Privacy and cookies policy of the internet service Plastech
General information
This document specifies the Privacy and cookies policy of the Internet Service Plastech.pl (hereinafter referred to as: "Internet Service"). Administrator of the Internet Service is Plastech Pawel Wisniewski limited joint-stock partnership with its registered office in Torun at Relaksowa 4, entered in the Register of Entrepreneurs kept by the District Court in Torun, VII Economic Division of the National Court Register under KRS number 0000956717, share capital: 50 000 PLN (paid in full), NIP 9562374503, REGON 521488202.
The words with capital letters bear the meanings defined in the rules and regulations of the Internet Service.
Personal data collected by the Administrator of the Internet Service is processed pursuant to the provisions of the Regulation of the European Parliament and of the (EU) Council 2016/679 of 27/04/2016 on the protection of natural persons as regards personal data processing, on the free movement of such data and on the repeal of Directive 95/46/EC (General Data Protection Regulation) (Official Journal of the EU L 119, pg. 1) hereinafter referred to as: GDPR.
The Administrator of the Internet Service does the utmost to protect privacy and information shared with him and related to Users of the Internet Service. The Administrator exercises due diligence to choose and apply proper technical measures, including ones of programming and organisational character, to ensure the protection of data; he especially secures data against sharing with unauthorised people, disclosure, loss, damage, unauthorised modification, and processing in breach of applicable legal provisions.
Target Users of Products and Services available at the website are not children under 16 years of age. The Controller of personal data does not provide for intentional acquisition of data related to children under 16 years of age.
Personal data
Controller of personal data
The controller of your personal data is:
Plastech Pawel Wisniewski S.K.A.
address: 4 Relaksowa Street,
87-100 Torun, Poland
Regarding your personal data, you may contact the Controller of personal data via:
- e-mail: info@plastech.pl,
- following postal address: ul. 4 Relaksowa, 87-100 Torun, Poland,
- using contact form available in Internet Service.
Aims of and legal basis for personal data processing
The Controller of personal data processes your personal data for the following purposes and within this scope:
- to take actions before entering into the agreement on your request (to create your account, etc.), that is data specified in the registration form in the Internet Service, to be exact your login, e-mail address, password, country and account language; to provide Services which require the creation of the Account, we process your data specified in the Account and data about completed services and data specified while buying Services;
- to provide services which do not require that you create the Account, that is to browse the website of the Internet Service, search for content or Services, we process personal data related to your activity in the Internet Service, in other words information about content and Services you browse, data on sessions of your device, operating system, browser, location, unique ID, IP address;
- to execute the Contract of Services, provide a Services, place the Order and to use functionalities demanding registration and also not requiring an Account, i.e. history of Account, we process personal data provided by you in the Account and as part of the submitted forms and data about your activity on the Website, i.e. data necessary to conclude and complete the Agreement, and also data about the Services you are viewing, as well as data about the session, your device and the operating system, browser, location and unique ID. Providing some data is a prerequisite for using individual Services and account functionality (mandatory data). Our system automatically marks mandatory data. The consequence of not providing this data is the inability to provide certain Services and functionalities of the Account. Providing other personal data than marked as mandatory is voluntary;
- to compile statistics on the use of respective functionalities available in the Internet Service, to facilitate the use of the Internet Service and to ensure the IT safety of the Internet Service, we process personal data related to your activity in the Internet Service and amount of time spent on each web page of the Internet Service, your search history, location, IP address, device ID, as well as data related to your web browser and operating system;
- to establish, assert and exercise legal claims and defend ourselves against them in court proceedings and other enforcement authorities, we may process your personal data specified while buying Products or creating the Account, together with other data necessary to prove the existence of a legal claim or which stems from a legal requirement, injunction or another legal procedure;
- to handle complaints, claims and requests, and to reply to questions from Users, we process personal data specified by you in the contract form, complaints, claims and requests or to answer questions in another way and certain personal data you specify in your Account, as well as information related to the order for a specific Product and other Services we provide which are the reason for your complaint, claim or request and data contained in documents enclosed to your complaints, claims and requests;
- to market our Services, we process personal data you specify as you create and update your Account, information related to your activity in the Internet Service, including orders, which are registered and stored with cookies, especially the history of orders, searches and clicks in the Internet Service, login and registration dates, history and your activity related to our communication with you. Our marketing messages include in particular the newsletter sent to your e-mail address – only with your consent given at registration or in your Account settings; you can withdraw the consent at any time in your Account settings;
Traffic statistics and abuse detection (anti-fraud)
Purpose: maintaining security and stability of the portal, detecting automated bots and harmful traffic (scrapers, DDoS attacks, exploit scanners), generating per-domain visit statistics for administrative purposes and Premium contractors.
