PRIVACY POLICY

Last updated: 15 May 2026

At STERNET, we attach great importance to privacy protection and the security of personal data. This Privacy Policy explains how we process personal data, in particular how we collect, store, use, disclose and transfer it, and what rights are available to data subjects. The scope of personal data processed depends on the nature of the use of our services, products or functions and on applicable law. Providing personal data is voluntary; however, where data is necessary to conclude or perform a contract, provide services, fulfil an order or use specific functionalities, failure to provide it may prevent the use of services or the performance of specific activities.

I. Processing of personal data in connection with the use of our online services, applications and websites

When using our external and internal websites, applications or online services, collectively referred to as “Online Services”, we may process the following categories of personal data:

  1. contact details, such as first and last name, address, telephone number, mobile phone number and e-mail address;
  2. organisational data, including job title and the name of the company or organisation, department, branch, installation or production line;
  3. information provided as part of a technical support request, survey, comment or forum post;
  4. other personal data provided by the user by completing forms available within our Online Services;
  5. information concerning the user’s interaction with the Online Service, including device and user identifier, operating system information, pages and services visited while using the Online Service, and the date and time of each request made by the user;
  6. personal data available on the basis of permissions granted to our mobile applications, such as device location data, microphone audio, stored files or media, Bluetooth connectivity, access to a local network and notification settings — to the extent that the user decides to use functions requiring such access. The user may grant or withdraw such permissions at any time in the device settings.

We process the user’s personal data for the following purposes:

  1. providing services and functions available within the Online Services, including creating and administering the user’s online account, updating, securing and troubleshooting, providing support, and improving and developing our Online Services;
  2. billing for the use of Online Services;
  3. verifying the user’s identity;
  4. responding to and carrying out the user’s requests, inquiries or instructions;
  5. handling the user’s orders or providing access to specific information or offers;
  6. contacting the user to provide information and offers concerning our products and services, sending further marketing information or contacting the user as part of customer satisfaction surveys;
  7. enforcing the terms of use of the Online Services, establishing, pursuing or defending claims, preventing fraud or other unlawful activities, including attacks on our IT systems — to the extent reasonably necessary.

Online Services provided by the user’s organisation

Our Online Services may be made available to the user by the organisation to which the user belongs, for example by our business customer. If the user’s organisation provides access to an Online Service, the processing of personal data provided by the user or their organisation, or collected from the user or their organisation in connection with content made available within that Online Service, takes place in accordance with the instructions of that organisation and on the basis of a data processing agreement concluded between that organisation and us.

In such a case, the user’s organisation is responsible for the personal data contained in that content, and any questions concerning the use of personal data contained in such content should be addressed to that organisation.

II. Processing of personal data in connection with the use of our “E-commerce” trading platforms

This applies, among others, to the online store, the MatchDrive AI product selection and quoting application, and other B2B sales tools.

When using our “E-commerce” platforms, we may process the following categories of personal data:

  1. contact details, such as first and last name, address, telephone number, mobile phone number and e-mail address;
  2. organisational data, including job title and the name of the company or organisation, department, branch, installation or production line;
  3. payment data, such as data necessary to process payments and prevent fraud, including bank account numbers, credit or debit card numbers, security codes and other related billing information;
  4. information provided as part of a technical support request, survey, comments or forum posts;
  5. other personal data provided by the user by completing forms available on E-commerce platforms;
  6. information required by law for compliance checks or export control, such as date of birth, citizenship, place of residence, identification numbers, identity document data and information concerning significant legal disputes or other legal proceedings;
  7. information concerning the user’s E-commerce interaction, including device and user identifier, operating system information, pages and services visited during the visit, and the date and time of each request made by the user.

