Privacy policy

Last updated: 13 August 2026

This Privacy Policy explains how NERLI GRUPPEN POLAND Spółka z ograniczoną odpowiedzialnością processes the personal data of users of the website www.nerligruppen.com

I. Personal Data Controller

The controller of your personal data is:

NERLI GRUPPEN POLAND Spółka z ograniczoną odpowiedzialnością
Kościerzyce 130, 49-314 Pisarzowice, Poland
Tax Identification Number (NIP): 1010006387
National Business Registry Number (REGON): 022329119
National Court Register Number (KRS): 0000490701

You can contact the Controller:

II. Scope and sources of the personal data processed

Depending on how you use the website, we may process the following personal data in particular:

  • first and last name;
  • company name and job title;
  • email address;
  • telephone number;
  • postal address;
  • data contained in a submitted message or form;
  • information relating to a request for quotation, an order or cooperation;
  • IP address;adres IP;
  • information about the device, operating system and browser;
  • information about the device, operating system and browser;
  • data concerning clicks, page scrolling and interactions with website elements;
  • online identifiers stored using cookies and similar technologies;
  • information concerning the consents given and the selected cookie settings.

We obtain personal data primarily directly from the data subject, for example through a contact form, email correspondence, a telephone conversation, newsletter subscription or use of the website.

In the case of business contacts, personal data may also be obtained from the data subject’s employer, co-worker or business partner, or from publicly available sources, such as a company website or a public professional profile.

If personal data has not been obtained directly from the data subject, the Controller provides that person with the information required under Article 14 of the GDPR, unless one of the exceptions provided for in that Article applies.

III. Purposes, legal bases and retention periods for personal data

1. Handling enquiries and contact forms

We process personal data provided through the contact form, by email or during a telephone conversation for the following purposes:

  • responding to the enquiry;
  • preparing an offer;
  • handling the enquiry;
  • establishing or maintaining business cooperation;
  • forwarding the enquiry to the appropriate business partner where necessary in order to handle it.

The legal bases for processing are:

  • Article 6(1)(b) of the GDPR – taking steps at the request of the data subject prior to entering into a contract or performing a contract;
  • Article 6(1)(f) of the GDPR – the Controller’s legitimate interest in conducting correspondence, handling enquiries and developing business relationships.

We retain personal data for the period necessary to handle the enquiry and subsequently for the period required to establish, pursue or defend against potential claims.

2. Entering into and performing a contract

We process the personal data of contractors, business partners and persons representing these entities for the following purposes:

  • preparing and entering into a contract;
  • fulfilling an order or carrying out business cooperation;
  • processing settlements and payments;
  • handling complaints;
  • maintaining business relationships.

The legal bases for processing are:

  • Article 6(1)(b) of the GDPR – performing a contract or taking steps prior to entering into a contract;
  • Article 6(1)(c) of the GDPR – compliance with legal obligations, particularly tax and accounting obligations;
  • Article 6(1)(f) of the GDPR – the Controller’s legitimate interest in managing business cooperation, contacting representatives of contractors and establishing, pursuing or defending against claims.

We retain personal data related to accounting documentation for the period required by law. Other personal data may be retained until the expiry of the applicable limitation period for claims.

3. Marketing of our own products and services

We process personal data in order to provide information about Nerli Gruppen’s products, services and business cooperation opportunities.

The legal bases for processing are:

  • Article 6(1)(f) of the GDPR – the Controller’s legitimate interest in marketing its own products and services;
  • Article 6(1)(a) of the GDPR – consent, where required due to the communication channel used;
  • Article 398 of the Polish Electronic Communications Law of 12 July 2024 – where commercial information or direct marketing communications are sent using electronic means of communication or telecommunications terminal equipment.

Where processing is based on consent, personal data is processed until consent is withdrawn. Where processing is based on a legitimate interest, personal data is processed until an effective objection is raised.

4. Customer service quality assessment

We process personal data to assess the satisfaction of our customers and partners and to improve the quality of our products and customer service.

The legal basis for processing is Article 6(1)(f) of the GDPR – the Controller’s legitimate interest in improving its products, services and customer service standards.

5. Establishing, pursuing and defending against claims

We retain and use personal data for evidentiary and archival purposes and to establish, pursue or defend against claims.

The legal basis for processing is Article 6(1)(f) of the GDPR – the Controller’s legitimate interest in protecting its rights.

Personal data may be retained until the expiry of the applicable limitation period for claims.

