PRIVACY POLICY
Ad Plus Polska Sp. z o.o.
This is a translation of the Polish document available at adplus.pl/polityka-prywatnosci. In case of any discrepancy between the language versions, the Polish version prevails.
Under which laws are or may your personal data be processed?
The rules on the protection of personal data are set out, among others, in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter GDPR), in the Polish Personal Data Protection Act of 10 May 2018, and in special acts (lex specialis) under national law.
Key definitions
- "Personal data" - means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person,
- "Processing" - means any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction,
- "Controller" - or data controller - means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law,
- "Joint controller" - under Article 26 GDPR, means two or more controllers who jointly determine the purposes and means of the processing of personal data,
- "Supervisory authority" - means an independent public authority established by a Member State. The supervisory authority is the President of the Personal Data Protection Office (Poland),
- "Recipient" - means a natural or legal person, public authority, agency or another body to which the personal data are disclosed, whether a third party or not,
- "Processor" - means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller,
- "Third party" - means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data,
- "Third country" - an entity outside the EEA (European Economic Area) to which personal data are disclosed,
- "Consent" - consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her,
- "Privacy Policy" - this document, presenting information on the rules for processing personal data within the scope indicated in Article 13 GDPR - the information clause on the processing of personal data,
- "Cookie Policy" - information on the use of cookies on the website operated by the controller. The cookie policy is available on the controller's website,
- "GDPR" - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
- Who does this Privacy Policy apply to? This Privacy Policy concerns the processing of personal data of natural persons, natural persons conducting sole proprietorships, and persons acting on behalf of legal persons, i.e. persons appointed to represent a legal person, proxies, employees and/or associates acting on behalf of a legal person.
Who is the controller of personal data?
The controller of personal data is Ad Plus Polska Spółka z ograniczoną odpowiedzialnością, with its registered office in Pęcław (05-530 Góra Kalwaria), Pęcław 57A, Poland, KRS 0001227688, NIP 1231599629, REGON 544183686.
Contact details of the controller
Contact details of the controller: Ad Plus Polska Sp. z o.o., Pęcław 57A, 05-530 Góra Kalwaria, Poland, kontakt@adplus.pl, tel.: +48 22 290 03 38.
Data Protection Officer
The controller has not appointed a Data Protection Officer. Enquiries regarding the protection of personal data should be addressed directly to the controller's postal address or to the dedicated e-mail address: kontakt@adplus.pl.
For what purposes are or may your personal data be processed?
Personal data are or may be processed for the following purposes:
No.
Purpose of processing
Lawfulness of processing
Retention period
Handling enquiries addressed to the controller
Article 6(1)(f) GDPR
Until an objection to the processing is raised,
Preparing and presenting an offer
Article 6(1)(a), (f) GDPR
For approximately 2 years, or until the consent given is withdrawn or an objection to the processing is raised,
Preparing, concluding and performing a contract
Article 6(1)(b), (f) GDPR
For the duration of the contract and until the limitation period for claims arising from it expires - as a rule 6 years, and for claims connected with business activity and periodic performance - 3 years (Polish Civil Code)
Organising and delivering training or a webinar
(Accepting registrations, identifying participants, organisational contact, confirmations, links, materials, attendance verification, delivery of the training, changes of dates, cancellations, post-training materials, certificates, documenting the training, contact with the participant or the employer)
Article 6(1)(b), (f), (c) GDPR
For the duration of the contract and until the limitation period for claims arising from it expires - as a rule 6 years, and for claims connected with business activity and periodic performance - 3 years (Polish Civil Code)
Customer account handling
(Creating and maintaining an account in BUR Manager, providing access to system functions, authenticating users)
Article 6(1)(b), (f), (c) GDPR
For the period the account exists or is active, and for the period allowing claims to be pursued after its deletion (see "Establishing and defending claims")
Payment handling
(Processing online payments)
Article 6(1)(b), (f), (c) GDPR
For the period necessary to execute and settle the payment, and thereafter in accordance with accounting obligations (see "Accounting and tax obligations")
Funding administration
(Settlement of a project financed from public funds)
Article 6(1)(c) GDPR (legal obligation) or Article 6(1)(b) GDPR - depending on whether the documentation obligation arises directly from a legal provision (e.g. the implementing act, EU regulations on funds) or only from the funding agreement
