PRIVACY POLICY
- This Privacy Policy outlines the principles for processing personal data collected through the website newyoujustynareszka.co.uk, hereinafter referred to as the „Website”.
- The owner of the website and the Data Controller is Justyna Reszka, hereinafter referred to as the Administrator.
- The personal data collected by the Administrator through the Website is processed in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also known as GDPR.
- The Administrator takes special care to respect the privacy of clients visiting the Website.
§ 1 Types of Data Processed, Purposes, and Legal Basis
- The Administrator collects information regarding natural persons who engage in legal actions not directly related to their business activities, natural persons conducting business or professional activities on their own behalf, as well as natural persons representing legal persons or organizational units without legal personality, who are granted legal capacity by law, conducting business or professional activities on their own behalf, hereinafter collectively referred to as Clients.
- The personal data of Clients is collected in the following cases:
- Using the contact form service on the Website for the purpose of executing a contract provided electronically. Legal basis: necessity for the performance of the contact form service agreement (Article 6(1)(b) GDPR).
- When using the contact form service, the Client provides the following data:
- Email address
- Name
- Phone number
- Additional information may be collected while using the Website, particularly: the IP address assigned to the Client’s computer or the external IP address of the Internet provider, domain name, browser type, access time, and operating system type.
- Navigation data may also be collected from Clients, including information about the links and references they decide to click or other activities undertaken on the Website. Legal basis: legitimate interest (Article 6(1)(f) GDPR), aimed at facilitating the use of electronic services and improving the functionality of these services.
- Providing personal data to the Administrator is voluntary.
§ 2 To Whom Data is Shared or Entrusted and How Long it is Stored
- The Client’s personal data is shared with service providers used by the Administrator to operate the Website. Service providers to whom personal data is shared, depending on contractual arrangements and circumstances, either act under the Administrator’s instructions regarding the purposes and means of processing such data (processors) or determine the purposes and means of processing data on their own (controllers). 1.1. Processors. The Administrator uses service providers who process personal data only upon the Administrator’s instructions. These include hosting providers, accounting services, marketing system providers, traffic analysis systems on the Website, and systems for analyzing the effectiveness of marketing campaigns. 1.2. Controllers. The Administrator uses service providers who do not act solely on instructions and independently determine the purposes and means of using Clients’ personal data. They provide electronic payment and banking services.
- Location. The service providers are mainly based in Poland and other countries within the European Economic Area (EEA).
- The Clients’ personal data is stored:
3.1. In cases where the legal basis for data processing is consent, the personal data of the Client is processed by the Administrator until the consent is withdrawn, and after withdrawal, for a period corresponding to the statute of limitations for claims that may be raised by the Administrator and against him. Unless otherwise stated by a special provision, the statute of limitations is six years, and for periodic benefits and claims related to business activities – three years. 3.2. In cases where the legal basis for data processing is the performance of a contract, the personal data of the Client is processed by the Administrator as long as it is necessary for the performance of the contract, and after that time, for a period corresponding to the statute of limitations for claims. Unless otherwise stated by a special provision, the statute of limitations is six years, and for periodic benefits and claims related to business activities – three years. - Upon request, the Administrator shares personal data with authorized state authorities, particularly organizational units of the Prosecutor’s Office, the Police, the President of the Office for Personal Data Protection, the President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications.
§ 3 Cookies Mechanism, IP Address
- The Website uses small files called cookies. They are stored by the Administrator on the device of the person visiting the Website if the web browser allows it. A cookie file usually contains the domain name from which it originates, its „expiry time”, and a randomly selected number identifying the file. Information collected through such files helps tailor the Administrator’s products to the individual preferences and actual needs of those visiting the Website.
- The Administrator uses two types of cookies:
2.1. Session cookies: After the browser session ends or the computer is turned off, the stored information is removed from the device’s memory. The session cookie mechanism does not allow for the collection of any personal data or confidential information from the Client’s computer.
2.2. Persistent cookies: These are stored on the Client’s end device and remain there until they are deleted or expire. The persistent cookie mechanism does not allow for the collection of any personal data or confidential information from the Client’s computer. - The Administrator uses its own cookies for:
3.1. Analysis and research, as well as viewership audits, particularly to create anonymous statistics that help understand how Clients use the Website, which enables improving its structure and content. - The Administrator uses external cookies for:
4.1. Presenting a map on the informational pages of the Website indicating the Administrator’s office location using the maps.google.com service (external cookie administrator: Google Inc. based in the USA). - The cookie mechanism is safe for Clients’ computers visiting the Website. In particular, it is not possible for viruses or other unwanted software or malicious software to enter the Clients’ computers this way. Nevertheless, Clients have the option to limit or disable the access of cookies to their computers in their browsers. If this option is used, the use of the Website will be possible, except for functions that by their nature require cookies.
- The Administrator may collect the Clients’ IP addresses. The IP address is a number assigned to the computer of the person visiting the Website by the Internet service provider. The IP number allows access to the Internet. In most cases, it is assigned to the computer dynamically, i.e., it changes with each connection to the Internet and, therefore, is commonly regarded as a non-personal identifying information. The IP address is used by the Administrator to diagnose technical problems with the server, create statistical analyses (e.g., determine from which regions we record the most visits), as useful information for administering and improving the Website, as well as for security purposes and possibly identifying unwanted automated programs browsing the Website’s content.
