<!doctype html>

Privacy Policy

This Privacy Policy sets out the rules for processing personal data collected via the online store www.lacare.com (the “Online Store”).

Controller: TG Ersatzteile Polska Sp. z o.o., ul. Smoluchowskiego 1, 20-474 Lublin, Poland · NIP (VAT ID): 946-23-62-587 · REGON: 432524119

Contents
  1. Introductory provisions
  2. § 1. Types of data, purposes & legal bases
  3. § 2. Data recipients & retention
  4. § 3. Cookies mechanism & IP address
  5. § 4. Rights of data subjects
  6. § 5. Security management — password
  7. § 6. Changes to this Policy

Introductory provisions

  1. This Privacy Policy sets out the rules for processing personal data collected via the Online Store www.lacare.com.
  2. The owner of the Online Store and the data controller is TG Ersatzteile Polska Sp. z o.o., with its registered office in Lublin (20-474), ul. Smoluchowskiego 1, entered in the Central Register and Information on Economic Activity maintained by the Minister of Development and Technology, NIP (VAT ID): 946-23-62-587, REGON: 432524119.
  3. Personal data are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the GDPR).
  4. The Controller pays particular attention to respecting the privacy of Customers visiting the Online Store.

§ 1. Types of data processed, purposes, and legal bases

  1. The Controller collects information concerning natural persons acting directly in relation to their business or professional activity, and persons representing legal entities or organizational units granted legal capacity by law (collectively, the “Customers”).
  2. Personal data are collected, in particular, when the Customer:
    1. registers a Customer Account — to create and manage the account. Legal basis: Art. 6(1)(b) GDPR;
    2. places an order — to perform the sales contract. Legal basis: Art. 6(1)(b) GDPR;
    3. uses the contact form — to perform the electronic service. Legal basis: Art. 6(1)(b) GDPR;
    4. uses the submit a review service — to perform the electronic service. Legal basis: Art. 6(1)(b) GDPR;
    5. subscribes to the Newsletter — to provide the electronic service. Legal basis: Art. 6(1)(a) GDPR (consent);
    6. uses the notify about availability service — to perform the electronic service. Legal basis: Art. 6(1)(b) GDPR.
  3. Data provided at registration may include:
    • e-mail address;
    • address details (postal code & city; country; street & building/flat number);
    • first and last name; telephone number; business name (if applicable); VAT ID (NIP).
  4. The Customer sets an individual password during registration; it can later be changed as described in § 5.
  5. Data provided at ordering may include e-mail, address details, name, phone, business name and VAT ID (NIP).
  6. For notify about availability — only e-mail; for the contact form — only e-mail; for submit a review — only a nickname/first name; for the Newsletter — only e-mail.
  7. Technical data collected while using the website may include IP address, domain name, browser type, access time, and OS type.
  8. If subscribed to the Newsletter, commercial e-mails about promotions and new products will be sent.
  9. Navigational data (e.g., clicked links, actions taken) may be collected under the Controller’s legitimate interests (Art. 6(1)(f) GDPR) to facilitate electronic services and improve functionality.
  10. For establishing, pursuing or defending claims, certain personal data (e.g., name, usage data, evidence of damage) may be processed under legitimate interests (Art. 6(1)(f) GDPR).
  11. Providing data is voluntary; however, failure to provide required form fields prevents registration or order submission/fulfilment.

§ 2. Data recipients and retention period

  1. Data may be shared with service providers used to operate the Online Store:
    1. Processors (acting on instructions): hosting, accounting, marketing, traffic analytics, campaign analytics;
    2. Controllers (acting on their own purposes): electronic payment and banking service providers.
  2. Location: providers are based in Poland and other EEA countries.
  3. Retention:
    1. where based on consent — until withdrawn, then for the claims limitation period (generally 6 years; 3 years for periodic or business-related claims);
    2. where based on contract — for the time necessary to perform the contract, then for the limitation period as above.
  4. Upon purchase, data may be transferred to a courier to deliver the goods.
  5. If the Customer selects T-pay, data will be transferred as needed to process the payment.
  6. If the Customer selects mBank Raty, data will be transferred to mBank S.A., Warsaw (KRS 0000025237) as needed to process the payment.
  7. If the Customer selects Raty Alior Bank, data will be transferred to Alior Bank S.A., Warsaw (KRS 0000305178) as needed to process the payment.
  8. Navigational data may be used to improve service, compile statistics, tailor the store to preferences, and administer the Online Store.
  9. If subscribed to the Newsletter, commercial e-mails about promotions and new products will be sent.
  10. Upon lawful request, data may be disclosed to authorized public authorities (e.g., Prosecutor’s Office, Police, PDPO, UOKiK, UKE).