Approximately 5 years from 31 December of the year in which the project was completed or settled - the exact period follows from the specific funding agreement and the programme guidelines
Accounting and tax obligations
(Issuing and storing invoices, keeping accounts, archiving documents, settlements)
Article 6(1)(c) GDPR
5 years counted from the end of the calendar year in which the tax obligation arose (Article 74 of the Accounting Act in conjunction with Article 70 of the Tax Ordinance)
Complaint handling
Article 6(1)(b) GDPR and Article 6(1)(c) GDPR (where the obligation arises from consumer law, e.g. on warranty)
Until the complaint procedure ends and until the limitation period for claims on that account expires (as a rule 6 years - Article 118 of the Civil Code)
Direct marketing by electronic and/or telephone means
(Sending commercial and marketing information regarding the controller's own products and services)
Article 6(1)(a) GDPR
Until consent is withdrawn or an objection is raised
Establishing and defending claims
Article 6(1)(f) GDPR
Until the limitation period for claims expires - as a rule 6 years, and for claims connected with business activity and periodic performance 3 years (Article 118 of the Civil Code)
Disclosure of personal data by the controller
Personal data are or may be disclosed by the controller:
- to recipients providing services to the controller on the basis of Article 28 GDPR - entrustment of the processing of personal data. The categories of recipients may be: providers of IT infrastructure at software and hardware level, website hosting providers, and other entities to which the controller has entrusted the processing of personal data. A list of the entities to which the controller has entrusted the processing of personal data is available at the request of the data subject,
- to recipients cooperating with the controller. The categories of recipients to which personal data may be disclosed are entities operating in the area of audits, postal services, courier services, financial institutions, law firms and notarial offices. Once personal data are disclosed, the recipient to which the data were disclosed becomes their controller. A list of the entities to which the controller has disclosed personal data is available at the request of the data subject,
- to recipients that are public or state authorities. The categories of recipients may be authorities such as the Tax Office, the Police, courts, the Personal Data Protection Office or other entities to which the controller discloses personal data under applicable law. Once personal data are disclosed, the recipient to which the data were disclosed becomes their controller. A list of the entities to which the controller has disclosed personal data is available at the request of the data subject.
Transfer of personal data to a third country (i.e. outside the EEA)
- Personal data are transferred to a third country, i.e. outside the EEA. Where personal data are transferred outside the European Economic Area, such a transfer may take place only on the terms set out in Chapter V GDPR:
- on the basis of Article 45 GDPR - transfer on the basis of an adequacy decision,
- on the basis of Article 46 GDPR - transfer subject to appropriate safeguards, including the use of standard data protection clauses adopted by the European Commission,
- The transfer of personal data outside the EEA may involve the risk that sufficient security of personal data is not ensured. Where a risk connected with the transfer of personal data outside the EEA arises, the controller provides such information in this Privacy Policy,
- A list of entities outside the EEA to which the controller discloses personal data is available at the request of the data subject,
- List of entities that may transfer personal data outside the EEA and that may not provide sufficient protection of personal data as required by the GDPR:
- No.
- Name of the entity
- Link to information
- Possible negative consequences for the data subject
- https://policies.google.com/terms?hl=en&gl=be
- unauthorised access to data,
- loss of control over one's data,
- inability to exercise the rights granted under the GDPR,
- other negative consequences indicated in recital (75) of the GDPR preamble: material and non-material damage
- Google Maps
- https://www.google.com/intl/en_be/help/terms_maps/
- unauthorised access to data,
- loss of control over one's data,
- inability to exercise the rights granted under the GDPR,
- other negative consequences indicated in recital (75) of the GDPR preamble: material and non-material damage
- Microsoft
- https://www.microsoft.com/en/servicesagreement/
- unauthorised access to data,
- loss of control over one's data,
- inability to exercise the rights granted under the GDPR,
- other negative consequences indicated in recital (75) of the GDPR preamble: material and non-material damage
- Meta (Facebook)
- https://www.facebook.com/privacy/policy/
- unauthorised access to data,
- loss of control over one's data,
- inability to exercise the rights granted under the GDPR,
- other negative consequences indicated in recital (75) of the GDPR preamble: material and non-material damage
In which circumstances is providing personal data a statutory or contractual requirement or a condition for concluding a contract?
