DATA PROTECTION AND PRIVACY POLICY
ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland
Version: 1.0
Effective Date: 16 June 2026
1. Purpose
The purpose of this Data Protection and Privacy Policy is to establish principles governing the collection, processing, storage, protection and deletion of personal data processed by ECOMMIGO GROUP Sp. z o.o.
The Company is committed to ensuring that personal data is processed lawfully, fairly, transparently and securely.
This policy reflects the Company’s commitment to privacy protection and compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable.
2. Scope
This policy applies to:
- Customers
- Business partners
- Contractors
- Employees
- Service providers
- Users of Company products and services
The policy covers all personal data processed through Company systems, services and business operations.
3. Data Protection Principles
The Company processes personal data according to the following principles:
Lawfulness
Personal data is processed only when there is a valid legal basis.
Fairness
Data subjects are treated fairly and without discrimination.
Transparency
Information regarding processing activities is made available where required.
Purpose Limitation
Personal data is collected for specific and legitimate purposes.
Data Minimization
Only information necessary for business operations is collected and processed.
Accuracy
Reasonable efforts are made to ensure that personal data remains accurate and up to date.
Storage Limitation
Personal data is retained only for as long as necessary.
Integrity and Confidentiality
Appropriate technical and organizational measures are implemented to protect personal data.
4. Categories of Data
The Company may process:
- Names and surnames
- Contact details
- Email addresses
- Telephone numbers
- Company information
- Account information
- Transaction information
- Technical and operational logs
- Customer communication records
The Company does not intentionally collect unnecessary personal information.
5. Legal Basis for Processing
Personal data may be processed based on:
- Contract performance
- Legal obligations
- Legitimate interests
- User consent
- Protection of vital interests where applicable
The Company ensures that all processing activities have an appropriate legal basis.
6. Security Measures
The Company implements technical and organizational measures including:
- Multi-Factor Authentication
- Access control mechanisms
- Encrypted communications
- Secure cloud infrastructure
- Security monitoring
- Audit logging
- Backup systems
- Personnel access restrictions
- Incident response procedures
Only authorized individuals are permitted to access personal data.
7. Data Subject Rights
Where applicable, individuals may exercise the following rights:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object
- Right to withdraw consent
Requests are reviewed and handled in accordance with applicable legal requirements.
8. Data Retention
Personal data is retained only for as long as necessary to:
- Fulfill contractual obligations
- Comply with legal requirements
- Resolve disputes
- Maintain security
- Support legitimate business activities
When retention is no longer necessary, data is securely deleted or anonymized.
9. Third-Party Service Providers
The Company may engage reputable service providers to support business operations.
Where third parties process personal data on behalf of the Company, appropriate contractual and security safeguards are implemented.
The Company seeks to ensure that service providers maintain adequate levels of data protection.
10. International Data Transfers
Where personal data is transferred internationally, the Company implements appropriate safeguards designed to ensure lawful and secure processing.
Reasonable efforts are made to ensure adequate protection of transferred information.
11. Data Breach Management
The Company maintains procedures for:
- Detecting potential breaches
- Investigating incidents
- Containing risks
- Assessing impact
- Notifying authorities where required
- Notifying affected individuals where required
All incidents are documented and reviewed.
12. Policy Review
This policy shall be reviewed periodically and updated whenever required due to legal, operational or technological changes.
Approval
Prepared and approved by:
Mateusz Michał Śliwka
President of the Management Board