Cookie Policy
KEY FOODS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Website: keyfoods.pl | Version: 5 August 2026 | KRS: 0001042859
This document explains when the keyfoods.pl Website stores information on the User's device or accesses information already stored there, how consent works, and how the User can manage it.
1. Purpose and Scope of the Cookie Policy
This Cookie Policy, hereinafter referred to as the "Cookie Policy", sets out the rules governing the use by the keyfoods.pl website of cookies and similar technologies that may result in information being stored on the User's telecommunications terminal equipment or access being gained to information already stored on it.
The Cookie Policy applies to all Users of the Website regardless of whether the information stored or accessed on the device constitutes personal data. The requirements of the Electronic Communications Law apply to the storage of or access to information on the device itself. If the information obtained makes it possible to identify a natural person or can be linked to such person, its further processing is additionally subject to the GDPR.
The Cookie Policy is a separate document from the KEY FOODS Privacy Policy. This document focuses on technologies operating on the User's device and the management of consents.
2. Controller and Privacy Contact
The controller of personal data processed in connection with the use of the Website is KEY FOODS spółka z ograniczoną odpowiedzialnością, with its registered office in Warsaw at ul. Jana Kasprowicza 119A lok. 151, 01-949 Warsaw, KRS 0001042859, NIP 1182264158, REGON 525626820, hereinafter referred to as the "Controller" or "KEY FOODS".
The Data Protection Officer is Łukasz Kiernicki. The Data Protection Officer may be contacted at iodo@keyfoods.pl or by post at the Controller's registered office, marked "Data Protection Officer".
3. What Cookies and Similar Technologies Are
Cookies are small text files stored on the User's terminal device while using a website. They may be used, among other things, to maintain a session, perform a function requested by the User, remember privacy preferences, secure a form, measure traffic or — where the User has provided the appropriate consent and the relevant function is actually used — personalise or measure marketing activities.
Similar technologies may include, in particular, local storage, session storage, tags, pixels, device identifiers, browser storage mechanisms, analytics scripts or other solutions that store information on a device or access information already stored on it. The technical name of a solution does not determine whether Article 399 of the Electronic Communications Law applies; what matters is how the technology actually operates.
Cookies may be first-party cookies or originate from a third party whose technology has been integrated into the Website. They may be session cookies, which are deleted after the browser session ends, or persistent cookies, which remain for a specified period or until deleted earlier by the User.
4. Legal Basis — Electronic Communications Law and GDPR
Pursuant to Article 399(1) of the Electronic Communications Law, the storage of information or access to information already stored on telecommunications terminal equipment is generally permitted after the User has first been provided with clear, easy-to-understand information about the purpose of such action and the possibility of determining the conditions for storing or accessing such information, and after the User's consent has subsequently been obtained.
Article 399(2) of the Electronic Communications Law allows consent to be given through the settings of software installed on the terminal equipment or through the configuration of the service. Pursuant to Article 400 of the Electronic Communications Law, the provisions on personal data protection apply accordingly to obtaining the consent of a subscriber or end User. In practice, this means that consent must meet the standard arising in particular from Article 4(11) and Article 7 of the GDPR: it must be freely given, specific, informed and unambiguous, and withdrawing consent should be as easy as giving it.
If identifiers or other information obtained through optional technologies constitute personal data, their processing for the purpose for which the User activated the relevant category is generally based on Article 6(1)(a) GDPR. If a technology is strictly necessary to provide the requested service, the processing of personal data may be based on another appropriate legal basis, in particular Article 6(1)(b) or (f) GDPR, depending on the function and the relationship with the User.
5. Exception for Strictly Necessary Technologies
Article 399(3) of the Electronic Communications Law excludes the obligation to meet the conditions specified in paragraph 1 where the storage of information or access to it is necessary to transmit an electronic communication through a public telecommunications network or to provide a telecommunications service or an electronic service requested by the User.
6. Categories of Technologies Used on the Website
The Website distinguishes categories according to purpose. The actual activation of individual categories depends on the current configuration of the Website. The mere description of a category does not mean that every category is being used at a given time.
| Category | Purpose | Activation rule |
|---|---|---|
| Necessary | Transmission, security, session maintenance, operation of functions requested by the User, form protection and remembering privacy preferences. | Without separate consent only to the extent meeting Article 399(3) of the Electronic Communications Law. |
| Functional | Remembering additional preferences, supporting optional functions, integrations or external content. | After prior consent, unless the specific function is objectively necessary for the service requested by the User. |
| Analytics | Measuring traffic, errors and use of the Website, creating statistics and improving functionality. | After prior consent. |
| Marketing | Measuring campaigns, personalising communications or advertisements, building audience groups and limiting frequency. | After prior consent. |
7. Consent Panel and First Visit to the Website
The Website uses optional technologies. During the first visit, the User is presented with a consent management panel. The panel allows at least the acceptance of all optional categories, their rejection and a more detailed selection of categories. Acceptance and refusal options should be presented clearly and without misleading the User.