Providing personal data is:
No.
Purpose of processing
Lawfulness of processing
Provision of personal data
Handling enquiries addressed to the controller
Article 6(1)(f) GDPR
Voluntary; failure to provide personal data will make it impossible to conduct and handle correspondence,
Preparing and presenting an offer
Article 6(1)(a), (f) GDPR
Voluntary; failure to provide personal data will make it impossible to present and discuss an offer,
Preparing, concluding and performing a contract
Article 6(1)(b), (f) GDPR
Contractual; failure to provide personal data will make it impossible to prepare, conclude and perform the provisions of the contract,
Organising and delivering training or a webinar
(Accepting registrations, identifying participants, organisational contact, confirmations, links, materials, attendance verification, delivery of the training, changes of dates, cancellations, post-training materials, certificates, documenting the training, contact with the participant or the employer)
Article 6(1)(b), (f), (c) GDPR
Contractual; failure to provide personal data will make participation in training and/or webinars impossible,
Customer account handling
(Creating and maintaining an account in BUR Manager, providing access to system functions, authenticating users)
Article 6(1)(b), (f), (c) GDPR
Contractual; failure to provide personal data will make it impossible to manage the customer account,
Payment handling
(Processing online payments)
Article 6(1)(b), (f), (c) GDPR
Contractual; failure to provide personal data will make it impossible, for example, to monitor payments and perform the provisions of the contract,
Funding administration
(Settlement of a project financed from public funds)
Article 6(1)(c) GDPR (legal obligation) or Article 6(1)(b) GDPR - depending on whether the documentation obligation arises directly from a legal provision (e.g. the implementing act, EU regulations on funds) or only from the funding agreement
Contractual and statutory, and necessary for performance between the parties to the contract and for fulfilling the controller's obligations under the law,
Accounting and tax obligations
(Issuing and storing invoices, keeping accounts, archiving documents, settlements)
Article 6(1)(c) GDPR
Contractual and statutory, and necessary for performance between the parties to the contract and for fulfilling the controller's obligations under the law,
Complaint handling
Article 6(1)(b), (c) GDPR
Contractual and statutory, and necessary for performance between the parties to the contract and for fulfilling the controller's obligations under the law,
Direct marketing by electronic and/or telephone means
(Sending commercial and marketing information regarding the controller's own products and services)
Article 6(1)(a) GDPR
Voluntary; failure to provide personal data will make it impossible to send commercial and marketing information,
Establishing and defending claims
Article 6(1)(f) GDPR
Voluntary; failure to provide personal data will make it more difficult for the parties to pursue any claims,
Processing of personal data on the basis of the data subject's consent
Where personal data are processed on the basis of consent given by the data subject (Article 6(1)(a) GDPR):
No.
Purpose of processing
Lawfulness of processing
Processing based on consent (Article 6(1)(a) GDPR)
Preparing and presenting an offer
Article 6(1)(a) GDPR
The data subject has the right to withdraw the consent given at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal. Withdrawal of consent should be sent to the e-mail address: kontakt@adplus.pl,
Direct marketing by electronic and/or telephone means
(Sending commercial and marketing information regarding the controller's own products and services)
Article 6(1)(a) GDPR
Processing of personal data on the basis of the legitimate interest pursued by the controller
Where personal data are processed on the basis of the legitimate interest pursued by the controller (Article 6(1)(f) GDPR):
No.
