Privacy Policy
Last updated: March 9, 2026
1. General Provisions
This Privacy Policy sets out the rules for processing and protecting the personal data of users of the website www.ultrarent.com (the “Website”) and clients using ULTRARENT’s services.
This Policy has been prepared in accordance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “GDPR”), and the Polish Act of 10 May 2018 on the Protection of Personal Data.
The purpose of this Policy is to fulfill the information obligation set out in Articles 13 and 14 of the GDPR and to ensure transparency in the processing of personal data.
2. Data Controller
The controller of personal data is:
ULTRARENT Sp. z o.o.
Registered office: Opatówek
Tax ID (NIP): 9681003397
Email: info@ultrarent.com
Phone: +48 888 905 440
The Controller operates in the field of advanced non-destructive testing (NDT), offering comprehensive quality control services for industry.
For matters related to personal data protection, you can contact the Controller via:
- email: info@ultrarent.com
- the contact form available on the Website
- traditional mail to the company’s registered office address
3. Scope and Purpose of Personal Data Processing
The Controller processes personal data for the following purposes and on the specified legal bases:
| Purpose | Data Categories | Legal Basis | Retention Period |
|---|
| Handling inquiries and contact | First name, last name, email, phone, company name | Legitimate interest (Art. 6(1)(f) GDPR) | Until the inquiry is resolved + 3 years |
| Performance of NDT service agreements | Identification data, contact data, company data, tax ID | Performance of contract (Art. 6(1)(b) GDPR) | Duration of contract + statute of limitations period (10 years) |
| Issuing and storing invoices | First name, last name / company name, address, tax ID | Legal obligation (Art. 6(1)(c) GDPR) – tax regulations | 5 years from the end of the year in which the tax payment deadline fell |
| Direct marketing of own services | Email, phone | Legitimate interest (Art. 6(1)(f) GDPR) | Until objection is raised or consent is withdrawn |
| Newsletter | Email, first name (optional) | Consent (Art. 6(1)(a) GDPR) | Until consent is withdrawn |
| Pursuit or defense against claims | Data arising from the business relationship | Legitimate interest (Art. 6(1)(f) GDPR) | Statute of limitations period |
| Website analytics and statistics | Technical data (IP address, analytics cookies) | Consent (Art. 6(1)(a) GDPR) | Maximum 25 months |
| Recruitment | First name, last name, CV, cover letter, contact details | Consent (Art. 6(1)(a) GDPR) | Until the recruitment process ends or consent is withdrawn |
Table 1: Purposes and legal bases for personal data processing
Detailed Explanations
The Controller’s legitimate interest (Art. 6(1)(f) GDPR) covers:
- conducting marketing activities for its own services,
- responding to inquiries and building business relationships,
- securing and pursuing claims,
- ensuring the security of IT systems,
- conducting statistical analyses (in anonymized form).
Performance of a contract (Art. 6(1)(b) GDPR) relates to:
- fulfilling orders for non-destructive testing services (RT, UT, MT, PT, TOFD, PAUT),
- preparing commercial offers,
- contact regarding service delivery.
Legal obligation (Art. 6(1)(c) GDPR) arises from:
- tax regulations (VAT Act, Tax Ordinance Act),
- accounting regulations (Accounting Act).
Consent (Art. 6(1)(a) GDPR) is the basis for:
- newsletter subscription,
- analytical and marketing cookies,
- processing of data in recruitment beyond the scope of Article 22¹ of the Polish Labor Code.
4. Recipients of Personal Data
The Controller may disclose personal data to the following categories of recipients:
- Hosting, IT, and cloud service providers – to the extent necessary to ensure the functioning of the Website and IT systems;
- Accounting office and tax advisors – for bookkeeping and fulfilling tax obligations;
- Law firms – where necessary to obtain legal advice or pursue claims;
- Courier and postal companies – for delivering technical documentation and test reports;
- Banks and payment operators – for processing payments;
- Public authorities – where required by law (e.g. the Tax Office, ZUS, law enforcement authorities).
