Privacy Policy
§ 1
GENERAL PROVISIONS
1. The controller of personal data collected via the website www.grafiqa.pl is Elżbieta Migoń, conducting business under the name Elżbieta Migoń GRAFIQA, entered in the Central Register and Information on Economic Activity of the Republic of Poland kept by the minister competent for economic affairs; place of business and address for service: ul. płk. Stanisława Dąbka 2, 30-732 Kraków, NIP (tax ID): 121218432, REGON: 9930042440, e-mail address: migon@grafiqa.pl, hereinafter referred to as the "Controller".
2. Personal data collected by the Controller via the website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the GDPR
§ 2
TYPE OF PERSONAL DATA PROCESSED, PURPOSE AND SCOPE OF DATA COLLECTION
1. PURPOSE AND LEGAL BASIS OF PROCESSING. The Controller processes the personal data of users of www.grafiqa.pl when a user submits the contact form. Personal data are processed on the basis of Article 6(1)(f) GDPR, i.e. the legitimate interest of the business.
2. TYPE OF PERSONAL DATA PROCESSED. When using the contact form, the user provides
a) first name and surname,
b) e-mail address,
c) telephone number.
3. PERSONAL DATA RETENTION PERIOD. Users' personal data are stored by the Controller:
a) where the basis for processing is the performance of a contract, for as long as necessary to perform the contract, and thereafter for a period corresponding to the limitation period for claims. Unless a specific provision states otherwise, the limitation period is ten years, and for claims for periodic payments and claims related to business activity – three years.
b) where the basis for processing is consent, until consent is withdrawn, and after withdrawal for a period corresponding to the limitation period for claims that may be raised by or against the Controller. Unless a specific provision states otherwise, the limitation period is ten years, and for claims for periodic payments and claims related to business activity – three years.
4. While the website is being used, additional information may be collected, in particular: the IP address assigned to the user's computer or the external IP address of the Internet provider, domain name, browser type, access time and operating system type.
5. Navigation data may also be collected from users, including information about the links they choose to click or other actions taken on the website. The legal basis for such activities is the Controller's legitimate interest (Article 6(1)(f) GDPR) in facilitating the use of services provided electronically and improving the functionality of those services.
6. Providing personal data is voluntary.
7. Personal data will also be processed by automated means in the form of profiling, provided that the user consents to this under Article 6(1)(a) GDPR. The consequence of profiling will be the assignment of a profile to the person concerned in order to make decisions regarding them or to analyse or predict their preferences, behaviour and attitudes.
8. The Controller takes particular care to protect the interests of data subjects and, in particular, ensures that the data it collects are:
a) processed lawfully,
b) collected for specified, lawful purposes and not further processed in a manner incompatible with those purposes,
c) factually correct and adequate in relation to the purposes for which they are processed, and stored in a form that permits identification of data subjects for no longer than is necessary to achieve the purpose of processing.
§ 3
DISCLOSURE OF PERSONAL DATA
1. Users' personal data are transferred to service providers used by the Controller to run the website. Depending on contractual arrangements and circumstances, the service providers to whom personal data are transferred either follow the Controller's instructions as to the purposes and means of processing (processors) or determine the purposes and means of processing themselves (controllers).
2. Users' personal data are stored exclusively within the European Economic Area (EEA).
§ 4
RIGHT TO CONTROL, ACCESS AND RECTIFY ONE'S OWN DATA
1. The data subject has the right of access to their personal data and the right to rectification, erasure, restriction of processing, the right to data portability, the right to object, and the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
2. Legal basis for the user's request:
a) Access to data – Article 15 GDPR
b) Rectification of data – Article 16 GDPR.
c) Erasure of data (the so-called right to be forgotten) – Article 17 GDPR.
d) Restriction of processing – Article 18 GDPR.
e) Data portability – Article 20 GDPR.
f) Objection – Article 21 GDPR
g) Withdrawal of consent – Article 7(3) GDPR.
3. To exercise the rights referred to in point 2, an appropriate e-mail may be sent to: migon@grafiqa.pl
4. Where a user exercises any of the above rights, the Controller shall comply with or refuse the request without undue delay, and in any event within one month of receipt. However, if – owing to the complexity or number of requests – the Controller is unable to comply within one month, it shall do so within a further two months, having informed the user within one month of receipt of the request of the intended extension and the reasons for it.
5. If the data subject considers that the processing of personal data infringes the GDPR, they have the right to lodge a complaint with the President of the Personal Data Protection Office.
§ 5
"COOKIES"
1. The Controller's website uses "cookies".
2. The installation of "cookies" is necessary for the proper provision of services on the website. "Cookies" contain information necessary for the website to function properly, and they also make it possible to compile general statistics on visits to the website.
3. Two types of "cookies" are used on the website: "session" and "persistent".
a) "Session" cookies are temporary files stored on the user's end device until they log out (leave the website).
b) "Persistent" cookies are stored on the user's end device for the time specified in the cookie parameters or until they are deleted by the user.
4. The Controller uses its own cookies to better understand how users interact with the website's content. The files collect information on how the user uses the website, the type of website from which the user was redirected, and the number of visits and duration of the user's visit to the website. This information does not record any specific personal data of the user, but is used to compile statistics on the use of the website.
5. The user has the right to decide on the access of "cookies" to their computer by selecting the appropriate settings in their browser window in advance. Detailed information on the options and methods of handling "cookies" is available in the software (web browser) settings.
§ 6
FINAL PROVISIONS
1. The Controller applies technical and organisational measures ensuring protection of the personal data processed appropriate to the risks and categories of data protected, and in particular protects the data against disclosure to unauthorised persons, removal by an unauthorised person, processing in breach of applicable law, and alteration, loss, damage or destruction.
2. The Controller provides appropriate technical measures to prevent unauthorised persons from obtaining and modifying personal data transmitted electronically.
3. In matters not regulated by this Privacy Policy, the provisions of the GDPR and other relevant provisions of Polish law shall apply accordingly.