General provisions

The administrator of personal data collected via the website www.eone.ai and email correspondence is Pana Wina, based at 61 Głuchów Dolny, 55-106 Poland, NIP: 9998887766, KRS: 0001234567, e-mail address: info@panawina.com (hereinafter referred to as the ‘Administrator’). The Administrator processes personal data in accordance with the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016) and other applicable regulations on the protection of personal data. The Administrator also processes personal data for purposes resulting from tax and accounting regulations, in accordance with applicable law.

Purpose and scope of data collection

The administrator processes personal data for the following purposes:

  • Provision of services by electronic means,
  • Establishing contact with customers and potential customers (including via e-mail correspondence),
  • Direct marketing, only with the user’s consent,
  • Technical security of the website,
  • Analysis of website traffic in order to improve its functioning,
  • Responding to enquiries sent via contact forms and requests for quotations.


The scope of data processed includes:

  • Name and surname,
  • E-mail address,
  • Telephone number,
  • Information related to the use of the website (e.g. IP address, cookie data),
  • Content of messages sent via contact forms,
  • Data provided for the purpose of preparing a commercial offer.

Usage data: The administrator may process operational data, such as identifiers of the user’s device, time of use of electronic services, and details of activity on the website. This data is used to ensure the security of services and to monitor their proper functioning. Providing personal data is voluntary, but necessary for the provision of services, contact, or presentation of offers.

The basis for data processing

The processing of personal data is based on the following legal grounds:

  • Consent of the data subject (Article 6(1)(a) of the GDPR),
  • Performance of a contract (Article 6(1)(b) of the GDPR),
  • Compliance with legal obligations incumbent on the Controller (Article 6(1)(c) of the GDPR), such as the obligation to provide information to state authorities,
  • Legitimate interests pursued by the Controller (Article 6(1)(f) of the GDPR), e.g. in the case of defence against claims.

Users’ rights regarding personal data

Every user has the right to:

  • Access to your data,
  • Rectification of data,
  • Deletion of data (right to be forgotten),
  • Restriction of data processing,
  • Transfer of data to another controller,
  • Objection to the processing of personal data.
    To exercise these rights, please contact the Controller at the following e-mail address: info@eone.ai.

Cookies

The website uses cookies to ensure the proper functioning of the service and to personalise content. Users can change their browser settings at any time to block cookies or delete already installed files.

During their first visit to the website, users have the option to manage their consent to cookies using a special mechanism (e.g. a cookie banner). Users may also withdraw their consent at any time by changing their browser settings or using a dedicated tool available on the website.

Cookies used on the website may include:

  • Session files, which are deleted after you leave the website.
  • Persistent files, which remain on your device for a specified period of time or until you manually delete them.

Cookies from external websites

The website uses external providers such as Google Analytics, Facebook, LinkedIn, Instagram and Google Maps, which may place their cookies on users’ devices. The administrator has no control over the operation of these services. Users can manage the settings of external providers’ cookies through their browser settings.

Disabling or restricting cookies in your browser settings may affect the functionality of some services available on the website.

Email correspondence

Personal data processed in the course of e-mail correspondence (current and potential customers) is collected and processed for the purpose of responding to enquiries and providing any services, in accordance with the principles of personal data protection. Correspondence is stored for the period necessary to achieve the purposes for which the data was collected, and then deleted or archived in accordance with internal procedures.

Contact forms, website traffic analysis, and requests for quotations

The administrator processes personal data provided by the user in contact forms available on the website solely for the purpose of responding to enquiries and presenting offers, and does not disclose this data to third parties. This data is protected by transmission encryption (SSL/TLS).

Final provisions

The administrator uses technical and organisational measures, such as data transmission encryption (SSL/TLS), firewall systems and regular IT security audits, to protect personal data from unauthorised access, alteration or deletion. The privacy policy may be updated periodically, and any changes will be published on the website.

Date of last modification: 09 July 2026.

GDPR information clause

The following information is a concise, understandable and transparent summary of the information contained in the Privacy Policy regarding the Data Controller, the purpose and manner of personal data processing, and your rights in relation to such processing, in the form required to comply with the GDPR information obligation. Details on the manner of processing and the entities involved in this process are available in the indicated policy.

Who is the data administrator?

The administrator of personal data (hereinafter referred to as the ‘Administrator’) is EOne.AI Prosta Spółka Akcyjna, operating at the following address: Nike 1, 80-299 Gdańsk, with tax identification number (NIP): 5842847283 and KRS number: 0001084591, providing services electronically via the Website.

How can you contact the data administrator?

You may contact the Administrator in one of the following ways:

Has the Administrator appointed a Personal Data Inspector?

The Controller has not appointed a Data Protection Officer pursuant to Article 37 of the GDPR. In matters relating to data processing, including personal data, please contact the Controller directly.

Where do we obtain personal data and what are its sources?

Data is obtained from the following sources:

  • Directly from the data subjects
  • In the case of registration or login via social media platforms – with the informed and explicit consent of those individuals.

What is the scope of personal data we process?

The detailed scope of data processing is described in the Privacy Policy.

We process personal data provided voluntarily by users, in particular:

  • First and last name,
  • Login,
  • E-mail address,
  • Telephone number,
  • IP address.

What are the purposes of data processing by us?

We process personal data for the following purposes:

  • Realization of electronic services,
  • Communication with users on matters relating to the Service,
  • Direct marketing, with your consent,
  • To ensure the legitimate interest of the Administrator, including defense against claims.

What are the legal grounds for data processing?

The legal bases for data processing are:

  • Consent of the data subject (Article 6(1)(a) of the RODO),
  • Fulfillment of the contract (Article 6(1)(b) of the RODO),
  • Legitimate legitimate interests of the Administrator (Article 6(1)(f) RODO),
  • Fulfillment of legal obligations (Article 6(1)(c) RODO).

What is the legitimate interest pursued by the Administrator?

The Administrator’s legitimate interests include:

  • Defense against claims,
  • Implementation of direct marketing activities,
  • Risk assessment of potential customers,
  • Analysis of planned marketing campaigns.

How long do we process personal data?

Personal data are processed for a period of time:

  • Service provision,
  • Up to 30 days after termination of service (e.g., account deletion),
  • Up to 3 years for actions related to defense against claims or suspected violations of the terms of use.

Who is the recipient of the data, including personal data?

Recipients of the data may be:

  • Administrator,
  • Entities performing services for the Administrator, including providers of IT tools and analytical services.

Will your personal data be transferred outside the European Union?

Personal data will not be transferred outside the European Union, unless published by the user (e.g. in a comment on the site).

Will personal data be the basis for automated decision making?

Personal data is not used for automated decision-making, including profiling.

What are your rights related to the processing of personal data?

The user has the right to:

  • Access to your personal information,
  • Correction of personal data,
  • Deletion of data (right to be forgotten),
  • Restrictions on data processing,
  • Transfers of personal data,
  • Object to the processing of personal data,
  • File a complaint with the President of the Office of Personal Data Protection (PUODO).