Website Privacy Policy
EchoSport
GENERAL PROVISIONS
- The controller of personal data collected through the website echosport.mobi is Piotr Krzyszkowski conducting business under the name Piotr Krzyszkowski registered in the Central Register and Information on Economic Activity of the Republic of Poland, maintained by the minister responsible for economic affairs, place of business: Gnojnik 716, address for service: Gnojnik 716, NIP: 8691799581, REGON: 122881753, email address: [email protected], hereinafter referred to as "Controller".
- Personal data collected by the Controller through the website is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as GDPR and the Personal Data Protection Act of 10 May 2018.
TYPE OF PERSONAL DATA PROCESSED, PURPOSE AND SCOPE OF DATA COLLECTION
- PURPOSE OF PROCESSING AND LEGAL BASIS. The Controller processes personal data through the website echosport.mobi in case of:
- use of the contact form by the user. Personal data is processed on the basis of Article 6(1)(f) of GDPR as a legitimate interest of the Controller.
- TYPE OF PERSONAL DATA PROCESSED.The Controller processes the following categories of users' personal data:
- First and last name,
- Date of birth,
- Address (of residence),
- Email address,
- Phone number,
- Tax ID
- PERIOD OF ARCHIVING PERSONAL DATA. Users' personal data is stored by the Controller:
- in case the basis for data processing is performance of a contract, as long as it is necessary to perform the contract, and thereafter for a period corresponding to the statute of limitations for claims. Unless a special provision states otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activities - three years.
- in case the basis for data processing is consent, as long as the consent is not withdrawn, and after the withdrawal of consent for a period corresponding to the statute of limitations for claims that the Controller may raise and that may be raised against it. Unless a special provision states otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activities - three years.
- While using the website, additional information may be collected, in particular: IP address assigned to the user's computer or external IP address of the Internet provider, domain name, browser type, access time, operating system type.
- Navigation data may also be collected from users, including information about links and references they decide to click on or other actions taken on the website. The legal basis for this type of activity is the legitimate interest of the Controller (Article 6(1)(f) GDPR), consisting of facilitating the use of services provided electronically and improving the functionality of these services.
- Providing personal data by the user is voluntary.
- Personal data will also be processed in an automated manner in the form of profiling, provided that the user consents to this on the basis of Article 6(1)(a) GDPR. The consequence of profiling will be assigning a profile to a given person in order to make decisions concerning them or to analyze or predict their preferences, behaviors and attitudes.
- The Controller takes special care to protect the interests of persons whose data are concerned, and in particular ensures that the data collected by it are:
- processed in accordance with the law,
- collected for specified, lawful purposes and not further processed in a manner incompatible with those purposes,
- substantively correct and adequate in relation to the purposes for which they are processed and stored in a form that allows identification of the persons concerned, no longer than is necessary to achieve the processing purpose.
DISCLOSURE OF PERSONAL DATA
- Users' personal data is transferred to service providers used by the Controller in running the website. Service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, either follow the Controller's instructions regarding the purposes and methods of processing such data (processors) or independently determine the purposes and methods of processing them (controllers).
- Users' personal data is stored exclusively within the European Economic Area (EEA).
RIGHT TO CONTROL, ACCESS TO OWN DATA AND THEIR CORRECTION
- The data subject has the right to access the content of their personal data and the right to rectify, delete, restrict processing, the right to data portability, the right to object, the right to withdraw consent at any time without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
- Legal basis for user requests:
- Access to data – Article 15 GDPR
- Rectification of data – Article 16 GDPR.
- Erasure of data (the so-called right to be forgotten) – Article 17 GDPR.
- Restriction of processing – Article 18 GDPR.
- Data portability – Article 20 GDPR.
- Objection – Article 21 GDPR
- Withdrawal of consent – Article 7(3) GDPR.
- To exercise the rights referred to in point 2, you can send an appropriate email to: [email protected].
- In the event that a user exercises a right arising from the above rights, the Controller fulfills the request or refuses to fulfill it without delay, but no later than one month after receiving it. However, if - due to the complex nature of the request or the number of requests - the Controller will not be able to fulfill the request within one month, it will fulfill it within the next two months, informing the user in advance, within one month of receiving the request - about the intended extension of the deadline and its reasons.
- If it is found that the processing of personal data violates GDPR provisions, the data subject has the right to lodge a complaint with the President of the Personal Data Protection Office.
"COOKIES" FILES
- The Controller's website uses "cookies" files.
- Installation of "cookies" files is necessary for the proper provision of services on the website. "Cookies" files contain information necessary for the proper functioning of the site, and also provide the opportunity to develop general statistics of website visits.
- Types of "cookies" files used on the site:
- The Controller uses its own cookies to better understand how the user interacts with the site's content. Files collect information about how the user uses the website, the type of site from which the user was redirected, and the number of visits and time of the user's visit to the website. This information does not record specific personal data of the user, but is used to compile statistics on the use of the site.
- The user has the right to decide on the access of "cookies" files to their computer by making a prior selection in their browser window. Detailed information about the possibility and methods of handling "cookies" files is available in the software settings (web browser).
FINAL PROVISIONS
- The Controller applies technical and organizational measures ensuring the protection of processed personal data appropriate to the threats and categories of data covered by protection, and in particular secures data against disclosure to unauthorized persons, taking by an unauthorized person, processing in violation of applicable regulations, and alteration, loss, damage or destruction.
- The Controller provides appropriate technical measures to prevent unauthorized persons from obtaining and modifying personal data transmitted electronically.
- In matters not regulated by this Privacy Policy, the provisions of GDPR and other relevant provisions of Polish law shall apply accordingly.