Last updated: 14 September 2026
GPSPATRON respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, disclose and protect personal data when you visit our website, contact us, request information or a demonstration, communicate with us in a business context, or otherwise interact with GPSPATRON.
It also explains your rights under applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1. Who We Are
The controller of personal data covered by this Privacy Policy is:
GPSPATRON Sp. z o.o.
Prosta 20
00-850 Warsaw
Poland
KRS: 0000991661
NIP: 5273018817
REGON: 523087170
In this Privacy Policy, “GPSPATRON”, “we”, “us” and “our” refer to GPSPATRON Sp. z o.o.
For privacy-related questions or requests, you may contact us through the Contact page on our website or by writing to our registered address above.
2. Scope of This Privacy Policy
This Privacy Policy applies primarily to:
- the GPSPATRON website;
- website forms and demo or quotation requests;
- sales and business correspondence;
- newsletters and marketing communications;
- website analytics, security and similar technologies;
- contacts with customers, prospective customers, distributors, partners and suppliers.
GP-Cloud and other GPSPATRON products may process technical, measurement, configuration or other data supplied by our customers.
Where GPSPATRON processes such data on behalf of a customer, GPSPATRON may act as a data processor rather than a data controller. Such processing is governed by the applicable service agreement, Data Processing Agreement, subscription agreement or other contractual documentation and is not governed solely by this Website Privacy Policy.
3. Personal Data We May Collect
Depending on how you interact with us, we may process:
Contact and identification data, such as your name, business email address, telephone number, job title and company.
Business information, such as your employer, industry, country, business requirements, correspondence, requested products or services and information relating to a business relationship.
Transaction and contractual information, including orders, invoices, payment-related records, delivery information and contractual correspondence.
Website and technical data, such as IP address, device and browser information, operating system, approximate location derived from IP address, referring website, pages visited, timestamps, identifiers and website interaction information.
Marketing information, including your communication preferences and information about your interaction with our communications or website.
Information you voluntarily provide to us, including information submitted through forms, email, meetings, demonstrations, support requests or other communications.
We do not intentionally request special categories of personal data such as medical information, biometric data, religious beliefs or political opinions through our Website.
Please do not provide such information unless it is specifically required and legally appropriate.
4. Where We Obtain Personal Data
We may obtain personal data:
- directly from you;
- from the organisation you represent;
- automatically when you use our Website;
- from customers, partners, distributors or other business contacts;
- from publicly available professional and business sources;
- from company websites, professional platforms, conferences and industry events;
- from reputable business-information or B2B service providers.
Where we obtain personal data from a source other than directly from you, we comply with the transparency requirements of Article 14 GDPR where applicable.
5. Why We Process Personal Data
We process personal data only where we have an appropriate legal basis.
Responding to enquiries and providing quotations or demonstrations
We process information submitted to us to respond to enquiries, arrange demonstrations, discuss technical requirements, prepare quotations and take steps towards entering into a contract.
The legal basis is Article 6(1)(b) GDPR where the processing relates directly to an individual entering into a contract, and Article 6(1)(f) GDPR where we communicate with representatives of companies or other organisations.
Our legitimate interest is conducting our business and responding to requests concerning our products and services.
Performing contracts and managing customer relationships
We process personal data where necessary to deliver products and services, manage subscriptions, communicate with customers, provide support, process orders and administer our contractual relationships.
The legal basis is Article 6(1)(b), Article 6(1)(c) and/or Article 6(1)(f) GDPR, depending on the circumstances.
Accounting and legal obligations
We may process and retain personal data where necessary to comply with accounting, tax, corporate, export-control, compliance or other legal obligations applicable to GPSPATRON.
The legal basis is Article 6(1)(c) GDPR.
Security and prevention of misuse
We process technical information where necessary to secure our Website, systems and services, prevent fraud, abuse and cyberattacks, diagnose technical problems and protect our legal rights.
The legal basis is Article 6(1)(f) GDPR.
Our legitimate interest is maintaining the security and integrity of our systems and business.
Business development and marketing
We may process business contact information for customer relationship management, business development and marketing purposes where permitted by applicable law.
The legal basis under the GDPR may be our legitimate interest under Article 6(1)(f) GDPR or your consent under Article 6(1)(a) GDPR, depending on the circumstances.
Where prior consent is required for sending commercial information or direct marketing using electronic communications, we will process such communications in accordance with applicable law, including Article 398 of the Polish Electronic Communications Law (Prawo komunikacji elektronicznej).
You may object to the use of your personal data for direct marketing at any time.
Analytics and non-essential tracking
Where we use non-essential analytics, advertising, visitor-identification or similar technologies, they are activated only where permitted by applicable law and, where required, after obtaining your consent.
The legal basis for related personal-data processing is normally Article 6(1)(a) GDPR.
6. Cookies and Similar Technologies
Our Website may use cookies, pixels, local storage and similar technologies.
Necessary technologies
Some technologies are required for the proper operation, security or functionality of the Website or to provide a service specifically requested by you.
Where the conditions of Article 399(3) of the Polish Electronic Communications Law are satisfied, these technologies may be used without separate consent.
Analytics, advertising and other non-essential technologies
Non-essential technologies, including analytics, advertising, remarketing and certain visitor-identification technologies, are used only in accordance with your cookie choices and applicable law.
Depending on the Website configuration, these services may include technologies provided by companies such as:
- Google Analytics;
- Google Ads;
- YouTube;
- Google Maps;
- Google reCAPTCHA;
- Albacross.
The exact technologies and providers active on the Website may change from time to time.
Where consent is required, such technologies should not be activated before you provide consent.
You can withdraw or modify your consent at any time through the Website’s cookie settings. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Browser settings may also allow you to delete or block cookies, although doing so may affect certain Website functions.
