate location based on the IP address,

·    user identifier,

·    sharing and use of software.

Sending notifications to the Customer

Performance of the Agreement or taking action at the request of the data subject prior to concluding the Agreement (Article 6(1)(b) of the GDPR)

 

Fulfilment of a legal obligation incumbent on the Administrator (Article 6(1)(c) of the GDPR)

5 years after the end of business relations with the Customer

·    first name and surname;

·    e-mail address;

·    telephone number;

·    address (street, house number, apartment number, postal code, town/city, country),

·    business entity data.

Providing customer service

Performance of the Agreement or taking action at the request of the data subject prior to concluding the Agreement (Article 6(1)(b) of the GDPR)

·  5 years after the end of business relations with the Customer

·  2 years after the last update of the Customer's inquiry

·    first name and surname;

·    e-mail address;

·    telephone number;

·    address (street, house number, apartment number, postal code, town/city, country),

·    business entity data,

Correct functioning of the website

Maintaining the performance of the Service and improving it (Article 6(1)(f) of the GDPR)

·  5 years after the end of business relations with the Customer

·    As in the cell above,

·    Information about actions performed on the website (button clicks, visit duration, notifications read, other information depending on the specific business case).

Tracking visits to the website for security reasons

Protection and security of the website, the interests of Customers, and ensuring the Customer's security (Article 6(1)(f) of the GDPR)

·  3 years

·    User ID,

·    IP address,

·    Browser,

·    Content and URLs that the User connects to,

·    Date and time of connections.

Monitoring compliance with terms and conditions, contracts, and the privacy policy

Protection and security of the website, the interests of Customers, and ensuring the Customer's security (Article 6(1)(f) of the GDPR)

·  5 years after the end of business relations with the Customer

·    transaction data,

·    business entity data.

Handling requests concerning personal data,

Article 6(1)(c) of the GDPR

·  The period of existence of the Administrator's legitimate interest, but no longer than the limitation period for claims against the data subject arising from the conducted business activity.

·    first name and surname;

·    e-mail address;

·    telephone number;

·    address (street, house number, apartment number, postal code, town/city, country),

·    Tax Identification Number (NIP);

·    company name.

Providing information to authorities responsible for law enforcement and to other state institutions,

Article 6(1)(c) of the GDPR

·  The period of existence of the Administrator's legitimate interest, but no longer than the limitation period for claims against the data subject arising from the conducted business activity.

·    first name and surname;

·    e-mail address;

·    telephone number;

·    address (street, house number, apartment number, postal code, town/city, country),

·    Tax Identification Number (NIP);

·    company name.

Fulfilment of a legal obligation specified in Article 16(1), (4), (5), and (6) of the DSA, consisting in:

1. accepting a report of the presence in the hosting service of information which, in the reporter's view, constitutes illegal content within the meaning of Article 3(h) of the DSA;

2. examining the report;

3. informing about the decision taken on the report made;

4. informing about the possibility of appealing against the decision taken, referred to in point 3).

Article 6(1)(c) of the GDPR

·  Until information is provided about:

1) the decision taken by the Administrator on the report made;

2) the possibility of appealing against the decision taken, referred to in point 2).

·    first name and surname;

·    e-mail address;

·    telephone number;

·    address (street, house number, apartment number, postal code, town/city, country),

·    Tax Identification Number (NIP);

·    company name.

Processing of personal data to the extent 

to which, on the basis of proceedings conducted before the competent

public administration authorities, including law enforcement authorities,

in matters concerning the purposes or bases of personal data processing, the Administrator is obliged to process them. 

Article 6(1)(c) of the GDPR

·  For the duration of such an obligation

·    first name and surname;

·    e-mail address;

·    telephone number;

·    address (street, house number, apartment number, postal code, town/city, country),

·    Tax Identification Number (NIP);

·    company name.



The Administrator may process the personal data of Customers residing in the territory of European Union Member States to the extent necessary to carry out international deliveries, perform the Sales Agreement, handle payments and complaints, and contact the Customer in connection with the processing of the Order.
 

