The administrator of the website www.ciarko.pl and at the same time the controller of your personal data is Ciarko sp. z o.o. sp. k. ul. Okulickiego 10 38-500 Sanok, Poland
In order to contact the Administrator, you can write to us at the following e-mail address: ciarko@ciarko.pl
The purpose of the Policy is to clarify the provisions of the Regulations in accordance with the applicable requirements provided for by applicable law on the processing of personal data.
Our goal is also to properly inform you about matters related to the processing of personal data, particularly in light of the new provisions on personal data protection, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("GDPR"). Therefore, in this document we provide information about the legal basis for processing personal data, the methods of collecting and using it, and the rights of data subjects in this regard.
Personal data and their processing
Personal data includes all information that allows for the identification of a natural person ("Data"). The Administrator collects personal data to the minimum extent necessary to achieve the purposes specified below. Its goal is to ensure that every user of the website, contact forms, and customers placing orders is aware of what personal data is being processed, for what purpose, by whom, and what rights they have in connection with such processing. Data processing is not always direct (e.g., when obtaining specific information when placing an order). The specific nature of the website means that the Administrator also collects data indirectly, using, among others, so-called cookies. Providing personal data is voluntary, but some of it may be necessary to ensure the proper use of the website and the Administrator's services.
How, on what legal basis and what type of personal data does the Controller process?
We strive to be transparent about the methods and legal basis for personal data processing, as well as the purposes for which the Controller processes personal data. We ensure that the necessary information is always provided to each person whose personal data we process as the Controller. To ensure our explanation of these matters is as clear as possible, we present the following summary of personal data processing operations.
At the same time, we would like to point out that whenever we process personal data based on the legitimate interest of the data controller, we strive to analyze and balance our interests and the potential impact on the data subject (both positive and negative) against that person's rights under data protection law. We do not process personal data based on our legitimate interest if we conclude that the impact on the data subject would outweigh our interests (in which case we may process personal data if, for example, we have appropriate consent or if it is required or permitted by law).
General information
Individuals who visit the Site, place an Order, or contact Us via the contact form on the Site have control over the personal data they provide to Us. The Site limits the collection and use of information about its users to the minimum necessary to provide them with the desired level of service, in accordance with Article 18 of the Act of 18 July 2002 on the provision of services by electronic means.
Registration on the Website
The personal data you provide to us when placing an Order on the Website, i.e. any data relating to your business activity, which may indirectly indicate a specific natural person, are processed:
- to the extent necessary to establish, shape the content, change, terminate and properly execute the Order;
- in order to process submitted complaints,
- to process other requests or inquiries that you may send to us.
In each of the above cases, the legal basis for data processing,
to a significant extent, it is necessary to perform the contract you enter into with the Company or to take steps to conclude it (Article 6, paragraph 1, letter b of the GDPR).
Furthermore, in order to fulfil the obligations imposed on us by law, e.g. the Accounting Act or tax regulations (e.g. issuing and storing invoices and accounting documents), we will also process your data relating to transactions made on the Website and information from your user account. We may also process your data in order to fulfil our obligation to apply the so-called accountability principle, i.e. the obligation to demonstrate
The Company complies with the provisions on personal data protection. In the cases listed in this paragraph, the legal basis for processing the above-mentioned data is our legal obligation (Article 6(1)(c) of the GDPR).
We will also process the following data based on the Company's legitimate interest (Article 6(1)(f) of the GDPR):
Your data, as well as the data of other users of the Website, in order to ensure the security of the services we provide electronically, including preventing possible abuse or fraud (our legitimate interest includes ensuring the security of the services, including preventing fraud and abuse).
Your data regarding orders for a specific advertisement for the purpose of establishing or pursuing our claims, as well as for the purpose of defending against such claims (our legitimate interest includes the possibility of protecting the Company's interests using legally prescribed means);
Your data provided in a question, complaint or suggestion for the purpose of responding to your questions, complaints or suggestions (our legitimate interest includes the ability to respond to questions, complaints and suggestions from customers);
Your data provided in the survey, which we may ask you to complete in order to measure the satisfaction of our customers and determine the quality of our service (our legitimate interest includes the possibility of obtaining information to improve customer service standards).
Your data, as well as the data of other users of the Website, for the purpose of conducting research and statistical analyses and for the purpose of improving the services and goods we offer (our legitimate interest includes the possibility of obtaining information in order to improve our business)
Contact form
The personal data you provide to us via the Contact Form on the Website, including your name and contact details (e-mail address), are processed to the extent necessary to respond to the message received via the Form and to contact you for this purpose.
Commercial information - marketing consent
The personal data you provide to us for the purpose of receiving commercial and marketing information from the Controller, i.e., your name, surname, and email address, are processed to the extent necessary to send you the aforementioned information based on your prior consent. Such consent may be withdrawn at any time.
Cookies
Virtually every website now uses cookies, files that are used to automatically collect personal data from website users ("Cookies"). The Administrator's Website is no exception. Information collected in this way is stored on the user's computer or other mobile device.
The primary purposes for using cookies are twofold: maintaining and saving a user's session, and ensuring security (e.g., for detecting abuse). In this respect, the use of cookies is necessary.
Cookies may not be strictly necessary, but they make using the website much easier. They are used for purposes such as:
- remembering specific user choices regarding the display of a specific message or displaying it a certain number of times,
- monitoring user activity on the website,
- collecting anonymous, aggregate statistics to improve the functionality of the website.
In this regard, the Administrator uses the services of external entities, the list of which evolves depending on market conditions and technical capabilities. These entities include:
- Google Analytics (Google Privacy Policy) – Through it, the Administrator verifies the user who has previously used the website, observes the traffic and behavior of users on the website.
