Skip to content
Alcohol is sold exclusively to adults. Age may be verified upon personal collection.
Wina Lane
Wina Lane
WinesFor restaurantsWeddings and eventsIndividual customersKegsCollectionContact

Privacy Policy

Version
1
Effective from
not specified
Last updated
21 July 2026

PRIVACY POLICY OF THE WINA LANE WEBSITE

Effective from 18 July 2026.

§ 1. General information

  1. This Privacy Policy explains the rules governing the processing of personal data of persons using the Wina Lane website, available at the wina-lane.pl domain, hereinafter referred to as the "Website".
  1. In particular, this Policy applies to data processed in connection with:
  1. browsing the Website,
  2. using the product catalogue,
  3. using the search engine and filters,
  4. submitting contact forms,
  5. submitting product reservations,
  6. submitting enquiries for the hospitality sector,
  7. submitting enquiries concerning weddings and other events,
  8. preparing and handling commercial offers,
  9. using interactive offers,
  10. submitting complaints,
  11. giving marketing consents,
  12. using cookies and similar technologies.
  1. This Privacy Policy supplements the Terms and Conditions of the Website and the Cookie Policy.

§ 2. Data controller

  1. The controller of personal data is:

MACIEJ STOLARSKI FIRMA HANDLOWO USŁUGOWA „PERFECTA”
ul. Ulubiona 9
32-085 Modlnica
NIP: 6761763789
REGON: 120771405

hereinafter referred to as the "Controller".

  1. The Controller may be contacted:
  1. by e-mail at: biuro@wina-lane.pl,
  2. by telephone at: +48 603 073 076,
  3. in writing at the address indicated above,
  4. using the contact form available on the Website.
  1. In matters concerning the processing of personal data, the exercise of rights or the submission of objections, the primary contact address is:

biuro@wina-lane.pl


§ 3. Data processing principles

  1. The Controller processes data:
  1. lawfully,
  2. fairly and transparently,
  3. solely for specified and legitimate purposes,
  4. to an extent adequate for those purposes,
  5. for no longer than necessary,
  6. using appropriate technical and organisational safeguards.
  1. Data is processed on at least one of the grounds specified in Article 6(1) of the GDPR (RODO), in particular consent, the necessity to take steps prior to entering into a contract, performance of a contract, compliance with a legal obligation, or the legitimate interests pursued by the Controller. (EUR-Lex)
  1. The Controller does not knowingly collect data of persons under 18 years of age for the purpose of enabling them to purchase or reserve alcohol.

§ 4. Data related to the use of the Website

  1. When the Website is used, technical data may be processed automatically, such as:
  1. IP address,
  2. date and time of the connection,
  3. address of the page visited,
  4. device type,
  5. browser type and version,
  6. operating system,
  7. approximate location inferred from the IP address,
  8. information about errors and technical events,
  9. data stored in cookies,
  10. information about cookie consent choices.
  1. This data may be processed for the purposes of:
  1. displaying the Website correctly,
  2. maintaining a session,
  3. ensuring security,
  4. detecting abuse and attempted unauthorised access,
  5. diagnosing errors,
  6. compiling technical statistics,
  7. establishing, pursuing or defending claims.
  1. The legal basis for processing is the Controller's legitimate interest in ensuring the security, stability and proper operation of the Website.
  1. Where data originates from optional analytics or marketing tools, the legal basis is the user's consent.

§ 5. Contact form

  1. A person using the contact form may provide, in particular:
  1. first name and surname,
  2. e-mail address,
  3. telephone number,
  4. message content,
  5. other data voluntarily included in the message.
  1. Data is processed for the purposes of:
  1. providing a response,
  2. conducting correspondence,
  3. clarifying the matter reported,
  4. preparing a cooperation proposal,
  5. preserving evidence of the contact.
  1. The legal basis for processing is:
  1. taking steps at the person's request prior to entering into a contract,
  2. performance of a contract, if the message concerns that contract,
  3. the Controller's legitimate interest in handling correspondence and securing claims.
  1. Providing data is voluntary; however, failure to provide data that enables contact may make it impossible to provide a response.