We process the user’s personal data for the following purposes:

  1. communicating with the user about our products, services and projects, for example by responding to inquiries or requests or providing information concerning purchased products;
  2. planning, implementing and managing the relationship, including the contractual relationship, with customers, for example by processing transactions and orders, processing payments, keeping accounts, audits, settlements and debt collection, arranging shipments and deliveries, handling repairs and providing support services;
  3. contacting the user to provide information and offers concerning our products and services, sending further marketing communications and conducting customer satisfaction surveys;
  4. maintaining and protecting the security of our products, services and websites, and preventing and detecting security threats, fraud or other criminal or malicious activities;
  5. ensuring compliance with legal obligations, such as record-keeping obligations, export and customs control, customer compliance verification obligations, in particular to prevent economic crime or money laundering, as well as compliance with our policies, including the General Terms and Conditions of Sale (https://sternet.pl/ogolne-warunki-sprzedazy/);
  6. resolving disputes, enforcing contractual provisions and establishing, pursuing or defending legal claims.

III. Processing of personal data in connection with the use of technical support and advisory tools and AI-based quoting — “AI Services”

When using our conversational or generative artificial intelligence services available on this website or as part of our applications or digital services, referred to as “AI Services”, we may process the following categories of personal data:

  1. information contained in input data actively provided by the user when using AI Services, such as prompts, questions, uploaded content, preferences, inquiries, documents made available for analysis, user device data, contextual information, response feedback and other information provided in connection with the use of AI Services;
  2. information contained in output data generated by AI Services in response to input data provided by the user;
  3. information concerning the user’s interaction with AI Services, including device and user identifier, session data, technical logs and usage patterns.

We process the user’s personal data for the following purposes:

  1. providing AI Services to the user;
  2. monitoring the quality of AI Services and ensuring that generated responses are appropriate, respect the rights and dignity of users and do not contain unlawful content, offensive language or prohibited materials;
  3. improving the quality of services, applications and functionalities, including by analysing the use of AI Services, identifying errors, improving response accuracy and developing system functionalities;
  4. establishing, pursuing or defending claims, preventing fraud or other unlawful activities, including attacks on our systems or networks, and ensuring compliance with applicable law — to the extent reasonably necessary.

Personal data processed as part of AI Services is not used to train public artificial intelligence models or to build models intended for commercial provision to third parties. Data may, however, be used to maintain, monitor, develop and improve the quality of our services, applications and AI-based solutions.

In connection with the use of AI Services, data may be transferred to AI technology or infrastructure providers cooperating with Sternet, only to the extent necessary to provide AI Services, in accordance with concluded agreements and applicable personal data protection law.

The retention period for prompts, responses generated by AI Services, technical logs and data related to the use of AI Services depends on the nature of the service, the purpose of processing, security requirements and retention rules applied by AI technology providers cooperating with Sternet. Data is stored only for the period necessary to achieve the indicated purposes or for the period required by law.

To the extent that data is used to ensure the quality, security and development of AI Services, the user may limit the scope of data provided by not entering confidential information, special categories of personal data or other data whose processing is not necessary to use a given functionality.

The use of AI Services does not involve automated decision-making producing legal effects for the user or similarly significantly affecting the user within the meaning of Article 22 GDPR.

In connection with a business relationship with us, we may process the following categories of personal data of contact persons, both current and potential customers, suppliers, vendors and partners, referred to as “Business Partners”:

  1. contact details, such as first and last name, address, telephone number, business mobile phone number and e-mail address;
  2. organisational data, including job title and the name of the company or organisation, department, branch, installation or production line;
  3. payment data, such as data necessary to process payments and prevent fraud, including bank account numbers, credit or debit card numbers, security codes and other related billing information;
  4. other information processed as necessary within a project or contractual relationship with us or voluntarily provided by the Business Partner, such as personal data concerning placed orders, payments made, requests, inquiries and project implementation stages;
  5. personal data obtained from publicly available sources, including business and professional social networking services and websites, credibility and reliability databases and credit information bureaus;
  6. information required by law for Business Partner compliance checks or export control, such as date of birth, citizenship, place of residence, identification numbers, identity document data and information concerning significant legal disputes or other legal proceedings involving Business Partners.