It should be emphasized that at no stage is the user obligated to accept cookies. It is possible to configure the web browser to prevent cookies from being stored on the user's computer or other mobile device. It is also possible to delete existing cookies. However, failure to accept cookies may negatively impact the operation of the website and, in some cases, even prevent the use of certain features.
Automatic processing of personal data
The information we collect in connection with your use of our Website may be processed by automated means (), but this will not produce any legal effects for you or significantly affect your situation in any other way. We attach particular importance to profiling and point out that:
-
- we do not process any sensitive data for profiling purposes,
-
- for profiling purposes, we usually process data that has been aggregated by us,
-
- if we cannot achieve the goal in any other way than by profiling non-personalized or non-aggregated personal data, we use typical data for this purpose: e-mail and IP address or cookies,
-
- we profile in order to analyze or forecast the personal preferences and interests of people using our Website and to tailor the content on our Website to these preferences,
-
- we profile for marketing purposes, i.e. to tailor the marketing offer to the above-mentioned preferences.
Legal Basis for Processing
The personal data of website users are processed on the basis of obligations arising from the provisions of applicable law (all), obtained consent (commercial information), the need to perform the contract (fulfilment of the request) (Customer data) and the legitimate interest of the Administrator.
How long does the Administrator store data?
The period of data storage depends on the legal basis for their processing:
-
- in the case of consent (e.g. to provide commercial information), this period lasts until it is withdrawn,
-
- when processing data for the purpose of performing a contract – for the duration of the contract and the limitation period for claims arising therefrom,
-
- when processing data based on obligations arising from applicable legal provisions, the Administrator processes the data for as long as necessary under these provisions,
-
- when processing data as part of the legitimate interest of the Controller, processing lasts as long as this interest lasts.
The data processing period may be extended if processing is necessary to establish, pursue, or defend against legal claims. After these periods, the data is immediately deleted or anonymized.
Data recipients
Sometimes the Administrator has the right to transfer user data if it is necessary to perform services, fulfill obligations and properly comply with applicable legal provisions.
The Administrator may use the services of external entities to perform certain tasks, such as data storage, accounting, legal, marketing, or IT services. If necessary, authorized authorities may also receive data.
When entrusting data to subcontractors to achieve the Controller's purpose, there is no change of data Controller and the Controller remains responsible for their security. User data may be transferred to the following entities:
-
- other data recipients, e.g. law enforcement authorities, banks.
-
- to processors whom we commission to carry out research for a specific purpose, e.g. an IT company or a law firm,
-
- a processor, e.g. Google Analytics (Google Privacy Policy),
Does the Administrator share user data and with whom?
Beyond the above scope, data is not made available to third parties, except for situations where the user expressly gives his/her voluntary consent (which he/she may withdraw at any time), the provision of data is necessary for the performance of a contract or the provision of services and in special cases if an authorized entity requests the disclosure of data on the basis of generally applicable legal provisions.
(e.g. it is a law enforcement agency).
Each of the above-mentioned situations is carefully analyzed by the Administrator,
and the final transfer of data takes place only if it is confirmed that there is a valid and effective legal basis for requesting the disclosure of user data by these entities.
Sharing data with entities outside the EEA
The Administrator may transfer the obtained data to other entities only if the legal basis allows it.
Some of the Controller's service providers are based outside the European Economic Area (EEA). When transferring data outside the EEA, the Controller exercises increased caution. It verifies whether the deliveries guarantee a high level of personal data protection, consistent with the legal requirements applicable within the EEA and adopted case law, including the ruling of the Court of Justice of the European Union of 27 July 2020, Schrems II. It minimizes the scope of data sent outside the EEA, and in the case of using SCCs (standard contractual clauses adopted by the European Commission), it verifies whether there is a risk of personal data being breached by entities outside the EEA. It examines, among other things, the data security process and whether the shared data may potentially be of interest to third countries.
Data protection
The Administrator uses all available physical and technical means
and organizational measures to ensure proper protection of personal data. In particular, it protects it against destruction, accidental loss, disclosure to unauthorized persons, alteration, and verifies the scope of access. The Administrator exercises the rights of individuals affected by data processing.
Your Rights
The User has the following rights in connection with the processing of his/her personal data (Articles 12-21 of the GDPR):
-
- for information in terms of processed personal data, the so-called "information obligation" (in accordance with Articles 12 and 13 of the GDPR),
-
- access to the content of your personal data (in accordance with Article 15 of the GDPR),
-
- filing a request correctionspersonal data (in accordance with Article 16 of the GDPR), i.e. correcting incorrect data and supplementing incomplete data,
-
- filing a request processing restrictionspersonal data (in accordance with Article 18 of the GDPR),
-
- the right to make a request transfer your personal data to another Controller (in accordance with Article 20 of the GDPR),
-
- bringing objection to processingdata for reasons related to a particular situation (in accordance with Article 21 paragraph 1 of the GDPR), however, this right is not absolute – i.e. despite the objection, the Controller may still process personal data if it proves that there are important, legitimate grounds for processing, overriding the rights and freedoms or grounds for establishing, pursuing or defending claims,
-
- bringing objection to processing personal data for direct marketing purposes, to the extent that the processing is related to such direct marketing. This objection does not require justification or conditions for its effectiveness. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
-
- filing a request deletepersonal data (in accordance with Article 17 of the GDPR) – the so-called "right to be forgotten", this right applies when the Controller processes data unlawfully, when the user objects to the processing of data for marketing purposes and when the data must be deleted in order for the Controller to fulfill its obligation under the law.
In addition, the User has the right filing a complaint to the supervisory authority, i.e. the President of the Office for Personal Data Protection (formerly GIODO). If the user wishes to exercise any of the above rights, they may contact the Controller via the email address or at the address indicated above.