Privacy policy
This Privacy Policy outlines the methods of protecting the personal data of Users (i.e., individuals using the website or application, including Purchasers as defined below) who access the website and mobile application available at www.catalistapp.com, hereinafter referred to as the "Application."
By using the Application, you agree to this Privacy Policy. Lack of acceptance of this Privacy Policy prevents the use of the Application, including its website and the ability to place Orders.
The data controller of Users’ personal data is MB INVEST Marcin Biczysko, with its registered office at Witoszów Dolny 52 L, 58-100 Świdnica, Poland, Tax Identification Number (NIP): 8842519764, National Business Registry Number (REGON): 020580789, hereinafter referred to as the "Seller." The Seller owns the Application and conducts the sale of Goods through it under the terms specified in the Regulations, without the simultaneous physical presence of the parties, using a telecommunications network.
Security and Protection of Personal Data
The Seller declares that it processes Users’ personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, hereinafter "GDPR"). The Seller implements appropriate technical and organizational measures to ensure that data processing complies with GDPR, taking into account the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity to the rights and freedoms of individuals.
Scope of Data Collection
The Seller collects Users’ personal data as specified in the Regulations, including:
- Account Creation: To create an account in the Application, Users must provide their first name, last name, email address, and set a password. The email address also serves as the login.
- Order Placement: To place an Order, Purchasers must provide their first name, last name, email address, delivery address, and telephone number to enable order fulfillment and contact.
- Automatically Collected Data: The Application may collect technical data such as IP address, device type, operating system, browser type, and usage data (e.g., pages visited, time spent) for analytics and performance optimization.
Purpose of Data Collection
Users’ personal data is processed for the following purposes:
- To enter into and perform a contract for the provision of electronic services (e.g., account management).
- To enter into and perform a sales contract, including handling complaints.
- To maintain accounting records in compliance with legal obligations (e.g., tax documentation).
- To respond to inquiries submitted via the contact form.
- To send marketing content about the Seller, if the User consents to receive such content.
- To handle notifications or requests related to personal data protection.
- For statistical and analytical purposes (e.g., improving services, sending satisfaction surveys), based on the Seller’s legitimate interest in enhancing the Application and adapting it to Users’ needs.
Providing personal data is voluntary but necessary to conclude contracts for electronic services or sales. Failure to provide such data will result in the inability to use these services or complete a purchase. For marketing purposes, providing data is optional, and failure to provide it will prevent the receipt of marketing content.
Data Sharing
The Seller may share personal data with the following third parties:
- Service Providers: Hosting providers, IT support, and payment processors to facilitate Application functionality and order processing.
- Delivery Partners: Courier or postal services to fulfill Orders.
- Analytics Providers: Third-party tools (e.g., Google Analytics) to analyze usage patterns and improve the Application (data is anonymized where possible).
- Legal Authorities: If required by law or to protect the Seller’s rights.
The Seller ensures that third-party recipients comply with applicable data protection laws and process data only for the specified purposes.
Legal Basis for Processing Personal Data
The legal bases for processing Users’ personal data are:
- Contract Necessity (Art. 6(1)(b) GDPR): To conclude and perform contracts for electronic services or sales, including complaint handling.
- Legal Obligation (Art. 6(1)(c) GDPR): To fulfill accounting and tax obligations under Polish law (e.g., Tax Ordinance Act of 29 August 1997, Accounting Act of 29 September 1994).
- Legitimate Interest (Art. 6(1)(f) GDPR): To handle inquiries, conduct internal analytics, and send marketing content (where consented).
- Consent (Art. 6(1)(a) GDPR): For optional marketing communications, where applicable.
Personal data will not be used for automated decision-making, including profiling, unless explicitly stated otherwise.
Personal Data Retention Periods
- Electronic Services: Data processed for account management is retained for as long as the User uses the services, then stored until the expiration of civil law claim limitation periods.
- Sales Contracts: Data related to sales, complaints, and accounting is retained until the expiration of tax and civil law limitation periods (typically 5-10 years under Polish law).
- Inquiries: Data from contact form inquiries is retained for the time needed to respond.
- Marketing: Data for marketing purposes is retained until consent is withdrawn, then stored only for defense against claims within statutory limitation periods.
- Data Protection Requests: Data related to such requests is retained until the expiration of claim limitation periods under data protection laws.
User Rights
Users have the following rights regarding their personal data:
- Access: Request access to their data.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Request deletion of their data (subject to legal exceptions).
- Restriction: Limit processing under certain conditions.
- Data Portability: Receive their data in a structured format or have it transferred to another controller.
- Objection: Object to processing based on legitimate interests (e.g., marketing or analytics).
- Withdraw Consent: Revoke consent at any time (e.g., for marketing) without affecting prior lawful processing.
- Lodge a Complaint: File a complaint with the Polish Data Protection Authority (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, Poland).
To exercise these rights, Users may contact the Seller via the details in the “Contact Us” section. Marketing consent can be withdrawn by clicking the unsubscribe link in marketing messages.
Cookies and Tracking Technologies
The Application uses cookies and similar technologies (e.g., device identifiers) to enhance functionality and user experience. These may include:
- Essential Cookies: For login, cart management, and order processing.
- Preferences Cookies: To remember User settings (e.g., language, layout).
- Analytics Cookies: To collect anonymized usage data for improving the Application.
- Marketing Cookies: To deliver personalized content or ads, if opted in.
Users can manage cookie preferences via browser or device settings. Disabling cookies may limit some Application features. If the Application uses tracking for analytics or ads across third-party apps/sites, Users will be prompted for consent per Apple’s App Tracking Transparency (ATT) framework.
Data Security
The Seller employs industry-standard security measures (e.g., encryption, access controls) to protect personal data from unauthorized access, loss, or alteration.
International Data Transfers
If data is transferred outside the European Economic Area (EEA), the Seller ensures compliance with GDPR through appropriate safeguards (e.g., Standard Contractual Clauses).
Contact Us
For questions, requests, or to exercise your rights, contact the Seller at:
- Email: catalist.app@kat-recykling.pl
- Address: MB INVEST Marcin Biczysko, Witoszów Dolny 52 L, 58-100 Świdnica, Poland
Changes to This Privacy Policy
The Seller may update this Privacy Policy to reflect legal or operational changes. Users will be notified of significant updates via the Application or email.
Last Updated: March 4, 2025