Glossline Serwis · Version dated 28 September 2026.

Privacy policy and GDPR information notice

This document explains how Glossline processes data of people who use the website, contact us or submit an accident-claim enquiry.

1. Data controller

The controller is GLOSSLINE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, 3 Odeska Street, 04-778 Warsaw, Poland, VAT ID PL9522270789. For data protection matters: +48 691 430 856 or the contact form on the Contact page.

If a data protection officer is required for a specific processing activity, the relevant contact details will be added here. Until then, privacy questions can be sent directly to the Controller.

2. Purposes and legal bases

We process form data to receive and handle an enquiry, contact the person submitting it and agree the next step. The legal basis is Article 6(1)(b) GDPR where steps are taken at the person’s request before a contract, and Article 6(1)(f) GDPR where handling correspondence and protecting against claims are the Controller’s legitimate interests.

Where a legal, accounting or tax obligation applies, the basis is Article 6(1)(c) GDPR. Electronic marketing, analytics and advertising require separate consent where consent is required by law.

3. Data scope and minimisation

We may process a name, phone number, incident date, vehicle information, insurance type, whether the vehicle is drivable and the description of the enquiry. Do not send identity documents or unnecessary sensitive data through the first form.

Required data is voluntary but needed to handle the enquiry. Optional data may be omitted. To assess the source of an enquiry, we may also record the landing page, referring address and campaign parameters supplied in the page address.

4. Recipients and transfers

Data may be shared with hosting, website maintenance, IT, accounting, legal or enquiry-handling providers where necessary and under appropriate arrangements.

Form enquiries are sent by the server to Telegram in a company channel operated by authorised persons. Telegram is an external communications provider and may process data under its privacy policy; any transfer outside the EEA requires an appropriate legal basis and safeguards. Meta Pixel and Meta Conversions API (Meta Platforms Ireland Limited) may receive visit and enquiry events — including a hashed phone number and first name — only after voluntary marketing consent is given. Google Analytics (Google tag) starts only after voluntary marketing consent is given and processes statistical visit data. Google Tag Manager remains inactive unless separately configured.

5. Retention

We retain data no longer than needed for handling the contact, carrying out agreed actions, meeting legal obligations or establishing, exercising or defending claims. The period depends on the purpose and applicable law; data is deleted or anonymised afterwards.

6. Your rights

You may have the right to access your data, obtain a copy, correct it, erase it, restrict processing, receive portable data and object to processing, as provided by the GDPR. Where processing is based on consent, you may withdraw it at any time; withdrawal does not affect earlier lawful processing.

You may also complain to the President of the Polish Personal Data Protection Office (UODO). Requests can be sent using the Controller’s details in section 1.

7. Automated decision-making

We do not make decisions producing legal or similarly significant effects about website visitors solely by automated means, including profiling.

8. Security and updates

We use technical and organisational measures appropriate to the risk, including data minimisation and secure transmission. This policy may be updated when the website, enquiry process or applicable law changes. The current version is published here.