Privacy Policy
- This Privacy Policy sets forth the principles of personal data processing obtained through the website speakandoo.pl, hereinafter referred to as the “Website”).
- The owner of the site and also the Data Administrator is Speakandoo, Tax Identification Number (NIP): 726 230 2119, hereinafter referred to as the “Administrator.”
- Personal data collected by the Administrator through the Website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also referred to as GDPR.
- The Administrator takes special care to respect the privacy of Customers visiting the Website.
- Types of processed data, purposes, and legal basis
- The Administrator collects information regarding individuals performing a legal act not directly related to their business activity, individuals conducting business or professional activities on their own behalf, and individuals representing legal persons or organizational units not being legal persons, to whom the law grants legal capacity, conducting business or professional activities on their own behalf, hereinafter collectively referred to as “Customers.”
- Personal data of Customers is collected in case of:
using the contact form service on the Website to execute an electronically provided service agreement. Legal basis: necessity for the performance of a contract for the provision of the contact form service (Art. 6(1)(b) GDPR).
- In case of using the contact form service, the Customer provides the following data:
- email address
- first name
- phone number
- Additional information may be collected while using the Website, including: IP address assigned to the Customer’s computer or external IP address of the Internet provider, domain name, type of browser, access time, operating system type.
- Navigation data may also be collected from Customers, including information about links and references they decide to click on or other actions taken on the Website. Legal basis – legitimate interest (Art. 6(1)(f) GDPR), consisting in facilitating the use of electronically provided services and improving the functionality of these services.
- Providing personal data to the Administrator is voluntary.
- 2 Recipients or categories of recipients of data and how long they are stored?
- Customer’s personal data is transferred to service providers used by the Administrator to operate the Website. Service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, either comply with the Administrator ‘s instructions regarding the purposes and methods of processing this data (data processors) or independently determine the purposes and methods of processing (administrators).
1.1. Data processors. The Administrator uses providers who process personal data exclusively on the Administrator ‘s instructions. These include, among others, hosting service providers, accounting services, providers of marketing systems, systems for analysing traffic on the Website, systems for analysing the effectiveness of marketing campaigns.
1.2 Administrators. The Administrator uses providers who do not act exclusively on instructions and independently determine the purposes and methods of using Customers’ personal data. They provide electronic payment and banking services.
- Location. Service providers are mainly located in Poland and other countries of the European Economic Area (EEA).
- Customers’ personal data is stored:
3.1. In case the legal basis for processing personal data is consent, then the Customer’s personal data is processed by the Administrator until the consent is withdrawn, and after withdrawal of consent, for a period corresponding to the limitation period for claims that the Administrator may raise or that may be raised against him. Unless a specific provision states otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to conducting business activity – three years.
3.2. In case the legal basis for processing data is the performance of a contract, then the Customer’s personal data is processed by the Administrator for as long as necessary to perform the contract, and after that time for a period corresponding to the limitation period for claims. Unless a specific provision states otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to conducting business activity – three years.
- If a request is made, the Administrator provides personal data to authorized state authorities, in particular to the organizational units of the Prosecutor’s Office, Police, President of the Office for Personal Data Protection, President of the Office of Competition and Consumer Protection, or President of the Office of Electronic Communications.
- Cookies mechanism, IP address
- The website uses small files called cookies. They are stored by the Administrator on the end device of the person visiting the Website if the web browser allows it. A cookie usually contains the domain name it comes from, its “expiration time,” and an individual, randomly selected identification number for that file. Information collected through such files helps tailor the products offered by the Administrator to the individual preferences and actual needs of Website visitors.
- The Administrator uses two types of cookies:
2.1. Session cookies: after the session of a given browser ends or the computer is turned off, the stored information is deleted from the device’s memory. The session cookies mechanism does not allow for the collection of any personal data or any confidential information from Customers’ computers.
2.2. Persistent cookies: they are stored on the end device’s memory of the Customer and remain there until they are deleted or expire. The persistent cookies mechanism does not allow for the collection of any personal data or any confidential information from Customers’ computers.
3.The Administrator uses its own cookies for:
3.1. analysis and research and audience audit, in particular to create anonymous statistics that help understand how Customers use the Website, enabling improvement of its structure and content.
- The Administrator uses third-party cookies to:
4.1. present on the informational pages of the Website a map indicating the location of the Administrator ‘s office, using the maps.google.com online service (external cookies administrator: Google Inc. headquartered in the USA).
- The cookies mechanism is safe for Customers’ computers visiting the Website. In particular, this method does not allow viruses or other unwanted software or malicious software to penetrate Customers’ computers. Nevertheless, Customers have the option to limit or disable access to cookies on their computers through their browsers. If this option is used, using the Website will be possible, except for functions that inherently require cookies.
- The Administrator may collect Customers’ IP addresses. An IP address is a number assigned to the computer of the person visiting the Website by the Internet service provider. The IP number enables access to the Internet. In most cases, it is dynamically assigned to the computer, i.e., it changes with each Internet connection, and therefore it is commonly treated as non-personal identifying information. The IP address is used by the Administrator to diagnose technical problems with the server, create statistical analyses (e.g., determining which regions have the most visits), as information useful in administering and improving the Website, as well as for security purposes and possible identification of burdensome servers, unwanted automated programs for browsing the Website.
- 4 Rights of data subjects
- Right to withdraw consent – legal basis: Art. 7(3) GDPR. 1.1.
1.1. The Customer has the right to withdraw any consent granted.
1.2. Withdrawal of consent takes effect from the moment of withdrawal.
1.3. Withdrawal of consent does not affect the processing carried out by the Administrator in accordance with the law before its withdrawal.