Legal basis: art. 6(1)(f) GDPR (legitimate interest of the controller – service security and anonymous analytics). Pursuant to recital 49 of the GDPR and Guidelines 5/2020 of the European Data Protection Board (§32), abuse detection and attack prevention constitutes a legitimate interest enabling processing without consent.
Scope of data:
- IP address (truncated to /24 prefix for statistical aggregates after 90 days)
- Session identifier (cookie
PHPSESSID, strictly-necessary) - Browser User-Agent
- Request URL, HTTP response code (200/404/etc.)
- Referer address (where the request came from)
- Preferred language (
Accept-LanguageHTTP header) - Geographic location at country level (from GeoIP database – does not identify streets or precise location)
- Browser characteristics for automation detection (screen resolution, viewport, timezone, touch interface presence, availability of standard JavaScript APIs such as
navigator.webdriver,navigator.plugins,localStorage,performance.now()precision)
What we do NOT collect:
- Persistent user identifier (personal cookie ID – removed from the system in May 2026)
- Biometric data (canvas / WebGL / font enumeration fingerprinting)
- Mouse/keyboard tracking or behavioral analytics
- Private content data (post bodies, private messages – outside portal functionality requirements)
Search quality (result relevance measurement)
Purpose: improving the relevance of the portal's search. We know what users search for, but without knowing which result they considered the right one, result ordering can only be tuned by intuition. We therefore record the fact that a result was chosen for a given phrase.
Scope of data: the search phrase, an indication of the chosen result (type and identifier of the target page), its position in the result list, the site language and the date of the event. Separately we keep a daily count of result-list views per phrase – without it, a click count alone says nothing about relevance.
What this record does NOT contain: IP address, session identifier, account identifier or User-Agent. The record cannot be linked to a particular person or device – it is not a set of personal data within the meaning of the GDPR (recital 26 – anonymous data falls outside the GDPR). It is not used for profiling, marketing or result personalisation; it is used solely in aggregate, to compare “at which position the good answer lands”.
Retention period: 365 days, after which records are deleted automatically.
Categories of relevant personal data
The Controller of personal data processes the following categories of relevant personal data:
- contact information;
- information related to ordered Services;
- information related to your activity in the Internet Service;
- information related to your complaints, claims and requests;
- information related to marketing services.
Voluntary provision of personal data
Your submission of required personal data is voluntary and is the condition on which the Controller of personal data may provide you with services via the Internet Service.
Data processing time
Personal data will be processed for a period necessary to deliver orders, provide services and for marketing activities and other services provided on behalf of the User. Personal data will be erased in the following cases:
- when the data subject asks for it to be erased or withdraws his/her consent to its processing;
- when the data subject does not take any actions for 10-plus years (inactive contact);
- after receiving the notification that stored data is expired or inaccurate.
Some data within this scope: e-mail and full name, may be stored for the next three years for evidentiary purposes or to hand complaints and legal claims related to services provided by the Internet Service – these types of data will not be used for marketing.
Information on orders for paid services will be stored for six years from the date an order is delivered.
We store data on Users who are not logged in for a period corresponding to the life cycle of cookies saved on devices or until they are deleted from the User's device by the User.
Your personal data related to preferences, behaviours and selection of marketing content may be used as basis for automated decisions to determine sales opportunities of the Internet Service.
Visit statistics
| Data category | Retention period | Form |
|---|---|---|
| User visits (raw events) | 90 days | Full records in operational database |
| User visits (raw events) | 36 months | Full records in archive (partitioned) |
| User visits (raw events) | indefinitely | Aggregated only (no personal identifiers) – CSV.gz export |
| Bot visits (identified as automation) | 90 days | Full records (forensic window) |
| Bot visits (identified) | indefinitely | Daily aggregates only (counts per bot category, no IP/UA beyond 90d) |
| Session identifiers (PHPSESSID) | Browser session; server-side the session expires after 4 hours of inactivity | Auto-expire |
After 36 months, raw records are aggregated into daily statistics and physically removed from the main database. CSV.gz export (anonymized) is used for long-term trend analysis – does not contain data enabling identification of a specific person (recital 26 GDPR – anonymous data is not subject to GDPR).