Data is transferred to these entities only to the extent necessary to achieve a specific purpose and on the basis of appropriate data processing agreements or legal provisions.
The Controller does not transfer personal data to third countries (outside the European Economic Area), except when using tools provided by U.S.-based entities that participate in the Data Privacy Framework or apply standard contractual clauses approved by the European Commission.
5. Rights of Data Subjects
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR) – you can obtain confirmation of whether we process your data and receive a copy of it;
- Right to rectification (Art. 16 GDPR) – you can request the correction of inaccurate data or completion of incomplete data;
- Right to erasure (“right to be forgotten”) (Art. 17 GDPR) – you can request the deletion of your data when:
- it is no longer necessary for the purposes for which it was collected,
- you withdraw the consent on which processing was based,
- you object to the processing,
- the data was processed unlawfully;
- Right to restriction of processing (Art. 18 GDPR) – you can request that processing be restricted in certain cases (e.g. you contest the accuracy of the data);
- Right to data portability (Art. 20 GDPR) – where processing is based on consent or a contract, you can receive your data in a structured format and transfer it to another controller;
- Right to object (Art. 21 GDPR) – you can object at any time to the processing of your data:
- on grounds relating to your particular situation – to processing based on legitimate interest,
- unconditionally – to processing for direct marketing purposes;
- Right to withdraw consent – where processing is based on consent, you can withdraw it at any time, without affecting the lawfulness of processing carried out before its withdrawal;
- Right to lodge a complaint – you can lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw) if you believe that the processing of your data infringes the GDPR.
To exercise the above rights, contact us at info@ultrarent.com or in writing at the company’s registered office address.
6. Automated Decision-Making and Profiling
The Controller does not make decisions in an automated manner, including through profiling, that would produce legal effects concerning data subjects or similarly significantly affect them.
Any statistical analyses are conducted solely in aggregated and anonymized form, without the possibility of identifying specific individuals.
7. Personal Data Security
The Controller applies appropriate technical and organizational measures to ensure the security of processed personal data, in particular:
- encryption of connections (SSL/TLS protocol),
- security of servers and IT systems (firewalls, antivirus software),
- restricting access to personal data to authorized persons only,
- regular data backups,
- security incident response procedures,
- employee training on personal data protection.
In the event of a personal data breach that could result in a high risk to the rights or freedoms of natural persons, the Controller will promptly (within 72 hours) report the incident to the supervisory authority and notify the affected data subjects.
8. Cookies and Tracking Technologies
The Website uses cookies and similar technologies for functional, analytical, and marketing purposes.
Detailed information on the cookies used, their purposes, retention periods, and how to manage them can be found in the separate Cookie Policy available on the Website.
Analytical and marketing cookies are used only after the user gives consent via the cookie banner.
9. Contact Details and Inquiries
If you have questions about the processing of your personal data or wish to exercise your rights, contact us:
The Controller undertakes to respond to your inquiry within one month of receipt (in accordance with Art. 12(3) GDPR). In complex cases, this period may be extended by a further two months, of which you will be informed.
10. Changes to the Privacy Policy
This Privacy Policy may be updated, in particular in the event of:
- changes in personal data protection laws,
- changes in the scope of business activity or the manner of data processing,
- the implementation of new technologies or services,
- the issuance of new guidelines by supervisory authorities.
The current version of the Privacy Policy is always available on the Website at www.ultrarent.com/polityka-prywatnosci
The date of the last update of the Policy is indicated at the beginning of the document.
In the event of significant changes, the Controller will inform users through a clear notice on the Website or via other available means of communication.
11. Final Provisions
In matters not regulated by this Privacy Policy, the provisions of the GDPR and Polish law shall apply, in particular the Act of 10 May 2018 on the Protection of Personal Data.
The Controller has made every effort to ensure that the information contained in this Policy is complete, up to date, and understandable. If you have any doubts or questions, please contact us.
Use of the Website and ULTRARENT’s services is equivalent to having read this Privacy Policy and accepted the principles of personal data processing set out therein.