1.4. Withdrawal of consent does not entail any negative consequences for the Customer; however, it may prevent further use of services or functionalities that, according to the law, the Administrator can provide only with consent.
- Right to object to data processing – legal basis: Art. 21 GDPR.
2.1. The Customer has the right at any time to object – for reasons related to his particular situation – to the processing of his personal data, including profiling, if the Administrator processes his data based on a legitimate interest, e.g., marketing of the Administrator ‘s products and services, conducting statistics on the use of individual functionalities of the Website and facilitating the use of the Website, as well as satisfaction surveys.
2.2. Resignation in the form of an email message from receiving marketing communications about products or services will mean the Customer’s objection to the processing of his personal data, including profiling for these purposes.
2.3. If the Customer’s objection is justified, the Administrator will not have any other legal basis for processing personal data; the Customer’s personal data will be deleted for which the Customer has objected to processing.
- 3. Right to erasure of data (“right to be forgotten”) – legal basis: Art. 17 GDPR.
3.1. The Customer has the right to request the erasure of all or some personal data.
3.2. The Customer has the right to request the erasure of personal data if:
3.2.1. the personal data are no longer necessary for the purposes for which they were collected or processed
3.2.2. he has withdrawn a specific consent, to the extent that personal data were processed based on his consent
3.2.3. he has objected to the use of his data for marketing purposes
3.2.4. personal data are processed unlawfully
3.2.5. personal data must be erased in order to comply with a legal obligation under Union law or the law of a Member State to which the Administrator is subject
3.2.6. personal data have been collected in connection with the offering of information society services
3.3. Despite the request for erasure of personal data, in connection with the objection or withdrawal of consent, the Administrator may retain some personal data to the extent that processing is necessary to establish, assert or defend claims, as well as to fulfil a legal obligation requiring processing under Union law or the law of a Member State to which the Administrator is subject. This applies in particular to personal data including: first name, last name, email address, which are kept for the purpose of handling complaints and claims related to the use of the Administrator ‘s services, or additionally the residential/correspondence address, order number, which data are kept for the purpose of handling complaints and claims related to concluded sales agreements or service provision.
- Right to restriction of processing – legal basis: Art. 18 GDPR.
4.1. The Customer has the right to request the restriction of the processing of his personal data. Submitting a request, until its consideration, prevents the use of certain functionalities or services, the use of which is related to the processing of data covered by the request. The Administrator will also not send any communications, including marketing ones.
4.2. The Customer has the right to request the restriction of the use of personal data in the following cases:
4.2.1. when he questions the correctness of his personal data – in this case, the Administrator restricts their use for the time needed to verify the correctness of the data, but not longer than for 7 days
4.2.2. when the processing of data is unlawful, and instead of deleting the data, the Customer requests a restriction of their use
4.2.3. when personal data are no longer necessary for the purposes for which they were collected or used, but they are needed by the Customer to establish, assert, or defend claims
4.2.4. when he has objected to the use of his data – in this case, the restriction lasts for the time needed to consider whether – due to the specific situation – the protection of the Customer’s interests, rights, and freedoms outweighs the interests pursued by the Administrator when processing the Customer’s personal data.
- Right to access data – legal basis: Art. 15 GDPR.
5.1. The Customer has the right to obtain from the Administrator confirmation as to whether personal data concerning him are being processed, and if so, the Customer has the right to:
5.1.1. access his personal data
5.1.2. obtain information about the purposes of processing, categories of personal data processed, recipients or categories of recipients of such data, the planned period of storage of the Customer’s data, or criteria for determining this period (when determining the planned period of data processing is not possible), about the Customer’s rights under the GDPR and the right to lodge a complaint with the supervisory authority, about the source of this data, about automated decision-making, including profiling, and about the safeguards applied in connection with the transfer of this data outside the European Union
5.1.3. obtain a copy of his personal data.
- Right to rectification of data – legal basis: Art. 16 GDPR.
6.1. The Customer has the right to request the Administrator to rectify without undue delay his inaccurate personal data. Taking into account the purposes of processing, the Customer, whose data are concerned, has the right to request completion of incomplete personal data, including by submitting an additional statement, directing a request to the email address according to §6 of the Privacy Policy.
- Right to data portability – legal basis: Art. 20 GDPR.
7.1. The Customer has the right to receive his personal data provided to the Administrator, and then to send it to another data Administrator chosen by him. The Customer also has the right to request that personal data be transmitted by the Administrator directly to such a data Administrator, if it is technically possible. In such a case, the Administrator will send the Customer’s personal data in the form of a csv file, which is a commonly used format suitable for machine reading and allowing the transmission of received data to another data Administrator.
- In the event of exercising by the Customer of a right resulting from the above rights, the Administrator fulfils the request or refuses to fulfil it immediately, but no later than within one month of its receipt. However, if – due to the complex nature of the request or the number of requests – the Administrator is unable to fulfil the request within one month, the Administrator will fulfil it within the next two months, informing the Customer in advance within one month of receiving the request about the intended extension of the deadline and its reasons.
- The Customer can report complaints, inquiries, and applications related to the processing of his personal data and the implementation of his rights to the Administrator.
- The Customer has the right to lodge a complaint with the President of the Office for Personal Data Protection regarding the violation of his rights to personal data protection or other rights granted under the GDPR.
- 5 Changes to the Privacy Policy
- The Privacy Policy may be changed, about which the Administrator is not obliged to inform.
- Questions regarding the Privacy Policy should be addressed to: speakandoonline@gmail.com
- Date of last modification: 27.02.2024