1. INTRODUCTION
THEP Spółka z ograniczoną odpowiedzialnością, operating under the brand PROTEGRA (the “Company”, also referred to as “we”, “us” or “our”), respects the privacy of the visitors of our website https://protegra.org (the “Website”) and of all other persons who provide personal data to us. This Privacy Policy (the “Policy”) explains how we process personal data and describes the legal rights that you have in relation to the processing of your personal data.
The controller of your personal data is THEP Spółka z ograniczoną odpowiedzialnością, KRS 0001182451, NIP 5253053236, REGON 542200222, registered address Chmielna 26, lok. 65, 00-020 Warszawa, Poland, e-mail dpo@protegra.io.
Our goal is to ensure the protection of personal data. In pursuing this goal, we consistently adhere to the requirements of European Union and national legislation. The principal legal act governing the processing of personal data is Regulation (EU) 2016/679 (the “GDPR”), read together with applicable Polish data protection legislation. References to “personal data” in this Policy mean any information that could reasonably be used to identify you, whether directly or indirectly.
This Policy provides a general overview of how we process personal data. Additional information may be provided in service contracts and in other documents. The cookie-related sections of this Policy explain how we use cookies and similar technologies on the Website.
2. WHO THIS POLICY APPLIES TO
This Policy applies to all persons who use, have used, or intend to use our services, as well as to those who are indirectly related to such services (for example, business owners, representatives or employees of our clients), persons who have any contractual relationship with us, persons whose personal data have otherwise become known to us, and anyone who visits our Website (referred to as “you” or the “Client”).
3. CATEGORIES OF PERSONAL DATA
Depending on the service provided or the nature of our cooperation, we process different categories of personal data. In each case, we process only the data that are necessary for the relevant purpose. The main categories include, but are not limited to:
* Identification data: name and surname.
* Contact details: e-mail address, telephone number and, where provided, correspondence address.
* Company and professional details: the name of the company or organisation you represent and your role or position.
* Enquiry content: the information you choose to include in the “Details” field or otherwise provide when contacting us through the Website, by e-mail or by other means.
* Data relating to relations with legal entities: data provided by you or obtained from public registers for the purpose of establishing or performing a transaction with the relevant legal entity.
* Financial data: data on invoices, accounts and transactions, where we are required to process such data in order to provide our services or to comply with the law.
* Marketing and communication data: your consent status and preferences relating to newsletters and other marketing communications.
* Technical data: data collected automatically through cookies and similar technologies when you visit the Website, as described below.
We are responsible for the accuracy of your data, so we would be grateful if you would inform us of any change in your personal data.
4. PURPOSES OF PROCESSING
We process personal data for the following main purposes:
* Responding to enquiries. When you complete the enquiry form on the Website or contact us directly, we use your data to respond to your request, provide the information you seek and, where relevant, prepare an offer.
* Providing our services and performing contracts. We collect the information necessary to do business, sign contracts and start or maintain a business relationship with you. Such processing is strictly necessary to fulfil our obligations towards you and to provide our services.
* Marketing communications. Where you have given your consent, we use your data to send you newsletters, information bulletins, and information about our services and events that may be of interest to you. You may withdraw this consent at any time.
* Recruitment. Where you send us a CV or cover letter, we use the data you provide to conduct the recruitment process. We keep such data for the duration of the relevant recruitment process, or for a longer period only with your consent.
* Compliance with legal obligations. We process personal data where necessary to comply with our legal, accounting and reporting obligations.
* Website operation and improvement. We use cookies and similar technologies to operate, secure and improve the Website.
5. LEGAL BASIS FOR PROCESSING
We process personal data only where we have a lawful basis to do so. Depending on the situation, we rely on one or more of the following bases:
* Contract. Processing is necessary for the performance of a contract with you, or to take steps at your request before entering into a contract (Article 6(1)(b) GDPR).
* Consent. Processing is based on the consent you have given, for the purposes stated in that consent and only for such purposes – for example, the sending of marketing communications (Article 6(1)(a) GDPR).
* Legitimate interest. In some cases we process data on the basis of our legitimate interests, such as responding to enquiries, ensuring the security of the Website, and developing our business. Before processing data on this basis, we verify that our legitimate interests do not override your rights and freedoms (Article 6(1)(f) GDPR).
* Legal obligation. Processing is necessary to comply with a legal obligation to which we are subject under European Union or Polish law (Article 6(1)(c) GDPR).
In most cases we receive personal data directly from you. In some cases we may also receive personal data from third parties – for example, from a representative of a potential client, or from public registers.
6. RECIPIENTS OF PERSONAL DATA
We may disclose personal data to the following categories of recipients:
* Partners with whom we jointly provide services or products;
* State institutions and authorities, and other persons performing functions delegated to them by law (for example, law enforcement agencies and tax authorities), where we are legally required to do so;
* Financial institutions and third parties such as banks, auditors, and legal and financial advisers;
* Persons managing public registers, or other persons who have the right to receive personal data from such registers;
* Other service providers acting as our data processors, such as IT and hosting providers, communication and postal service providers, and other third parties whose services we use to perform our contracts or administrative functions.
All service providers to whom we transfer personal data must follow our instructions on how they process that data. Such transfers are governed by data processing agreements. All such providers are considered data processors and must have appropriate technical and organisational measures in place to ensure an equivalent level of data protection.