7. Business Visitor Identification
We may use business-intelligence services such as Albacross to better understand which organisations visit our Website and which GPSPATRON products may be relevant to them.
Such technologies may process information including IP addresses, technical identifiers, visit information and information allowing traffic to be associated with a business or organisation.
Where such processing requires access to information stored on your device, the relevant technology is activated only subject to the consent requirements applicable under Polish law.
Albacross is provided by Albacross Nordic AB, Sweden. Additional information concerning its processing practices is available in Albacross’s own privacy documentation.
We use this information for B2B analytics and business-development purposes and not to make decisions producing legal or similarly significant effects concerning individual Website visitors.
8. Recipients of Personal Data
We may disclose personal data where reasonably necessary to:
- hosting, cloud, cybersecurity and IT service providers;
- CRM, communication and customer-support providers;
- analytics and website technology providers;
- marketing and business-intelligence providers, subject to applicable consent requirements;
- accounting, legal, insurance and professional advisers;
- payment, logistics or delivery providers where relevant to a transaction;
- distributors or business partners where necessary to respond to your request or provide requested services;
- public authorities, courts or law-enforcement bodies where disclosure is required by law;
- a purchaser, investor or successor in connection with a genuine corporate transaction, merger, restructuring or sale of all or part of our business.
Service providers acting on our behalf are permitted to process personal data only for authorised purposes and are subject to appropriate contractual and confidentiality obligations where required by law.
We do not sell personal data to third parties.
9. International Transfers
Some of our service providers or their infrastructure may be located outside the European Economic Area (“EEA”).
Where personal data is transferred outside the EEA, we use a legally recognised transfer mechanism where required.
Depending on the destination and provider, this may include:
- an adequacy decision adopted by the European Commission;
- the EU-US Data Privacy Framework for participating US organisations;
- Standard Contractual Clauses approved by the European Commission;
- another mechanism permitted under Chapter V of the GDPR.
Where appropriate, we also assess whether supplementary technical, contractual or organisational safeguards are necessary.
Merely using our Website does not constitute consent to an international transfer of personal data.
10. How Long We Keep Personal Data
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected and for any additional period required to comply with legal obligations or protect our legal rights.
Retention periods depend on the type of information and may take into account:
- the duration of our contractual or business relationship;
- applicable accounting and tax-retention requirements;
- applicable limitation periods for legal claims;
- security and fraud-prevention requirements;
- whether consent has been withdrawn or an objection has been made.
Where you object to direct marketing or withdraw marketing consent, we may retain a minimal suppression record so that we can respect your request and avoid contacting you again for that purpose.
Data that is no longer required is deleted, anonymised or securely archived in accordance with applicable requirements.
11. Your Rights
Subject to the conditions and limitations provided by the GDPR, you may have the right to:
- obtain confirmation as to whether we process your personal data and obtain access to it;
- request correction of inaccurate or incomplete data;
- request deletion of your personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- object at any time to processing for direct marketing;
- receive certain personal data in a portable format;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a competent supervisory authority.
Withdrawal of consent does not affect processing lawfully carried out before the withdrawal.
We may ask for reasonable information necessary to verify your identity before acting on a request, particularly where disclosure of information could affect the privacy or security of another person.
Rights under the GDPR are not absolute. In certain cases we may lawfully retain information or refuse part of a request, for example where retention is necessary to comply with a legal obligation or establish, exercise or defend legal claims.
12. Complaints
If you believe that we have processed your personal data unlawfully, we encourage you to contact us first so that we can investigate the matter.
You also have the right to lodge a complaint with the competent data protection supervisory authority.
For GPSPATRON in Poland, the relevant authority is:
President of the Personal Data Protection Office
(Prezes Urzędu Ochrony Danych Osobowych – UODO)
Warsaw, Poland.
You may also have the right to complain to the data protection authority in the EU or EEA country where you live or work or where an alleged infringement occurred.
13. Automated Decision-Making and Profiling
We do not use Website visitor data to make solely automated decisions that produce legal effects or similarly significantly affect individuals within the meaning of Article 22 GDPR.
Analytics or marketing tools may be used to create statistical or business-interest segments, but these are not used by GPSPATRON to make legally significant automated decisions concerning Website visitors.
14. Security
We use reasonable technical and organisational safeguards appropriate to the nature of the information and the risks associated with its processing.
These may include access controls, authentication, encryption where appropriate, system monitoring, backup procedures, employee access restrictions and contractual safeguards with service providers.
However, no electronic transmission or storage system can be guaranteed to be completely secure.
Accordingly, while we take reasonable measures to protect personal data, we cannot guarantee absolute security.
15. Children
GPSPATRON provides professional and business-to-business products and services. Our Website is not directed at children.
We do not knowingly collect personal data from children through the Website for marketing or commercial purposes.
If you believe that a child has provided personal data to us inappropriately, please contact us so that we can investigate and, where appropriate, delete the information.
16. Third-Party Websites and Embedded Content
Our Website may contain links to external websites or embedded content provided by third parties.
Those third parties may process information independently under their own privacy policies.
GPSPATRON does not control and is not responsible for the privacy practices, security or content of independent third-party websites.
We recommend reviewing the privacy information provided by the relevant third party.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, technologies, service providers or applicable law.
The current version will be published on this page together with its “Last updated” date.
Where a change requires a new consent under applicable law, we will request such consent before carrying out the relevant processing.
18. Contact
For questions concerning privacy, personal data or the exercise of your rights, please contact:
GPSPATRON Sp. z o.o.
Prosta 20
00-850 Warsaw
Poland
or use the Contact page available on the GPSPATRON website.