Tamkun Design
Privacy Policy
1. This Privacy Policy sets out the rules for processing personal data obtained through the website tamkundesign.com, hereinafter referred to as the ‘Website’.
2. The owner of the website and the data controller is Tamkundesign, 58-500 Wrocław, Chełmońskiego 19b/1, Tax Identification Number (NIP): 6112630838, hereinafter referred to as the Controller.
3. rsonal data collected by the Administrator via the Website is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also known as the GDPR.
4. The Administrator takes special care to respect the privacy of Customers visiting the Website.
§ 1 Type of data processed, purposes and legal basis
1. The administrator collects information about natural persons performing legal transactions not directly related to their business activities, natural persons conducting business or professional activities on their own behalf, and natural persons representing legal persons or organisational units that are not legal persons but are granted legal capacity by law, conducting business or professional activities on their own behalf, hereinafter collectively referred to as Customers.
2. The administrator processes Customers’ personal data in relation to the use of the contact form on the Website to the extent necessary to perform the contract or take action prior to its conclusion – the basis for processing is Article 6(1)(b) of the GDPR.
3. When using the contact form service, the Customer provides the following data:
- E-mail address
- Name
- Phone Number
4. When using the Website, additional information may be collected, in particular: the IP address assigned to the Customer’s computer or the external IP address of the Internet provider, domain name, browser type, access time, operating system type. Navigation data may also be collected from Customers, including information about links and references they decide to click on or other activities undertaken on the Website for purposes related to the provision of services, as well as for technical, administrative, analytical and statistical purposes. – in this respect, the basis for processing is also Article 6(1)(f) of the GDPR, i.e. necessity for the purposes of the legitimate interests pursued by the Controller, which is to ensure IT security and management of the Website and to improve the functionality of the Website and the services provided.
§ 2 Data recipients
1. The Customer’s personal data is transferred to service providers used by the Administrator in the operation of the Website. Depending on contractual arrangements and circumstances, service providers to whom personal data is transferred either follow the Administrator’s instructions regarding the purposes and methods of processing such data (processors) or independently determine the purposes and methods of processing (controllers).
1.1. Processors. The Administrator uses providers who process personal data solely on the Administrator’s instructions. These include, among others, providers offering hosting services, accounting services, marketing systems, website traffic analysis systems, and marketing campaign effectiveness analysis systems.
1.2. Administrators. The administrator uses providers who do not act solely on instruction and who themselves determine the purposes and means of using customers’ personal data. They provide electronic payment and banking services.
2. Location. Service providers are mainly based in Poland and other countries of the European Economic Area (EEA).
3. If requested, the Controller shall disclose personal data to authorised state authorities, in particular to organisational units of the Public Prosecutor’s Office, the Police, the President of the Personal Data Protection Office, the President of the Office of Competition and Consumer Protection or the President of the Office of Electronic Communications.
§ 3 Data storage period
1. Customers’ personal data is stored:
1.1. If the basis for the processing of personal data is consent, the Customer’s personal data shall be processed by the Controller until the consent is revoked, and after the consent is revoked, for a period corresponding to the limitation period for claims that may be raised by the Controller and that may be raised against it. Unless a specific provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activity – three years.
1.2. If the basis for data processing is the performance of a contract, the Customer’s personal data shall be processed by the Controller for as long as it is necessary to perform the contract, and thereafter for a period corresponding to the limitation period for claims. Unless otherwise provided for in a specific provision, the limitation period is six years, and for claims for periodic benefits and claims related to business activities – three years.
§ 4 Cookies mechanism, IP address
1. The website uses small files called cookies. They are saved by the Administrator on the end device of the person visiting the Website, if the web browser allows it. A cookie usually contains the name of the domain from which it originates, its ‘expiry time’ and an individual, randomly selected number identifying the file. The information collected using this type of file helps to tailor the products offered by the Administrator to the individual preferences and actual needs of visitors to the Website.
2. The administrator uses two types of cookies:
- 2.1. Session cookies: after the end of a given browser session or after turning off the computer, the stored information is deleted from the device’s memory. The session cookie mechanism does not allow the collection of any personal data or confidential information from customers’ computers.
- 2.2. Persistent cookies: are stored in the memory of the Customer’s end device and remain there until they are deleted or expire. The persistent cookie mechanism does not allow any personal data or confidential information to be downloaded from the Customer’s computer.
3. The administrator uses its own cookies for the following purposes:
- 3.1. analyses and research, and audience auditing, in particular to create anonymous statistics that help us understand how customers use the Website, enabling us to improve its structure and content.
4. The administrator uses external cookies for the following purposes:
- 4.1. presenting a map showing the location of the Administrator’s office on the Website’s information pages, using the maps.google.com website (external cookie administrator: Google Inc. based in the USA)
5. The cookie mechanism is safe for computers of Customers visiting the Website. In particular, it is not possible for viruses or other unwanted software or malicious software to enter Customers’ computers in this way. Nevertheless, customers have the option of restricting or disabling access to cookies on their computers in their browsers. If this option is used, it will still be possible to use the Website, except for functions that by their nature require cookies.
6. The administrator may collect the IP addresses of Customers. An IP address is a number assigned to the computer of a person visiting the Website by their internet service provider. The IP number enables access to the Internet. In most cases, it is assigned to a computer dynamically, i.e. it changes with each connection to the Internet and for this reason is generally treated as non-personal identifying information. The IP address is used by the Administrator to diagnose technical problems with the server, creating statistical analyses (e.g. determining which regions generate the most visits), as information useful for administering and improving the Website, as well as for security purposes and the possible identification of unwanted automatic programmes for browsing the Website’s content that overload the server.