7. TRANSFER OF PERSONAL DATA OUTSIDE THE EU/EEA
As a general rule, personal data are processed within the European Union / European Economic Area (EU/EEA). In certain cases, personal data may be transferred to and processed outside the EU/EEA – for example, where this is necessary for the conclusion or performance of a contract, or where data are stored using solutions whose servers are located outside the EEA. Any such transfer will be based on one of the following safeguards:
* an adequacy decision of the European Commission;
* standard data protection clauses adopted by the European Commission;
* standard data protection clauses adopted by a competent data protection authority;
* other appropriate safeguards or derogations permitted by applicable law.
8. RETENTION OF PERSONAL DATA
We retain personal data only for as long as necessary to achieve the purposes for which it was collected, including to satisfy any legal, accounting or reporting requirements. When personal data is no longer required and there is no legal obligation to retain it, we securely delete or anonymise it. Where data is processed on the basis of your consent, we retain it until you withdraw that consent, unless a longer retention period is required by law.
9. YOUR RIGHTS AS A DATA SUBJECT
Subject to the conditions and exceptions set out in the GDPR, you have the following rights in relation to your personal data:
* Right of access. You have the right to obtain confirmation as to whether we process your personal data and, if so, to access that data and information about how it is processed.
* Right to rectification. You have the right to request that we correct any personal data that you believe to be inaccurate or incomplete.
* Right to object. In the cases provided for by law, you have the right to object to the processing of your personal data, including processing for direct marketing purposes.
* Right to erasure. You may request that your personal data be deleted where it is no longer required for the purposes for which it was collected, where you consider the processing unlawful, or where deletion is required to comply with a legal obligation. In certain cases the law may prevent us from deleting data; we will inform you if such an obligation applies.
* Right to restriction of processing. In certain circumstances, you have the right to request that we restrict the processing of your personal data.
* Right to data portability. Where your personal data is processed automatically on the basis of your consent or a contract, you may request that we provide it in a structured, commonly used and machine-readable format, or that it be transferred to another controller where technically feasible.
* Right to withdraw consent. Where processing is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
* Right to refuse marketing. You may opt out of our marketing communications at any time by contacting us or by using the unsubscribe option included in such communications.
10. CHANGES TO THIS POLICY
This Policy may be amended or updated from time to time. The latest version will always be published on the Website, and we invite you to review it periodically. Any changes take effect on the day they are published on the Website.
11. SOCIAL NETWORKS AND OTHER WEBSITES
Any information that you provide to us through social media, including messages, “like” and “follow” actions, and other communications, is also controlled by the relevant social network in accordance with its own privacy policy. The Website may contain links to third-party websites. We have not reviewed and do not control such websites and are not responsible for their content or privacy practices. We recommend that you review the privacy policy of any third-party website before providing it with your personal data.
12. COOKIES - WHAT THEY ARE
Cookies are small data files which are saved to your computer or other device and allow an analysis of your usage behaviour on the Website. Cookies may collect information such as your session identifier, the time spent on the Website, pages visited, links clicked, language preferences, selected interface settings, and similar technical information. In this Policy, “cookies” also covers similar technologies such as tags, beacons and local storage.
We use the following types of cookies:
* Essential cookies: these cookies are strictly necessary for the Website to function properly. They enable navigation, access to secure areas and remembering your preferences. The Website cannot function properly without these cookies. Essential cookies do not require your consent.
* Performance / analytics cookies: these cookies collect information about how visitors use our Website, such as which pages they visit most often. This data helps us improve the Website. Information collected through these cookies is processed in a pseudonymised form and, where reported to us, is presented in aggregated statistics.
* Functionality cookies: these cookies allow the Website to remember choices you make (such as your language or region) and provide enhanced, more personal features. Where such choices are strictly necessary for a feature you have requested, these cookies are treated as essential and do not require consent. Where they are not strictly necessary, they are set only with your consent.
13. LEGAL BASIS FOR THE USE OF COOKIES
Where required by applicable law, we obtain your consent before placing non-essential cookies on your device. Essential cookies are processed as necessary to ensure the proper functioning, security and operation of the Website. You may withdraw or modify your consent at any time through the Cookie Settings available on the Website.
14. MANAGING AND DISABLING COOKIES
You can control your cookies, including enabling or disabling them, via your browser settings or through the Cookie Settings section on our Website.
For guidance by browser: Chrome | Firefox | Safari | Edge | Opera. Note that blocking all cookies (including essential ones) may prevent you from accessing certain parts or features of our Website.
15. COOKIE CONSENT
When you first visit our Website, you will be presented with a cookie banner. Essential cookies do not require consent where they are strictly necessary for the operation of the Website. Where required by applicable law, we will request your consent before placing non-essential cookies on your device. You may withdraw your consent or update your preferences at any time through the Cookie Settings section on our Website. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
16. HOW TO CONTACT US AND WHERE TO GET INFORMATION
You have the right to contact us to submit enquiries, withdraw any consent you have given, and exercise your rights as a data subject. You may contact us by e-mail at dpo@protegra.io, or at our data protection contact address: dpo@protegra.io.
If you are concerned about a possible breach of data protection law, please contact us first so that we can investigate and address your concern. If you are not satisfied with the outcome, you have the right to lodge a complaint with the competent supervisory authority. In Poland, the competent authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych – UODO), ul. Stawki 2, 00-193 Warszawa, tel. +48 22 531 03 00, website https://uodo.gov.pl. You also have the right to apply to a court of competent jurisdiction.