Privacy policy and RODO
Who we are:
Our website is located at https://podpisano.pl and is managed by Podpisano Ltd. (https://podpisano.pl/), based at 8 Wislana St., 00-317 Warsaw, NIP: 5252892153, KRS: 0000946614.
Content of privacy policy and RODO
- Podpisano Sp. z o.o. is the controller of Data Personal data within the meaning of RODO to the extent that it has obtained Personal Data in connection with entering into an Agreement with Podpisano Ltd. („Administrator”).
- Podpisano Sp. z o.o. ensures that Personal Data is collected only to the extent necessary for the stated purpose and only for as long as necessary.
- Personal Data obtained by Podpisano Sp. z o.o. in connection with the conclusion of the Agreement will be processed by Podpisano Sp. z o.o., subject to sec. 6, exclusively for the purpose of:
- Response to the submitted form (legal basis: Article 6(1)(a) RODO, Article 6(1)(f) RODO);
- ongoing contact in connection with the conclusion or execution of the Agreement, presentation of an offer, sending an order, answering questions (legal basis: 6(1)(b) RODO, Article 6(1)(f) RODO);
- to conduct e-mail and traditional correspondence related to the execution of contracts, orders, submitted offers and inquiries (legal basis: 6(1)(b) RODO, Article 6(1)(f) RODO);
- telephone contact related to the services provided and the business conducted, including execution of contracts, information about services (legal basis: 6(1)(b) RODO, Article 6(1)(f) RODO);
- Execution of contracts, orders including the investigation of claims or defense against claims (legal basis: 6(1)(b) RODO, Article 6(1)(f) RODO);
- Establish or assert possible claims or defend against such claims (legal basis: Article 6(1)(f) RODO).
- The Administrator is committed to ensuring the security of the Personal Data entrusted to it. Administrator:
- Ensures transparency of Data Processing;
- informs on Data Processing at the time of collection, except in situations where it is not obliged to do so under separate regulations;
- ensures that Data is collected only to the extent necessary for the indicated purpose and Processed only for the period of time it is necessary,
- ensures the confidentiality of the Data by providing access to the Data only by authorized persons.
- If, despite the security measures taken, a breach of the protection of Personal Data has occurred and the breach could cause a high risk of violation of the rights and freedoms of Data Subjects, the Administrator shall immediately inform Data Subjects of such event.
- Recipients of Personal Data will be:
- tax administration authorities - to the extent that the transfer of Personal Data is an obligation of the Administrator under tax regulations (the legal basis for the transfer is Article 6(1)(c) of the RODO Regulation);
- public administration bodies performing social security tasks, to the extent that the transfer of Personal Data is an obligation of the Administrator under the law (the legal basis for the transfer is Article 6(1)(c) of the RODO Regulation);
- entities providing accounting, tax and legal services (the legal basis for the transfer of data is Article 6(1)(f) of the RODO Regulation);
- entities/authorities authorized under the law.
- The Administrator will Process Personal Data during the period of execution of the Agreement, including the exchange of correspondence or until the consent to Data Processing is withdrawn.
- In the case of Data Processing based on the legitimate interest of the Administrator - the Data will be Processed for the period of time that allows the fulfillment of this interest or until an effective objection to the Data Processing is made.
- The Processing period may be extended within the limits of the law in the event that the processing of Personal Data is necessary for the investigation or defense against claims.
- After the Processing period, the Data will be deleted or anonymized.
- Provision of Personal Data is voluntary; however, failure to provide data will condition the conclusion and performance of the Agreement.
- Subject to the situations stipulated by law, Data Subjects are entitled to:
- The right to access the content of your Data;
- The right to rectify inconsistencies or errors in the processed Data or to supplement them;
- The right to information about the Processed Data including the purposes and grounds for the Processing;
- The right to restrict the Processing of Personal Data;
- The right to withdraw consent at any time without affecting the lawfulness of the Processing, as long as the Processing is carried out on the basis of consent;
- The right to portability of Personal Data;
- The right to object to the Data Processing;
- The right to lodge a complaint to the supervisory authority, i.e. the President of the Office for the Protection of Personal Data, in the event that the Processing of Personal Data is deemed to violate the law, including the RODO.
- In order to exercise the rights referred to in paragraph 12, the customer may contact the data controller at: [email protected].
- Podpisano Sp. z o.o. declares that in case it is necessary in terms of the law, it will completely or to a certain extent delete the personal data entrusted to it for processing after the end of the processing entrustment period.
- Podpisano Ltd. undertakes to comply with the regulations on the processing of personal data, in particular the RODO.
- Podpisano Sp. z o.o. undertakes to apply technical and organizational measures to ensure high protection of personal data, including securing personal data against its access to unauthorized persons, collection by an unauthorized person, damage or destruction.
- Podpisano Sp. z o.o. ensures that (taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing and the risk of violation of the rights or freedoms of natural persons of different probability and severity) it has implemented appropriate technical and organizational measures to ensure a degree of security of personal data processing corresponding to the relevant risk. Podpisano Sp. z o.o. also ensures compliance with Article 28(2) and (4) of the RODO.