§ 6. Reservations by individual customers

  1. In connection with a product reservation, the following data may be processed:
  1. first name and surname,
  2. e-mail address,
  3. telephone number,
  4. information about the products selected,
  5. variants and quantities,
  6. preferred collection date,
  7. comments,
  8. confirmation of legal age,
  9. contact history and reservation status.
  1. Data is processed for the purposes of:
  1. accepting and handling a reservation,
  2. confirming availability,
  3. agreeing a collection date,
  4. providing information about the price and deposit,
  5. cancelling or changing a reservation,
  6. establishing, pursuing or defending claims.
  1. The legal basis for processing is the necessity to take steps at the person's request prior to entering into a contract and the Controller's legitimate interest in handling the submission.
  1. The Website is not intended for entering into distance retail contracts for the sale of alcohol. The reservation and sale completion rules are set out in the Terms and Conditions.

§ 7. Hospitality enquiries and B2B cooperation

  1. In connection with a B2B enquiry, the Controller may process:
  1. company name,
  2. NIP,
  3. REGON,
  4. KRS,
  5. foreign tax identification number,
  6. company or premises address,
  7. first name and surname of the contact person,
  8. position or function,
  9. e-mail address,
  10. telephone number,
  11. type of business activity,
  12. number of premises,
  13. products of interest,
  14. volumes of interest,
  15. estimated monthly consumption,
  16. information about the dispensing installation,
  17. preferred method of contact,
  18. message content,
  19. information concerning the licence to sell alcohol,
  20. documents and attachments provided.
  1. Data is processed for the purposes of:
  1. verifying the business counterparty,
  2. preparing an offer,
  3. conducting negotiations,
  4. establishing and carrying out cooperation,
  5. verifying entitlement to purchase alcohol,
  6. issuing accounting documents,
  7. carrying out settlements,
  8. handling the return of packaging,
  9. establishing, pursuing or defending claims.
  1. The legal basis for processing is:
  1. taking steps prior to entering into a contract,
  2. performance of a contract,
  3. compliance with the Controller's legal obligations,
  4. the legitimate interest in verifying the business counterparty, conducting cooperation and securing claims.
  1. Where the contact person's data is provided by their employer, associate or the company they represent, the Controller may process it on the basis of the legitimate interest in conducting business communications.

§ 8. Data obtained from public registers

  1. After a NIP is entered, the Website may obtain business data from public registers, in particular from:
  1. the Wykaz podatników VAT Ministerstwa Finansów (VAT Taxpayer List of the Polish Ministry of Finance),
  2. the REGON register, if integration with that register is active,
  3. other public business registers.
  1. The following data may be obtained from a public register:
  1. company name,
  2. NIP,
  3. REGON,
  4. KRS,
  5. business address,
  6. registered office address,
  7. VAT taxpayer status.
  1. Data is obtained for the purposes of:
  1. making the form easier to complete,
  2. reducing the risk of errors,
  3. verifying the business counterparty's data,
  4. preparing a correct offer and documentation.
  1. The legal basis for processing is the Controller's legitimate interest.
  1. The person using the form may review and correct the data obtained automatically.
  1. Where data has been obtained from a source other than directly from the person, the information obligation specified in Article 14 of the GDPR (RODO) may apply. (UODO)

§ 9. Enquiries concerning weddings and other events

  1. In connection with an event enquiry form, the following data may be processed:
  1. type of event,
  2. date and location of the event,
  3. total number of guests,
  4. number of adult guests,
  5. expected duration,
  6. type of menu,
  7. preferred types of wine,
  8. preferred serving method,
  9. information about the packaging required,
  10. information about the dispensing installation,
  11. preferred budget,
  12. first name and surname,
  13. e-mail address,
  14. telephone number,
  15. message content.
  1. Data is processed for the purposes of:
  1. preparing an individual proposal,
  2. estimating the quantity of products,
  3. selecting variants and packaging,
  4. determining the terms of performance,
  5. communicating with the organiser,
  6. establishing, pursuing or defending claims.
  1. The legal basis is taking steps at the person's request prior to entering into a contract and the Controller's legitimate interest.

