Privacy Policy
Privacy Policy of the website www.retjet.com: what data we collect, for what purpose, and what rights you have regarding it.
This is an informational translation. The legally binding version of this document is the Polish original, available at www.retjet.pl/polityka-prywatnosci. In case of any discrepancy between the language versions, the Polish version prevails.
§ 1. General provisions
-
Subject to point 3 of this paragraph, the controller of personal data collected via the Website and the Application is RetJet SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, entered into the Register of Entrepreneurs by the SĄD REJONOWY W BIELSKU – BIAŁEJ, VIII WYDZIAŁ GOSPODARCZY KRAJOWEGO REJESTRU SĄDOWEGO, KRS (National Court Register) number: 0001129805, registered office and address for service: ul. 1 Maja 22, 43-300 Bielsko-Biała, NIP (Tax Identification Number): 5472248276, REGON (National Business Registry Number): 529760483, e-mail address: [email protected], hereinafter referred to as the “Controller” and simultaneously the Service Provider.
-
Personal data collected by the Controller via the website of the Website and entrusted to it by Service Recipients are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter GDPR (RODO), and the Polish Consumer Rights Act of 30 May 2014 (ustawa o prawach konsumenta).
-
The controllers of data entered into the Application and collected and processed in connection with its use are the Service Recipients.
-
All words or phrases used with an initial capital letter in the text of this Privacy Policy shall be understood in accordance with their definition contained in the Terms of Service of the Website.
§ 2. Purpose and scope of data collection
-
PURPOSE OF PROCESSING AND LEGAL BASIS. The Controller processes the personal data of Service Recipients of the Website in the case of:
-
use of the Contact Form in order to send a message to the Controller, pursuant to Art. 6(1)(f) GDPR (the legitimate interest of the trader),
-
registration of an Account on the Website, in order to create an individual account and manage that Account, pursuant to Art. 6(1)(b) GDPR (performance of the agreement for the provision of services by electronic means in accordance with the Terms of Service of the Website),
-
placing an Order, in order to perform the Agreement for the provision of the Digital Service pursuant to Art. 6(1)(b) GDPR (performance of the agreement),
-
subscribing to the Newsletter in order to send commercial information by electronic means. Personal data are processed after separate consent has been given, pursuant to Art. 6(1)(a) GDPR,
-
the Service Recipient’s use of the License and the provision to the Service Recipient of all other services related to the Application, in order to perform the Agreement for the provision of the Digital Service pursuant to Art. 6(1)(b) GDPR (performance of the agreement).
-
-
TYPE OF PERSONAL DATA PROCESSED. The Service Recipient provides, in the case of:
-
the Contact Form: first and last name, e-mail address, telephone number,
-
the Account: first and last name, address, NIP, e-mail address, telephone number,
-
the Order: first and last name, address, NIP, e-mail address, telephone number,
-
the Newsletter: e-mail address, as well as, if the Service Recipient has consented to analytical cookies, identifiers assigned by the Google Analytics tool (user and session identifier), stored together with the e-mail address solely in order to determine the source of the subscription,
-
the License: first and last name, NIP, e-mail address.
-
-
PERIOD OF ARCHIVING PERSONAL DATA. Personal data of Service Recipients are stored by the Controller:
-
where the basis for processing the data is performance of an agreement, for as long as is necessary to perform the agreement, and after that time for a period corresponding to the limitation period for claims. Unless a special provision states otherwise, the limitation period is six years, and for claims for periodic performance and claims related to the conduct of business activity - three years,
-
where the basis for processing the data is consent, for as long as the consent has not been withdrawn, and after withdrawal of consent for a period corresponding to the limitation period for claims that the Controller may raise and that may be raised against it. Unless a special provision states otherwise, the limitation period is six years, and for claims for periodic performance and claims related to the conduct of business activity - three years.
-
-
While using the Website, additional information may be collected, in particular: the IP address assigned to the Service Recipient’s computer or the external IP address of the Internet provider, domain name, browser type, access time, operating system type.