3. After the performance of the contract has ended, personal data may be processed for marketing purposes only to the extent permitted by the applicable legal provisions and where an appropriate legal basis exists, in particular the consent of the data subject or the legitimate interest of the Administrator.
4. The Administrator may use profiling for direct marketing purposes, but the decisions made by the Administrator on that basis do not concern the conclusion or refusal to conclude a contract, or the ability to use electronic services. The effect of using profiling may be, for example, granting a person a discount, sending them a discount code, reminding them of unfinished purchases, sending a proposal for a product that may match the person's interests or preferences, or offering better terms compared with the standard offer. Despite profiling, it is the person concerned who freely decides whether they wish to take advantage of the discount or better terms obtained in this way and make a purchase. Profiling consists in the automatic analysis or prediction of a person's behaviour on the Administrator's website, e.g.by adding a particular product to the basket, viewing the page of a particular product, or by analysing the previous history of activity on the website. The condition for such profiling is that the Administrator holds the personal data of the person concerned in order to be able to subsequently send them, for example, a discount code.

5.     To the extent necessary for the proper functioning of the website and its functionality, the site may, while the User is using it, collect other information, including but not limited to:

a)   IP address;

b)   information about the device, hardware, and software, such as hardware identifiers, mobile device identifiers (e.g. Apple Identifier for Advertising [“IDFA”] or the advertising identifier on a device with the Android system [“AAID”]),

c)    the type of platform,

d)   settings and components,

e)    data concerning the web browser, including the browser type and preferred language;

6. Taking into account the nature, scope, context, and purposes of the processing, as well as the risk of violation of the rights or freedoms of natural persons of varying likelihood and severity, the Administrator implements appropriate technical and organizational measures so that the processing takes place in accordance with the Regulation and so that this can be demonstrated. These measures are reviewed and updated as necessary. The Administrator applies technical measures to prevent unauthorized persons from obtaining and modifying personal data transmitted electronically.

 

§ 3 Data Sharing 

 

1. The Administrator ensures that all collected personal data serve to fulfil obligations towards users. This information will not be shared with third parties except where:

a)   the persons concerned have previously given their explicit consent to such action, or

b)   the obligation to transfer such data results or will result from the applicable legal provisions, e.g. to law enforcement authorities.

2. Additionally, the personal data of service recipients and customers may be transferred to the following recipients or categories of recipients:

o  providers of services supplying the Administrator with technical, IT, and organizational solutions enabling the Administrator to conduct business activity, including the website and the electronic services provided through it (in particular providers of computer software, marketing agencies, e-mail and hosting providers, providers of business management software and of technical support to the Administrator, and the product delivery operator) – the Administrator discloses the collected personal data of the Customer to the selected provider acting on its behalf only in the case and to the extent necessary to achieve the given data processing purpose consistent with this privacy policy.

o  providers of accounting, legal, and advisory services providing the Administrator with accounting, legal, or advisory support (in particular an accounting office, a law firm, or a debt-collection company) – the Administrator discloses the collected personal data of the Customer to the selected provider acting on its behalf only in the case and to the extent necessary to achieve the given data processing purpose consistent with this privacy policy.

o  payment service providers and electronic payment operators – the Administrator may transfer Customers' personal data to entities providing payment handling services only to the extent necessary to process payment for the Order. In the Administrator's business, such services are provided by Stripe Payments Europe, Ltd., a company registered in Ireland under number 513174, with its registered office in Dublin, Ireland.

In connection with the processing of Orders, including international deliveries, Customers' personal data may be transferred to logistics operators, courier companies, and entities providing transport services within the territory of the European Union, solely to the extent necessary to perform the Sales Agreement.

Customers' personal data may be processed in connection with the processing of Orders placed from the territory of European Union Member States in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

 

3. The Administrator may make anonymized data (i.e. data that do not identify specific Users) available to external service providers in order to better recognize the attractiveness of advertisements and services for users, and in this respect, due to the registered office of the software providers, the data may be transferred – while maintaining the principles of their protection – to third countries which nevertheless ensure the standard contractual clauses approved by the European Commission regarding the processing of personal data, or which have the appropriate authorization for such action on the basis of bilateral data-processing entrustment agreements between the European Union and the given third country which is not a member of the European Economic Area. In the case of the Administrator, these entities are:

Ø Google LLC. (registered office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) for the Google Analytics tool used to analyze website statistics, Google Tag Manager used to manage scripts by easily adding code snippets to a website or application and to track actions performed by users on the website, Google Ads used to display sponsored links in Google search results and on partner sites within the Google AdSense program, and Google Workspace enabling comprehensive editing of the website and coordination of the work of the people involved in it (including Google Drive, Gmail, Google Sheets, Google Forms, Google Looker Studio);

Ø Meta Platforms, Inc. (registered office: 1601 Willow Road, Menlo Park, CA 94025, USA) for the Facebook pixel used to track conversions from Facebook ads, optimize them on the basis of the collected data and statistics, and build an audience list targeted at future ads.

