VinoVinoPL
Privacy Policy

Last updated: 05 NOVEMBER 2025

Company BPR EKOGROUP Spółka z ograniczoną odpowiedzialnością, ("VINO&VINO", "we", "us", "our") values your privacy and is committed to transparency in the processing of your personal data. This Personal Data Processing Policy ("Policy") will allow you to learn how and for what purposes we process information about you. We guarantee that we will take reasonable measures to ensure that your personal data are used only in accordance with this Policy and applicable laws and regulations.

This Policy governs the processing of personal data when you interact with us, including: (1) visiting (using) our website located at: https://vino-vino.pl/ ("Website"), (2) visiting our VINO&VINO stores, (3) communicating with us and in other cases described in this Policy.

Before providing us with any personal data, please read this Policy and our Terms of Use ("Terms").

  1. WHO ARE WE?
  2. HOW DO WE COLLECT PERSONAL DATA?
  3. HOW DO WE PROCESS PERSONAL DATA?
  4. HOW LONG DO WE RETAIN YOUR PERSONAL DATA?
  5. TRANSFER OF YOUR DATA TO THIRD PARTIES
  6. HOW DO WE PROCESS COOKIES?
  7. YOUR RIGHTS
  8. PRIVACY OF CHILDREN
  9. CROSS-BORDER TRANSFER
  10. AUTOMATED DECISION-MAKING
  11. CHANGES TO THE PRIVACY POLICY

1. WHO ARE WE?

BPR EKOGROUP Spółka z ograniczoną odpowiedzialnością, KRS 0000830005, duly registered in accordance with the legislation of the Republic of Poland, with the registered office at: Aleja Prymasa Tysiąclecia 83A loc. U-10, Warsaw 01-242 Poland, acts as the data controller. This means that we determine the purposes and means of processing personal data.

2. HOW DO WE COLLECT PERSONAL DATA?

We process personal data in the following ways:

  1. when you provide us with personal data. You provide us with your personal data for the purpose of implementing the processing purposes. For example, to create an account on the Website we need your personal data;
  2. when personal data are collected automatically. There are tools that allow us to collect technical personal data about you when you use the Website. For certain purposes (for example, to enable you to technically use the Website, to track and fix errors on the Website) we automatically collect your personal data where there are lawful grounds to do so.

3. HOW DO WE PROCESS PERSONAL DATA?

We process your personal data only when it is necessary to achieve the purpose of the processing, and only to the extent necessary to achieve that purpose. In addition, we retain your personal data for a limited period of time and delete all existing copies of your personal data after the processing period has expired.

Below we provide a full description of the purposes of processing data of Website users and VINO&VINO store customers, which personal data we process, the legal bases for the processing and information on retention periods.

Website users

Purpose of processingProcessed personal dataLegal basisData retention period
Registration of a personal account on the WebsitePhone numberContract (Terms of Use)For the duration of the use of the account and 3 years after its deletion
Filling in and managing your personal account on the WebsiteEmail
Phone number
Name and surname
Date of birth
Address
Your order details
Information about products added to "Favorites"
Contract (Terms of Use)For the duration of the use of the account and 3 years after its deletion
Placing an order and making paymentsIndividual data: order information, name and surname, phone number, IP address, email
Representative data of a legal entity: name and surname, phone number, IP address, email
Contract (Terms of Use)1 year from the date of placing the order
Delivery of the goodsIndividual data: name and surname, phone number, address, passport data to verify the age and identity of the buyer prior to delivery of the goods
Representative data of a legal entity: name and surname, phone number
Contract (Terms of Use)1 year from the date of placing the order
Informing you about important news, products and updatesEmail
Phone number
Consent3 years from the date of obtaining consent
Birthday greetings, provision of additional discounts on VINO&VINO products in honor of the birthdayEmail
Phone number
Consent3 years from the date of obtaining consent
Review and preparation of responses to incoming inquiriesName
Email
Other data that you provide in the inquiry and subsequent correspondence
Legitimate interest
you are interested in receiving an answer to the inquiry;
we are interested in providing good customer service
1 year after receipt of the request
Ensuring proper operation of the Website, tracking technical issues and resolving themUsage information: information related to the use of the Website, device type, features you use, access times, IP address ("Usage information").
Device information: information about the device, including device manufacturer, device model, its OS, device time zone, device language, device OS version, device region ("Device information").
Legitimate interest
you are interested in our Website being error-free;
we are interested in maintaining the Website in working order
Retention period depends on the type of cookie, but does not exceed 1 year
Better understanding of users of our Website and their preferencesUsage information
Device information
ConsentXSRF-TOKEN — 2 hours, vinovinopl_session — 2 hours, city_id — 1 month, store_id — 1 month, cart_id — 6 months, basketPLState — 6 months
Sending a presentation about VINO&VINO and a price list for further cooperation at your requestEmailConsent3 years from the date of submitting the request for the presentation
Enabling participation in loyalty programsIndividual data: name and surname, phone number, email, data about your order
Representative data of a legal entity: name and surname, phone number, email
Consent3 years from the date of obtaining consent to participate in the loyalty program

