Privacy policy of the montinea.pl website
Last updated: 4 September 2026
This is an English translation provided for convenience. In case of any discrepancy, the Polish version of this policy prevails.
1. Data controller
The controller of the personal data of people using the montinea.pl website is:
hereinafter: the „Controller”.
For matters relating to the processing of personal data and the exercise of your rights, you can contact the Controller by post, by email or by phone.
The Controller has not appointed a data protection officer, as it is not required to do so under applicable law.
2. Scope of this policy
This policy covers the processing of personal data in connection with:
- use of the montinea.pl website;
- enquiries sent through the contact form;
- contact by email or telephone;
- keeping the website secure and working correctly;
- the use of cookies and similar technologies.
3. What data we process
In connection with the contact form we may process:
- your name;
- your email address;
- the content of your message;
- any other information you choose to include in your message.
While you use the website, technical data may also be processed, such as:
- IP address;
- date and time of the connection;
- the address of the page visited;
- the referring page address;
- browser, operating system and device type;
- identifiers of cookies or similar technologies;
- information needed to detect spam, abuse and attempted attacks.
Please do not include special categories of personal data in the form — such as information about health, beliefs, origin, political opinions or private life — unless it is necessary in order to handle your matter.
4. Purposes and legal bases
Handling enquiries and correspondence
Data is processed in order to receive your message, reply to it, continue the correspondence and resolve the matter you raised.
The legal basis is the legitimate interest of the Controller in communicating with people interested in its activity and services — Article 6(1)(f) GDPR.
Preparing an offer or entering into a contract
If your enquiry concerns preparing an offer, starting cooperation or entering into a contract directly with the person sending the message, the data may be processed in order to take steps at your request before entering into a contract — Article 6(1)(b) GDPR.
If you contact us on behalf of a company or another organisation, the basis for processing your contact details is the legitimate interest of the Controller and of the organisation you represent in conducting business communication — Article 6(1)(f) GDPR.
Website security
Technical data may be processed in order to protect the website and the form against spam, abuse, malicious software and unauthorised access attempts, and in order to diagnose errors.
The legal basis is the legitimate interest of the Controller in ensuring the security of the website and of communications — Article 6(1)(f) GDPR.
Establishing, pursuing or defending claims
Data may be processed in order to establish, pursue or defend against claims relating to correspondence, an offer or cooperation.
The legal basis is the legitimate interest of the Controller — Article 6(1)(f) GDPR.
Compliance with legal obligations
If an enquiry leads to a contract, data may also be processed in order to meet tax, accounting or other obligations arising from the law — Article 6(1)(c) GDPR.
Optional technologies and third-party content
Optional technologies, such as an interactive Google map or other external elements that are not required for the basic operation of the website, are activated on the basis of consent — Article 6(1)(a) GDPR.
You may refuse or withdraw consent at any time through the „Privacy settings” panel. Withdrawing consent does not affect the lawfulness of processing carried out beforehand.
We do not use data from the form to send newsletters or marketing information unrelated to your enquiry without a separate legal basis.
5. Providing data is voluntary
Providing your data is voluntary, but your name and email address are needed in order to submit the form and receive a reply.
If the data required by the form is not provided, we will not be able to answer your enquiry. Providing additional information in the body of the message is optional.
6. Recipients of the data
Data may be shared only to the extent necessary to achieve the purposes set out above, with:
- hosting and server infrastructure providers;
- email service providers;
- providers of systems used to handle correspondence or customer relationships;
- people and entities providing technical, IT and security support for the website;
- legal or accounting service providers, where necessary;
- Google Ireland Limited and companies in the Google group — in connection with the use of reCAPTCHA and, subject to consent, other Google services;
- public authorities, courts or other authorised bodies, where an obligation to transfer data arises from the law.
Entities processing data on behalf of the Controller act on the basis of appropriate agreements and may process the data only in accordance with the instructions they receive.
The Controller does not sell personal data.
7. Transfers outside the European Economic Area
Some technology providers, in particular companies belonging to the Google group, may process data outside the European Economic Area.
Where such a transfer takes place, it is based on:
- an adequacy decision of the European Commission, including — where applicable — the EU–US Data Privacy Framework;
- standard contractual clauses approved by the European Commission;
- another mechanism provided for in Chapter V of the GDPR.