Ø TikTok Technology Limited (registered office: 10 Earlsfort Terrace, Dublin, D02 T380, Ireland) for the purpose of tracking conversions from TikTok ads, optimizing them on the basis of the collected data and statistics, and building an audience list targeted at future ads.

Ø Microsoft Corporation (registered office: One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland) for the Microsoft Clarity analytics tools used to analyze website statistics and to track actions performed by users on the website;

4. The Administrator always informs about the intention to transfer personal data outside the EEA at the stage of collecting them.
5. The Administrator continuously conducts a risk analysis to ensure that personal data are processed by it in a secure manner – ensuring above all that only authorized persons have access to the data, and only to the extent necessary in view of the tasks they perform. The Administrator ensures that all operations on personal data are recorded and carried out only by authorized employees and associates.
6. The Administrator takes all necessary actions to ensure that its subcontractors and other cooperating entities also guarantee the application of appropriate security measures whenever they process personal data on behalf of the Administrator.
7. The Administrator's website may use the functionality of Google Analytics, a website traffic analysis service provided by Google, LLC. (“Google”). Google Analytics uses cookies to help website operators analyze how visitors use the site. The information generated by the cookie about visitors' use of the site is generally transmitted to Google and stored by it on servers in the United States. In accordance with current IT standards, the IP addresses of users visiting the Administrator's website are truncated. Only in exceptional cases is the complete IP address transmitted to a Google server in the United States and truncated there. On behalf of the Administrator, Google will use this information to evaluate the website for its users, to compile reports on website traffic, and to provide other services related to website traffic and Internet use for website operators. In doing so, Google will not associate the IP address transmitted within Google Analytics with any other data held by it. More information on how Google Analytics collects and uses data can be found on Google's official page at: www.google.com/policies/privacy/partners. Furthermore, every User may prevent Google from collecting and processing data concerning their use of the website by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout.
8. When sharing data with third parties, the Administrator makes every effort to ensure that this takes place only with entities meeting the criteria and requirements indicated in Articles 46 or 49 of the GDPR. Where applicable, the Administrator will rely on the EU standard contractual clauses and other safeguards in order to enable transfers outside the EEA. In accordance with the judgment of the Court of Justice of the European Union of 16 July 2020, the Administrator continues to assess the legal system of the countries to which data are transferred and, as necessary, updates the measures aimed at ensuring appropriate levels of protection. 
9. In respect of data transferred to the United States, when sharing data with third parties the Administrator makes every effort to ensure that, in accordance with the European Commission decision of 10 July 2023, this takes place only with entities and organizations in the USA that ensure compliance with the new “EU–US Data Privacy Framework.” The list of these organizations has been published by the U.S. Department of Commerce. The transfer of personal data from the EEA to organizations that have joined the “EU–US Data Privacy Framework” program and are on this list is possible without the need to obtain additional authorizations or to apply legal instruments such as standard contractual clauses or binding corporate rules. However, where a given data importer in the USA has not joined the “EU–US Data Privacy Framework” program, the transfer of personal data to it is possible and will take place after meeting the conditions set out in Articles 46 or 49 of the GDPR. In such cases, the Administrator will rely on the EU standard contractual clauses and other safeguards in order to enable transfers outside the EEA. 

 

§ 4 User Rights 

 

1. A User whose personal data are processed has the right to:

a)     access, rectification, restriction, erasure, or portability – the data subject has the right to request from the Administrator access to their personal data, its rectification, erasure (“the right to be forgotten”), or restriction of processing, and has the right to object to the processing, as well as the right to data portability. The detailed conditions for exercising the rights indicated above are set out in Articles 15–21 of the GDPR.

b)     withdrawal of consent at any time – a person whose data are processed by the Administrator on the basis of the consent given (pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR) has the right to withdraw consent at any time without affecting the lawfulness of the processing carried out on the basis of consent before its withdrawal.

c)      lodging a complaint with a supervisory authority – a person whose data are processed by the Administrator has the right to lodge a complaint with a supervisory authority in the manner and procedure set out in the provisions of the GDPR and Polish law, in particular the Act on the Protection of Personal Data. The supervisory authority in Poland is the President of the Personal Data Protection Office (Prezes Urzędu OchronyDanych Osobowych) in Warsaw.

d)     objection – the data subject has the right at any time to object – on grounds relating to their particular situation – to the processing of personal data concerning them which is based on Article 6(1)(e) (public interest or tasks) or (f) (the legitimate interest of the administrator), including profiling based on those provisions. In such a case the Administrator may no longer process those personal data unless it demonstrates the existence of compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or grounds for the establishment, exercise, or defence of legal claims.

e)     objection regarding direct marketing – if personal data are processed for direct marketing purposes (based on the legitimate interest of the Administrator, not on the data subject's consent), the data subject has the right to object at any time to the processing of personal data concerning them for such marketing, including profiling, to the extent that the processing is related to such direct marketing.