Purpose of processing
Lawfulness of processing
Processing based on Article 6(1)(f) GDPR
Handling enquiries addressed to the controller
Article 6(1)(f) GDPR
Conducting efficient communication with persons contacting the controller, ensuring proper handling of enquiries and building relationships with (potential) customers and other persons interested in the controller's activity,
Preparing and presenting an offer
Article 6(1)(f) GDPR
Acquiring customers and conducting offer-related activities necessary for the development of the controller's business, in particular where the offer is addressed to a representative or employee of an entity (a potential business customer) who will not personally be a party to the future contract,
Preparing, concluding and performing a contract
Article 6(1)(f) GDPR
Conducting business activity by concluding and performing contracts with customers that are legal entities (e.g. employers, companies) - as regards the data of natural persons representing those entities or acting on their behalf (contact persons, representatives) who are not personally a party to the contract,
Organising and delivering training or a webinar
(Accepting registrations, identifying participants, organisational contact, confirmations, links, materials, attendance verification, delivery of the training, changes of dates, cancellations, post-training materials, certificates, documenting the training, contact with the participant or the employer)
Article 6(1)(f) GDPR
Ensuring the proper organisation and delivery of the training or webinar, including communication with participants registered by an employer or another entity organising or financing their participation, and building relationships with participants in connection with the training activity conducted,
Customer account handling
(Creating and maintaining an account in BUR Manager, providing access to system functions, authenticating users)
Article 6(1)(f) GDPR
Ensuring efficient, functional and secure access to the customer account for persons acting on its behalf (employees, representatives), including proper authentication of users and prevention of unauthorised access to the account,
Payment handling
(Processing online payments)
Article 6(1)(f) GDPR
Ensuring efficient and secure financial settlements with customers, including legal entities, and counteracting abuse connected with online payments,
Establishing and defending claims
Article 6(1)(f) GDPR
The ability to establish, pursue or defend against claims connected with the controller's activity, e.g. in complaint, settlement, court or enforcement proceedings - an interest indicated directly as an example of a controller's legitimate interest in recital 47 GDPR,
Processing of personal data using social media
The controller may run a fan page through social media such as Facebook (Meta Platforms Ireland Limited), Instagram, LinkedIn, YouTube and Google. Where the controller determines the purposes and means of processing, it becomes the controller of those data and entrusts the processing of personal data to the social media. Where personal data are processed by social media for purposes not determined by the controller, the controller is not responsible for the further processing of personal data, including through the cookies, profiling tools, statistics tools and other purposes used by them, and therefore is not responsible for the consequences of breaches of the security of personal data processing by social media. In the case of the controller's fan page on Facebook, personal data may be transferred outside the EEA (to a third country), to entities that may not guarantee a sufficient level of protection of personal data and privacy, and may not ensure that the rights and/or freedoms of data subjects can be exercised. The negative consequences of transferring personal data outside the EEA may include material or non-material damage, loss of control over one's data, and the inability to exercise the rights or freedoms of data subjects granted under the GDPR. The use of the Facebook fan page by natural persons is entirely voluntary and depends solely on the decision of the data subject. In addition, the negative consequences for the protection of personal data and the privacy of users of the fan page run by the controller may include, among others (based on recital 75 GDPR): material or non-material damage, discrimination, identity theft, identity fraud, financial loss, damage to reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage, deprivation of the rights and freedoms of a natural person or of the ability to exercise control over their personal data, and other material and non-material consequences for a natural person. Every Facebook user may, within the rights available under the currently applicable laws on privacy and personal data protection, request exhaustive information from the social media on the above breach and pursue claims on their own account (Articles 80 and 82 GDPR). Users of the fan page may lodge a complaint directly with the President of the Personal Data Protection Office via the form available at: https://uodo.gov.pl/pl/.
Joint controllers and joint controllership of personal data - social media
The controller runs or may run a fan page on social media (Facebook, LinkedIn). In such a situation, joint controllership of personal data may occur. In accordance with Article 26 GDPR, the above joint controllers have made joint arrangements regarding their obligations under the GDPR. Information on the joint arrangements between the joint controllers is available at:
a) Facebook: https://www.facebook.com/legal/controller_addendum,
b) LinkedIn: https://legal.linkedin.com/pages-joint-controller-addendum.
