Privacy Policy

Effective date: July 6, 2026

1. General Provisions

This Privacy Policy defines the rules for processing personal data of users using the netDecor Business website available at https://business.netdecor.app/ (hereinafter: 'Service').

The administrator makes every effort to ensure the security of personal data and to process them in accordance with applicable laws, in particular with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).

2. Personal Data Administrator

The administrator of personal data is:

CAD Projekt K&A Sp. z o.o.

ul. Rubież 46, 61-612 Poznań, Poland

A company entered in the register of entrepreneurs kept by the District Court Poznań – Nowe Miasto i Wilda in Poznań, 8th Commercial Division of the National Court Register under KRS number 0000637767, NIP: 9721266721, share capital: PLN 60,000.

Contact with the Administrator:

e-mail: [email protected]

phone: +48 61 662 38 83

3. Scope of Processed Data

The Administrator may process the following personal data:

  • first name and last name,
  • e-mail address,
  • phone number,
  • company name,
  • job position,
  • IP address,
  • technical data concerning the device and internet browser,
  • information about the user's activity in the Service,
  • data provided through contact or registration forms.

Providing data is voluntary, but in some cases it may be necessary to answer an inquiry, present an offer, or perform the services provided.

4. Purposes and Legal Grounds for Data Processing

Personal data are processed for the following purposes: replying to inquiries, presenting commercial offers, enabling netDecor Business services, concluding/executing contracts, communicating with users, ensuring security, developing the Service, marketing, and investigating or defending against claims.

The legal basis for processing data is: user consent (Art. 6 sec. 1 lit. a GDPR), execution of a contract or action prior to its conclusion (Art. 6 sec. 1 lit. b GDPR), compliance with a legal obligation (Art. 6 sec. 1 lit. c GDPR), or a legitimate interest of the Administrator (Art. 6 sec. 1 lit. f GDPR).

5. Data Recipients

Personal data may be transferred to entities cooperating with the Administrator, in particular: hosting service providers, IT service providers, email operators, analytical service providers, marketing tool providers, law and accounting firms, and entities authorized under applicable law.

The Administrator transfers data only to the extent necessary to achieve the specified purposes.

6. Data Retention Period

Personal data will be stored for the period necessary to achieve the purpose for which they were collected, for the duration of the contract and after its completion as required by law, until the statute of limitations for potential claims, or until the withdrawal of consent (if consent was the basis of processing).

7. User Rights

Every person whose data is processed has the right to: access their data, correct data, delete data, restrict processing, transfer data, object to processing, withdraw consent at any time (if processing is based on consent), and lodge a complaint with the President of the Personal Data Protection Office.

8. Cookies

The Service uses cookies and similar technologies to ensure the proper operation of the Service, maintain user sessions, remember preferences, conduct visit statistics, analyze Service usage, and conduct marketing activities (only after obtaining appropriate consent).

Users can manage cookie settings using their browser settings or through the cookie consent banner available in the Service.

9. External Tools

The Service may use tools provided by third parties, such as: Google Analytics, Google Tag Manager, Google Ads, Meta Pixel, Microsoft Clarity, YouTube, CRM systems, and contact form and email handling systems.

The use of these tools may involve the processing of data by their providers in accordance with their privacy policies.

10. Data Transfer Outside the European Economic Area

If, in connection with the use of external tools, personal data are transferred outside the European Economic Area, the Administrator ensures the application of appropriate safeguards required by GDPR, in particular standard contractual clauses approved by the European Commission.

11. Automated Decision Making

Personal data of users are not used for decisions based solely on automated processing, including profiling, which would produce legal effects concerning the user or similarly significantly affect them.

12. Data Security

The Administrator applies appropriate technical and organizational measures to ensure the protection of personal data against loss, destruction, unauthorized access, disclosure, or modification.

13. Changes to the Privacy Policy

The Administrator reserves the right to change this Privacy Policy in case of changes in legal regulations, Service functionalities, or data processing methods.

The current version of the Privacy Policy is always published in the Service.

14. Contact

In matters related to the processing of personal data, you can contact the Administrator:

CAD Projekt K&A Sp. z o.o.

ul. Rubież 46, 61-612 Poznań, Poland

E-mail: [email protected]

Phone: +48 61 662 38 83