I. General provisions
Definitions of terms used herein:
- Controller – GPD Agency spółka z ograniczoną odpowiedzialnością spółka komandytowa, with its registered office in Poznań at the following address: ul. Roosevelta 18, 60-829 Poznań, entered in the register of entrepreneurs of the National Court Register (KRS) kept by the District Court for Poznań-Nowe Miasto and Wilda in Poznań, 8th Commercial Division of the National Court Register, under KRS number 0000527454, business statistical identification number (REGON): 302860051, tax identification number (NIP): PL 7811902177;
- Personal data – any information relating to an identified or identifiable natural person, in particular by reference to an identifier such as a name, an identification number (PESEL), location data, or an online identifier;
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;
- Website – an online platform available on www.gpd.com.pl;
- User – any natural person visiting the Website or using at least one of the services provided thereon.
The Controller’s primary objective is to protect the Users’ privacy and ensure compliance of the processing operations performed on the personal data collected in connection with the Users’ activity on the Website with applicable laws, including the GDPR.
II. Principles of personal data processing
- The Controller shall process the personal data on the following grounds:
- Article 6 1b of the GDPR – the data shall be processed in connection with and for the purpose of the performance of the agreement (which includes all personal data provided to the Controller in connection with the agreement concluded that need to be processed for the purpose of such a performance, and covers the processing operations required to take actions requested by the data subject prior to the conclusion of such an agreement);
- Article 6 1c of the GDPR – for the purpose of compliance with the Controller’s legal obligation under applicable laws (e.g. accounting or tax laws);
- Article 6 1f of the GDPR – for purposes resulting from the legitimate interests pursued by the Controller and involving:
- archiving of documents (also files concerning commercial relations) including, among others, portfolios, offers, inquiries, and email correspondence sent/received as part of the cooperation;
- setting up and maintaining contractor databases, including photo shoot location databases;
- exercising or defending claims;
- performing quality analyses and maintaining statistics regarding the services provided and projects implemented;
- and responding to the correspondence sent to the Controller.
Pursuant to Article 6(1)(a) of the GDPR, in individual cases and upon a prior consent, the Controller may process personal data for purposes other than those listed above.
- The Controller shall exercise due diligence to protect the interests of data subjects, and it shall, in particular, ensure that the personal data it collects are: processed in accordance with applicable laws; collected for specific and lawful purposes and not subjected to any further processing operations non-compliant therewith; and substantively correct and commensurate with the purposes of processing.
- The Controller processes personal data of the Users who visit the Controller’s profiles on social media platforms (Facebook and Instagram) and undertake any activity thereon. The data are processed pursuant to the legitimate interests of the Controller and solely for marketing purposes (also relating to the promotion of the Controller’s brand, activity, services and products) and with a view to establishing and maintaining communication.
III. Rights of Users
- Each User has the right to:
- access their personal data, i.e. to receive confirmation about whether or not the Controller processes the personal data, and the information about the scope of and the legal grounds for processing;
- rectify their personal data (where the data processed by the Controller are incorrect or incomplete);
- request the data to be erased;
- request the processing of their data to be restricted;
- data portability, i.e. the right to receive their personal data as provided to the Controller and to transmit those data to another controller, where the processing is based on the consent or agreement and carried out by automated means;
- object to the processing of their personal data for the purpose of the legitimate interest pursued by the Controller;
- object to the processing of their personal data for marketing purposes;
- withdraw the consent to the processing of their personal data, at any time, which shall not affect the lawfulness of processing based on consent before its withdrawal;
- and lodge a complaint with a relevant supervisory authority in Poland or any other EU Member State, particularly where the User believes that their personal data are processed in a manner violating the provisions of the GDPR (as of 25 May 2018, the supervisory authority in Poland is the President of the Personal Data Protection Office).
- To exercise the above-listed rights, the User may submit their request:
- in writing (the request should be sent to the Controller’s address);
- or electronically (by an e-mail sent to: email@example.com).
- The request referred to in Item 2 above must be clear and, in particular, it needs to specify the right the User wishes to exercises as well as the purpose of processing and the category of the personal data it concerns. Where needed, the Controller may ask the User to supplement their request with more specific or additional data necessary to properly respond and comply with such a request.
- The Controller shall advise the User of the measures implemented in relation to their request within a month of its receipt. Where required, the Controller shall advise the User of the necessity to extend the deadline for the response and state the grounds therefor.
- The Controller shall send its response using the same means of communication via which it has received the User’s request. Where the request was made in writing, the Controller may respond via an e-mail (provided that the User requested so and provided the e-mail address).
IV. Data retention period:
- personal data processed for the purpose of agreement conclusion or performance shall be retained throughout the term of the agreement and, upon its expiry, for a period necessary to provide clients with after-sales services or secure/exercise potential claims of or against the Controller;
- personal data processed for the purpose of the fulfilment of the Controller’s legal obligation shall be retained until such an obligation is met;
- personal data processed based on a consent shall be retained until the consent is withdrawn;
- personal data processed for the purposes of the legitimate interests pursued by the Controller shall be retained until an objection to such processing has been made, unless the Controller proves that there are legitimate grounds for their processing that override the data subject’s interests, rights and freedoms, or grounds necessary for the establishment, exercise or defence of legal claims;
- and personal data processed for marketing purposes shall be processed until an objection to such processing has been lodged.
Where a data subject objects to the processing of their personal data for marketing purposes, their data shall no longer be processed for such purposes.