Information about the safeguards applied is available on request from the Controller. Information on how Google transfers data is available at: policies.google.com/privacy/frameworks.
8. Retention periods
Data relating to an ordinary contact enquiry is kept for as long as needed to reply and conclude the correspondence, and then for no longer than 12 months from the last meaningful contact.
If contact leads to an offer, negotiations or a contract, data may be kept:
- for the duration of the negotiations;
- for the duration of performance of the contract;
- for as long as required by tax and accounting regulations;
- until the relevant limitation period for claims has expired.
Data in the server's technical logs is kept, as a rule, for no longer than 30 days, unless longer retention is necessary to investigate a security incident or to pursue claims.
Information about consents given and privacy settings may be kept for as long as the consent is in force and for as long as necessary to demonstrate that it was obtained correctly.
Data contained in backups may remain there until the backup is overwritten in the normal rotation cycle. Such data is not used for any other purpose.
9. Rights of data subjects
Depending on the basis and circumstances of the processing, you have the right to:
- be informed about the processing of your data;
- access your data and receive a copy of it;
- have inaccurate data corrected;
- have incomplete data completed;
- have your data erased;
- restrict processing;
- data portability, where processing is carried out by automated means on the basis of consent or a contract;
- object to processing based on legitimate interest;
- withdraw consent at any time, where processing is based on consent.
These rights are not absolute. In some situations, continued processing may be required by law or necessary in order to establish, pursue or defend against claims.
A request concerning the exercise of your rights can be sent to info@montinea.pl. We may ask for information allowing us to confirm the identity of the person making the request.
If you believe your data is being processed unlawfully, you may lodge a complaint with:
10. Automated decision-making
The Controller does not take decisions about users based solely on automated processing that would produce legal effects concerning them or similarly significantly affect them.
The reCAPTCHA mechanism may automatically assess the likelihood that the form is being used by a human rather than by a computer program. This assessment serves solely to protect the form against spam and abuse.
If the protection prevents you from submitting the form, you can contact us directly at info@montinea.pl or by phone.
11. Cookies and similar technologies
Cookies are small pieces of information stored on the user's device. The website may also use the browser's local storage and other technologies serving similar purposes.
Essential technologies
Essential technologies are used in order to:
- provide the basic operation of the website;
- protect the form;
- remember privacy settings;
- ensure the security and continuity of transmission.
Their use does not require consent where it is necessary to provide the service requested by the user.
Language settings
The website may use the _icl_visitor_lang_js file to remember the preferred language. This file is stored for around 24 hours. If it is not necessary in order to carry out a choice made by the user, it should be activated only after consent has been obtained.
Google reCAPTCHA
The form may be protected by Google reCAPTCHA, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA may process, among other things, the IP address, information about the browser and device, the address of the page visited, the time of the visit and the way the user interacts with the page. The service may store cookies necessary to distinguish users from automated programs.
reCAPTCHA is used on the basis of the legitimate interest of the Controller in protecting the form against spam and abuse.
More information:
- Google privacy policy: policies.google.com/privacy
- Google terms of service: policies.google.com/terms
Google Maps and other external services
The interactive Google map and other optional content loaded from external servers are activated only after consent has been given.
Once activated, the provider may receive the IP address, information about the device and browser, the time of the visit and the address of the page visited, and may store or read cookies.
Withholding consent may prevent a map or other external element from being displayed, but it does not limit your ability to use the rest of the website or to contact the Controller.
Managing consent
On a first visit, the user can:
- accept optional technologies;
- reject optional technologies;
- configure individual settings.
Consent can be changed or withdrawn at any time using the „Privacy settings” link available in the footer of the page.
An up-to-date list of the cookies used, their providers, purposes and lifetimes should be available in the privacy settings panel.
12. Data security
The Controller applies organisational and technical measures appropriate to the nature of the data processed and the risk involved. The connection to the website is encrypted using the HTTPS protocol.
Access to the data is given only to people and entities for whom it is necessary in order to carry out the tasks entrusted to them.
13. Changes to this policy
This policy may be updated if the way the website works, the services used, the purposes of processing or the applicable law change.
The current version of the policy is always available on montinea.pl together with the date of the last update.