§ 4 Rights of Data Subjects
- Right to withdraw consent – legal basis: Article 7(3) GDPR.
1.1. The Client has the right to withdraw any consent they have given.
1.2. Withdrawal of consent takes effect from the moment of withdrawal.
1.3. Withdrawal of consent does not affect the processing carried out by the Administrator in accordance with the law before its withdrawal.
1.4. Withdrawal of consent does not entail any negative consequences for the Client, but it may prevent further use of services or functionalities that, by law, the Administrator may provide only with consent. - Right to object to data processing – legal basis: Article 21 GDPR.
2.1. The Client has the right to object at any time – for reasons related to their particular situation – to the processing of their personal data, including profiling, if the Administrator processes their data based on legitimate interest, e.g., marketing of the Administrator’s products and services, statistics on the use of the Website’s functionalities, and facilitating the use of the Website, as well as satisfaction surveys.
2.2. Opting out by email from receiving marketing communications regarding products or services will mean the Client objects to the processing of their personal data, including profiling for these purposes.
2.3. If the Client’s objection is justified, and the Administrator has no other legal basis for processing the personal data, the personal data subject to the objection will be deleted. - Right to data erasure („right to be forgotten”) – legal basis: Article 17 GDPR.
3.1. The Client has the right to request the deletion of all or some of their personal data.
3.2. The Client has the right to request the deletion of personal data if:
3.2.1. The personal data is no longer necessary for the purposes for which it was collected or otherwise processed.
3.2.2. The Client has withdrawn specific consent, to the extent that personal data was processed based on that consent.
3.2.3. The Client has objected to the use of their data for marketing purposes.
3.2.4. The personal data is processed unlawfully.
3.2.5. The personal data must be deleted to comply with a legal obligation under Union or Member State law to which the Administrator is subject.
3.2.6. The personal data was collected in connection with the offering of information society services.
3.3. Despite the request to delete personal data in connection with an objection or withdrawal of consent, the Administrator may retain certain personal data to the extent necessary for the purposes of establishing, asserting, or defending claims, as well as fulfilling a legal obligation that requires processing under Union or Member State law. This applies in particular to personal data including:- first name, last name, email address, which is retained for complaint-handling purposes and claims relating to services provided;
- personal data included in invoices, which are retained for accounting purposes.
- Right to data processing restriction – legal basis: Article 18 GDPR.
4.1. The Client has the right to request the restriction of processing of their personal data. Submitting a request, until it is considered, prevents the use of certain functionalities or services, the use of which will involve processing the data covered by the request. The Administrator will not send any messages, including marketing communications.
4.2. The Client has the right to request the restriction of the use of personal data in the following cases:
4.2.1. When they contest the correctness of their personal data – in this case, the Administrator restricts its use for the time necessary to verify the accuracy of the data, but no longer than seven days.
4.2.2. When the data processing is unlawful, and instead of deleting the data, the Client requests the restriction of its use.
4.2.3. When the personal data is no longer necessary for the purposes for which it was collected or used, but it is necessary for the Client to establish, assert, or defend claims.
4.2.4. When they have objected to the use of their data – in this case, the restriction applies for the time necessary to consider whether, due to the particular situation, the protection of the Client’s interests, rights, and freedoms outweighs the interests pursued by the Administrator in processing the Client’s personal data. - Right to access data – legal basis: Article 15 GDPR.
5.1. The Client has the right to obtain confirmation from the Administrator whether their personal data is being processed.
5.2. If the Administrator processes personal data, the Client has the right to:
5.2.1. Access their personal data;
5.2.2. Obtain information about the purposes of processing, categories of personal data processed, recipients or categories of recipients of this data, the planned period of storage of the Client’s data or the criteria for determining this period (when determining the planned period of data processing is impossible), the Client’s rights under GDPR, and the right to lodge a complaint with a supervisory authority, the source of this data, automated decision-making, including profiling, and safeguards applied in connection with the transfer of this data outside the European Union;
5.2.3. Obtain a copy of their personal data. - Right to data rectification – legal basis: Article 16 GDPR.
6.1. The Client has the right to request the Administrator to rectify any personal data concerning them that is inaccurate. Taking into account the purposes of processing, the data subject has the right to request the completion of incomplete personal data, including by providing an additional statement, using the email address provided in §6 of the Privacy Policy. - Right to data portability – legal basis: Article 20 GDPR.
7.1. The Client has the right to receive their personal data, which they have provided to the Administrator, and then send it to another personal data controller of their choice.
7.2. The Client also has the right to request that their personal data be sent by the Administrator directly to such a controller, if technically feasible. In this case, the data will be sent in a commonly used, machine-readable format that allows for sending the received data to another controller of personal data.
7.3. The right to data portability applies only to data processed based on a contract or based on the Client’s consent. - Right to lodge a complaint – legal basis: Article 77 GDPR.
8.1. If the Client believes that their personal data is being processed unlawfully or that the rights granted by GDPR have been violated, they have the right to lodge a complaint with the supervisory authority, particularly in the Member State of their habitual residence, place of work, or the place of the alleged violation. In Poland, the supervisory authority is the President of the Office for Personal Data Protection.
§ 5 Security of Personal Data
- The Privacy Policy may change, of which the Administrator is not obliged to inform.
- Please send questrions regarding the Privacy Policy to: j.marcon@wp.pl
- Date of last modification: 12.08.2024r