Privacy Policy AMTRA
This Privacy Policy aims to provide you with information about the processing of your personal data in connection with the use of our websites: amtra.pl, moje-auto.pl, ma-pro.com.pl, clinex.com.pl, tecmaxx.pl, bondini.pl, wunderbaum.pl, turtlewax.pl, sejfboksy.pl and produkt.amtra.pl.
According to this Privacy Policy, “personal data” includes both data that allows for the direct identification of a natural person (e.g. name and surname) and any data relating to an identified or identifiable natural person (e.g. IP address, information about preferences, contact details, etc.).
On the other hand, “processing” means any operation or set of operations which is performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
We understand that by using our services, you entrust us with your most valuable asset—your data. Therefore, we care about and protect your privacy, prioritizing transparency. Therefore, it is crucial for us to clearly communicate to you the categories of your personal data we process, the purposes for which we do so, the basis on which we process your data, and your related rights. This document has been divided into sections to facilitate your navigation. Please read this policy carefully.
If you have any questions or concerns, please contact us using the method described in point 2 below.
What is GDPR?
GDPR, i.e. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), aims to protect the fundamental rights and freedoms of natural persons, in particular by increasing the protection of personal data of natural persons that are collected and processed by companies and organisations operating within the European Union.
This Privacy Policy is for informational purposes and constitutes the implementation of the information obligations provided for in Articles 13 and 14 of the GDPR.
1. Who are we?
We are AMTRA Spółka z ograniczoną odpowiedzialnością and will act as the Controller of your personal data in connection with your use of our website.
Full registration details of the controller: “AMTRA” SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ with its registered office in Sosnowiec, at the address: ul. Schonów 3, 41-200 Sosnowiec, Poland, entered into the Register of Entrepreneurs of the National Court Register, maintained by the District Court Katowice-Wschód in Katowice, 8th Commercial Division of the National Court Register, under the KRS number: 0000063436, NIP number: 6250009241, REGON number: 272530098, with the share capital of PLN 468 800.00.
2. Contact us
In all matters related to the processing of your personal data, you can contact the Administrator as follows:
- via e-mail at: rodo@amtra.pl
- via traditional mail to the following address: ul. Schonów 3, 41-200 Sosnowiec
3. For what purposes do we process personal data?
Personal data is processed for the purpose:
3.1. Handling inquiries from the contact form and correspondence
If you attempt to contact us or if you correspond with us, we will process your identification and contact details and the content of your inquiry or correspondence.
The legal basis for such processing is Article 6(1)(f) of the GDPR, i.e., the necessity of processing to pursue the legitimate interests of the controller or a third party. In this case, the Controller’s legitimate interest will consist in conducting electronic correspondence.
In some cases, the legal basis may be Article 6(1)(b) of the GDPR, i.e. the necessity of processing to take steps prior to entering into a contract with you – if the correspondence is aimed at concluding a contract with us.
3.2. Recruitment
If you submit a job application via our website or other portal, we will process your personal data for recruitment purposes. For this purpose, we will process your identification and contact details, as well as the information you provided in your application.
The legal basis for such processing is Article 6(1)(b) and (c) of the GDPR, i.e., the necessity of processing in order to take steps necessary before entering into an employment contract and to comply with the legal obligation imposed on the Controller by the Labor Code. This applies to the processing of personal data such as: name and surname, contact details, date of birth, education, and employment history. For other personal data, the legal basis for their processing is your consent (Article 6(1)(a) of the GDPR), as you determine the data you provide to us in your application.
The retention period for personal data depends on the duration of the recruitment process. After its completion, your data will be retained for a maximum period of three years. If you have consented to its use in future recruitment processes, we may use your data in subsequent recruitment processes conducted by the Administrator within the next 12 months.
In situations where the legal basis for processing is your consent, you have the right to withdraw that consent.
3.3. Organization of trainings, events and webinars
If we organise events, training courses or webinars, we will process your data in order to ensure your participation in such an event.
We will process your contact and identification data, and the basis for such processing will be Article 6(1)(f) of the GDPR, i.e. the necessity of processing to pursue the legitimate interest of the controller or your consent (Article 6(1)(a) of the GDPR).
You may withdraw your consent at any time, but this will not affect any processing that took place before your withdrawal.
3.4. Establishing business contacts at trade fairs and events
If we meet with you at trade shows, conferences, or other networking events, we may process your data to establish and maintain business contact. For this purpose, we will process your identification and contact data, as well as information you provide to us, in particular: name, phone number, email address, company name, and job title.
