Data security

Privacy Policy

We explain how we process personal data, use cookies and protect information relating to users of the FOLKUL DRAIN website.

Last updated: 22 July 2026

We respect user privacy

This document explains what data may be processed when you use the Website, the purposes for which it is used and the rights available to data subjects.

01
Data Controller

General provisions

This Privacy Policy sets out the rules for processing and protecting the personal data of users of the website www.folkul.pl, hereinafter referred to as the “Website”.

The Controller of personal data is:

Controller FOL-KUL Sp. z o.o.
Address 2 Rudzka Street, 95-030 Rzgów, Poland
Tax ID (NIP) 7282878041
REGON 526690470
KRS 0001064168
Email biuro@folkul.pl

You may contact the Controller:

The Controller has not appointed a Data Protection Officer. All matters concerning personal data may be addressed directly to the Controller at the email address stated above.

02
Legal compliance

Legal grounds for processing

Personal data is processed in accordance with applicable law, in particular:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, hereinafter referred to as the “GDPR”,
  • the Polish Act of 10 May 2018 on Personal Data Protection,
  • the Polish Act of 18 July 2002 on the Provision of Electronic Services,
  • the Polish Electronic Communications Law of 12 July 2024.

Depending on the purpose, data may be processed on the basis of:

  • the user’s consent – Article 6(1)(a) GDPR,
  • the necessity to take steps before entering into a contract or to perform a contract – Article 6(1)(b) GDPR,
  • compliance with a legal obligation imposed on the Controller – Article 6(1)(c) GDPR,
  • the legitimate interests pursued by the Controller – Article 6(1)(f) GDPR.
03
Use of data

Scope and purposes of processing

The Controller may process user data for the following purposes:

  • responding to enquiries submitted via a form, email or telephone,
  • preparing and presenting a commercial offer,
  • taking steps at the user’s request before entering into a contract,
  • managing commercial relationships and B2B cooperation,
  • conducting analytics and statistics concerning use of the Website,
  • measuring the effectiveness of advertising campaigns,
  • conducting remarketing and displaying tailored advertisements after obtaining the relevant consent,
  • ensuring the operation and security of the Website and protecting it against spam, misuse and attacks,
  • establishing, pursuing or defending potential claims.

Depending on the method of contact, the Controller may process in particular:

  • first name and surname,
  • company name,
  • tax identification number,
  • email address,
  • telephone number,
  • project or delivery address,
  • the content of an enquiry or message,
  • technical information concerning the device, browser and use of the Website.
Data minimisation

Users should not provide special categories of personal data in forms, such as health data, information about origin, religious beliefs or any other data that is not required to handle the enquiry.

04
Contact and enquiries

Online forms

The Website may include contact forms, quotation request forms, product selection forms, cooperation forms and other forms connected with the FOLKUL DRAIN offer.

Data provided through a form is processed for the purpose of:

  • receiving and handling the submitted enquiry,
  • contacting the user,
  • preparing an offer or technical response,
  • taking steps before entering into a contract,
  • archiving correspondence to document its course and protect against claims.

Providing data is voluntary, but may be necessary to submit a form and receive a response. Failure to provide data marked as required may prevent the enquiry from being handled.

The legal basis is Article 6(1)(b) GDPR where the enquiry is intended to lead to a contract, or Article 6(1)(f) GDPR, namely the Controller’s legitimate interest in handling correspondence, presenting its offer and building customer relationships.

05
Analytics and advertising

External tools

The Website may use the analytical, advertising and security tools listed below. The scope of each tool depends on its configuration and the choices made by the user in the consent panel.

Google Analytics

This tool may be used to create statistics concerning use of the Website, including the number of visits, approximate traffic source, pages visited, visit duration, device type and browser type.

The legal basis for using analytical cookies is the user’s consent under Article 6(1)(a) GDPR.

Google Ads

This tool may be used to measure advertising effectiveness, record conversions, build audience groups and conduct remarketing.

Advertising data and marketing cookies are used only after the relevant user consent has been obtained.

Meta Pixel

Meta Pixel may be used to measure the effectiveness of advertisements displayed through Meta services, analyse user activity on the Website, build audience groups and conduct remarketing.

This marketing tool should be activated only after the user accepts the relevant cookie category.

Google reCAPTCHA

reCAPTCHA may be used to protect forms against automated spam, bots and attempted misuse.

During operation, technical data may be transmitted to Google, including the IP address, device and browser information, time spent using the Website and the way the user interacts with the form.

The Controller processes this data on the basis of Article 6(1)(f) GDPR, namely the legitimate interest in protecting the Website and forms against misuse.

Tool providers

Google provides Google Analytics, Google Ads and Google reCAPTCHA. Meta Platforms provides Meta Pixel. Detailed information on how these providers process data is available in their privacy policies.

06
Web technologies

Cookies

The Website uses cookies and similar technologies. Cookies are small files stored on the user’s device while using the Website.

Cookie categories

  • Essential – ensure basic operation, security and correct display of the Website.
  • Functional – remember user settings and preferences.
  • Analytical – help determine how users use the Website and which elements require improvement.
  • Marketing – may be used to measure campaigns, conduct remarketing and tailor advertisements.

Analytical, advertising and marketing cookies are used on the basis of the user’s consent. Users may accept all cookies, reject optional cookies or select specific categories.

