We respect and value the privacy of every person (the "User") who uses our website (the "Site"), and we collect and use personal data only in the way described here, in line with our obligations and the User's rights under the law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the "GDPR").

The controller of the Site is Oxycon (the "Controller"). The Controller can be reached at [email protected].

1. What personal data do we collect?

We may collect some personal data of the Users of our Site, in particular:

  • Personal data the User provides when contacting us, including: e-mail address and the data contained in the message.
  • Data the User provides in order to receive requested content by e-mail: e-mail address, name.
  • Technical data recorded automatically when the Site is used, such as the data written to server logs, needed to keep the Site running and secure.
  • Data we collect automatically for statistical purposes. Statistical data does not allow a natural person to be identified directly.

2. How do we use the personal data we collect?

Under the GDPR, using personal data must always have a legal basis. We use the personal data of Users only to the extent necessary to achieve the purpose of the processing. The personal data of Users may be used for the following purposes:

  • To provide services in line with the terms of use (Article 6(1)(b) GDPR);
  • In the legitimate interest of the Controller (Article 6(1)(f) GDPR), which is:
    • Receiving and handling the messages Users send to us;
    • Delivering the content requested by the User;
    • Keeping the Site and its Users secure and the Site stable;
    • Managing the Site and improving it so that it is comfortable for the User to browse;
    • Establishing, pursuing and defending claims, and protection against possible claims.
  • To meet the legal and regulatory obligations that apply to the Controller (Article 6(1)(c) GDPR).

3. What rights do the Users of the Site have?

The User has the right to request access to their personal data and to obtain information about it, to update, rectify or erase their personal data, to restrict the processing or to object (on justified grounds) to the processing of their personal data, and the right to data portability, to the extent limited by law, including Articles 12 to 22 GDPR.

Everyone has the right to lodge a complaint with the competent supervisory authority, which in Poland is the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw), if they consider that personal data is being processed unlawfully.

To exercise these rights, please contact us by e-mail: [email protected]

4. How long do we keep personal data?

Personal data is kept in a form that allows identification for no longer than is necessary for the purposes for which the personal data was collected.

In particular:

  • Data provided when contacting us is kept for as long as is needed to answer, and then until the limitation period for claims has passed.
  • Data provided in order to receive the content requested by the User is kept for as long as that service is provided, or until the User opts out of it.
  • Personal data processed in order to establish, pursue and defend claims is kept until the limitation period for the individual claims has passed.
  • Data collected automatically for statistical purposes while the Site is being used is kept for the validity period of the individual cookies or log entries.

5. How do we protect personal data?

We have put in place appropriate and reasonable technical and organisational security measures to store the personal data we collect and keep it confidential, and to protect it against unauthorised or unlawful disclosure or access, and against accidental loss, destruction, alteration or damage, taking into account the state of technology and the cost of implementation.

6. Who do we share personal data with?

Personal data is available only to a limited list of recipients, on a restricted access basis or where the law requires it, including but not limited to:

  • Suppliers and service providers acting as the Controller's subcontractors, in particular the entities responsible for hosting and running the Site, which may have access to the personal data of Users to the extent necessary.

7. Transfers of data to third countries

Some recipients of the data may be established outside the European Economic Area, in a country that does not ensure an adequate level of protection (a "third country"). In every such case the transfer takes place only with the appropriate safeguards for that processing in place, including, among others, the Standard Contractual Clauses approved by the European Commission or other measures in line with Chapter V of the GDPR.

8. Automated decision-making

Your personal data will not be used to make a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you.

9. Cookies

The Site uses cookies. Cookies are small text files that are saved and stored by the web browser on the device.

The Site uses only the necessary cookies required for it to work correctly. Statistics about how the Site is used are collected with a privacy-friendly analytics tool that does not use cookies for tracking and does not allow a natural person to be identified directly.

Last updated: 21 August 2026