We may process personal data for the following purposes:

  1. communicating with Business Partners about our products, services and projects;
  2. planning, implementing and managing the relationship, including the contractual relationship, with Business Partners;
  3. creating a personal profile containing business-related information concerning interactions between the user and us in order to offer tailored information and offers and improve individual communication; profile creation is not automated;
  4. administering and conducting market analyses, promotional lotteries, contests or other activities or events addressed to customers;
  5. contacting the user to provide information and offers concerning our products and services, sending marketing communications and conducting customer satisfaction surveys;
  6. maintaining and protecting the security of our locations, facilities, products, services and websites, and preventing and detecting security threats, fraud or other criminal or malicious activities;
  7. ensuring compliance with legal obligations, including record-keeping, export and customs control, Business Partner compliance verification, prevention of economic crime or money laundering, and compliance with policies or industry standards;
  8. resolving disputes, enforcing contractual provisions and establishing, pursuing or defending legal claims.

In the case of registration for our on-site events or participation in them, referred to as “Events”, we process:

  1. personal data and organisation data described in Section IV concerning business relationships;
  2. additional information provided during registration, such as dietary preferences or accommodation preferences.

To the extent that dietary preferences or accommodation preferences reveal special categories of personal data, for example dietary requirements indicating religious beliefs or health information, we will process such data only where permitted or required by applicable law.

We may process personal data for the following purposes:

  1. organising and managing the Event, including registration, access control and logistical support for the user;
  2. providing access to the Event and opportunities for business networking.

If the user participates in a virtual meeting during which recording, transcription or AI-based support functions are activated to the extent permitted by law, we may process the following categories of personal data:

  1. audio, video and text content of the user’s statements and activities during the meeting, including voice, image, shared content and chat messages;
  2. information concerning the user’s participation in the meeting, such as first and last name, e-mail address, meeting join and leave times, interaction details and technical connection data, including IP address.

We process the user’s personal data in this context for the following purposes:

  1. providing participants with requested or made available recording, transcription or AI support functions;
  2. creating meeting recordings, transcripts and summaries generated using artificial intelligence;
  3. establishing, pursuing or defending claims, preventing fraud and ensuring compliance with applicable law — to the extent necessary.

VII. Cookies

All relevant information concerning the processing of personal data in connection with the use of cookies is available in our Cookie Notice at www.sternet.pl/cookies/.

VIII. Processing of personal data for customer satisfaction surveys and direct marketing

To the extent and in cases permitted by applicable law, we may process the user’s contact details for direct marketing purposes, for example to send invitations to trade fairs, newsletters containing information and offers concerning our products and services, and to conduct customer satisfaction surveys — in each case also by electronic mail.

Marketing communication by electronic or telephone channels is carried out only after meeting the requirements of applicable regulations, in particular after obtaining the required consent for the communication channel.

The user may at any time object to the processing of their contact details for these purposes by writing to [email protected] or by using the unsubscribe or objection mechanism made available in the received communication.

When applying for a job, we process the user’s personal data in accordance with the rules set out in the privacy notice available on the Sternet portal at www.sternet.pl/rodo_applications/ or in the relevant privacy notice of another recruitment platform that we use and that the user uses.

X. Transfer and disclosure of personal data

We transfer personal data only when it is necessary and lawful, in particular in the cases described below.

Sales partners and suppliers

In order to conduct, maintain and develop a business relationship with a customer or user, we may share personal data with sales partners, agents and suppliers where necessary to identify devices, handle an order, provide a service or contact the customer.

E-commerce transactions

If, as part of our e-commerce services, we make available products, services or offers of third parties, we may transfer personal data of customers or users to those entities to the extent necessary to handle a given transaction, order or service.

Service providers

We use entities that perform certain activities on our behalf or for our benefit, including subcontracting, audit, marketing, IT, payment processing, debt collection and other services supporting our business. These entities process personal data only to the extent necessary and in accordance with our instructions.

Other third parties

We may transfer personal data to other entities where necessary to fulfil legal obligations, establish, pursue or defend claims, or protect our rights. This applies in particular to courts, public administration authorities, law enforcement authorities, regulators, arbitrators, advocates, legal advisers, consultants and experts.