Optional scripts and technologies will not be activated before the appropriate consent has been obtained. Consent fields are not pre-selected. Silence, inactivity, merely scrolling the page or continuing to use the Website do not constitute consent. Consent is not inferred from the fact that the browser generally allows cookies.
8. Granularity of Consent
The Website uses several separate optional purposes, and the User has the possibility to make a sufficiently detailed selection, at least at the category level. Combining all non-essential purposes into one indivisible consent is permitted only where the purposes are genuinely inseparable and the User has received clear information about their scope.
The Controller does not regard as valid consent a choice made under coercion or through a solution where refusal causes unjustified harm to the User. Giving consent to analytics or marketing is not a condition for submitting an ordinary business inquiry or accessing publicly available Website content, unless the relevant technology is objectively necessary for the requested function.
9. Withdrawal or Change of Consent
The User may change or withdraw consent to optional cookies and similar technologies at any time. The Website provides a permanent and easily accessible link or button labelled "Cookie Settings" or an equivalent solution leading to the consent panel.
Withdrawing consent should be as easy as giving it. After consent is withdrawn, the Website ceases to activate the technologies covered by the withdrawn consent in the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Withdrawal of consent does not always automatically delete information already stored on the device by a third party. The User may additionally delete existing files through the browser settings. To the extent within its control, the Controller ceases further reading and use of the technology covered by the withdrawn consent, unless there is another valid legal basis and the User has been informed of it.
10. Consent Register and Demonstrating Accountability
The Controller may retain information necessary to demonstrate whether and when the User gave consent, the scope of that consent, which version of the notice was displayed, and whether consent was subsequently changed or withdrawn.
Data used solely to document the User's choice are not used to reactivate marketing or analytics after consent has been withdrawn. Their scope is limited to the minimum necessary to demonstrate compliance and respect an objection or withdrawal of consent.
11. Current List of Cookies and Similar Technologies
The current list of cookies and similar technologies used should be presented in the cookie settings panel or another permanently accessible list linked to the actual configuration of the Website. The list should indicate at least the name or identifier of the technology, provider, purpose, category, type or source, and period of operation.
The actual configuration of the Website is decisive. The use of a tool should not be declared merely because a particular category is described in this Policy. Likewise, before launching a new tool, the Controller updates the panel configuration, purpose classification and information provided to Users.
| Information in the list | What it should specify |
|---|---|
| Name / identifier | Technical designation of the cookie or similar technology. |
| Provider / domain | The entity or domain associated with the technology. |
| Purpose | The actual and sufficiently specific way in which the information is used. |
| Category | Necessary, functional, analytics or marketing — according to the actual purpose. |
| Period | Cookie lifetime or another understandable retention period; for session cookies, information indicating the end of the session. |
| Activation basis | The exception under Article 399(3) of the Electronic Communications Law or the relevant consent category. |
12. Analytics Technologies
If the Website uses analytics tools based on storing or accessing information on the User's device, they are activated only after the appropriate consent has been obtained, unless the specific configuration of the technology does not require such storage or access and has a separate valid legal basis. The Controller does not automatically assume that every form of statistical analysis is technically necessary to provide the Website.
Analytics data may include an identifier, IP address to the extent processed by the relevant tool, device and browser parameters, source of entry, pages viewed, events occurring on the Website, and information about the time and approximate location derived from the IP address. The scope depends on the actual tool used and its configuration.
13. Marketing Technologies and Campaign Measurement
If the Website uses marketing technologies, they may be used to measure campaign effectiveness, prevent the same content from being displayed repeatedly, create audience groups or — where the User has provided the appropriate consent — personalise communications. Such technologies are treated as optional and activated only after consent has been obtained.
The Controller does not treat consent to cookies as consent to receive commercial information by email or telephone. Consent relating to the User's device under Article 399 of the Electronic Communications Law and consent to use a terminal device for marketing under Article 398 of the Electronic Communications Law concern different operations and are kept separate where both processes occur.
14. External Content, Maps, Videos and Plugins
The Website may contain links to external websites. Merely placing an ordinary link does not, as a rule, activate a third party's technology. The situation may be different in the case of embedded videos, maps, social-media modules, chats, external forms or other components that establish a connection with the provider's servers when the page is displayed.
