Privacy Policy
This Policy describes how Layner Sp. z o.o. (hereinafter “Layner”, “Company”, “we”) collects, uses, stores and protects personal data in accordance with the EU General Data Protection Regulation (GDPR), Polish law and applicable ePrivacy norms.
Last updated: 09.09.2025
1. Controller & Contacts
Controller: Layner Sp. z o.o., ul. Cybernetyki 19B/lok.524, 02-674 Warszawa, Poland. KRS: 0000817066, NIP: PL5223173869, EORI: PL522317386900000.
Representative / contact person: Tolstikhin Mykhailo (Owner). Tel.: +48 575 725 571, Email: [email protected].
The Company currently does not appoint a separate Data Protection Officer (DPO), since under the criteria of Art. 37 GDPR such obligation does not apply. Please direct all questions to the provided contact address.
2. Processing Principles
We follow the principles of lawfulness, transparency, minimization, accuracy, storage limitation, integrity and confidentiality, and accountability (Art. 5 GDPR).
3. Data Categories
- Identification: first name, last name (if provided), company.
- Contact: phone, email, loading address and delivery address.
- Logistics information: cargo description, volume, dates, access conditions.
- Commercial data: order value, payment details (limited — we do not store full card data; possible transaction or invoice information).
- Technical: IP address, session identifiers, browser type, basic form interaction data (minimal — to ensure functionality).
- Communications: email correspondence, clarifications regarding transport, claims.
4. Sources
Main source — data you enter on the site (“Get a quote” / “Detailed form”) or provide by phone/email. Additionally — automatic server technical logs. Third parties (e.g., corporate clients) may provide your contact data for performance of a transport contract — in such case we assume they have a lawful basis to do so.
5. Purposes & Legal Bases of Processing
| Purpose |
Legal Basis (Art. 6 GDPR) |
Description |
| Assessment & offer preparation (calculation) |
b) contract / pre-contractual steps |
Processing requests, route determination, tariff calculation. |
| Performance of transport contract |
b) contract |
Organizing loading, documentation flow, client communication. |
| Accounting & tax compliance |
c) legal obligation |
Issuing invoices, storing primary documents. |
| Insurance & claims handling |
b) contract / c) obligation / f) legitimate interests |
Arranging coverage, handling insurance cases. |
| Transport load analytics (no profiling) |
f) legitimate interests |
Route optimization (in aggregated form). |
| Marketing notifications (email) |
a) consent |
Only with voluntary consent. Can be withdrawn at any time. |
| Protection of rights & interests |
f) legitimate interests |
Preventing abuse, defending against claims. |
Where necessary (e.g., use of non-essential analytics cookies) we rely on your prior consent (Art. 6(1)(a) GDPR).
6. Retention Periods
- Contract correspondence and documents: until expiry of limitation periods (usually 3–6 years in Poland) + mandatory tax period (usually 5 years).
- Requests without contract conclusion: up to 12 months (for analytics and service quality verification) or earlier upon your deletion request.
- Marketing contacts: while consent is active or until unsubscribe.
- Technical security logs: 6–24 months depending on criticality.
Upon expiry data are deleted or anonymized (de-identified).
7. Cookies & Similar Technologies
We use necessary cookies for site operation (navigation, form session). Details — in the Cookies Policy. Non-essential (analytics/marketing) are enabled only with your consent via the banner. You can change your choice by clearing browser cookies or using the settings link (if implemented).
8. Recipients & Disclosure
- Hosting IT providers (server, CDN) — provide infrastructure.
- Insurance organization (for carrier policy: NR PO/01203615/2025) — when arranging coverage.
- Accounting / tax advisors — processing financial reporting.
- Transport partners / subcontractors (when needed) — to the extent required to perform transport.
- Legal advisors — when protecting legal interests.
- Government authorities — upon lawful requests.
Each recipient receives only the minimally necessary set of data (“need-to-know”).
9. International Transfers
Main processing takes place within the European Economic Area (EEA). If there is a need to transfer data to a third country (including when using external cloud services), we apply the mechanisms provided: adequacy decisions, Standard Contractual Clauses (SCC) or equivalent safeguards. You may request a copy of applied safeguards by writing to [email protected].
10. Security
We implement organizational and technical measures: access restriction (role/account), encrypted connections (HTTPS/TLS), segmentation, backups, log monitoring, data minimization, internal incident procedures. If a security breach that may create risk to rights and freedoms is identified, notification actions will be taken according to Art. 33–34 GDPR.
11. Data Subject Rights
You have the rights (Art. 15–22 GDPR):
- Access (copy of data).
- Rectification (correct inaccuracies).
- Erasure (“right to be forgotten”) under applicable conditions.
- Restriction of processing.
- Portability (structured format).
- Objection to processing based on legitimate interests.
- Withdrawal of consent (does not affect prior lawful processing).
- Not to be subject to decisions based solely on automated processing (we do not apply fully automated decision-making / profiling).
To exercise rights send a request to [email protected]. We will respond without undue delay, usually within 30 days. For complex requests the term may be extended by another 60 days with notification.
12. Minors’ Data
Our services target adult users (18+). We do not knowingly collect data of persons under 16 without permission of legal representatives. If you believe such data were provided, contact us for deletion.
13. Policy Changes
We may update the Policy reflecting changes in services or legislation. The current version is published on this page with a new “Last updated” date. Continued use of the site after changes constitutes acceptance of the new edition.
14. Complaints & Supervisory Authority
You may lodge a complaint with your national data protection authority:
President of UODO (Urząd Ochrony Danych Osobowych)
ul. Stawki 2, 00-193 Warszawa, Poland
Web: uodo.gov.pl
You also retain the right to seek judicial remedy.