-
After giving separate consent, pursuant to Art. 6(1)(a) GDPR, data may also be processed for the purpose of sending commercial information by electronic means or making telephone calls for the purpose of direct marketing - respectively in connection with Art. 10(2) of the Polish Act of 18 July 2002 on the Provision of Electronic Services (ustawa o świadczeniu usług drogą elektroniczną) or Art. 172(1) of the Polish Telecommunications Law Act of 16 July 2004 (Prawo Telekomunikacyjne), including those directed as a result of profiling, provided that the Service Recipient has given the relevant consent.
-
Navigation data may also be collected from Service Recipients, including information about links and references they choose to click, or other actions taken on the Website. The legal basis for this type of activity is the Controller’s legitimate interest (Art. 6(1)(f) GDPR), consisting of facilitating the use of services provided by electronic means and improving the functionality of those services.
-
Providing personal data by the Service Recipient is voluntary.
-
The Controller exercises particular diligence to protect the interests of data subjects, and in particular ensures that the data it collects are:
-
processed lawfully,
-
collected for specified, lawful purposes and not subjected to further processing incompatible with those purposes,
-
substantively correct and adequate in relation to the purposes for which they are processed, and stored in a form permitting identification of the data subjects for no longer than is necessary to achieve the purpose of processing.
-
§ 3. Recipients of personal data
-
Personal data of Service Recipients are transferred to service providers used by the Controller in operating the Website and the Application.
-
The service providers referred to in point 1 of this paragraph, to whom personal data are transferred, depending on contractual arrangements and circumstances, either follow the Controller’s instructions as to the purposes and methods of processing this data (processors) or independently determine the purposes and methods of its processing (controllers).
-
The categories of recipients referred to in point 1 include in particular: the provider of analytical and advertising tools (Google LLC) and the provider of the newsletter dispatch service (Mailchimp, Intuit Inc.). The current list of processors is made available on request sent to the address indicated in § 1.
-
Personal data of Service Recipients are stored within the European Economic Area (EEA), subject to point 5 of this paragraph and § 5 points 5 and 6 of the Privacy Policy.
-
Personal data of Service Recipients subscribed to the Newsletter, i.e. the e-mail address together with the identifiers indicated in § 2 point 2 sub-point 4, are processed in the Mailchimp service (Intuit Inc., with its registered office in the USA), acting as a processor on behalf of the Controller. This involves the transfer of data outside the EEA. The transfer takes place on the basis of a European Commission adequacy decision, i.e. an active certificate of compliance under the EU-US Data Privacy Framework (DPF) program. The service provider’s privacy policy is available at: https://www.intuit.com/privacy/statement/.
§ 4. Right of control, access to the content of one’s data, and their correction
-
The data subject has the right to access the content of their personal data and the right to have it rectified, erased, have its processing restricted, the right to data portability, the right to object, and the right to withdraw consent at any time without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal. Legal bases for the Service Recipient’s request:
-
access to data - Art. 15 GDPR,
-
rectification of data - Art. 16 GDPR,
-
erasure of data (the so-called right to be forgotten) - Art. 17 GDPR,
-
restriction of processing - Art. 18 GDPR,
-
data portability - Art. 20 GDPR,
-
objection - Art. 21 GDPR,
-
withdrawal of consent - Art. 7(3) GDPR.
-
-
In order to exercise the rights referred to in point 2, an appropriate e-mail message may be sent to the address:[email protected]
-
If a Service Recipient exercises a right arising from the above rights, the Controller fulfills the request or refuses to fulfill it without undue delay, but no later than within one month of its receipt. However, if - due to the complex nature of the request or the number of requests - the Controller is unable to fulfill the request within one month, it will fulfill it within the following two months, having previously informed the Service Recipient, within one month of receiving the request, of the intended extension of the deadline and its reasons.
-
If it is found that the processing of personal data violates the provisions of the GDPR, the data subject has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
§ 5. “Cookies” files
-
The Controller’s website uses “cookies” files.