§ 10. Interactive and PDF offers

  1. In connection with preparing and handling offers, the Controller may process:
  1. company or customer details,
  2. contact person details,
  3. e-mail address,
  4. telephone number,
  5. address details,
  6. NIP,
  7. information about the products selected,
  8. variants and quantities,
  9. prices and deposits,
  10. customer comments,
  11. history of opening and responding to the offer,
  12. offer status,
  13. technical access token for the offer.
  1. Data is processed for the purposes of:
  1. preparing an offer,
  2. providing an individual link,
  3. collecting the customer's selection,
  4. calculating the value of products and deposits,
  5. conducting negotiations,
  6. preserving the content of the arrangements,
  7. preventing unauthorised access.
  1. A public offer token should be difficult to guess, and a secure representation of that token may be stored in the database.
  1. Submitting a selection from an interactive offer does not automatically constitute entering into a contract or give rise to an obligation to pay.

§ 11. Complaints

  1. In connection with a complaint, the Controller may process:
  1. first name and surname,
  2. company details,
  3. contact details,
  4. information concerning the purchase or service,
  5. description of the problem reported,
  6. proof of purchase,
  7. photographs and attachments,
  8. correspondence history,
  9. the request made and the manner in which it was resolved.
  1. Data is processed for the purposes of:
  1. accepting and considering a complaint,
  2. conducting correspondence,
  3. complying with legal obligations,
  4. establishing, pursuing or defending claims.
  1. The legal basis for processing is compliance with a legal obligation, performance of a contract or the Controller's legitimate interest.

§ 12. Marketing communications

  1. Data may be used to send marketing information only where the person has given the required consent.
  1. Marketing consent:
  1. is voluntary,
  2. is not a condition for submitting an enquiry,
  3. is not a condition for receiving an individual offer,
  4. may be withdrawn at any time.
  1. Withdrawal of consent does not affect the lawfulness of actions taken before its withdrawal.
  1. The Controller may process information concerning:
  1. the content and date of consent,
  2. the communication channel selected,
  3. the date on which consent was withdrawn,
  4. an objection to marketing.
  1. The use of e-mail, telephone or other terminal equipment for direct marketing requires the end user's prior consent. (ELI - European Legislation Identifier)

§ 13. Cookies

  1. The Website uses cookies and similar technologies.
  1. Cookies may be used for the purposes of:
  1. ensuring the proper operation of the Website,
  2. maintaining a session,
  3. remembering user settings,
  4. recording consent choices,
  5. ensuring security,
  6. compiling statistics,
  7. carrying out analytics activities,
  8. carrying out marketing activities, where the user has given consent.
  1. Cookies may be divided into:
  1. necessary,
  2. preference,
  3. analytics,
  4. marketing cookies.
  1. Necessary cookies may be used without separate consent where they are required to transmit a communication or provide a service expressly requested by the user.
  1. Analytics, preference and marketing cookies that require consent are activated only after the user has made the relevant choice.
  1. The user may change their choice at any time using the button:

"Change cookie consents"

  1. Detailed information about cookie names, providers, purposes and periods of operation is contained in the Cookie Policy and the consent management panel.
  1. The Polish Electronic Communications Law (Prawo komunikacji elektronicznej) requires the user to be clearly informed in advance about the purpose of storing information on or reading information from a device and requires consent to be obtained, except for technologies necessary to transmit a communication or provide a service requested by the user. (ELI - European Legislation Identifier)

§ 14. Data recipients

  1. Data may be disclosed to entities supporting the Controller, in particular:
  1. hosting and server infrastructure providers,
  2. IT administrators and service providers,
  3. e-mail service providers,
  4. providers of systems used to handle forms and offers,
  5. accounting service providers,
  6. legal, tax and insurance advisers,
  7. providers of security and backup tools,
  8. providers of analytics or marketing tools, after the required consent has been obtained,
  9. courier or transport companies, where a given transaction lawfully includes transport,
  10. payment service providers, if payments are enabled for the relevant services,
  11. public authorities entitled by law to receive data.
  1. Entities processing data on behalf of the Controller are required to protect it and may use it solely in accordance with their agreement and the Controller's instructions.
  1. Data is not sold to third parties.

