1. General regulations
1. The administrator of personal data collected via the website open-service.pl is a company Open-Service Marcin Dudek, headquarters adress: Mokrzyska ul. Na Stoku 6, 32-800 Brzesko, Poland, NIP: 873-270-59-22, entered in the Central Register and Information on Economic Activity, hereinafter referred to as the "Administrator", being also the Service Provider. Place of business: Mokrzyska ul. Na Stoku 6, 32-800 Brzesko, Poland, mailing address: Mokrzyska ul. Na Stoku 6, 32-800 Brzesko, Polska, e-mailing address: email@example.com.
2. Personal data collected by the Administrator via the website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free flow of such data and repealing Directive 95/46 / EC (general regulation on data protection), hereinafter referred to as the GDPR and the Act on the protection of personal data of 10 May 2018.
2. Type, purpose and scope of the collection and processing of personal data and legal basis
1. The administrator processes personal data via the open-service.pl website if the user uses the contact form. Personal data is processed on the basis of art. 6 clause 1 lit. f) GDPR as the Administrator's legitimate interest.
2. The administrator processes the following categories of user's personal data:
- Company name,
- First and last name ,
- E-mail address,
- Phone number.
3. Archiving period of personal data
1. Users' personal data is stored by the Administrator:
- in the event that the basis for data processing is the performance of the contract, as long as it is necessary to perform the contract, and after that time for a period corresponding to the period of limitation of claims. Unless a special regulation provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business operations - three years.
- in the event that the basis for data processing is consent, as long as the consent is not revoked, and after revoking the consent for a period of time corresponding to the limitation period of claims that may be raised by the Administrator and which may be raised against him. Unless a special regulation provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activity - three years.
2. When using the website, additional information may be downloaded, in particular: the IP address assigned to the user's computer or the external IP address of the Internet provider, domain name, type of browser, access time, type of operating system.
3. Navigation data may also be collected from users, including information about links and links in which they choose to click or other actions taken on the website. The legal basis for this type of activity is the Administrator's legitimate interest (Article 6 (1) (f) of the GDPR), consisting in facilitating the use of electronic services and improving the functionality of these services. Providing personal data by the user is voluntary.
4. Personal data will also be processed in an automated way in the form of profiling, if the user agrees to it pursuant to art. 6 clause 1 lit. a) GDPR. The consequence of profiling will be assigning a profile to a given person in order to make decisions about him or to analyze or predict his preferences, behaviors and attitudes.
5. The administrator takes special care to protect the interests of data subjects, and in particular ensures that the data collected by him are:
- processed in accordance with the law,
- collected for specified, lawful purposes and not subjected to further processing incompatible with those purposes,
- factually correct and adequate in relation to the purposes for which they are processed and stored in a form that enables identification of persons to whom they relate, no longer than is necessary to achieve the purpose of processing.
4. Sharing personal data
1. Users' personal data is transferred to service providers that the Administrator uses when running the website. Service providers to whom personal data are transferred, depending on contractual arrangements and circumstances, or are subject to the Administrator's instructions as to the purposes and methods of processing this data (processing entities) or define the purposes and methods of their processing (administrators).
2. Users' personal data is only stored in the European Economic Area (EEA).
5. The right to control, access and amend your own data
1. The data subject has the right to access their personal data and the right to rectify, delete, limit processing, the right to transfer data, the right to object, the right to withdraw consent at any time without affecting the lawfulness of the processing that has been carried out based on consent before its withdrawal.
2. Legal grounds for user requests:
- Access to data - art. 15 GDPR
- Correction of data - Art. 16 GDPR
- Deleting data (so-called the right to be forgotten) - art. 17 GDPR
- Restriction of processing - Art. 18 GDPR
- Data transfer - art. 20 GDPR
- Opposition - art. 21 GDPR
- Withdrawal of consent - art. 7 item 3 GDPR
3. In order to exercise the rights referred to in point 2 you can send an appropriate e-mail to the e-mail address: firstname.lastname@example.org. In the event of a user having the right under the above rights, the Administrator shall comply with the request or refuse to comply with it immediately, but no later than within a month after receiving it. However, if - due to the complicated nature of the request or the number of requests - the Administrator will not be able to fulfill the request within a month, he will fulfill it within the next two months informing the user in advance within one month of receiving the request - about the intended extension of the deadline and its reasons.
4. In the event that the processing of personal data violates the regulations of the GDPR, the data subject has the right to bring a complaint with the President of the Personal Data Protection Office.
6. "Cookies" files
1. The Administrator's website uses "cookies".
2. The installation of "cookies" is necessary for the proper working of services on the website. "Cookies" contain information necessary for the proper functioning of the website, and also provide the opportunity to compile general statistics of website visits.
3. The site uses types of "cookies":
- Session "cookies" are temporary files that are stored on the user's end device until logging out (leaving the site).
- Permanent "cookies" files are stored on the user's end device for the time specified in the parameters of "cookies" or until they are deleted by the user.
4. The administrator uses its own cookies to better understand the user's interaction in the content of the page. The files collect information on how the user uses the website, the type of page from which the user was redirected, and the number of visits and the time of the user's visit to the website. This information does not record specific personal data of the user, but is used to compile statistics on the use of the website.
5. The user has the right to decide on the access of "cookies" to his computer by selecting them in his browser window. Detailed information about the possibilities and ways of handling "cookies" are available in the software (web browser) settings.
7. Final regulations
1. The administrator uses technical and organizational measures to ensure the protection of processed personal data appropriate to the threats and categories of data protected, and in particular protects the data against disclosure to unauthorized persons, removal by an unauthorized person, processing in violation of applicable laws and change, loss, damage or destruction.
2. The administrator provides appropriate technical measures to prevent the acquisition and modification by unauthorized persons of personal data sent electronically.