Privacy policy
Last updated: May 2026
Data controller
The controller of your personal data is PRIMO LAND Sp. z o.o. with its registered office in Kraków (address in the contact section on the home page). For privacy matters you can write to kontakt@primorent.pl.
What data we collect
When you contact us by email or phone, browse the site or share materials, we may process for example:
- name or alias, email address, phone number,
- message content, attachments and information you provide in correspondence or calls,
- technical data: IP address, browser type, request time, cookie identifiers,
- data from cookies and similar technologies, if used,
- images shown in the project gallery (as public site content only, without automated recognition of individuals).
Purpose and legal basis
We use data to respond to enquiries, prepare offers, communicate before a contract and keep the site secure. Legal basis: GDPR Art. 6(1)(b) (pre-contract steps), (f) (legitimate interests, e.g. abuse prevention) or (a) (consent) where you give consent.
Retention
We keep correspondence and contact data for up to 24 months from last contact unless you ask for deletion earlier or law requires a longer period.
Your rights
You have the right of access, rectification, erasure, restriction, objection to processing based on legitimate interests and data portability where applicable. You may lodge a complaint with your supervisory authority (in Poland: the President of the Personal Data Protection Office).
Cookies and similar technologies
We use cookies necessary for the site to work (e.g. session, security). If we enable analytics or marketing cookies, we will ask for consent as required by law and let you withdraw it.
Hosting and server logs
The site is hosted with a provider in the EEA or with safeguards compliant with GDPR if data is transferred. Server logs may include IP addresses and technical data processed to ensure stability and security.
Processors
We may share data with hosting providers, email providers, IT tools and advisers supporting legal and accounting work, only under data processing agreements and to the minimum extent necessary.
Transfers outside the EEA
If we used services outside the EEA, we would apply mechanisms approved by the European Commission (e.g. standard contractual clauses) or another basis under Art. 46 GDPR.
Security
We apply organisational and technical measures appropriate to the risk: access control, HTTPS transmission, least privilege and incident response procedures.
Marketing
We send newsletters or marketing messages only on the basis of consent or another lawful ground. You can opt out at any time.
Profiling
We do not carry out solely automated decision-making about you, including profiling within the meaning of GDPR Art. 22.
Children
The site is not aimed at children under 16 and we do not knowingly collect their data.
Changes to this policy
The current version is always published on this page. For material changes we will inform you on the site or by contact channels if the law requires it.