§ 15. Transfers of data outside the European Economic Area

  1. The Controller endeavours to use providers that process data within the European Economic Area.
  1. If a provider of technical, analytics or marketing services processes data outside the European Economic Area, the transfer may take place only on the grounds and subject to the safeguards required by the GDPR (RODO).
  1. Such safeguards may include, in particular:
  1. a European Commission adequacy decision,
  2. standard contractual clauses,
  3. additional technical and organisational measures.
  1. Information about providers that use optional cookies should be available in the Cookie Policy or the consent panel.

§ 16. Data retention period

  1. Data is retained for the period necessary to fulfil the purpose for which it was collected.
  1. Data from contact forms is retained for the duration of the correspondence and subsequently for the period necessary to secure any potential claims.
  1. Data concerning requests for quotation is retained for the duration of preparing an offer and conducting negotiations, and subsequently for the period necessary to document the arrangements and secure claims.
  1. Data connected with a contract entered into or a sale is retained:
  1. for the duration of performing the contract,
  2. for the period required by tax and accounting laws,
  3. until the limitation periods for claims expire.
  1. Data connected with a complaint is retained for the duration of its consideration and for the period necessary to secure claims.
  1. Data processed on the basis of consent is retained until:
  1. consent is withdrawn,
  2. the purpose of processing ceases to exist,
  3. the data is deemed no longer current,

whichever occurs first.

  1. Data processed for direct marketing purposes is retained until an effective objection is raised or consent is withdrawn.
  1. Technical information and logs may be retained for the period necessary to ensure security, diagnose errors and detect abuse.
  1. Data may be retained for longer where this is necessary to:
  1. comply with a legal obligation,
  2. establish, pursue or defend claims,
  3. investigate a security incident.

§ 17. Voluntary provision of data

  1. As a rule, providing data is voluntary.
  1. Providing data marked as required may be necessary to:
  1. provide a response,
  2. prepare an offer,
  3. handle a reservation,
  4. handle a complaint,
  5. verify the business counterparty's entitlement,
  6. perform a contract.
  1. Failure to provide the required data may make it impossible to handle the submission.
  1. Marketing consent is always voluntary, and the absence of such consent does not affect the ability to submit an enquiry concerning an offer.

§ 18. Rights of data subjects

  1. A data subject may have the right to:
  1. obtain information about processing,
  2. access their data,
  3. receive a copy of their data,
  4. rectify inaccurate data,
  5. complete incomplete data,
  6. erase data,
  7. restrict processing,
  8. data portability,
  9. object to processing,
  10. withdraw consent,
  11. lodge a complaint with a supervisory authority.
  1. The scope of each right depends on the legal basis and purpose of processing.
  1. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
  1. An objection to direct marketing takes effect when it is received by the Controller.
  1. UODO indicates that a person should be informed, among other matters, about the rights of access, rectification, erasure, restriction, portability and objection, as well as the rules governing automated decision-making. (UODO)

§ 19. Exercising rights

  1. To exercise their rights, a person should contact the Controller at:

biuro@wina-lane.pl

  1. The request should state:
  1. first name and surname,
  2. data enabling the request to be identified,
  3. the right to be exercised,
  4. the preferred method of receiving a response.
  1. If the Controller has reasonable doubts about the identity of the person making the request, the Controller may ask for additional information necessary to confirm that person's identity.
  1. The Controller should not request a broader scope of data than is necessary to handle the request securely.
  1. Information and actions connected with exercising rights are, as a rule, provided free of charge, subject to cases of manifestly unfounded or excessive requests. (EUR-Lex)

§ 20. Complaint to the supervisory authority

  1. A person who believes that their data is being processed unlawfully may lodge a complaint with:

Prezes Urzędu Ochrony Danych Osobowych (President of the Polish Personal Data Protection Office).

