Skip to main content

DATA PROTECTION AND PRIVACY POLICY

ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland

Version: 1.0
Effective Date: 16 June 2026


1. Purpose

The purpose of this Data Protection and Privacy Policy is to establish principles governing the collection, processing, storage, protection and deletion of personal data processed by ECOMMIGO GROUP Sp. z o.o.

The Company is committed to ensuring that personal data is processed lawfully, fairly, transparently and securely.

This policy reflects the Company’s commitment to privacy protection and compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable.


2. Scope

This policy applies to:

  • Customers
  • Business partners
  • Contractors
  • Employees
  • Service providers
  • Users of Company products and services

The policy covers all personal data processed through Company systems, services and business operations.


3. Data Protection Principles

The Company processes personal data according to the following principles:

Lawfulness

Personal data is processed only when there is a valid legal basis.

Fairness

Data subjects are treated fairly and without discrimination.

Transparency

Information regarding processing activities is made available where required.

Purpose Limitation

Personal data is collected for specific and legitimate purposes.

Data Minimization

Only information necessary for business operations is collected and processed.

Accuracy

Reasonable efforts are made to ensure that personal data remains accurate and up to date.

Storage Limitation

Personal data is retained only for as long as necessary.

Integrity and Confidentiality

Appropriate technical and organizational measures are implemented to protect personal data.


4. Categories of Data

The Company may process:

  • Names and surnames
  • Contact details
  • Email addresses
  • Telephone numbers
  • Company information
  • Account information
  • Transaction information
  • Technical and operational logs
  • Customer communication records

The Company does not intentionally collect unnecessary personal information.


5. Legal Basis for Processing

Personal data may be processed based on:

  • Contract performance
  • Legal obligations
  • Legitimate interests
  • User consent
  • Protection of vital interests where applicable

The Company ensures that all processing activities have an appropriate legal basis.


6. Security Measures

The Company implements technical and organizational measures including:

  • Multi-Factor Authentication
  • Access control mechanisms
  • Encrypted communications
  • Secure cloud infrastructure
  • Security monitoring
  • Audit logging
  • Backup systems
  • Personnel access restrictions
  • Incident response procedures

Only authorized individuals are permitted to access personal data.


7. Data Subject Rights

Where applicable, individuals may exercise the following rights:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Right to withdraw consent

Requests are reviewed and handled in accordance with applicable legal requirements.


8. Data Retention

Personal data is retained only for as long as necessary to:

  • Fulfill contractual obligations
  • Comply with legal requirements
  • Resolve disputes
  • Maintain security
  • Support legitimate business activities

When retention is no longer necessary, data is securely deleted or anonymized.


9. Third-Party Service Providers

The Company may engage reputable service providers to support business operations.

Where third parties process personal data on behalf of the Company, appropriate contractual and security safeguards are implemented.

The Company seeks to ensure that service providers maintain adequate levels of data protection.


10. International Data Transfers

Where personal data is transferred internationally, the Company implements appropriate safeguards designed to ensure lawful and secure processing.

Reasonable efforts are made to ensure adequate protection of transferred information.


11. Data Breach Management

The Company maintains procedures for:

  • Detecting potential breaches
  • Investigating incidents
  • Containing risks
  • Assessing impact
  • Notifying authorities where required
  • Notifying affected individuals where required

All incidents are documented and reviewed.


12. Policy Review

This policy shall be reviewed periodically and updated whenever required due to legal, operational or technological changes.


Approval

Prepared and approved by:

Mateusz Michał Śliwka
President of the Management Board