Recipients of personal data
We share your personal data with the following categories of recipients:
- national authorities, such as the prosecutor's office, Inspector General for Personal Data Protection, President of the Office of Competition and Consumer Protection, if they ask us for it,
- providers of services we use to run the Internet Service, for instance to deliver orders. Depending on contractual arrangements and circumstances, these entities, acting on our request or independently, specify aims and processing methods; you will find the index of providers at the website of our Internet Service at this link: List of providers
- OpenAI, L.L.C. (3180 18th Street, San Francisco, CA, USA) – for semantic search processing (understanding query context regardless of literal word matching). The text of your search query (e.g. "cheap polyester granulate") is transmitted to OpenAI API to generate a vector representing query meaning. Public document content (article titles, company names, B2B offer descriptions) is transmitted during indexing for the same purpose. Per OpenAI Enterprise policy (post-2023), data sent via API is not used for model training; retention: 30 days for abuse monitoring. We also use OpenAI services for automatic translation of published Service content (e.g. news, B2B offers, company descriptions) between language versions – only the content of published materials is transmitted. Legal basis: Art. 6(1)(f) GDPR (legitimate interest – providing functional search). Data transfer to USA is performed under Standard Contractual Clauses (SCC 2021/914) approved by the European Commission.
Statistical data – sharing with Premium contractors
Companies with the Premium package (subdomain within the portal) may receive aggregated statistics of visits regarding their subdomain:
- Number of visits per day / week / month
- Top countries of origin (at ISO country code level)
- Top entry pages
- Conversion rate (clicks on phone / email from the company card)
The data is aggregated only – does not contain IP addresses, sessions, or other identifiers of specific persons. It constitutes statistical information about traffic on their own company page (recital 26 GDPR – anonymous data).
The data is NOT shared with:
- Third parties for marketing purposes
- Advertising networks
- Exported to external analytics tools (Google Analytics, Hotjar, Matomo, etc.)
- Data brokers
Rights of the data subject:
Under the GDPR you have the right to:
- request the access to your personal data;
- request that your personal data be rectified;
- request that your personal data be erased;
- request that the processing of your personal data be restricted;
- object to the processing your personal data;
- request that your personal data be transferred.
The Personal Data Controller, without undue delay – at any rate, within a month since the request is received – will provide information about actions taken in relations to your request. In necessary, the period of one month period may be extended for the next two months due to the complexity of the request or the number of requests.
At any rate, the Controller of personal data will inform you about the extension of this period within a month since the request is received and specify the cause for delay.
The Right of access to the personal data (art. 15 GDPR)
You have the right to obtain from Controller information (confirmation) as to whether or not your personal data are being processed.
If the Controller processes your personal data, you have the right to:
- access to your personal data;
- obtain information about purposes of the processing, categories of personal data, recipients or categories of recipients of that data, planned retention period for your personal data or criteria to establish this period, your rights under the GDPR and the right to complain to the supervisory authority, about source of that data, about automated decision-making, including profiling, about safeguards used in relations to the transferred data to non-EU countries.
- receive a copy of your personal data.
If you want to request access to your personal data, submit your request via: info@plastech.pl.
Right to rectification (art. 16 GDPR)
If your personal data is inaccurate, you have the right to request that the Controller rectify it immediately.
You also have the right to request that the Controller complete your personal data.
If you would like to request that your personal data be rectified or completed, send your request to this address: info@plastech.pl.
Right to erasure (‘right to be forgotten’) (art. 17 GDPR)
You have the right to request that the Controller of personal data erase your personal data, if:
- Your personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- you have withdrawn your consent in so far as your personal data has been processed under your consent;
- the personal data have been unlawfully processed;
- you have objected to the processing of your personal data for the purpose of direct marketing, including profiling, in so far as this processing is related to direct marketing;
- you have objected to the processing of your personal data in connection with the processing, which is necessary to perform the task carried out in the public interest or processing necessary for purposes arising from legitimate interests pursued by the Personal Data Controller or a third party.
Despite the request that your personal data be erased, the Controller of personal data may still process your data to establish, assert and exercise legal claims, of which you will be informed.
If you want to request removal of your personal data, submit your request: info@plastech.pl.
