PRIVACY POLICY
1. General Provisions
- 1.1. This personal data processing policy is developed in accordance with the requirements of the 'Personal Data Protection Act' (hereinafter referred to as the Personal Data Act) and defines the procedure for processing personal data and the measures taken to ensure the security of personal data implemented by the ZOMBURG server group (hereinafter referred to as the Operator).
- 1.2. The Operator considers compliance with the rights and freedoms of individuals during the processing of their personal data, including protection of privacy rights, personal and family secrets, as the most important goal and condition for conducting its activities.
- 1.3. This Operator's policy on personal data processing (hereinafter referred to as the Policy) applies to all information that the Operator may obtain about visitors to the website https://zomburg.com.
2. Key Terms Used in the Policy
- 2.1. Automated processing of personal data – processing of personal data using computing tools.
- 2.2. Blocking of personal data – temporary cessation of processing personal data (except in cases where processing is necessary to clarify personal data).
- 2.3. Website – a collection of graphic and informational materials, as well as computer programs and databases, that ensure their availability on the internet at the network address https://zomburg.com.
- 2.4. Personal data information system – a collection of personal data contained in databases, ensuring their processing through information technology and technical means.
- 2.5. Depersonalization of personal data – actions that make it impossible to determine without additional information the belonging of personal data to a specific User or another subject of personal data.
- 2.6. Processing of personal data – any action (operation) or a series of actions (operations) performed with or without the use of automation tools on personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of personal data.
- 2.7. Operator – a government body, municipal body, legal or natural person who independently or jointly with others organizes and/or carries out processing of personal data, as well as determines the purposes of processing personal data, the composition of personal data to be processed, and the actions (operations) performed on personal data.
- 2.8. Personal data – any information related directly or indirectly to a specific or determined User of the website https://zomburg.com.
3. Key Terms Used in the Policy
- 3.1. The Operator has the right to:
- 3.1.1. obtain accurate information and/or documents containing personal data from the subject of personal data;
- 3.1.2. in case the subject of personal data withdraws consent for processing personal data, the Operator has the right to continue processing the personal data without the subject's consent, if there are grounds specified in the Personal Data Act;
- 3.1.3. independently determine the set of necessary and sufficient measures to ensure compliance with the obligations set out in the Personal Data Act and related legal acts, unless otherwise provided by the Personal Data Act or other laws.
- 3.2. The Operator is obliged to:
- 3.2.1. provide the subject of personal data with information regarding the processing of their personal data upon request;
- 3.2.2. organize the processing of personal data in accordance with the procedures established by the current legislation;
- 3.2.3. respond to requests and inquiries from subjects of personal data and their legal representatives in accordance with the requirements of the Personal Data Act.
4. User's Main Rights and Obligations
- 4.1. The subjects of personal data have the right to:
- 4.1.1. receive information regarding the processing of their personal data, except in cases provided by law.
- 4.1.2. demand from the operator clarification, blocking, or destruction of personal data if the data is incomplete, outdated, inaccurate, unlawfully obtained, or no longer necessary for the stated processing purpose.
- 4.2. The subjects of personal data are obliged to:
- 4.2.1. provide the Operator with accurate data about themselves;
- 4.2.2. inform the Operator about any clarifications (updates, changes) to their personal data.
5. The Operator May Process the Following Personal Data of the User
- 5.1. Email address.
- 5.2. Year, month, day, and place of birth.
- 5.3. Photographs.
- 5.4. Additionally, the website collects and processes depersonalized data about visitors (including 'cookie' files) using internet statistics services (Google Analytics and others).
6. Principles of Personal Data Processing
- 6.1. Personal data processing is carried out on a lawful and fair basis.
- 6.2. Personal data processing is limited to achieving specific, predefined, and legal purposes. Processing of personal data incompatible with the collection purpose is prohibited.
- 6.3. Combining databases containing personal data processed for incompatible purposes is prohibited.
- 6.4. Only personal data that meets the processing objectives is processed.
- 6.5. The content and volume of processed personal data correspond to the stated processing goals. Processing excessive personal data in relation to the stated purposes is prohibited.
- 6.6. During personal data processing, accuracy, sufficiency, and relevance of the data to the purposes of processing are ensured. The Operator takes necessary measures to delete or correct incomplete or inaccurate data.
- 6.7. Personal data is stored in a form that allows the identification of the subject of personal data no longer than required by the processing purposes, unless a retention period is established by law or contract. Processed personal data is destroyed or depersonalized after achieving processing purposes or when those purposes are no longer necessary, unless otherwise provided by law.
