EVEREST

(A) Privacy

Privacy
notice

How Everest Enterprise Solutions collects, uses and protects the personal data of people who visit this site and write to us.

Last updated 22 September 2026 In force from the date of publication

01Who processes your data

The controller of the personal data collected through this site is:

Company
Everest Enterprise Solutions sp. z o.o.
Registered office
ul. Szlak 77/222, 31-153 Kraków, Poland
Register
KRS 0001126406 — District Court for Kraków-Śródmieście in Kraków, 11th Commercial Division of the National Court Register
Identifiers
NIP 6832141524 · REGON 529985271
Share capital
PLN 5,000

We have not appointed a data protection officer: the law does not require us to. For anything to do with personal data, write to the email address above with “personal data” in the subject line.

We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the Polish Personal Data Protection Act of 10 May 2018.

02What data we collect

Data you give us

We only collect the data you send us of your own accord in order to get in touch:

  • first and last name;
  • email address;
  • your company or organisation, if you mention it;
  • telephone number, if you leave one;
  • the content of the message you write to us, including any technical information about the vessel or installation that you choose to share.

When you send the contact form, the data is transmitted to Wix Forms and the enquiry appears in the site's administration area, with a notification to office@everest-entprise.com. If sending fails — because your browser blocks the request, for instance — the site opens your mail program with the message already written, and it is sent from your own address. The data therefore reaches us as an ordinary email. If you use a form that submits directly, the message is also collected and stored in the site administration area provided by Wix.

Data collected automatically

Like every site published on the internet, the server hosting these pages — operated by Wix.com Ltd. — records the technical data needed to serve them and to keep them secure: IP address, date and time of the request, page requested, browser and operating system, referring page. These logs are for diagnostics and abuse protection, not to identify or profile you.

Third-party data you pass to us

If your message contains the details of a colleague, a shipowner or a supplier, it is you who is passing them to us: please keep to what is necessary and inform the person concerned. We process those details in order to answer your enquiry, and we provide this notice for you to pass on where necessary, under Article 14 GDPR.

03Why we process it and on what legal basis

PurposeLegal basisFor how long
Answering enquiries and preparing an offerArt. 6(1)(b) GDPR — steps taken at your request before entering into a contractUp to 12 months from the last contact, if no contract follows
Performing and managing the supply or service contractArt. 6(1)(b) GDPR — performance of the contractFor the duration of the contract
Invoicing, accounting and tax obligationsArt. 6(1)(c) GDPR — legal obligation (Polish Tax Ordinance, Accounting Act)5 years from the end of the relevant tax year
Defending or pursuing legal claimsArt. 6(1)(f) GDPR — our legitimate interestUntil claims become time-barred (as a rule 3 years between businesses, 6 years otherwise)
Site security and abuse prevention (server logs)Art. 6(1)(f) GDPR — our legitimate interestNormally 30 days, unless an investigation is under way
Commercial messages about similar products, by emailArt. 6(1)(f) GDPR and Art. 398 of the Polish Electronic Communications Law — with your consent where requiredUntil you object or withdraw consent

We take no payments through this site and we do not process card data. We do not collect special categories of data (Art. 9 GDPR): please do not enter any in the contact form.

04Who else can see your data

We do not sell or trade personal data. We disclose it only to those we need in order to work, and always on the basis of a processor agreement (Art. 28 GDPR) or a legal obligation:

  • Wix.com Ltd. (Tel Aviv, Israel), which hosts this site and provides its infrastructure, server logs and administration area: it acts as a processor under its own data processing agreement (DPA);
  • Microsoft Ireland Operations Limited (Microsoft 365), which provides the company mailbox through which your messages reach us;
  • the IT providers who maintain and support the site;
  • our accountants and legal or tax advisers, within the scope of their engagement;
  • couriers and forwarders, when we have to deliver something to you;
  • our technical subcontractors, where work on board requires it;
  • public authorities, where the law obliges us.