§ 5 Prawa osób, których dane dotyczą
Osobom, których dane są przetwarzane przysługuje:
1. The right to withdraw consent to data processing at any time:
- 1.1. The customer has the right to withdraw any consent they have given.
- 1.2. Withdrawal of consent takes effect from the moment of withdrawal.
- 1.3. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal
- 1.4. Withdrawal of consent does not entail any negative consequences for the Customer, but may prevent further use of services or functionalities which, in accordance with the law, the Controller may provide only with consent
2. Right to object to data processing:
- 2.1. The customer has the right to object at any time, on grounds relating to his or her particular situation, to the processing of his or her personal data based on Article 6(1)(e) or (f) of the GDPR, including profiling based on those provisions. The controller shall no longer process that personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
- 2.2. Opting out of receiving marketing communications about products or services by e-mail will constitute the Customer’s objection to the processing of their personal data, including profiling for these purposes.
3. Right to erasure (‘right to be forgotten’):
- 3.1. The customer has the right to request the deletion of all or some of their personal data.
- 3.2. The customer has the right to request the deletion of personal data if:
- 3.2.1. personal data is no longer necessary for the purposes for which it was collected or processed
- 3.2.2. has withdrawn specific consent, to the extent that personal data was processed on the basis of his or her consent
- 3.2.3. he or she has objected to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or he or she has objected to the processing pursuant to Article 21(2) of the GDPR
- 3.2.4. the personal data have been unlawfully processed
- 3.2.5. the personal data must be erased for compliance with a legal obligation in Union or Member State law to which the Controller is subject
- 3.2.6. the personal data have been collected in relation to the offer of information society services
- 3.3. Despite a request to delete personal data, in connection with an objection or withdrawal of consent, the Controller may retain certain personal data to the extent that processing is necessary to establish, investigate or defend claims, as well as to comply with a legal obligation requiring processing under Union law or the law of the Member State to which the Controller is subject. This applies in particular to personal data including: first name, surname, e-mail address, which are retained for the purpose of handling complaints and claims related to the use of the Administrator’s services, or additionally the address of residence/correspondence address, order number, which are retained for the purpose of handling complaints and claims related to concluded sales contracts or the provision of services.
4. Right to restrict data processing:
- 4.1. The customer has the right to request the restriction of the processing of their personal data. Until the request is considered, it prevents the use of certain functionalities or services, the use of which will involve the processing of data covered by the request. The controller will also not send any communications, including marketing communications.
- 4.2. The customer has the right to request the restriction of the use of personal data in the following cases:
- 4.2.1. when the Customer questions the accuracy of their personal data – in such a case, the Controller shall restrict the use of such data for the time necessary to verify its accuracy, but for no longer than 7 days
- 4.2.2. when the processing of data is unlawful and, instead of deleting the data, the Customer requests that its use be restricted
- 4.2.3. when personal data is no longer necessary for the purposes for which it was collected or used, but is needed by the Customer to establish, pursue or defend claims
- 4.2.4. when the data subject has objected to the processing of their data – until it is determined whether the legitimate grounds on the part of the controller override the grounds for the objection of the data subject
5. The right to request access to your personal data from the Administrator and to receive a copy thereof:
- 5.1. The Customer has the right to obtain confirmation from the Administrator as to whether personal data is being processed, and if so, the Customer has the right to:
- 5.1.1. access your personal data
- 5.1.2. obtain information about the purposes of processing, categories of personal data processed, recipients or categories of recipients of such data, the planned period of storage of Customer data or the criteria for determining that period (where it is not possible to specify the planned period of data processing), about the rights of the Customer under the GDPR and the right to lodge a complaint with a supervisory authority if the personal data has not been collected from the data subject – any available information about its source, about automated decision-making, including profiling referred to in Article 22(1) and (4) of the GDPR, and, at least in those cases, relevant information about the rules for making such decisions, as well as the significance and anticipated consequences of such processing for the data subject and the safeguards applied in connection with the transfer of personal data outside the European Union.
- 5.1.3. obtain a copy of your personal data. The right to obtain a copy must not adversely affect the rights and freedoms of others.
6. Right to rectify (correct) data:
- 6.1. The Customer has the right to request the Administrator to immediately correct any personal data concerning him/her that is incorrect. Taking into account the purposes of processing, the Customer whose data is concerned has the right to request the completion of incomplete personal data, including by submitting an additional statement, by sending a request to the e-mail address in accordance with §6 of the Privacy Policy.
7. Right to data portability:
- 7.1. The Customer has the right to receive their personal data that they have provided to the Controller and then send it to another personal data controller of their choice. The Customer also has the right to request that the personal data be sent by the Controller directly to such a controller, if technically possible. In this case, the Controller will send the Customer’s personal data in the form of a csv file, which is a commonly used format, suitable for machine reading and allowing the received data to be sent to another personal data controller.
8. Right to lodge a complaint with a supervisory authority:
- 8.1. The customer has the right to lodge a complaint with the President of the Personal Data Protection Office regarding the violation of their rights to personal data protection or other rights granted under the GDPR.
9.If the Customer exercises their rights under the above provisions, the Controller shall comply with the request or refuse to comply with it immediately, but no later than within one month of receiving it. However, if, due to the complex nature of the request or the number of requests, the Controller is unable to comply with the request within one month, it shall comply with it within the next two months, informing the Customer in advance, within one month of receiving the request, of the intended extension of the deadline and the reasons for it.
10. The Customer may submit complaints, enquiries and requests to the Administrator regarding the processing of their personal data and the exercise of their rights.
§ 6 Changes to the Privacy Policy
1. The Privacy Policy may be subject to change, and the Administrator is not obliged to notify you of such changes.
2. Please direct any questions regarding the Privacy Policy to the following e-mail address:
tamkundesign@gmail.com
3. Last modified: 23 October 2025.