This Privacy Policy is intended to inform you, clearly, concisely and transparently, about the collection, use, processing, storage and other handling of personal data. In accordance with Article 13 of the General Data Protection Regulation of 27 April 2016 (GDPR), we hereby inform you as follows:
1. Data Controller
The controller of your personal data is:
"BAMET" Sp. z o.o. with its registered office in Wielka Wieś (32-089), at ul. Krakowska 74, Poland, entered in the Register of Entrepreneurs of the National Court Register, maintained by the District Court for Kraków-Śródmieście in Kraków, 12th Commercial Division of the National Court Register, under KRS number: 0001077705, NIP (Tax ID): 5130290878, REGON (Statistical ID): 527342149.
Hereinafter referred to as the "Controller" or "BAMET".
2. Purposes, Legal Bases and Scope of Data Processing by BAMET
2.1. Activities related to the processing of your personal data:
- provision of services,
- verification of data,
- management of systems and services,
- maintenance of documentation,
- pursuit of claims arising from the Controller's business activities,
- safeguarding information in case of a legal need to demonstrate facts,
- fulfilment of tax obligations, including bookkeeping,
- provision of marketing services,
- ensuring the highest quality of the services provided,
- conducting video and GPS monitoring.
2.2. Purposes and Legal Bases of Data Processing
In each case, the purpose, legal basis, retention period, scope and recipients of the personal data processed by BAMET result from the actions you take in connection with the services or activities listed below.
| Purpose of Data Processing |
Legal Basis and Data Retention Period |
Maximum Scope of Processed Data |
| Recruitment |
Art. 6(1)(a) GDPR – CONSENT Data is stored for a period of 2 years. |
First name, surname, PESEL (national ID number), date of birth, residential address, phone number, email address, professional experience, knowledge of foreign languages, and other data contained in the CV document. |
| Conclusion of a Contract |
Art. 6(1)(b) GDPR – CONTRACT Data necessary for the conclusion of a contract is stored until the contract is performed and for a period of 5 years from the date of issuance of the financial document. |
Data necessary to conclude a contract, including the contractor's name, address, NIP (Tax ID), and contact details of representatives. |
| Settlement / Accounting |
Art. 6(1)(c) GDPR – LEGAL OBLIGATION Data relating to financial settlements is stored in accordance with the Act of 11 March 2004 on Tax on Goods and Services for a period of 5 years from the date of issuance of the financial document. |
Data necessary to issue a sales document, including the contractor's name, address, and NIP (Tax ID). |
| Marketing, Fan Page |
Art. 6(1)(f) GDPR – LEGITIMATE INTEREST Data is stored until an objection to the processing is raised. |
IP address, first name, surname, phone number, email address. |
| Correspondence |
Art. 6(1)(f) GDPR – LEGITIMATE INTEREST Data originating from electronic and traditional correspondence is stored for a period of 2 years. |
Identification data, first name and surname, postal address, email address, IP address, data contained in correspondence. |
| Pursuit of Rights |
Art. 6(1)(f) GDPR – LEGITIMATE INTEREST Data is stored until the rights or claims related to the performance of services expire. |
Data necessary to conduct proceedings. |
| Projects and Funding |
Art. 6(1)(c) GDPR – LEGAL OBLIGATION Data necessary for the implementation of projects and funding, based on specific regulations applicable to the project, is stored for the duration of the project, and thereafter, pursuant to external regulations, for the period required by law and related to the project's durability period. |
Data necessary for the implementation of the project, data of representatives and contact persons in the form of names, surnames, contact details, as well as persons designated to directly participate in the implementation of the project. |
| Video, Audio and GPS Monitoring |
Art. 6(1)(f) GDPR – LEGITIMATE INTEREST Monitoring data is processed for the purpose of protecting people and property, as well as protecting rights and claims. The retention period for video monitoring data is 30 days. Audio monitoring data is stored for up to 60 days, and GPS data is stored for a period of 2 years. |
Video monitoring data from the company's premises and the surrounding area, audio monitoring data from the company's main conference room, as well as data from company vehicle GPS tracking. |
| Whistleblowing Reports |
Art. 6(1)(c) GDPR – LEGAL OBLIGATION Data originating from reports is stored in accordance with the Act of 24 June 2024 on the Protection of Whistleblowers for a period of up to 3 years from the date a report of an irregularity related to a breach of law is made. |
Data originating from electronic reports, including first name, surname, email address or phone number, as well as the content of the message related to the report, in which the reporting person may disclose data of third parties. |
| Submission of Innovation Proposals |
Art. 6(1)(a) GDPR – CONSENT Data is stored for a period of 2 years. |
First name, surname, email address, content of the message sent via the SAFE application. |
After the periods listed above have elapsed, data is permanently deleted or anonymized.