Wix in turn uses its own sub-processors — mainly cloud infrastructure providers located in the European Union and the United States — listed in the contractual documentation Wix publishes.

05Transfers outside the European Union

The site is hosted by Wix.com Ltd., a company based in Tel Aviv, Israel. The transfer of data to Israel takes place on the basis of European Commission adequacy decision 2011/61/EU, confirmed on 15 January 2024: the European Union recognises that the country provides a level of data protection essentially equivalent to its own, so no further safeguards are required. For any Wix sub-processors located in the United States, the standard contractual clauses under Art. 46 GDPR apply and, where the provider adheres to it, the EU-US Data Privacy Framework.

Email

The mailbox office@everest-entprise.com is hosted on Microsoft 365. Our contracting party is Microsoft Ireland Operations Limited, based in Dublin. Microsoft undertakes to store and process customer data for its enterprise cloud services within the EU Data Boundary — the European Union and the EFTA countries; limited transfers to the United States remain possible for systems security, covered by the EU-US Data Privacy Framework, to which Microsoft Corporation adheres.

Content loaded from third parties

Some elements of the pages — typefaces, animation and 3D libraries, images — are served by external content delivery networks. When your browser requests them, the operator of that service receives your IP address and the technical data of the request (browser, operating system, referring page):

  • Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — Google Ireland Limited, Dublin, with transfers to Google LLC in the United States covered by the EU-US Data Privacy Framework: serves the site’s typefaces;
  • jsDelivr (cdn.jsdelivr.net) — an open-source delivery network, used for the JavaScript libraries and for the map’s geographic data;
  • Cloudflare (cdnjs.cloudflare.com) — Cloudflare, Inc., United States, which adheres to the EU-US Data Privacy Framework: serves some animation libraries;
  • Wix (static.wixstatic.com) — the store of the site’s photographs and videos.

These providers receive the technical data needed to deliver the requested file: they do not set cookies on our behalf and we do not use them to profile you. You can ask us for a copy of the safeguards applied by writing to the address above.

06How long we keep the data

The periods are set out in the table in section 03. In general we keep data for as long as the purpose for which we collected it requires, and afterwards for as long as the law obliges us to or as long as we might need it to defend ourselves. Once those periods end, the data is deleted or anonymised.

07Your rights

In relation to your personal data you have the right to:

  • access the data concerning you and obtain a copy of it (Art. 15 GDPR);
  • rectify it if it is wrong or incomplete (Art. 16 GDPR);
  • erase it, in the cases set out in Art. 17 GDPR;
  • restrict its processing (Art. 18 GDPR);
  • receive it in a readable format and transfer it to another controller, where the processing is based on the contract or on consent and is automated (Art. 20 GDPR);
  • object to processing based on our legitimate interest, including direct marketing (Art. 21 GDPR);
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise them, simply write to office@everest-entprise.com. We reply within one month; if the request is complex we may extend this by two months, and we will tell you.

Complaint to the supervisory authority

If you believe the processing of your data breaks the law, you can lodge a complaint with the Polish supervisory authority:

Authority
President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, PUODO)
Address
ul. Stawki 2, 00-193 Warsaw, Poland

08Providing data and automated decisions

Giving us your data is voluntary, but without contact details we cannot reply to you; in the case of a contract, without identification and tax details we cannot issue the documents the law requires.

We do not take decisions based solely on automated processing and we do not carry out profiling within the meaning of Art. 22 GDPR.

10Security

We apply technical and organisational measures appropriate to the risk: encrypted connection (HTTPS), access limited to the people who need it, authentication on mailboxes, backups and up-to-date systems.

No system is immune to incidents: if a personal data breach occurred that posed a high risk to your rights, we would inform you and notify PUODO within the periods set by Articles 33 and 34 GDPR.

11Changes to this notice

We may update this document when our tools, our providers or the law change. The version in force is always the one published on this page, with the update date shown at the top. Substantial changes will be flagged clearly.

This document is available in Italian, English, Polish and German. In case of discrepancy, the Polish version prevails for matters governed by Polish law.