Right to obtain restriction of processing (art. 18 GDPR)
You have the right to restrict the processing of your personal data if:
- you question the accuracy of your personal data – the Controller of personal data will restrict the processing of your personal data for a period allowing for the verification of this data;
- the processing is unlawful and instead the erasure of the personal data, you request the restriction of their use;
- Your data is no longer required for processing but still necessary to establish, assert or defend your legal claims;
- You have objected to the processing of your personal data until it has been determined if legitimate interests of the Controller of personal data override the grounds you have specified in your objection.
If you would like to request that the processing of your personal data be restricted, send your request to this address: info@plastech.pl.
The Right to object to personal data processing (art. 21 GDPR)
You have the right to object at any time to the processing of your personal data, including profiling, in relation to:
- processing necessary to perform a task in the public interest or processing for purposes derived from legally justified interests pursued by the Controller of personal data or third party;
- processing for direct marketing purposes.
If you want to object to processing of your personal data, submit your request via: info@plastech.pl.
Objection against anti-fraud processing (traffic statistics):
- The objection results in excluding your visits from being counted in statistics (manual administrative flagging).
- Bot detection (security layers) remains active – the controller has an overriding legitimate interest in protecting the service against attacks.
- Submission: contact the Personal Data Controller – response within 14 days.
The Right to data portability (art. 20 GDPR)
You have the right to receive from Personal Data Controller your personal data in structured, commonly used, and machine-readable format and transmit those data to another controller of personal data.
You may also claim that Personal Data Controller transmit direct your personal data to another Controller (if technically possible).
If you would like to request that your personal data be transferred, send your request to this address: info@plastech.pl.
The Right to withdraw consent
You may withdraw your consent to the processing of your personal data at any moment.
The withdrawal of your consent to the processing of your personal data does not affect the lawfulness of the processing based on your consent before the withdrawal.
If you want to withdraw your consent to the processing of your personal data, submit your request via info@plastech.pl or use appropriate functions of the Account.
The Right to lodge a complaint with a supervisory authority
If in your opinion processing of your personal data is incompliance with GDPR, you have the right to lodge a compliant with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.
In Poland, the supervisory authority within the meaning of the GDPR is the President of the Personal Data Protection Office (pol. „Prezes Urzędu Ochrony Danych Osobowych” also "PUODO").
Profiling and automated decisions
Bot detection – automated traffic classification
We use automated methods to classify traffic as legitimate vs automated (bot). The decision is based on:
- Blacklist of known bots (User-Agent patterns)
- Request frequency (rate limit per IP / session)
- Recurring 4xx errors (probe scanners)
- Browser characteristics (see "Browser characteristics measurement")
- Honeypot (hidden links / form fields visible only to bots)
Effects of classification: traffic flagged as bot is not counted in statistics. Classification does not affect access to content – bots (if not blocked at infrastructure layer) receive standard server response.
The classification does not produce decisions with legal effects within the meaning of art. 22 GDPR (we do not refuse access to services, do not impose restrictions, do not contact external authorities). In case of incorrect classification (false-positive), you may request manual override by contacting the administrator – response within 14 days.
"Cookies"
Cookie files (strictly-necessary)
We use the following cookie files necessary for the operation of the service:
| Cookie | Purpose | Lifetime |
|---|---|---|
PHPSESSID | User session identification (login, browsing state; CSRF form protection is tied to the session) | Until the browser session ends; server-side the session expires after 4 hours of inactivity |
REMEMBERME | Optional "remember me" at login (signed token) | 150 days (set only when the option is ticked) |
cartpl / carten | Order cart of a non-logged-in user | 24 hours |
proposalpl / proposalen | Protection against multiple voting on the forum | 24 hours |
spamessage | Rate-limiting of messages sent via forms (anti-spam) | 12 hours |
REMADMIN | Technical identification of an administrative session (administrator accounts only) | 24 hours |
All of the above are necessary for service operation (strictly-necessary) – they do not require user consent under art. 173(3)(2) of the Polish Telecommunications Law (transposition of art. 5(3) of Directive 2002/58/EC).