VINO&VINO store customers

Purpose of processingProcessed personal dataLegal basisData retention period
Enabling participation in loyalty programsIndividual data: name and surname, phone number, email, data about your order
Representative data of a legal entity: name and surname, phone number, email
Consent3 years from the date of obtaining consent to participate in the loyalty program
Informing you about important news, products and updatesEmail
Phone number
Consent3 years from the date of obtaining consent
Review and preparation of responses to incoming inquiriesName
Email
Other data that you provide in the inquiry and subsequent correspondence
Legitimate interest
you are interested in receiving an answer to the inquiry;
we are interested in providing good customer service
1 year after receipt of the request
Use of a video surveillance system, including video surveillance with an audio recording function, to ensure the protection of individuals and VINO&VINO property from unlawful infringements on VINO&VINO commercial premisesImage of a person
 
Legitimate interest
Your interest is ensuring the safety of customers using our buildings and adjacent premises;
we are interested in protecting our property and goods, as well as ensuring the safety of customers using our buildings and adjacent premises
Up to 30 days, then data are deleted by overwriting on the device recording the image

Please note that we do not process and do not have access to your payment-related personal data (bank card details, card expiry date, security code and others). Your personal data related to payment are processed by third-party payment service providers that we engage to process and execute the payment.

4. HOW LONG DO WE RETAIN YOUR PERSONAL DATA?

We retain your personal data for as long as necessary to achieve the purpose of the processing. Specific periods are indicated in section 3.

In certain circumstances we are obliged to retain your personal data for a longer period in accordance with applicable law. This may include, in particular, situations related to legal proceedings, investigations or governmental requests. We will retain your personal data for as long as necessary to comply with these legal obligations and will take appropriate measures to ensure their security and confidentiality during that period.

5. TRANSFER OF YOUR DATA TO THIRD PARTIES

Your privacy is of paramount importance to us, and we treat your personal data with the utmost care and responsibility. Although we strive to minimize the transfer of your personal data, there are certain circumstances in which it becomes necessary to disclose them to third parties.

In such cases we transfer your personal data:

  • to comply with applicable law.
    We undertake to comply with all applicable laws, rules and legal obligations. In certain situations we may be required to disclose your personal data to comply with legal requirements, for example to respond to a court subpoena, court orders or other requests from public authorities. We may also share your personal data if we reasonably believe that such disclosure is necessary to protect our rights, to enforce our Terms of Use, to investigate fraud or to protect your safety.
  • to achieve the purposes set out above.
    In order to provide an exceptional experience, we closely cooperate with a group of trusted partners and service providers. These partners play an important role in supporting various aspects of our business, for example by improving the performance of the Website. When selecting partners to whom we transfer your personal data, we take a cautious approach, ensuring that we work only with companies that take measures to protect personal data from unauthorized access, disclosure or misuse.

Although we carefully vet our partners, it is important to understand that we cannot guarantee absolute compliance with data protection laws in all cases. We recommend that you review the privacy policies of these third parties to get an understanding of their methods of processing your personal data.