-
The installation of “cookies” files is necessary for the proper provision of services on the Website. “Cookies” files contain information necessary for the proper functioning of the website, and also make it possible to develop general statistics of website visits.
-
Two types of “cookies” files are used on the website: “session” and “persistent” files.
-
“session” “cookies” are temporary files stored on the Service Recipient’s end device until logging out (leaving the website),
-
“persistent” “cookies” files are stored on the Service Recipient’s end device for the period specified in the parameters of the “cookies” files or until they are deleted by the Service Recipient.
-
-
The Controller uses its own cookies files in order to better understand how Service Recipients interact with the content of the website. The files collect information about how the Service Recipient uses the website, the type of website from which the Service Recipient was redirected, and the number of visits and the time of the Service Recipient’s visit to the website. This information does not record specific personal data of the Service Recipient, but is used to develop statistics on the use of the website.
-
The Controller uses external cookies files in order to collect general and anonymous statistical data via the Google Analytics analytical tools (administrator of the external cookies: Google LLC, with its registered office in the USA).
-
Cookies files may also be used by advertising networks, in particular the Google network, in order to display advertisements tailored to the way the Service Recipient uses the Website. For this purpose, they may retain information about the Service Recipient’s navigation path or the time spent on a given page.
-
The Service Recipient has the right to decide on the access of “cookies” files to their computer by changing the settings in their browser window. Detailed information on the possibilities and methods of handling “cookies” files is also available in the software (web browser) settings.
§ 6. Additional services related to user activity on the website
-
So-called social plugins (“plugins”) of social networking services are used on the Website. When displaying the website www.retjet.com, containing such a plugin, the Service Recipient’s browser will establish a direct connection with the servers of Facebook, Twitter (X), Skype, and Instagram.
-
The content of the plugin is transmitted by the given service provider directly to the Service Recipient’s browser and integrated with the website. Thanks to this integration, service providers receive information that the Service Recipient’s browser has displayed the website www.retjet.com, even if the Service Recipient does not have a profile with the given service provider, or is not currently logged in to it. Such information (together with the Service Recipient’s IP address) is transmitted by the browser directly to the server of the given service provider (some servers are located in the USA) and stored there.
-
If the Service Recipient logs in to one of the above social networking services, that service provider will be able to directly assign the visit to the website www.retjet.com to the Service Recipient’s profile in the given social networking service.
-
If the Service Recipient uses a given plugin, e.g. by clicking the “Like” button or the “Share” button, the relevant information will also be sent directly to the server of the given service provider and stored there.
-
The purpose and scope of the collection of data and its further processing and use by the service providers, as well as the possibility of contact and the Service Recipient’s rights in this regard and the possibility of making settings ensuring protection of the Service Recipient’s privacy, have been described in the service provider’s privacy policy:
-
If the Service Recipient does not want social networking services to assign data collected during visits to the website www.retjet.com directly to their profile in the given service, they must log out of that service before visiting the website www.retjet.com. The Service Recipient may also completely prevent the loading of plugins on the website by using appropriate browser extensions, e.g. blocking scripts using “NoScript”.
-
The Controller uses remarketing tools on its website, i.e. Google Ads, which involves the use of cookies files of Google LLC related to the Google Ads service. Within the framework of the cookie settings management mechanism, the Service Recipient has the possibility to decide whether the Service Provider will be able to use Google Ads (administrator of the external cookies: Google LLC, with its registered office in the USA) in relation to them.
§ 7. Final provisions
-
The Controller applies technical and organizational measures ensuring protection of the personal data processed, appropriate to the threats and categories of data covered by protection, and in particular secures the data against disclosure to unauthorized persons, seizure by an unauthorized person, processing in violation of applicable regulations, and alteration, loss, damage, or destruction.
-
The Controller applies appropriate technical measures to prevent the acquisition and modification, by unauthorized persons, of personal data transmitted electronically.
-
In matters not regulated by this Privacy Policy, the relevant provisions of the GDPR and other applicable provisions of Polish law shall apply accordingly.