Recipients of personal data may be located outside the user’s country of residence. In the case of transfers of data outside the European Economic Area, we apply safeguards required by law.

Personal data published by the user as part of publicly available services or services for registered users, such as chats or forums, may be available to other users of a given service, including globally.

XI. Data retention periods

Unless otherwise indicated at the time of collecting the user’s personal data, we delete personal data when its further storage is no longer necessary for the purposes for which it was collected or otherwise processed, or for the purposes of fulfilling legal obligations.

In particular, personal data may be stored:

  1. for the duration of the contractual or business relationship — to the extent necessary for its performance and handling;
  2. for the period required by law, in particular tax, accounting, commercial or documentation obligation regulations;
  3. until consent is withdrawn — where processing is based on consent, unless there is another legal basis for further processing;
  4. until an effective objection is lodged — where data is processed on the basis of a legitimate interest, including for direct marketing purposes;
  5. for the period necessary to establish, pursue or defend claims — no longer than until the expiry of the relevant limitation periods;
  6. for the period necessary to ensure the security of services and IT systems and to prevent abuse.

After the relevant retention period expires, personal data is deleted, anonymised or restricted to the extent that its further storage is required or permitted by applicable law.

XII. User rights

Data protection laws applicable in the country where the user resides may grant the user specific rights in relation to their personal data.

In particular, subject to legal requirements, the user may be entitled to:

  1. obtain confirmation as to whether we process personal data concerning them and obtain access to that data;
  2. request rectification of inaccurate personal data;
  3. request erasure of personal data;
  4. request restriction of processing;
  5. data portability in relation to data actively provided by the user;
  6. object, on grounds relating to the user’s particular situation, to further processing;
  7. withdraw consent where processing is based on consent.

Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

XIII. Security

In order to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access or other unlawful processing, we apply appropriate technical and organisational measures selected according to the nature, scope, context and purposes of processing and the related risks. We regularly review and update these measures where necessary.

XIV. Contact regarding personal data protection

Sternet sp. z o.o. provides support in the event of questions, comments, concerns or complaints regarding personal data protection and in connection with the exercise of data protection rights.

The contact address for personal data protection matters is [email protected].

Sternet sp. z o.o. will make reasonable efforts to review and resolve requests or complaints. Regardless of contacting Sternet, the user always has the right to submit a request or complaint to the competent data protection supervisory authority.

This section applies to the processing of user data in the European Economic Area. Sternet sp. z o.o. informs that it is the controller responsible for processing the user’s personal data under the General Data Protection Regulation (GDPR).

In the course of a business relationship with the user, we may share the user’s contact details with business partners. Our business partners administer personal data in accordance with GDPR requirements.

GDPR requires us to provide information about the legal bases for processing personal data.

The legal basis for processing the user’s personal data is that processing is necessary to:

  1. perform our rights and obligations under a contract — Article 6(1)(b) GDPR, “performance of a contract”;
  2. fulfil our legal obligations — Article 6(1)(c) GDPR, “fulfilment of legal obligations”;
  3. pursue legitimate interests — Article 6(1)(f) GDPR, “legitimate interest”.

As a rule, our legitimate interest consists in effectively providing or managing the user’s use of the Services, conducting the business relationship and pursuing the purposes described in the table below.

If the table below indicates legitimate interest, we consider that this interest is not overridden by the user’s interests, rights or freedoms due to:

  1. regular reviews and documentation of processing activities;
  2. protection of personal data ensured by our data protection processes;
  3. transparency regarding processing activities;
  4. rights available to the user in connection with a given processing activity.

If our mobile applications access device data on the basis of permissions, we provide configuration options enabling the user to manage and withdraw such access at any time.

In some cases, we may ask the user for consent for a specific use of personal data. In such cases, the legal basis may be consent pursuant to Article 6(1)(a) GDPR.

