A clear purpose
We use data only for a clearly stated purpose and on the appropriate legal basis.
We use data only for a clearly stated purpose and on the appropriate legal basis.
You can exercise your rights and contact us about privacy matters.
We build security into processes, systems and supplier relationships from the outset.
The complete source document in a clear, semantic HTML format.
This Privacy Policy describes the rules governing the processing of personal data by MIVARE GROUP PROSTA SPÓŁKA AKCYJNA in connection with use of the websites of Mivare Group, Mivare Interiors, Mivare Motors, Mivare Systems and Mivare Labs, contact with Mivare, preparation of offers, establishment and performance of B2B or B2C relationships, and compliance with legal obligations connected with those processes.
Where a separate privacy notice is provided for a particular service, contract or form, it should be read together with this Policy; to the extent that it describes the relevant process in greater detail, the specific notice takes precedence.
Data is obtained directly from the data subject, from a customer or contractor who identifies a contact person, from publicly available registers and professional sources, and from technical systems supporting the website. We do not purchase databases and do not create profiles of individuals based on data obtained from third parties.
The server and infrastructure automatically generate logs necessary for data transmission, security, diagnostics and protection against abuse. Logs include, in particular, the IP address, time of request, requested resource, response code, and browser and device information.
We do not use logs for marketing profiling. We retain them for no longer than 12 months; longer only where a specific record is required to investigate an incident, protect claims or comply with a legal obligation.
Providing data through the form is voluntary, but fields marked as required are necessary to handle an enquiry. A message sent through the form is delivered to a Mivare mailbox, and a confirmation of receipt is sent to the e-mail address provided. The form does not store submissions in a separate database.
Please do not provide special-category data or excessive data concerning third parties. Where a message contains another person's data, the sender should have a lawful basis for disclosing it.
Where we receive the business contact details of a contact person from that person's employer, a customer, contractor, co-worker, or from a publicly available register or professional source, we process first name, surname, position or role, business e-mail, business telephone number and information necessary to manage the relationship. The legal basis is Article 6(1)(f) GDPR — the legitimate interest in organising and conducting cooperation.
We provide the information required by Article 14 GDPR within a reasonable period, no later than one month after obtaining the data, and where the data is used for communication with the person — at the latest at the time of the first contact.
The website does not use Google Analytics or any other analytics, advertising or remarketing tools or tracking pixels. If such a tool is implemented, it will be activated only after consent has been obtained, and this Policy and the Cookie Policy will be updated beforehand.
Typefaces and all other website resources are served from Mivare’s own server. When a page loads, the browser does not connect to Google or any other third-party servers.
We use Google Search Console administratively to monitor the indexing and visibility of the website in search results. This tool is not embedded in the website and does not store cookies on the user's device.
We disclose data only to the extent necessary: to hosting, infrastructure and e-mail providers, IT and security service providers, providers of legal, accounting and audit services, banks and payment operators participating in a particular transaction, subcontractors requiring data in order to perform an order, and public authorities entitled to receive data under the law.
Where a provider or its subcontractor processes data outside the European Economic Area, the transfer takes place only on the basis of a mechanism provided for in Chapter V GDPR.
Please send requests to hello@mivaregroup.com. We may verify identity to the extent necessary to protect data against unauthorised disclosure. We respond without undue delay and, as a rule, within one month; this period may be extended only under the conditions laid down in Article 12(3) GDPR.
Providing data in ordinary communications is voluntary, but failure to provide data necessary to respond may make it impossible to handle an enquiry. Data required to enter into or perform a contract is necessary where the contract cannot be concluded or performed without it. Data required by law is mandatory to the extent resulting from that law.
Mivare does not make decisions concerning users based solely on automated processing that produce legal effects concerning them or similarly significantly affect them (Article 22 GDPR), and does not profile website users.
We apply technical and organisational measures selected according to risk, including access controls, the principle of least privilege, updates, backups, encryption in transit, event monitoring and incident-response procedures.
Mivare websites are not directed at children. If a particular service requires the processing of a child's data in connection with a service provided to a parent or guardian, we will provide a separate privacy notice before such processing begins.
A link to an external website does not mean that Mivare is the controller of data processed by its operator. Before implementing embeds such as videos, maps, chat or external forms, we will update this Policy.
We update the Policy following changes in law, process, tools, purposes, recipients or processing methods. Changes do not apply retroactively to the detriment of data subjects. The current version includes a version number and effective date.