Third parties providing us with payment services

When making payments on the Website you may be required to provide payment data. If you make payments using third-party services, such processing is governed by the privacy policy of the third-party payment systems. We may transfer your personal data to the following data processors:

Third parties involved in order delivery

We strive to make the ordering process for VINO&VINO products accessible and convenient for you. Therefore, we organize the delivery of the goods you order and for this purpose we may transfer your personal data to the following companies that organize delivery, and we may also receive your data from such companies:

Third-party companies engaged in marketing mailings

We strive to provide you with all necessary information about our services, news and VINO&VINO promotions in a timely manner in order to rapidly grow our business and keep our customers informed. We may transfer your personal data to the following data processor:

We transfer your personal data to third parties in accordance with the requirements of GDPR. Where possible we always enter into data processing agreements with them and take the transfer of personal data seriously. If our partner has an appropriate data processing agreement, we may join it.

6. HOW DO WE PROCESS COOKIES?

  1. To improve the functionality of the Website and make it more convenient for users, we may use cookies. A cookie is a piece of data that may be stored in the browser of your computer or mobile device used to access the Website. It allows the Website to "remember" your actions or preferences for a certain period of time or during a particular session. This information may not always identify you, but it can provide you with a more personalized web experience.
  2. We use the following types of cookies:
    • Necessary. Cookies categorized as "necessary" are required for the proper functioning of the Website and for you to effectively use its features. These cookies play a key role in providing functions such as security, network management, cookie settings and accessibility.
    • Analytical. Cookies are used to track how you use our Website, for example analytics cookies. These cookies are necessary for statistical purposes and are aimed at improving the performance of the Website to create a more convenient environment for you.
    • Advertising. Advertising cookies are used to deliver personalized advertising to Website users based on their habits and interests. They are specifically designed to collect information about your device to show you ads based on relevant topics that may interest you.
    • Functional. Functional cookies allow you to navigate our Website and use its features to the fullest extent. Functional cookies process technical personal data and personal data about usage.
  3. If you consent to the use of additional cookies, you may change and withdraw your consent at any time (except for necessary cookies) through your browser settings.
  4. Below we describe how you can manage cookie settings: 

    Delete cookies from your device
    To delete all cookies from your device, you need to do the following:

    • go to the browser settings on your device;
    • clear history, including advanced settings.

    Please note that clearing history in this way will result in the loss of your preferences on other sites, including saved login details and passwords, as well as other personalized site settings. 

    Configure cookie settings on our Website
    You can set your preferences for cookie processing in the pop-up banner when opening the Website via the link or in your browser settings. 

    Block cookies
    Almost all browsers allow users to block cookie processing on all websites. However, complete blocking will block, among other things, the processing of necessary cookies, which may result in improper functioning of the Website and other websites. 

    To disable cookies, each browser has its own set of available controls. For further instructions, please refer to your browser's help menu:

    • Google Chrome
    • Internet Explorer
    • Mozilla Firefox
    • Safari (desktop)
    • Safari (mobile)
    • Opera
    • Opera Mobile

7. YOUR RIGHTS

As a data subject, you have certain rights regarding your personal data. We undertake to respect these rights and ensure their effective exercise.

Below you will find information about your rights as a data subject under EU law:

  1. Right of access
    This right allows you to request access to the personal data we hold about you. To exercise this right, contact us by the email address provided above. Upon receiving your request, we will provide you with a copy of the personal data we process in the form in which you requested this information. Please note that in some cases we may charge you a reasonable fee for providing this information. If for any reason we are unable to comply with your request, we will provide you with an explanation and inform you of your rights to challenge the decision.
  2. Right to rectification
    This right allows you to request correction or updating of any inaccurate or incomplete personal data that we hold about you. You can exercise this right in two ways:

    1. yourself, by taking the following steps:
      • log into your account on the Website
      • open your personal profile on the Website
      • find the personal data you wish to correct and edit them
      • save the changes to instantly update the data
    2. by contacting us by the email address provided above.