V. Categories of data recipients
The Users’ personal data may be disclosed to the Controller’s employees, business partners, affiliates, debt collection companies, mail service providers, carriers, business partners providing technical services, providers of hosting services and IT systems, and contractors, or any other entities providing services to the Controller, its employees or business partners.
VI. Cookies and site data
- Cookies collect data concerning the User’s activity on the Website and their main purpose is to make it easier for the User to browse the Website, adapt the Website to the User’s needs and expectations (customisation of the Website’s tabs), analyse the traffic generated on the Website, and enable the Controller to carry out marketing activities.
- The User may find on the Website links directing to other websites. Privacy and cookie policies applicable to such websites are beyond the Controller’s control. Before browsing other websites, all Users are recommended to read their privacy and cookie policies (where available) or if no such documents are provided – to contact the website administrator to obtain relevant information.
- Cookie settings may vary depending on the User’s browser. The information about cookies may be found under each browser’s Help tab and on the following website: http://www.aboutcookies.org. Browser cookies – relevant privacy settings need to be selected from the browser’s options:
Google Chrome’s default settings allow cookies to be stored. To change the settings:
- go to the ‘Google Chrome Settings’ menu and click ‘Settings’;
- click ‘Show advanced settings’ at the bottom of the page;
- click ‘Privacy’ and select the ‘Content settings’ option;
- select a required setting;
- to enable special settings for a given website, click ‘Manage exceptions’ and select your own website settings;
- to confirm the changes, click ‘Done’.
Microsoft Internet Explorer
Microsoft Internet Explorer’s default settings allow cookies to be stored but they block files that may originate from websites with no privacy policies. To change the settings:
- go to the ‘Tools’ menu and click ‘Internet options’;
- go to the ‘Privacy’ tab;
- using the slider, customise the security zone (the highest blocks cookies entirely, while the lowest allows all types of cookies to be stored);
- click ‘Advanced’ and select a required setting yourself;
- to enable special settings for a given website, click ‘Websites’ and select your own website settings;
- confirm by clicking on the ‘OK’ button.
Mozilla Firefox’s default settings allow cookies to be stored. To change the settings:
- go to the ‘Tools’ menu (in other versions: click on the ‘Firefox’ button) and select ‘Options’;
- then go to the ‘Privacy’ tab and select a required setting;
- to enable special settings for a given website, click ‘Exceptions’ and select your own website settings;
- confirm by clicking on the ‘OK’ button.
Opera’s default settings allow cookies to be stored. To change the settings:
- click ‘Preferences’, select the ‘Advanced’ option and then click ‘Cookies’;
- select a required setting;
- to enable special settings for a given website, go to the website, right-click and select the ‘Website preferences’ option, go to the ‘Cookies’ tab, and then enter the required settings.
- confirm by clicking on the ‘OK’ button.
Safari’s default settings allow cookies to be stored. To change the settings:
- go to the ‘Safari’ menu and select the ‘Preferences’ option;
- click ‘Privacy’;
- select a required setting;
- to enable special settings for a given website, click ‘Details’ and select your own website settings.
VII. Analytical and marketing tools used by the Controller
The Controller employs the following analytical and marketing methods and tools:
- GOOGLE ANALYTICS – files used by Google to analyse the Users’ activity on the Website (reports and statistics). The tool does not use the data to identify Users. More information about Google Analytics may be found on: https://www.google.com/intl/pl/policies/privacy/partners.
- GOOGLE ADS – this tool measures the effectiveness of the Controller’s advertising campaigns. It enables the analysis of keywords and the measurement of the unique reach. It also allows advertisements to be displayed for Users who have previously visited the Website. More information about Google Ads may be found on: https://policies.google.com/technologies/ads?hl=pl.
- FACEBOOK PIXELS – this tool allows the measurement of the effectiveness of advertising campaigns on Facebook and, as other Facebook tools, it facilitates an in-depth data analysis to optimise the Controller’s activities. More information about Facebook Pixels may be found on: https://pl-pl.facebook.com/help/443357099140264?helpref=about_content.
- SOCIAL MEDIA ADD-ONS – they allow Users to share the content published on the Website on selected social media platforms. When these add-ons are applied, a social media platform receives the information about the use of the Website and it may assign it to the User’s profile created on that social media platform. The Controller is not familiar with the purpose for which social media platforms collect the User’s data or with the scope of the data collected. More information about the service may be found on: https://www.facebook.com/policy.php.
- HOTJAR – this tool allows the User’s activity on the Website to be analysed with, for example, user satisfaction surveys or on-site click analytics. The tool does not enable User identification. More information about the data collected by HotJar and methods to disable User monitoring may be found on: https://www.hotjar.com/privacy.
- DOUBLECLICK – this tool measures the effectiveness of the Controller’s advertising campaigns (Google Ads campaigns) and enables the analysis of results.
- GOOGLE TAG MANAGER – this tool allows the User’s activity to be analysed by managing other analytical or marketing tools used by the Controller.
VIII. Final provisions
- The Controller implements technical and organisational measures to ensure that the level of protection used for the personal data it processes is commensurate with the risk and appropriate for the categories of personal data under protection; in particular, the Controller secures the personal data against unauthorised access or removal, unlawful processing, alteration, loss, damage or destruction.
The Controller appointed the Data Protection Officer, who can be reached at firstname.lastname@example.org.