If displaying embedded content results in optional storage of or access to information on the device, the component remains blocked until the appropriate consent has been obtained.
15. Browser and Device Settings
The User may also delete or restrict cookies through the settings of the browser or device. Depending on the software, this may include deleting stored website data, blocking third-party cookies, automatically deleting data after closing the browser or blocking selected types of storage.
Browser settings are complementary to the consent panel, particularly where consent concerns technologies other than traditional cookies. Blocking necessary cookies may cause the Website, form or a function requested by the User to operate incorrectly. Blocking optional technologies should not, however, prevent access to basic publicly available content.
16. Personal Data Obtained Through Cookies
Depending on the tool, information obtained through cookies may constitute or create personal data, particularly where it includes a unique identifier, IP address, set of device parameters, history of events on the Website or another set of data allowing a User to be distinguished. The fact that the Controller does not know the User's first and last name does not exclude the information from being considered personal data.
Where personal data from optional technologies are processed on the basis of consent, the User may withdraw that consent. In relation to processing based on other legal grounds, the User has the rights provided for under the GDPR, depending on the legal basis and nature of the specific processing operation. A full description of these rights is provided in the KEY FOODS Privacy Policy.
17. Providers, Recipients and Roles of Third Parties
A provider of technology integrated into the Website may act as a processor on behalf of the Controller, as a separate controller or — to a specified extent — as a joint controller. The role depends on who determines the purposes and means of processing and on the terms of the specific service; the technical name of an integration alone does not determine this classification.
Where a provider acts as a processor, the Controller enters into an agreement with it meeting the requirements of Article 28 GDPR. Where the provider is a separate controller, the User should receive information enabling them to familiarise themselves with that entity's processing rules, where required and possible under the particular model.
18. Transfers of Data Outside the European Economic Area
Certain third-party technologies may involve the transfer of personal data outside the EEA or access to data from a third country. Where this occurs, the transfer is subject to Chapter V GDPR and is carried out on an appropriate legal basis.
19. Periods of Operation and Retention
The operating period of a specific cookie or similar technology is indicated in the current list in the settings panel. Session cookies generally expire at the end of the session; persistent cookies have a specified lifetime or remain until deleted earlier by the User. The Controller selects the period according to the purpose and should not retain an identifier longer than necessary.
The lifetime of a cookie is not always the same as the period for which data are stored on the provider's server. If personal data are subsequently stored in an analytics system or another tool, retention should follow the configuration of that system and be adapted to the purpose. After consent is withdrawn, new data are not collected on the basis of that consent, subject to information retained solely to document consent or its withdrawal and other valid legal bases.
20. User Rights in Relation to Personal Data
Where information from cookies constitutes personal data, the User may, within the limits arising from the GDPR, have the right to access the data, rectify them, erase them, restrict processing, obtain data portability, object to processing and, where consent is the legal basis, withdraw consent. The scope of a particular right depends on the legal basis for processing and the nature of the data.
Requests concerning personal data may be submitted to the Data Protection Officer at iodo@keyfoods.pl. The User also has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stanisława Moniuszki 1A, 00-014 Warsaw. A detailed description of the procedure for exercising rights is provided in the KEY FOODS Privacy Policy.
21. Security and Data Minimisation
The Controller limits the number and scope of technologies to functions that are actually necessary, periodically reviews the configuration of scripts, consent panels and providers, and applies appropriate security measures. When a provider is changed or a new integration is added, the purpose, category, required consent, scope of data, retention period and any transfer outside the EEA are analysed.
22. Changes to the Cookie Policy
The Cookie Policy is updated in the event of changes to legislation, guidance issued by competent authorities, the manner in which the Website operates, cookie categories, technology providers, processing purposes, retention periods or rules governing transfers outside the EEA. The current version is published on the Website together with the update date.
If a change concerns a purpose or scope covered by previously given consent in a manner requiring new consent, the Controller does not treat the previous choice as consent to the new scope. Before activating the modified technology, the User is provided with information and an opportunity to make a new decision where required.
23. Minimum Compliance Standard for Website Configuration
The content of this Cookie Policy corresponds to the actual operation of the Website. In particular, before publishing a new tool, we ensure that its category in the consent panel corresponds to its actual purpose, that an optional script does not activate before consent is obtained, that refusal is available without unjustified obstacles, and that withdrawal of consent blocks further activation of the tool.
24. Contact
Questions concerning cookies, consent and the processing of personal data may be addressed to the Data Protection Officer: Łukasz Kiernicki, iodo@keyfoods.pl, or by post to KEY FOODS sp. z o.o., ul. Jana Kasprowicza 119A lok. 151, 01-949 Warsaw, Poland, marked "Data Protection Officer".