Privacy policy
This document explains who processes the personal data collected on this website, for what purpose, on what legal basis, how long it is stored and what rights you have. It is based on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, referred to below as the GDPR.
This is a translation of the Polish version prepared for convenience. In the event of any discrepancy, the Polish version of this document prevails.
§ 1. Data controller
- The controller of personal data is Michał Mil, conducting unregistered business activity within the meaning of art. 5 sec. 1 of the Act of 6 March 2018 Entrepreneurs' Law, referred to below as the Controller.
- Contact in matters concerning personal data: michalmil.official@gmail.com. The Controller provides a postal address at the request of the data subject and at the request of the supervisory authority.
- The Controller is not obliged to appoint a data protection officer and has not appointed one. All requests are handled personally at the address given in section 2.
§ 2. What data is collected
- Through the contact form: full name, email address, phone number together with the country code, optionally the company name and information about the consents you have given.
- In correspondence and during calls: the data you provide on your own initiative, including information about your business and its commercial situation.
- Technical data recorded by the provider of the server that hosts the website: IP address, date and time of the request, browser and operating system type. The Controller does not combine this data with the data from the form.
- The Controller does not collect special categories of data referred to in art. 9 of the GDPR and asks you not to send such data in the content of your enquiries.
§ 3. Purposes and legal bases of processing
- Getting back to you, answering your enquiry and presenting the terms of cooperation: art. 6 sec. 1 letter b of the GDPR, that is steps taken at your request before entering into a contract, and for enquiries not aimed at entering into a contract art. 6 sec. 1 letter f of the GDPR, that is the legitimate interest of the Controller consisting in conducting correspondence.
- Entering into and performing a cooperation agreement: art. 6 sec. 1 letter b of the GDPR.
- Sending information about news and special offers by email: art. 6 sec. 1 letter a of the GDPR, that is your voluntary consent, in connection with art. 398 of the Act of 12 July 2024 Electronic Communications Law. The consent covers contact at the given email address only. The Controller does not carry out telephone marketing and does not send text messages.
- Fulfilling tax and accounting obligations: art. 6 sec. 1 letter c of the GDPR.
- Establishing, pursuing and defending claims, including securing evidence of the course of cooperation: art. 6 sec. 1 letter f of the GDPR.
- Ensuring the security of the website and preventing abuse: art. 6 sec. 1 letter f of the GDPR.
§ 4. Providing data is voluntary
- Providing data is voluntary, however without your full name, email address and phone number the Controller will not answer your enquiry, because there will be no way to contact you.
- Consent to receive marketing messages by email is voluntary, and not giving it affects neither the handling of your enquiry nor the terms of cooperation. You can withdraw it at any time, including by replying to any message you have received.
§ 5. Data retention period
- Enquiries that did not lead to cooperation: up to 12 months from the last contact, unless you object to the processing earlier.
- Data related to a concluded contract: for the duration of the contract and, after it ends, until the limitation periods for claims under the law expire.
- Settlement documents: for the period required by tax and accounting regulations.
- Data processed on the basis of consent: until the consent is withdrawn.
- Technical data in server logs: for the period applied by the server provider, in line with its policy.
§ 6. Data recipients
- Data may be shared only with entities necessary for the operation of the website and the handling of enquiries: the server provider, the email provider, the provider of the tool that handles the form, and entities providing accounting and legal services.
- Data processing agreements are concluded with entities processing data on behalf of the Controller.
- Data may be disclosed to public authorities if such an obligation follows from mandatory provisions of law.
- The Controller does not sell personal data and does not share it with third parties for marketing purposes.
§ 7. Transfers outside the European Economic Area
- Simply viewing the website does not cause data to be transferred outside the European Economic Area. The website does not fetch fonts, scripts or other resources from external servers, all files are served from the Controller's server.
- For correspondence the Controller uses email provided by Google Ireland Limited, which means the content of correspondence may be stored on servers belonging to the Google group, including outside the European Economic Area.
- Transfers to the United States take place on the basis of the implementing decision of the European Commission of 10 July 2023 establishing an adequate level of protection of personal data under the Data Privacy Framework, and if that decision is repealed, on the basis of standard contractual clauses adopted by the European Commission.
§ 8. Your rights
- You have the right to access your data and to receive a copy of it.
- You have the right to request rectification of inaccurate data and completion of incomplete data.
- You have the right to request erasure of data and restriction of its processing in the cases indicated in the GDPR.
- You have the right to data portability for data processed on the basis of consent or a contract, in a commonly used format.
- You have the right to object to processing based on the legitimate interest of the Controller, including against direct marketing.
- You have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
- You have the right to lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland.
- Requests are handled without undue delay, no later than within one month of receiving the request. The deadline may be extended in accordance with art. 12 sec. 3 of the GDPR, of which you will be informed.
§ 9. No profiling
Data is not used for automated decision making or for profiling that produces legal effects or similarly significantly affects your situation, within the meaning of art. 22 of the GDPR.
§ 10. Cookies and technical data
- The website does not use analytical, advertising or profiling cookies, whether its own or coming from third parties. No analytical tools or tracking pixels run on it, which is why no cookie consent request is displayed.
- The website does not load resources from external servers. Fonts come from the Controller's server, so simply visiting the page does not pass your IP address to any third party.
- You can change the settings for cookies and site data in your browser. Limiting their handling may affect the way the website is displayed.
§ 11. Security and confidentiality
- The Controller applies technical and organisational measures appropriate to the risk, in particular limits access to data solely to himself and to the entities referred to in § 6.
- Information provided in the course of talks about cooperation, including information about your business, is treated by the Controller as confidential and used solely for the purpose of preparing and carrying out the cooperation.
- The confidentiality rules binding both parties to the cooperation are set out in the Terms of service.
§ 12. Links to external websites
The website contains links to external websites, including LinkedIn. Once you go to such a website, your data is processed by its provider, under its own rules and as a separate controller. The Controller is not responsible for the way data is processed on external websites.
§ 13. Changes to the policy
- The policy may be changed, in particular if the law, the scope of services or the tools used on the website change.
- A new version is in force from the day it is published on the website. The date it takes effect is given at the beginning of the document.