Privacy Policy

Version effective from: 7 September 2026


§ 1. Data controller

  1. The controller of your personal data is AMBER ABRAM Michał Abramczuk, ul. Nobla 8, 80-172 Gdańsk, Poland, Tax ID (NIP): PL5832926199, Statistical Number (REGON): 220867600.
  2. Contact regarding personal data: info@amber-abram.pl, tel. +48 728 377 605.
  3. The controller has not appointed a Data Protection Officer. For all matters concerning data processing, you may contact the controller directly at the address indicated in section 2.
  4. This Privacy Policy applies to the B2B platform available at amber-abram.pl, including its language versions.

§ 2. What data we collect

When registering an Account: email address, password (stored only in hashed form), first and last name of the contact person, company name, VAT number, country, address, city, postal code and telephone number.

When submitting quotation requests and fulfilling orders: cart contents, quotation and order history, data necessary to issue invoices and deliver products, and business correspondence.

When subscribing to the newsletter: email address, consent content, subscription date and IP address (as evidence of consent). Subscription uses the single opt-in method — the address is added to the list immediately after the form is submitted, without a confirmation message.

When using the contact form: data entered in the form. The message is not stored in the website database — it is sent exclusively by email.

In connection with using the Account: cart contents and changes over time, cart value, activity and login times, information about abandoning a cart without submitting a quotation request, and later submitting a request corresponding to the cart contents. This data concerns logged-in Customers only; we do not collect it from logged-out users.

Service notes: in the shop admin panel we keep an internal note concerning the fulfilment of your orders and contact with you (e.g. arrangements regarding delivery, payment or the preferred form of contact). The note is not visible in your Account, but it constitutes your personal data — at your request we provide a copy of it under the terms described in § 10.

Log of sent messages: we record the fact that an email was sent from the website — the recipient address, subject, date and information about a sending error. We do not store the content of new messages; copies of the content of messages sent before 7 September 2026 remain in the log until the end of the retention period indicated in § 3. An entry confirms that the message was handed over for sending — we do not record its delivery or opening.

Automatically, in connection with using the website: IP address, browser and device information, visit date and time, login and security events, and cookie data.


§ 3. Purposes and legal bases for processing

Purpose Legal basis Retention period
Account registration and operation Article 6(1)(b) GDPR — performance of the contract for the provision of electronic services until the Account is deleted
Verification of business status (VAT number check) Article 6(1)(b) and (f) GDPR — legitimate interest in allowing access to the platform only to business entities until the Account is deleted
Maintaining a list of rejected applications Article 6(1)(f) GDPR — legitimate interest in preventing repeated applications from entities that were denied access 3 years from rejection of the application
Handling quotation requests, preparing quotations and performing contracts Article 6(1)(b) GDPR for the duration of performance, then as specified below
Issuing invoices and maintaining accounting records Article 6(1)(c) GDPR — legal obligation under tax and accounting regulations 5 years from the end of the calendar year in which the tax obligation arose
Establishing, pursuing or defending claims Article 6(1)(f) GDPR until the limitation periods expire, but no longer than 6 years
Sending the newsletter Article 6(1)(a) GDPR — consent; additionally, consent to receive commercial information electronically until consent is withdrawn
Proof of giving and withdrawing newsletter consent (consent content, date and IP address) Article 6(1)(c) and (f) GDPR — accountability obligation and defence against claims 3 years from withdrawal of consent
Handling contact-form submissions and correspondence Article 6(1)(b) or (f) GDPR 3 years from the last contact; if the correspondence concerns a concluded contract — until the limitation periods for claims indicated in the row “Establishing, pursuing or defending claims” expire
Monitoring logged-in Customers’ carts, including carts abandoned without submitting a quotation request, in order to secure raw materials in advance and shorten order-fulfilment times Article 6(1)(f) GDPR — legitimate interest in identifying demand for products where the supply of amber raw material is variable and unpredictable, planning its purchase, and identifying obstacles in the quotation-request process no longer than 90 days after cart monitoring ends
Ensuring website security (protection against unauthorised access, event logs, IP address blocking) Article 6(1)(f) GDPR 30 days
Cookie consent register Article 6(1)(c) and (f) GDPR — demonstrating consent in accordance with the retention setting in the consent register
Analytics and online marketing Article 6(1)(a) GDPR — consent given through the cookie banner until consent is withdrawn, but no longer than the periods specified in § 8
Keeping service notes concerning order fulfilment and contact with the Customer Article 6(1)(f) GDPR — legitimate interest in maintaining continuity of information between the persons serving the Customer until the Account is deleted
Keeping a log of sent emails (recipient address, subject, date, sending error; we do not store the content of new messages) Article 6(1)(f) GDPR — legitimate interest in demonstrating that correspondence was handed over for sending and in resolving mail failures 12 months

§ 4. Providing data

  1. Providing data is voluntary, but necessary for:
    — creating an Account and accessing the catalogue,
    — submitting a quotation request and entering into a contract,
    — issuing an invoice,
    — subscribing to the newsletter.
  2. Failure to provide the data makes the above purposes impossible.