    Upon receiving your request for correction, we will verify the accuracy and completeness of your personal data and make the necessary corrections or updates.

  3. Right to erasure
    This right allows you to request the deletion or destruction of your personal data in certain circumstances, for example when such data are no longer necessary for the purposes for which they were collected and processed ("right to be forgotten"). You can exercise this right by contacting us at the email address provided above. Upon receiving your request for deletion, we will assess whether the conditions for deletion are met and, if so, promptly delete or anonymize your personal data from our systems and notify any third parties to whom these data were disclosed.
  4. Right to restriction of processing
    This right allows you to request the restriction of processing of your personal data in certain circumstances, for example when the processing is unlawful, when we no longer need the personal data, or when you have objected to the processing. To exercise this right, contact us at the email address provided above. Upon receiving your request to restrict processing, we will not process your personal data (except for storage), unless it is based on consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest.
  5. Right to data portability
    This right allows you to receive a copy of your personal data in a structured, commonly used and machine-readable format, where technically possible, and to transfer those data to another controller. To exercise this right, contact us at the email address provided above. Upon receiving your request for data portability, we will provide you with a copy of your personal data in the requested format, where technically possible.
  6. Right to object
    This right allows you to object to the processing of your personal data in certain circumstances, for example when processing is based on legitimate interests or for direct marketing purposes. To exercise this right, contact us at the email address provided above. Upon receiving your objection to processing, we will assess the validity of your objection and, if it is valid, cease processing your personal data for the purposes to which you objected.
  7. Right to withdraw consent
    You have the right to withdraw your consent to the processing of your personal data at any time. This means that if we process your personal data on the basis of your consent, you have the right to withdraw that consent. To exercise this right, contact us at the email address provided above. After receiving your request to withdraw consent, if we have no other lawful basis for processing your personal data, we will cease processing them.
  8. Right to lodge a complaint
    If you believe that our processing of your personal data violates applicable law, you have the right to lodge a complaint with a supervisory authority. As we are registered under the laws of the Republic of Poland, the supervisory authority responsible for data protection is Urząd Ochrony Danych Osobowych (Office for Personal Data Protection). You always have the right to lodge a complaint related to data protection with the supervisory authority at any time. You may also contact your local data protection authority. A list of local data protection authorities can be found here. If you wish to exercise your data protection rights, you may send a request to our email address: info@vino-vino.pl.

Please note that these rights are subject to certain limitations and exceptions provided by law. To exercise any of these rights or to submit additional requests, contact us using the contact information provided.

We will consider your request as soon as possible, but no later than one (1) month. Please note that this period may be extended by a further two (2) months if necessary, taking into account the complexity and number of your requests. In such case we will inform you of the extension within one (1) month of receipt of your request and explain the reasons for the delay.

8. PRIVACY OF CHILDREN

We do not collect or request personal data from persons under the age of 16 and do not allow such persons to use our site. If you are under 16, please do not provide us with any personal data. If we become aware that we have collected personal data about a child under 16, we will delete it as soon as possible. If you believe that we may have any personal data of a child under 16, contact us at the email address provided above.

9. CROSS-BORDER TRANSFER

We do not transfer your personal data outside the European Union (EU) or the European Economic Area (EEA). All data processing activities take place within the EU/EEA, which ensures the protection of your data in accordance with data protection laws and regulations.

10. AUTOMATED DECISION-MAKING

We do not engage in automated decision-making or profiling using your personal data. All decisions that may significantly affect you are made with human involvement. We believe that human judgment should be preserved in matters concerning our customers.

11. CHANGES TO THE PRIVACY POLICY

This Policy may be amended from time to time in connection with the introduction of new technologies, legal requirements or for other purposes. Your continued use of the Website after the effective date of the updated Policy will be governed by the new Policy. Any changes we may make to this Policy in the future will be posted on this page and, if necessary, communicated by email. Please visit the Website regularly to stay informed of updates or changes to this Policy. If we make any material changes to our Policy and require your explicit consent for further processing of your personal data, we will request your consent or renewed consent (if it was previously obtained).