Browser characteristics measurement (anti-fraud telemetry)
After page load, a JavaScript script performs a one-time read of browser characteristics for the purpose of detecting automated bots (anti-fraud purpose, art. 6(1)(f) GDPR):
- Screen resolution and viewport
- Device pixel ratio
- Timezone
- Touch availability
- Standard automation API flags (
navigator.webdriver,chrome.runtime,plugins.length,languages,hardwareConcurrency,deviceMemory) localStorageavailability test (write + immediate removal of test key – without retaining data)- Clock precision of
performance.now()
This data is not stored as cookies – it is sent once to the server and linked to the session identifier (PHPSESSID). The localStorage test is transient (value immediately removed, no retention).
Pursuant to EDPB Guidelines 5/2020 §32, this measurement constitutes strictly necessary processing for the purpose of fraud detection and does not require consent. We do not perform detailed fingerprinting (canvas, WebGL, font enumeration) or behavioral profiling (mouse/scroll/keystroke timing tracking).
Analytical / marketing cookies
We do not currently use external analytical (e.g. Google Analytics) or marketing cookies. All cookies we use are necessary for the operation of the Service and do not require consent, which is why the Service does not display a consent banner. Should analytical or marketing cookies be introduced in the future, we will announce it in this Policy and ask for consent before their first activation.
General information
While browsing the web pages of the Internet Service, HTTP cookies are used, hereinafter referred to as cookies, in other words small text data files, saved on your end-device while using the Internet Service. Their use is aimed at facilitating the operation of our Internet Service website.
These files allow us to identify the software you are using and tailor our Internet Service to your needs.
Cookies usually contain the name of the domain from which they come, duration of their storage on the device and values assigned to them.
Safety
Cookies we use are safe for your devices. Therefore, no viruses and no unwanted or malicious software can affect your devices via cookies.
Types of cookies
We use two types of cookies:
- Session cookies: stored and kept on your device until the web browser is closed. Saved information is then permanently deleted from the memory of your device. This mechanism does not allow the acquisition of any personal data or confidential information from your device.
- Persistent cookies: stored and kept on your device until deleted. Closing the web browser or switching off the device does not cause them to be removed from your device. This mechanism does not allow the acquisition of any personal data or confidential information from your device.
Third-party services embedded in the Service
The Internet Service does not use external analytics or advertising tools (we do not embed Google Analytics, Google Ads, the Facebook pixel or similar scripts). We use third-party services only to the extent necessary for selected features of the Service:
-
embedded video (YouTube) – in articles, on company pages and in the
PlastechTV section we embed the YouTube player (Google Ireland Ltd) in privacy-enhanced
mode (youtube-nocookie.com domain) – the player sets no cookies until you start playing
the video. Processing on YouTube's side is governed by the Google privacy policy:
https://policies.google.com/privacy; - maps (Google Maps) – company pages display a location map; loading the map means connecting to Google servers (Google Ireland Ltd) and transmitting technical connection data (including the IP address);
- image and library delivery (CDN) – some images of the Service are served from the infrastructure of Cloudinary Inc. (USA), and content-editor libraries from the cdn.jsdelivr.net network; these providers receive technical connection data (IP address, browser headers) necessary to deliver the resource.
Form spam protection (ALTCHA) is operated entirely on the Administrator's servers and involves no transfer of data to third parties (details in the "Form spam protection" section below).
Sign-in with external accounts (Google, Facebook, LinkedIn)
The Service offers optional sign-in with a Google, Facebook or LinkedIn account. Redirection to the selected identity provider happens only after clicking the respective button on the login page – on all other pages of the Service no resources of these providers are loaded and they set no cookies. After authorisation we receive basic profile data from the provider (name and e-mail address) in order to create the Account or sign you in. Data processing on the identity provider's side is governed by its own privacy policy.
You may change the cookie settings by yourself at any moment in the options of the web browser or service, to specify conditions for storing such files and granting access to your device via them. You may change these settings to block the automatic handling of cookies in the options of your web browser or to be informed every time they are stored on your device. Detailed information on the options and methods for handling cookies is available in the settings of your software (web browser).
Form spam protection
The forms of the Internet Service (including registration, password recovery, contact forms and comments) are protected against spam and automated abuse by ALTCHA, a proof-of-work mechanism operated entirely on the Administrator's servers. Verification consists of the user's browser performing a short computation and requires no puzzles to be solved.
Within this mechanism no data is transferred to third parties, no cookies are set and no user profile is created. The verification result is recorded in the Service's internal security logs (together with technical connection data such as the IP address). The legal basis is the Administrator's legitimate interest (art. 6(1)(f) GDPR) in protecting against spam and abuse.