6. Ensuring website security

We process technical data, including the IP address, device information and server logs, for the following purposes:

  • ensuring the proper operation of the website;
  • protecting the website against misuse and cyberattacks;
  • diagnosing technical errors;
  • ensuring the security of forms and IT systems.

The legal basis for processing is Article 6(1)(f) of the GDPR – the Controller’s legitimate interest in ensuring the security of the website and IT systems.

IV. Voluntary provision of personal data

The provision of personal data is voluntary but may be necessary for:

  • responding to an enquiry;
  • preparing an offer;
  • entering into and performing a contract;
  • handling an order or complaint;
  • receiving the newsletter.

Failure to provide the required personal data may make it impossible to fulfil the relevant purpose.

V. Recipients of personal data

Personal data is disclosed to entities supporting the Controller in conducting its business activities, to the extent necessary for the provision of their services.

Recipients of personal data include in particular:

  • hosting and IT service providers;
  • website administrators and maintenance providers;
  • email and office software providers;
  • providers of analytics, functional, marketing and advertising systems;
  • the provider of the cookie consent management platform;
  • the newsletter distribution service provider;
  • providers of accounting, legal, auditing and advisory services;
  • courier companies, carriers and postal operators;
  • business partners or distributors, where the disclosure of personal data is necessary to handle the user’s enquiry;
  • public authorities, where the obligation to disclose personal data arises from applicable law.

Depending on the nature of the cooperation, recipients process personal data as processors acting on the Controller’s instructions, independent controllers or, within a specified scope, joint controllers.

VI. Transfer of personal data outside the European Economic Area

Some providers of tools used on the website belong to international corporate groups or use infrastructure located outside the European Economic Area, particularly in the United States.

Due to the use of Google Analytics 4, Google Maps, YouTube, Microsoft Clarity and Meta Pixel, personal data may be transferred or made accessible to entities located outside the EEA.

Personal data is transferred outside the EEA using mechanisms provided for under the GDPR, in particular:

  • an adequacy decision issued by the European Commission;
  • the EU–US Data Privacy Framework – where the relevant recipient in the United States holds a valid certification;
  • standard contractual clauses approved by the European Commission;
  • additional organisational and technical safeguards, where required.

Information regarding the safeguards applied may be obtained by contacting the Controller.

VII. Rights of data subjects

Depending on the legal basis and manner of processing, the data subject has the right to:

  • access their personal data and receive a copy thereof;
  • rectify their personal data;
  • erase their personal data;
  • restrict the processing of their personal data;
  • have their personal data transferred;
  • object to processing based on Article 6(1)(f) of the GDPR;
  • object at any time to direct marketing, including related profiling;
  • withdraw consent at any time;
  • lodge a complaint with the President of the Polish Personal Data Protection Office.

The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

Requests concerning the exercise of these rights may be submitted to: info@nerligruppen.com.

VIII. Automated decision-making and profiling

Personal data collected using analytics and marketing tools is used to create audience groups, measure advertising effectiveness and tailor advertising communications to users’ predicted interests.

These activities may constitute profiling within the meaning of the GDPR. However, we do not make decisions concerning users based solely on automated processing that would produce legal effects concerning them or similarly significantly affect them.

IX. Newsletter

Personal data provided when subscribing to the newsletter is processed for the purpose of sending information about Nerli Gruppen’s products, offers, news and activities.

The legal bases for processing are:

  • Article 6(1)(a) of the GDPR – consent to the processing of personal data;
  • Article 398 of the Polish Electronic Communications Law – with regard to sending commercial information by electronic means of communication.

Subscribing to the newsletter is voluntary; however, providing an email address is necessary to receive it.

Consent may be withdrawn at any time:

Personal data is processed until consent is withdrawn or the newsletter is discontinued.

Information confirming the granting and withdrawal of consent may be retained until the expiry of the limitation period for potential claims. The legal basis for such retention is Article 6(1)(f) of the GDPR – the Controller’s legitimate interest in demonstrating compliance with applicable requirements.

The withdrawal of consent does not affect the lawfulness of actions taken before its withdrawal.

X. Data security

The Controller implements appropriate technical and organisational measures to protect personal data, taking into account the type of data, the scope of processing and the identified risks.

Access to personal data is granted only to authorised persons and entities with which appropriate agreements have been concluded, where required.

XI. Amendments to the Privacy Policy

The Privacy Policy may be updated, in particular, in the event of:

  • changes in applicable law;
  • changes to the website’s functionality;
  • the implementation of new tools;
  • changes to the manner in which personal data is processed;
  • changes in service providers.

The current version of the Privacy Policy is published on the website together with the date of its most recent update.

Logowanie