2.3. Legal Regulations:
- Act of 18 July 2002 on Providing Services by Electronic Means;
- Act of 29 September 1994 on Accounting;
- Act of 23 April 1964, the Civil Code;
- Act of 11 March 2004 on Tax on Goods and Services;
- Act of 16 July 2004, the Telecommunications Law;
- Act of 30 May 2014 on Consumer Rights;
- Act of 24 June 2024 on the Protection of Whistleblowers;
- Act of 10 May 2018 on the Protection of Personal Data;
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR);
- and detailed regulations issued pursuant to the above acts.
3. Recipients of Your Data
The recipients of your data are:
- other entities cooperating in ensuring the continuity of the services provided,
- suppliers providing technical / organizational solutions for the provision of services / management of BAMET (including providers of IT services, courier / postal services, equipment, and other suppliers), including applications supporting communication and legal compliance,
- providers of legal and advisory services, including the application (SAFE) used for reporting irregularities,
- persons authorized by you in the exercise of your rights,
- the recipient of data in the scope of processing within IT systems is Microsoft and SAP,
- the recipients of data in the scope of communication, marketing and innovation are Microsoft, Google, LinkedIn, SAP, Meta, Usercentrics, Plausible Analytics* and the company KODO.
Detailed information regarding the cookies we use can be found in our Cookie Policy:
https://bamet.eu/cookies-en
* We use the Plausible Analytics tool provided by Plausible Analytics OÜ (Estonia) for the purpose of basic visit statistics and website optimization. Data is processed on servers located within the European Union. Plausible Analytics does not use cookies to track users, and the data collected is aggregated and does not serve to directly identify individual users. Further details regarding security and privacy protection can be found in the Plausible Privacy Policy (https://plausible.io/privacy) and on the website of the Estonian Data Protection Authority (https://www.aki.ee/en).
4. Transfer of Data Outside the EEA
BAMET is an international company, and personal data may therefore, in certain cases, be transferred by BAMET outside the European Economic Area. In such situations, we will inform you in advance of this fact.
5. Profiling
Your personal data is not subject to profiling or automated decision-making.
6. Rights of Data Subjects
- You have the right to request from the Controller access to your personal data, its rectification, erasure or restriction of processing, the right to object to processing, the right to data portability, and the right to withdraw your consent at any time.
- You have the right to lodge a complaint with a supervisory authority.
- The provision of personal data is mandatory where required by law; refusal to provide such data may result in a refusal to provide a health service. In all other respects, the provision of data is voluntary.
7. Data Protection Officer
We have appointed a Data Protection Officer, who may be contacted regarding data protection matters and related issues at the following dedicated email address: privacy[at]bamet.eu
Controller's Statement
BAMET declares and warrants that the organizational and technical measures applied for the purpose of ensuring the security of personal data processing operations meet the requirements set out in the GDPR, in particular the provisions of Article 32 GDPR.
To exercise your rights or obtain information related to data protection, please send a message to the address of the Data Protection Officer.
Detailed information will be available at BAMET's registered office.
Wielka Wieś, 19 January 2026