  1. Before lodging a complaint, the person may contact the Controller to clarify the matter.
  1. Contacting the Controller does not restrict the right to lodge a complaint.

§ 21. Automated decision-making

  1. The Controller does not make decisions concerning users based solely on automated processing that would produce legal effects concerning them or similarly significantly affect them.
  1. The automatic:
  1. filtering of the catalogue,
  2. calculation of prices,
  3. calculation of deposits,
  4. grouping of products,
  5. preliminary completion of company data on the basis of a NIP

does not constitute decision-making that produces legal effects.

  1. Availability, the possibility of performance, terms of sale and the content of an offer require confirmation by a person.

§ 22. Data security

  1. The Controller applies technical and organisational measures appropriate to the type of data and the risk.
  1. These measures may include:
  1. access controls,
  2. individual administrator accounts,
  3. password protection,
  4. encryption in transit,
  5. backups,
  6. software updates,
  7. limiting the number of persons with access,
  8. logging administrative operations,
  9. protecting forms against abuse,
  10. secure offer token mechanisms.
  1. Despite the security measures applied, using the Internet is not entirely free of risk.
  1. The user should not provide excessive data, special categories of data or information not required to handle the matter in forms.

§ 23. Links to other websites

  1. The Website may contain links to other websites, in particular:
  1. Tawerny Rybnej Skipper,
  2. Restauracji Golonkarnia,
  3. Skipper Delikatesy,
  4. public registers,
  5. maps and external information services.
  1. After accessing an external website, that website's own privacy policy applies.
  1. The Controller is not responsible for the data processing rules applied by independent operators of external websites.

§ 24. Amendments to the Privacy Policy

  1. This Policy may be amended, in particular, in the event of:
  1. a change in the law,
  2. a change in the scope of the Website's services,
  3. the launch of new forms,
  4. a change of technical service providers,
  5. the implementation of new cookie tools,
  6. a change in the Controller's details,
  7. the need to clarify information.
  1. The current version of this Policy is published on the Website.
  1. In the event of material changes, the Controller may display additional information on the Website.
  1. An amendment to this Policy does not affect the lawfulness of processing carried out before the amendment takes effect.

§ 25. Final provisions

  1. Matters not regulated by this Policy are governed by the GDPR (RODO), the Polish Personal Data Protection Act (ustawa o ochronie danych osobowych), the Polish Electronic Communications Law (Prawo komunikacji elektronicznej), and other applicable laws.
  1. This Policy should be read together with:
  1. the Terms and Conditions of the Website,
  2. the Cookie Policy,
  3. the settings in the consent management panel.
  1. This Policy enters into force on 18 July 2026.

Wina Lane

MACIEJ STOLARSKI FIRMA HANDLOWO USŁUGOWA „PERFECTA”

ul. Ulubiona 9, 32-085 Modlnica

NIP: 6761763789, REGON: 120771405

Sales and collection point

Skipper
ul. Krakowskie Przedmieście 116A/7, 32-087 Zielonki

Monday: closed Tuesday–Thursday: 12:00–19:00 Friday–Saturday: 12:00–20:00 Sunday: 12:00–19:00

Contact

About us+48 603 073 076biuro@wina-lane.pl

Related places

Tawerna Rybna SkipperGolonkarnia RestaurantSkipper Delikatesy

Legal information

Terms and conditionsPrivacy policyCookie policy

Alcohol is sold exclusively to adults. The buyer's age may be verified upon personal collection.

© 2026 Wina Lane

Confirm your age

This website presents alcoholic beverages and is intended exclusively for adults. This confirmation does not replace age verification upon personal collection.

Leave the website