§ 3. Cookies mechanism and IP address

  1. The Online Store uses small files called cookies. A cookie typically contains its source domain, expiry time, and a unique identifier. They help tailor products to user preferences and compile visit statistics.
  2. Types used:
    1. Session cookies — deleted after the browser session ends or the device is turned off; do not retrieve personal/confidential data.
    2. Persistent cookies — stored until deleted or expired; do not retrieve personal/confidential data.
  3. Own cookies are used for:
    1. authenticating the Customer and maintaining session (after login);
    2. analytics and audience measurement (anonymous statistics to improve structure/content).
  4. Third-party cookies are used for:
    1. Google Analytics (administrator: Google LLC, USA);
    2. Google Ads (administrator: Google Ireland Limited, Ireland).
  5. Cookies are safe; Customers can limit/disable them in their browsers, though some features may then not function.
  6. Changing cookie settings in popular browsers: Internet Explorer, Microsoft Edge, Mozilla Firefox, Chrome/Chrome Mobile, Safari/Safari Mobile, Opera.
  7. The Controller may collect IP addresses for diagnostics, statistics, administration, improvements, and security (including identifying harmful automated programs).
  8. The Online Store contains links to third-party websites; their privacy practices are outside the Controller’s responsibility.

§ 4. Rights of data subjects

  1. Right to withdraw consent (Art. 7(3) GDPR): effective upon withdrawal; does not affect prior lawful processing; some services may then be unavailable.
  2. Right to object (Art. 21 GDPR): at any time, for reasons related to the person’s situation, to processing based on legitimate interests (incl. marketing, statistics, facilitation, satisfaction surveys). Unsubscribing from marketing equals objection for that purpose.
  3. Right to erasure (Art. 17 GDPR): in particular, when data are no longer needed, consent is withdrawn, marketing objection is made, processing is unlawful, erasure is required by law, or data were collected in relation to information society services. Despite erasure request, data necessary for claims handling or legal obligations may be retained (e.g., name, email, address, order number).
  4. Right to restriction (Art. 18 GDPR): e.g., while accuracy is verified (up to 7 days), when processing is unlawful but erasure is not requested, when data are no longer needed but required for claims, or pending an objection assessment.
  5. Right of access (Art. 15 GDPR): confirmation, access, information on processing, and a copy of data.
  6. Right to rectification (Art. 16 GDPR): prompt correction/completion (requests via the e-mail in § 6).
  7. Right to data portability (Art. 20 GDPR): receive data and transmit to another controller; where feasible, direct transmission in a .csv file.
  8. Response time: without undue delay, within 1 month (extendable by 2 months for complex/multiple requests; notice within 1 month).
  9. Customers may submit complaints, queries, and requests to the Controller concerning processing and the exercise of rights.
  10. Customers may request a copy of the standard contractual clauses (contact as per § 6).
  11. Right to lodge a complaint with the President of the Personal Data Protection Office.

§ 5. Security management — password

  1. The Controller provides secure, encrypted (SSL) connections for transmitting personal data and logging into the Customer Account.
  2. If a Customer loses their password, they can generate a new one via the Forgot your password? link. Passwords are stored encrypted; reminders are not sent.
  3. The Controller never requests login credentials (especially passwords) by e-mail or other correspondence.

§ 6. Changes to this Policy

  1. This Policy may be amended; Customers will be notified 7 days in advance.
  2. Contact: purchase@grn.com.pl
  3. Last modified: 13 September 2025.

Controller details

TG Ersatzteile Polska Sp. z o.o. ul. Smoluchowskiego 1 20-474 Lublin Poland NIP (VAT ID): 946-23-62-587 REGON: 432524119 E-mail: purchase@grn.com.pl

If any part of this English version differs from the Polish original, the Polish version may prevail where required by law.