§ 5. Data recipients

We may transfer your data only to entities that process it on our behalf or under legal provisions:

Hosting and infrastructure

  • cyber_Folks S.A. — website hosting, with servers located in the Republic of Poland. Database backups are stored on the same server.
  • An additional database backup is stored on a company computer at the Controller’s registered office in Gdańsk. The backup is not transferred to third parties.

Email

  • Google Ireland Limited (Google Workspace) — handling the Controller’s email, including business correspondence and messages sent from the website.

Accounting

  • FIRMA W SĄSIEDZTWIE Agnieszka Julke-Brillowska, ul. Źródło Marii 46/2, 81-573 Gdynia, Poland, Tax ID (NIP) 5861495247 — accounting and tax settlements.

We issue invoices using software operating locally on our equipment. Invoice data is not transferred to the software provider.

Email newsletter

  • The subscriber list is maintained in the website’s own database on the hosting server indicated above. We do not use an external platform to collect subscriptions.
  • Messages are sent through the Controller’s email service in Google Workspace (Google Ireland Limited), indicated above.

Delivery

  • Carriers handling shipments: UPS, DHL, FedEx, InPost. The data transferred is limited to information necessary to deliver the shipment.
  • If delivery is handled by a carrier selected by the Customer, data is transferred to that carrier on the Customer’s instructions and at the Customer’s risk.

Public authorities

  • Public administration authorities and courts — only where the obligation to transfer data arises from legal provisions.

Analytics and advertising

  • Google Ireland Limited — Google Analytics 4 and Google Ads services. Data is transferred only after consent has been given through the cookie banner.

§ 6. Transfers of data outside the European Economic Area

  1. We use services provided by Google Ireland Limited. Google may transfer data to the United States.
  2. The transfer is based on the European Commission adequacy decision under the EU–U.S. Data Privacy Framework and, for transfers not covered by that decision, on standard contractual clauses approved by the European Commission.
  3. Except in the cases indicated above, your data is not transferred outside the European Economic Area.

§ 7. Technical access to store data

  1. The website has a mechanism enabling authorised technical access to store data for administrative and development work.
  2. This mechanism provides order data in a form stripped of personal data — order number, status, dates, amounts, currency, number of items, billing country and payment method. It does not provide names, addresses, email addresses or telephone numbers.
  3. Access is secured by tokens linked to the website domain, and all requests are logged.

§ 8. Cookies

  1. The website uses cookies. Detailed rules for their use are set out in the Cookies Policy, available at amber-abram.pl/polityka-cookies.
  2. Cookies necessary for the website to operate (session, login, cart, language and currency selection, and recording consent decisions) are used on the basis of the Controller’s legitimate interest and do not require consent.
  3. Other cookie categories are used only after consent has been given through the banner. You may change or withdraw your consent at any time using the consent settings available on the website.
  4. The consent register is maintained to demonstrate that consent was given. The IP address is recorded in the register only in anonymised form (cryptographic hash).

§ 9. Profiling and automated decision-making

  1. The decision to accept or reject a registration application is made by a person. We do not use automated decision-making that produces legal effects concerning you.
  2. Your data may be subject to profiling for online marketing purposes — only after consent has been given and only to the extent covered by that consent. This profiling does not produce legal effects concerning you.
  3. If you have an Account, we monitor your cart contents and activity times to identify demand for products in advance. The supply of amber raw material is variable and unpredictable, and we manufacture products only after accepting an Order for fulfilment — knowing what you need allows us to secure raw materials in advance and shorten the fulfilment time of your Order. This monitoring constitutes profiling within the meaning of Article 4(4) GDPR, but it is not the basis for any automated decisions and does not produce legal effects concerning you.
  4. We do not use this data to make any commercial contact or marketing efforts towards you — in particular, we do not call you or send messages in connection with your cart contents. This data is used solely for our internal analysis.
  5. Because this monitoring is based on our legitimate interest, you may object to it at any time by contacting us at the address indicated in § 1(2). Once we receive your objection, we disable monitoring of your Account.

§ 10. Your rights

In connection with data processing, you have the right to:

  1. access to your data and receipt of a copy,
  2. rectification of inaccurate data or completion of incomplete data,
  3. erasure of data — to the extent that we are not required to retain it under legal provisions,
  4. restriction of processing,
  5. data portability where data is processed on the basis of consent or a contract,
  6. objecting to processing based on a legitimate interest,
  7. withdrawing consent at any time — without affecting the lawfulness of processing carried out before its withdrawal,
  8. lodging a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland.

To exercise the above rights, contact us at info@amber-abram.pl. We will respond without undue delay, no later than one month after receiving the request.


§ 11. Data security

  1. We apply technical and organisational measures providing data protection appropriate to the risks, including: encrypted connection (HTTPS), storing passwords only in hashed form, protection against attacks on the login form, limiting the number of requests to programming interfaces, and recording security events.
  2. Access to data in the administration panel is granted only to persons authorised by the Controller.
  3. Database backups are stored on the hosting server and on a company computer at the Controller’s registered office, secured against access by unauthorised persons.

§ 12. Changes to the Policy

  1. The Policy may change, in particular due to changes in legal provisions, the launch of new website functions, or changes to data processors.
  2. Customers with an Account are informed electronically about material changes.
  3. The current version of the Policy is always available on the website. Its effective date is indicated at the beginning of the document.