2.     The exercise of the above rights takes place on the basis of a request from the user sent to the e-mail address support@crazy-box.eu. Such a request should contain the user's first name and surname. 

3. The User ensures that the data provided or published by them on the website are correct.

 

§ 5 Cookies 

 

1. By “cookies” we mean IT data, in particular text files, stored on users' end devices (usually on the computer's hard drive or on a mobile device) used by the user's browser to save certain settings and data for the purpose of using websites. These files make it possible to recognize the user's device and display the website appropriately, ensuring comfort while using it. The storage of “cookies” therefore makes it possible to suitably tailor the website and the offer to the user's preferences – the server recognizes the user and remembers, among other things, preferences such as: visits, clicks, and previous actions.
The Administrator uses a cookie consent management mechanism that allows the user to give or refuse consent to the use of analytical, advertising, and functional cookies. Cookies other than necessary ones are installed only after obtaining the appropriate consent of the user.

2.     The following cookies are used on the website:

Cookie

Domain

Description

Type

OCSESSID

.crazy-box.eu

This cookie is used to store the user's session identifier on the website.

Necessary

language

.crazy-box.eu

This cookie is used to store the user's language preferences.

Functional

currency

.crazy-box.eu 

This cookie is used to store the user's currency preferences.

Functional

CLID

www.clarity.ms

Microsoft Clarity sets this cookie to store information about how visitors interact with the website. The cookie helps to provide an analytical report. The collected data include the number of visitors, the place from which they visit the website, and the pages visited.

Analytics

_ttp

.tiktok.com

TikTok sets this cookie to track and improve the performance of advertising campaigns and to personalize the user's experience.

Advertising

_clck

.crazy-box.eu

Microsoft Clarity sets this cookie to retain the browser's Clarity user identifier and settings exclusively for this website. This ensures that actions taken during subsequent visits to the same website are associated with the same user identifier.

Analytics

_fbp

.crazy-box.eu

Facebook sets this cookie in order to display advertisements on Facebook or on a digital platform powered by Facebook advertising after the website has been visited.

Analytics

_tt_enable_cookie

.crazy-box.eu

TikTok sets this cookie in order to collect data on behaviour and actions on the website and to measure the effectiveness of advertisements.

Advertising

_ttp

.crazy-box.eu

TikTok sets this cookie to track and improve the performance of advertising campaigns and to personalize the user's experience.

Advertising

_ga_*

.crazy-box.eu

Google Analytics sets this cookie in order to store and count page views.

Analytics

_ga

.crazy-box.eu

Google Analytics sets this cookie in order to calculate visitor, session, and campaign data and to track the use of the website for the website's analytical report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors.

Analytics

_clsk

.crazy-box.eu

Microsoft Clarity sets this cookie to store and consolidate a user's page views into a single session recording.

Analytics

SM

.c.clarity.ms

Microsoft Clarity sets this cookie in order to synchronize the MUID identifier across Microsoft domains.

Analytics

MUID

.c.clarity.ms

Bing sets this cookie in order to recognize the unique web browsers of visitors to Microsoft websites. This cookie is used for advertising purposes, website analysis, and other operations.

Advertising

MR

.c.bing.com

This cookie, set by Bing, is used to collect information about users for analytical purposes.

Analytics

SRM_B

.c.bing.com

Used by Microsoft Advertising as a unique identifier for visitors.

Performance

ANONCHK

.c.clarity.ms

The ANONCHK cookie, set by Bing, is used to store the user's session identifier and to verify clicks on advertisements in the Bing search engine. The cookie also helps with reporting and personalization.

Advertising

3. “Cookies” contain, in particular, the domain name of the website from which they originate, the time of their storage on the end device, and a unique number used to identify the browser from which the connection to the website is made.
4. “Cookies” are used for the purpose of:

a.    adapting the content of websites to the user's preferences and optimizing the use of websites,

b.    creating anonymous statistics which, by helping to determine how the user uses websites, make it possible to improve their structure and content,

c.    providing website users with advertising content tailored to their interests.

