/// Legal
GDPR Information Notice
The following information constitutes a concise, transparent, intelligible and easily accessible summary of the information set out in the Privacy Policy regarding the Data Controller, the purpose and manner of processing personal data, and your rights in connection with such processing, in the form required to fulfil the GDPR information obligation. Detailed information concerning the manner of processing and the entities involved in this process is available in the aforementioned policy.
Who is the data controller?
The Controller of Personal Data (hereinafter the “Controller”) is the company “CodeAgency.pl Sp. z o.o.”, carrying out its business activity at the following address: ul. Królowej Jadwigi 18, 85-231 Bydgoszcz, holding Tax Identification Number (NIP): 9671412160, entered in the National Court Register (KRS) under number: 0000725181, providing services by electronic means through the Service.
How can the data controller be contacted?
The Controller may be contacted in one of the following ways:
-
Postal address - CodeAgency.pl Sp. z o.o., ul. Królowej Jadwigi 18, 85-231 Bydgoszcz
-
Email address - contact@codeagency.pl
-
Contact form - available at: https://codeagency.pl/kontakt
Has the data controller appointed a Data Protection Officer?
Pursuant to Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer.
In matters concerning the processing of data, including personal data, you should contact the Controller directly.
Where do we obtain personal data from and what are its sources?
Data is obtained from the following sources:
- from the data subjects themselves
What is the scope of the personal data processed by us?
The Service processes ordinary personal data, provided voluntarily by the data subjects
(e.g. first name and surname, login, email address, telephone number, IP address, etc.)
The detailed scope of the data processed is available in the Privacy Policy.
What are the purposes of our data processing?
Personal data voluntarily provided by Users is processed for one of the following purposes:
-
Provision of electronic services:
- Newsletter services (including the sending of advertising content with consent)
-
Communication between the Controller and Users in matters relating to the Service and data protection
-
Securing the legitimate interest of the Controller
What are the legal bases for data processing?
The Service collects and processes Users’ data on the basis of:
-
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
-
Article 6(1)(a)
the data subject has given consent to the processing of his or her personal data for one or more specific purposes -
Article 6(1)(b)
processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract -
Article 6(1)(f)
processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party
-
-
The Act of 10 May 2018 on the Protection of Personal Data (Journal of Laws 2018, item 1000)
-
The Act of 16 July 2004 — Telecommunications Law (Journal of Laws 2004, No. 171, item 1800)
-
The Act of 4 February 1994 on Copyright and Related Rights (Journal of Laws 1994, No. 24, item 83)
What is the legitimate interest pursued by the Controller?
-
For the purpose of any potential establishment, exercise or defence of claims – the legal basis for processing is our legitimate interest (Article 6(1)(f) of the GDPR) consisting in the protection of our rights, including, among others;
-
For the purpose of assessing the risk of potential clients
-
For the purpose of assessing planned marketing campaigns
-
For the purpose of carrying out direct marketing
For what period do we process personal data?
As a general rule, the personal data indicated is stored solely for the period during which the service is provided within the framework of the Service operated by the Controller. It is deleted or anonymised within a period of up to 30 days from the moment of cessation of the provision of services (e.g. deletion of a registered user account, unsubscribing from the Newsletter list, etc.)
In exceptional situations, in order to safeguard the legitimate interest pursued by the Controller, this period may be extended. In such a situation, the Controller will store the data indicated, from the time of the User’s request for its deletion, for no longer than a period of 3 years in the event of a breach or suspected breach of the provisions of the Service’s terms and conditions by the data subject.
Who is the recipient of the data, including personal data?
As a general rule, the sole recipient of the data is the Controller.
The processing of data may, however, be entrusted to other entities providing services to the Controller for the purpose of maintaining the operation of the Service. Such entities may include, among others:
-
Hosting companies providing hosting services or related services to the Controller
-
Companies through which the Newsletter service is provided
Will your personal data be transferred outside the European Union?
Personal data will not be transferred outside the European Union, unless it has been published as a result of an individual action of the User (e.g. the entry of a comment or a post), which will make the data available to every person visiting the Service.
Will personal data form the basis for automated decision-making?
Personal data will not be used for automated decision-making (profiling).
What rights do you have in connection with the processing of personal data?
-
Right of access to personal data
Users have the right to obtain access to their personal data, exercised upon a request submitted to the Controller -
Right to rectification of personal data
Users have the right to obtain from the Controller, without undue delay, the rectification of personal data which is inaccurate and/or the completion of incomplete personal data, exercised upon a request submitted to the Controller -
Right to erasure of personal data
Users have the right to obtain from the Controller, without undue delay, the erasure of personal data, exercised upon a request submitted to the Controller.
In the case of user accounts, the erasure of data consists in the anonymisation of the data enabling the identification of the User.
In the case of the Newsletter service, the User is able to erase their personal data independently by using the link included in every email message sent. -
Right to restriction of processing of personal data
Users have the right to restriction of the processing of personal data in the cases indicated in Article 18 of the GDPR, including, among others, contesting the accuracy of the personal data, exercised upon a request submitted to the Controller -
Right to data portability
Users have the right to obtain from the Controller the personal data concerning the User in a structured, commonly used and machine-readable format, exercised upon a request submitted to the Controller -
Right to object to the processing of personal data
Users have the right to object to the processing of their personal data in the cases specified in Article 21 of the GDPR, exercised upon a request submitted to the Controller -
Right to lodge a complaint
Users have the right to lodge a complaint with the supervisory authority responsible for the protection of personal data.