Withdrawal of consent

Consent may be withdrawn at any time using the cookie settings available on the Website. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

Users may also delete or block cookies in their browser settings. Restricting essential cookies may, however, cause certain elements of the Website to malfunction.

07
Service providers

Data recipients

Data may be disclosed to entities supporting the Controller in operating the Website and handling enquiries, in particular:

  • hosting and server infrastructure providers,
  • IT, maintenance and administrative service providers,
  • providers of WordPress, Elementor, forms and plugins used on the Website,
  • email service providers,
  • analytical, advertising and marketing service providers, including Google and Meta, to the extent permitted by the consent granted,
  • law firms, advisers, accountants or insurers where necessary to protect the Controller’s rights,
  • public authorities where disclosure is required by law.

Entities processing data on behalf of the Controller act under appropriate agreements and are required to ensure an adequate level of protection. Certain entities, such as Google or Meta, may act as independent controllers in relation to specific processing operations.

08
Information retention

Data retention period

Data is retained no longer than necessary to fulfil the purpose for which it was collected.

  • Data from forms and correspondence may be retained until the matter is closed and then for up to 12 months from the last contact, unless further retention is necessary for contract performance, compliance with a legal obligation or protection against claims.
  • Data connected with entering into and performing a contract may be retained for the duration of the contract and subsequently for the period required by tax, accounting and limitation rules.
  • Data processed on the basis of consent is retained until consent is withdrawn or the processing purpose ceases to apply.
  • Data processed on the basis of a legitimate interest is retained until an effective objection is made or that interest ceases to apply.
  • Analytical and advertising data is retained for the period resulting from the configuration of the relevant tool, the Controller’s account settings and the lifetime of the relevant cookies.
  • Technical logs may be retained for the period necessary to ensure security, analyse incidents and maintain the correct operation of the Website.
09
Control over personal data

User rights

Subject to the conditions laid down in the GDPR, data subjects have the right to:

  • access their personal data,
  • receive information about how their data is processed,
  • rectify or complete their data,
  • request erasure of their data,
  • request restriction of processing,
  • data portability, where applicable,
  • object to processing based on Article 6(1)(f) GDPR,
  • withdraw consent at any time,
  • lodge a complaint with the President of the Polish Personal Data Protection Office.

Requests relating to the exercise of these rights should be sent to: biuro@folkul.pl .

The Controller may request additional information necessary to verify the identity of the person making the request. This is intended to protect personal data against disclosure to an unauthorised person.

10
International services

Transfers of data outside the EEA

In connection with the use of Google and Meta services, data may be transferred or made available to entities located outside the European Economic Area, in particular in the United States.

In such cases, transfers are based on mechanisms permitted under the GDPR, in particular:

  • an adequacy decision issued by the European Commission, where applicable,
  • standard contractual clauses approved by the European Commission,
  • other safeguards provided for in Chapter V GDPR.

Detailed information on international transfers carried out by providers is available in their documentation and privacy policies.

11
Information protection

Data security

The Controller applies appropriate technical and organisational measures to protect data against accidental or unlawful loss, destruction, alteration, disclosure or access by unauthorised persons.

Security measures may include in particular:

  • encryption of the connection using an SSL certificate,
  • updating WordPress, plugins and other software,
  • securing administrator accounts and limiting permissions,
  • creating backups,
  • protecting forms against spam and automated misuse,
  • controlling access to data and systems,
  • cooperating with service providers that maintain appropriate security standards.

No method of transmitting data over the Internet or storing information electronically can completely eliminate all risks. The Controller regularly reviews its safeguards and adapts them to the nature of the data being processed.

12
Technical information

Server logs

While the Website is being used, technical information may be recorded automatically in server logs.

This information may include:

  • the device’s IP address,
  • the date and time of the connection,
  • the address of the requested resource,
  • browser information,
  • operating system information,
  • the referring page address,
  • information about errors and technical events.

Log data is used to administer the Website, diagnose errors, create technical statistics, ensure security and detect attempted misuse.

The legal basis is Article 6(1)(f) GDPR, namely the Controller’s legitimate interest in ensuring the security and proper operation of the Website.

13
Personalised advertising

Profiling and automated decisions

Where marketing cookies are accepted, data concerning user activity may be used by Google Ads or Meta Pixel to build audience groups, measure advertising effectiveness and tailor advertising messages.

Such activities may constitute marketing profiling. Profiling does not produce legal effects concerning the user or similarly significantly affect the user.

The Controller does not make decisions concerning users based solely on automated processing where such decisions would produce legal effects or similarly significantly affect the user.

Users may withdraw consent to marketing cookies at any time through the cookie settings panel.

14
Document updates

Changes to the Privacy Policy

The Controller may update this Privacy Policy, in particular where:

  • applicable law changes,
  • the way the Website operates changes,
  • new forms, services or features are introduced,
  • new analytical, advertising or technical tools are implemented,
  • service providers change.

The current version of this document is published on the Website at: www.folkul.pl/en/privacy-policy/ .

The date of the most recent update is shown at the top of the document.

Do you have any questions?

Contact the Data Controller

For questions concerning the processing of personal data, cookies or the exercise of rights under the GDPR, please contact FOL-KUL Sp. z o.o.