Purpose of processingLegal basis
Providing services and functions available within the Services, including account administration, updates, security, troubleshooting, support and development.Performance of a contract – Article 6(1)(b) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Billing for the user’s use of the Service.Performance of a contract – Article 6(1)(b) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Verifying the user’s identity.Performance of a contract – Article 6(1)(b) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Verifying the user’s age.Performance of a contract – Article 6(1)(b) GDPR. Fulfilment of legal obligations – Article 6(1)(c) GDPR.
Responding to requests, inquiries or instructions.Performance of a contract – Article 6(1)(b) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Handling orders or providing access to information or offers.Performance of a contract – Article 6(1)(b) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Sending marketing information or contacting the user as part of customer satisfaction surveys.Consent, if freely given – Article 6(1)(a) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Enforcing terms of use, claims, defence, fraud prevention and protection against IT attacks.Fulfilment of legal obligations – Article 6(1)(c) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Purpose of processingLegal basis
Communication concerning products, services and projects.Performance of a contract – Article 6(1)(b) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Planning, implementing and managing contractual relationships, transactions, payments, accounting, deliveries, repairs and support.Performance of a contract – Article 6(1)(b) GDPR. Fulfilment of legal obligations – Article 6(1)(c) GDPR.
Creating a business-related personal profile to provide tailored information and offers.Legitimate interest – Article 6(1)(f) GDPR.
Administering market analyses, lotteries, contests and customer events.Consent, if freely given – Article 6(1)(a) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Customer satisfaction surveys and direct marketing.Consent, if freely given – Article 6(1)(a) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Security of products, services and websites and fraud prevention.Legitimate interest – Article 6(1)(f) GDPR.
Compliance with legal obligations, export and customs control, partner verification and policy compliance.Fulfilment of legal obligations – Article 6(1)(c) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Dispute resolution, contract enforcement and legal claims.Fulfilment of legal obligations – Article 6(1)(c) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Purpose of processingLegal basis
Providing AI Services to the user.Performance of a contract – Article 6(1)(b) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Monitoring AI Services quality and content compliance.Performance of a contract – Article 6(1)(b) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Improving services, applications and AI functionalities.Legitimate interest – Article 6(1)(f) GDPR.
Claims, fraud prevention, system protection and legal compliance.Fulfilment of legal obligations – Article 6(1)(c) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Purpose of processingLegal basis
Organisation and management of the Event, including registration, access control and logistics.Performance of a contract – Article 6(1)(b) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Providing access to the Event and business networking opportunities.Performance of a contract – Article 6(1)(b) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Purpose of processingLegal basis
Providing recording, transcription or AI support functions.Performance of a contract – Article 6(1)(b) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Creating recordings, transcripts and AI-generated summaries.Performance of a contract – Article 6(1)(b) GDPR. Legitimate interest – Article 6(1)(f) GDPR.
Claims, fraud prevention and legal compliance.Fulfilment of legal obligations – Article 6(1)(c) GDPR. Legitimate interest – Article 6(1)(f) GDPR.

Processing of personal data for customer satisfaction surveys and direct marketing

Purpose of processingLegal basis
Processing contact details for direct marketing, invitations, newsletters and satisfaction surveys.Consent, if freely given – Article 6(1)(a) GDPR. Legitimate interest – Article 6(1)(f) GDPR.

International data transfers

If personal data is transferred outside the European Economic Area, we ensure protection in accordance with GDPR and apply legally required safeguards.

  1. we transfer personal data to external recipients outside the European Economic Area only if the recipient:
    1. has entered into EU standard contractual clauses with us; or
    2. has implemented binding corporate rules within its organisation.

The user may request further information about safeguards by contacting: [email protected].

Data controller

The controller of personal data is: STERNET sp. z o.o.; address: ul. Chemiczna 110, 33-101 Tarnów, Poland, tel. +48 14 6330990, e-mail: [email protected].

Competent data protection supervisory authority

In the event of questions, concerns or requests regarding personal data protection, we encourage you to contact us at [email protected].

The user always has the right to submit a request or complaint to the Personal Data Protection Office. Contact details and relevant instructions are available on the UODO website: https://uodo.gov.pl/.