The legal basis for such processing is Article 6(1)(f) of the GDPR, i.e., the necessity of processing to pursue the Controller’s legitimate interest, which in this case will be establishing and maintaining business relationships and potential commercial cooperation. If you consented to data processing during the event, the legal basis will also be Article 6(1)(a) of the GDPR.
The retention period for personal data depends on the nature of the relationship. If no cooperation is established, your data will be stored for a maximum of two years from the date of its acquisition. If cooperation is established, the data will be processed for the duration of the relationship and for the period required by law after its termination.
3.5. Newsletters
If you have agreed to receive one of our newsletters, we will process your data to send you marketing information, news, offers, and other content related to our brands. For this purpose, we will process your identification and contact details, in particular: name, company, position, and email address.
The legal basis for this processing is Article 6(1)(a) of the GDPR, i.e., your consent to the processing of your personal data for the purpose of receiving the newsletter. You may withdraw your consent at any time, but this will not affect processing that took place before your withdrawal. You can withdraw your consent by clicking the unsubscribe link in every newsletter message or by sending a message to our email address.
The storage period for personal data depends on the duration of your consent. Upon withdrawal of consent, your data will be immediately deleted from the newsletter subscriber database, unless further processing is necessary for other purposes based on separate legal bases.
3.6. Direct marketing
We may also process your personal data for direct marketing purposes related to our brands, products, and services. For this purpose, we will process your identification and contact details, as well as information about the company you work with.
The legal basis for such processing will most often be Article 6(1)(a) of the GDPR, i.e., the consent of the data subject, or Article 6(1)(f) of the GDPR, i.e., the necessity of processing to pursue the legitimate interest of the controller in marketing the Controller’s products and services. In situations where the legal basis for processing is your consent, you have the right to withdraw that consent.
3.7. Access to AMTRA API (produkt.amtra.pl)
If you wish to access our API available at produkt.amtra.pl, we will process your personal data provided in the registration form (name, surname, company name, registration and address details, position, telephone number, e-mail address) and information about your use of the API.
The legal basis for this processing is Article 6(1)(b) of the GDPR, i.e., the necessity of processing to fulfill the API access agreement (this agreement is acceptance of the Terms and Conditions). We will process your data for the duration of your account.
4. Source of personal data
We collect data directly from you in connection with your use of our website or contact form, and the scope of this data depends largely on you.
In the case of electronic business correspondence, we may have obtained your data from publicly available sources (e.g. your company’s website), from our contractor with whom you cooperate, or directly from you.
In other cases, we received your data directly from you, e.g. in connection with subscribing to our newsletter.
5. Recipients of personal data
Only employees authorized by the Controller and entities that, on behalf of the Controller, provide certain services requiring access to data, as well as entities from our capital group, will have access to your personal data.
Your personal data may also be made available to authorized state authorities if they contact us in connection with the tasks they perform.
6. Transfer of data outside the European Economic Area (EEA)
In some cases, your personal data may be transferred, stored and processed in countries outside the European Economic Area (EEA), but only subject to appropriate safeguards – e.g. standard contractual clauses approved by the European Commission.
You have the right to obtain a copy of the security measures applied when transferring data to recipients outside the European Economic Area – for this purpose, please contact us at rodo@amtra.pl .
7. Data storage period
Your personal data will be stored only for the time necessary to achieve the processing purposes, and will be deleted after that time. We may retain your data until any claims that may arise during processing expire. In such a case, we will delete your data upon the expiration of the limitation period for such claims.
We store personal data collected using cookies for a period corresponding to the life cycle of cookies stored on your devices.
8. Rights of data subjects
You have the following rights:
- The right to access personal data, including the right to obtain a copy of personal data;
- the right to request rectification of data,
- The right to request the deletion of personal data;
- the right to restrict data processing.
- The right to object to the processing of personal data;
- The right to data portability;
- The right to withdraw consent if consent is the legal basis for the processing of your personal data.
If you wish to exercise any of the above rights, please contact us as set out in section 2 above.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office.
9. Data security
As a company that values the security of our clients’ and collaborators’ data, we understand your concerns about the security of personal data and other information processed via our website. However, we assure you that we are committed to protecting the security of your information and personal data.
To ensure the security of information and personal data, we use adequate, modern technical and organizational measures, including cryptographic protection and access control mechanisms, as well as internal control systems.
10. Changes to the privacy policy
This privacy policy may be amended from time to time due to changes in the functionality of our websites or due to changes in legal regulations.
Last updated: November 2025