“Cookies” are not used to identify the user, and their identity is not established on their basis.

5. The fundamental classification of “cookies” is their distinction into:

a)   Necessary “cookies” – are absolutely essential for the proper functioning of the website or of the functionalities the user wishes to use, because without them we could not provide many of the services we offer. Some of them also ensure the security of the services we provide electronically.

b)   Functional “cookies” – are important for the operation of the website because:

– they serve to enrich the functionality of websites; without them the website will work correctly, but it will not be tailored to the user's preferences,

– they serve to ensure a high level of website functionality; without them the level of website functionality may decrease, but their absence should not make it completely impossible to use the website,

– they serve most website functionalities; blocking them will cause selected functions not to work correctly.

c)    Business “cookies” – enable the implementation of the business model on the basis of which the website is made available; blocking them will not make all functionality unavailable, but may reduce the level of service provision because the website owner is unable to generate the revenue that subsidizes its operation. This category includes, for example, advertising “cookies”.

d)   Cookies” used for website configuration – enable the settings of functions and services on websites.

e)    Cookies” used for the security and reliability of websites – enable the verification of authenticity and the optimization of website performance.

f)    Cookies” examining the session state – enable information to be saved about how users use the website. This may relate to the most frequently visited pages or any error messages displayed on certain pages. “Cookies” used to save the so-called “session state” help to improve services and increase browsing comfort.

g)   Cookies” examining the processes occurring on the website – enable the efficient operation of the website and of the functions available on it.

h)   Cookies” handling advertising – enable the display of advertisements that are more interesting for users and at the same time more valuable for publishers and advertisers; “cookies” may also be used to personalize advertising and to display advertisements outside websites.

i)     Cookies” accessing location – enable the displayed information to be adapted to the user's location.

j)     Cookies” conducting analyses, research, or audience audits – enable the website owner to better understand the preferences of their users and, through analysis, to improve and develop products and services. Usually the website owner or a research company collects information anonymously and processes data about trends, without identifying the personal data of individual users.

6. The use of “cookies” to adapt the content of websites to the user's preferences does not, as a rule, mean the collection of any information allowing the user to be identified, although such information may sometimes be of the nature of personal data, that is, data enabling certain behaviours to be attributed to a specific user. Personal data collected using “cookies” may be collected solely for the purpose of performing specific functions for the user. Such data are encrypted in a manner that prevents access to them by unauthorized persons. 
7. The cookies used by this website are not harmful either to the user or to the end device used by them; therefore, for the proper functioning of the website, it is recommended not to disable their handling in browsers. In many cases, the software used for browsing websites (the web browser) by default permits the storage of information in the form of “cookies” and other similar technologies on the user's end device. The user may change the way cookies are used by the browser at any time. To do this, the browser settings should be changed. The way to change the settings differs depending on the software (web browser) used. You will find the relevant guidance on the subpages, depending on the browser you use.
8. As part of cookie technology, the Administrator may use tracking pixels or clear GIF files in order to collect information about how the user uses its services and about their reactions to marketing messages sent by e-mail. A pixel is a piece of software code that allows an object, usually a pixel-sized image, to be embedded on a page, which makes it possible to track the behaviour of users on the websites on which it is placed. After the appropriate consent has been given, the browser automatically establishes a direct connection with the server storing the pixel; therefore, the processing of data collected by the pixel takes place within the data protection policy of the partner that administers the above-mentioned server.
9. The Administrator may use Internet log files (which contain technical data, such as the user's IP address) in order to monitor traffic within its services, resolve technical problems, detect and counteract fraud, and enforce the provisions of the User Agreement.
10. The Administrator informs that the website does not respond to DNT (Do Not Track) signals; however, the user may disable certain forms of online tracking, including some analytical data and personalized advertisements, by changing the cookie settings in their browser or by using our cookie consent tools (if applicable).

11.  Detailed information on changing cookie settings and deleting them yourself in the most popular web browsers is available in the help section of the web browser and on the following pages (just click on the relevant link):

a)     Google Chrome

b)     Mozilla Firefox

c)      Microsoft Edge

d)     Opera

e)     Safari macOS

f)      Safari iOS/iPad OS

12. Detailed information on managing cookies on a mobile phone or other mobile device should be found in the user manual of the given mobile device.