7. Purposes of Personal Data Processing
- 7.1. The purpose of processing the User's personal data:
7.1.1. informing the User through sending emails; 7.1.2. providing the User access to services, information, and/or materials available on the website https://zomburg.com.
- 7.2. The Operator may also send the User notifications about new products and services, special offers, and various events. The User can always opt-out of receiving informational messages by sending an email to contact@zomburg.com with the subject 'Opt-out from notifications about new products, services, and special offers.'
- 7.3. Depersonalized data about Users collected through internet statistics services is used to gather information about User activity on the site and improve the website and its content.
8. Legal Basis for Personal Data Processing
- 8.1. The legal grounds for processing personal data by the Operator are:
- 8.1.1. the law 'On Information, Information Technologies, and Information Protection'
- 8.1.2. laws and other normative legal acts in the field of personal data protection;
- 8.1.3. the User's consent to process their personal data, including those permitted for distribution.
- 8.2. The Operator processes the User's personal data only when filled in and/or
sent by the User through specific forms on the website https://zomburg.com or via email. By filling out these forms and/or sending their personal data to the Operator, the User expresses consent to this Policy.
- 8.3. The Operator processes depersonalized data about the User if permitted by the User's browser settings (e.g., enabling cookies and JavaScript).
- 8.4. The subject of personal data independently decides whether to provide personal data and freely gives consent, voluntarily and in their own interest.
9. Conditions of Personal Data Processing
- 9.1. Personal data processing is carried out with the consent of the subject of personal data.
- 9.2. Personal data processing is necessary to achieve purposes defined by an international agreement of Poland or law, for performing functions, powers, and obligations imposed by Polish legislation on the operator.
10. Procedure for collecting, storing, transferring, and other types of processing of personal data
- 10.1. The security of personal data processed by the Operator is ensured through the implementation of legal, organizational, and technical measures necessary to fully comply with the requirements of current legislation in the field of personal data protection.
- 10.2. The Operator ensures the preservation of personal data and takes all possible measures to prevent unauthorized access to personal data.
- 10.3. User personal data will never, under any circumstances, be transferred to third parties, except in cases related to the enforcement of current legislation or if the data subject has provided consent to the Operator for transferring the data to a third party for the execution of obligations under a civil law contract.
- 10.4. In case of inaccuracies in personal data, the User can update them independently by sending a message to the Operator's email address contact@zomburg.com with the subject 'Update of personal data'.
- 10.5. The term of personal data processing is determined by the achievement of the purposes for which the personal data was collected, unless another term is provided by the contract or current legislation. The User can withdraw their consent for personal data processing at any time by sending a message to the Operator via email at contact@zomburg.com with the subject 'Withdrawal of consent for personal data processing'.
- 10.6. All information collected by third-party services, including payment systems, communication tools, and other companies with access to personal data through https://zomburg.com, is subject to processing in accordance with their own privacy policies.
11. List of actions carried out by the Operator with the received personal data
- 11.1. The Operator collects, records, organizes, accumulates, stores, updates (modifies, changes), extracts, uses, transfers (distributes, provides access), anonymizes, blocks, deletes, and destroys personal data.
- 11.2. The Operator carries out automated processing of personal data with the receipt and/or transmission of the obtained information through information and telecommunication networks or without such information.
12. Cross-border transfer of personal data
- 12.1. Before starting the cross-border transfer of personal data, the Operator must ensure that the foreign country, whose territory is intended for the transfer of personal data, ensures reliable protection of the rights of personal data subjects.
- 12.2. Cross-border transfer of personal data to foreign countries that do not meet the above requirements can only be carried out if there is written consent from the personal data subject for the cross-border transfer of their personal data and/or the execution of a contract to which the personal data subject is a party.
13. Confidentiality of personal data
- 13.1. The Operator and other persons who have access to personal data are obliged not to disclose or distribute personal data to third parties without the consent of the personal data subject, unless otherwise provided by law.
14. Final provisions
- 14.1. The User can get any clarifications regarding the processing of their personal data by contacting the Operator via email contact@zomburg.com.
- 14.2. This document will reflect any changes to the personal data processing policy by the Operator. The policy is valid indefinitely until replaced by a new version.
- 14.3. The current version of the Policy is freely available online at https://zomburg.com/privacy-policy
Last updated: 20 July 2026 · Contact: contact@zomburg.com