Information on automated decision-making, including profiling
When you visit the controller's website, you are not subject to automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR. At the same time, in connection with the marketing tools used on the website (including Meta Pixel and FastTony), profiling for marketing purposes may occur, in particular remarketing and ad matching. This profiling does not produce legal effects concerning you and does not similarly significantly affect you. Information on the cookies used by the controller is available in the Cookie Policy, available on the website as a separate document.
The controller uses the services of entities such as Google and Google Maps, in which profiling may occur; information on that profiling by the above entities is available in the privacy policies published on the websites of those entities:
- Google: https://policies.google.com/terms?hl=en&gl=be
- Google Maps: https://www.google.com/intl/en_be/help/terms_maps/.
What is the source of the data?
Personal data may:
- come directly from the data subject,
- come indirectly from the data subject: from entities cooperating with the controller,
- in the case of legal persons, the source of personal data may be publicly available registers (e.g. the National Court Register) and the legal person that provides the personal data of persons appointed on its behalf to represent it or to perform the arrangements concluded between the parties (e.g. a contract).
What scope of personal data is processed?
The controller processes ordinary personal data and only to the extent necessary to fulfil the purposes indicated in this Privacy Policy, including first name and surname, telephone number and/or e-mail address, registration data of a legal person or sole proprietorship, correspondence details, bank account number and other personal data. In accordance with the principle of minimisation, we process only such scope of personal data as is necessary to fulfil the purpose of processing or as follows from the currently applicable law.
What rights does the data subject have?
You have the right to request that the controller give effect to the following rights:
- the right of access to the personal data concerning the data subject,
- the right to rectification of personal data,
- the right to erasure of personal data,
- the right to restriction of processing of personal data,
- the right to object to processing,
- the right to data portability,
- the right to receive a copy of one's personal data.
- Owing to the individual purposes of processing referred to in this Privacy Policy, the exercise of data subjects' rights may be limited in whole or in part, for example because of applicable laws which oblige the controller to process the data.
Who is the supervisory authority?
You have the right to lodge a complaint with the supervisory authority, i.e. the President of the Personal Data Protection Office (Poland), which is the controller's supervisory authority.
Under Article 77 GDPR you may also lodge a complaint with the supervisory authority of the EU or EEA Member State of your habitual residence, of your place of work, or of the place of the alleged infringement. The GDPR applies in the same wording across the entire EU, so a complaint filed with your national authority (for example the AEPD in Spain) is examined under the same rules.
How do we secure personal data?
In order to protect privacy and personal data, the controller has implemented appropriate technical and organisational measures to ensure the security of the processing of personal data.
Notification of a personal data breach
In accordance with Article 34 GDPR, where a personal data breach occurs that is likely to result in a high risk to the rights or freedoms of natural persons, the controller notifies the data subject of such a breach without undue delay. In accordance with Article 34 GDPR, personal data may be processed in connection with the occurrence of a breach as referred to above. The legal basis for processing personal data is Article 6(1)(c) GDPR. Where a personal data breach occurs, the controller will take all possible and available technical and organisational measures to meet the requirements set out in Articles 33 and 34 GDPR.
Entrustment of the processing of personal data to Ad Plus Polska Sp. z o.o. (Article 28 GDPR)
Depending on the type of service or product ordered, a situation may arise in which the controller processes personal data on behalf of the customer and on the customer's documented instructions, acting as a processor within the meaning of Article 4(8) and Article 28 GDPR. This applies only to services whose performance requires the processing of personal data entrusted by the customer. In such cases, before the processing of personal data begins, the parties are obliged to conclude a personal data processing agreement meeting the requirements set out in Article 28 GDPR. If the nature of the service or product ordered requires the conclusion of a personal data processing agreement, please contact the controller before the service begins. The controller will provide a draft personal data processing agreement and all information necessary to conclude it. Concluding a personal data processing agreement is a condition for the controller to begin processing data as a processor, to the extent required by the GDPR.