This Privacy Policy describes how we process information about you, including personal data and cookies.
https://quaspe.pl
We make every effort to protect the personal data we collect in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as the “GDPR”) (Official Journal of the EU L 119 of 4 May 2016), as well as with national regulations.
We provide this Privacy Policy so that people with whom we establish relationships clearly know who the controller of their personal data is, to what extent and for what purpose the data is processed, on what legal basis and to whom it may be disclosed. We also inform you about the rights you have in connection with data processing.
1. Personal Data Controller and Data Protection Officer
The controller of data processed in connection with use of the Website is Quaspe sp. z o.o., with its registered office at ul. Zbigniewa Religi 4/lok. B2.3, 15-797 Białystok, Poland. The Controller can be contacted by phone at 668 010 500 or by email at biuro@quaspe.pl.
The Controller has appointed a Data Protection Officer, Mr Paweł Maliszewski, who can be contacted in matters related to personal data processing at iod@quaspe.pl.
2. Data Processing in Connection with Use of the Website
In connection with the User’s use of the Website, the Controller collects data to the extent necessary to provide the services offered, as well as information about the User’s activity on the Website.
3. Purposes and Legal Bases for Data Processing on the Website
Each time a website page is requested, meaning each visit to our website, the server automatically records technical log data, such as the name of the requested file, IP address, date and time of the request and the amount of data transferred, and also records the page request.
Personal data of all people using the Website (including IP addresses or other identifiers and information collected through cookies or similar technologies) is processed by the Controller in order to provide electronic services consisting in making the content collected on the Website available to Users. In this case, the legal basis for processing is that it is necessary for the performance of a contract (Article 6(1)(b) GDPR). Data is also processed for technical and administrative purposes, to ensure the security of the IT system and to manage that system. In this case, the legal basis for processing is the Controller’s legitimate interest (Article 6(1)(f) GDPR).
- Email and contact forms
The Controller enables contact by email and through contact forms. Using these forms of contact requires providing the personal data necessary to correspond with the User and reply to the enquiry sent. The User may also provide other data to make handling the enquiry easier. Providing data is voluntary, but refusal to provide it will make correspondence impossible. Personal data provided in an email message/contact form will be processed for the purposes of conducting correspondence, providing information and answering questions, which constitutes the Controller’s legitimate interest (Article 6(1)(f) GDPR).
- Social media platforms
The Website contains links to external websites: Facebook, Instagram and YouTube, where the Controller maintains its profiles, the so-called “fan pages”. Personal data processed through these websites is controlled by third parties. The processing of your personal data by these entities is governed by the laws applicable to the administrators of those services and by their internal regulations, such as privacy policies. This Privacy Policy does not regulate personal data processing by those entities.
However, the Controller may also be an independent controller of personal data processed as part of operating fan pages, processing personal data under the rules described below and for the following purposes:
- carrying out marketing activities consisting in informing people about the Company’s activities and services through fan pages, including by publishing posts, which constitutes the Controller’s legitimate interest (Article 6(1)(f) GDPR);
- replying to private messages sent through social media platform functionality; in this case, the basis for data processing is the Controller’s legitimate interest in conducting correspondence (Article 6(1)(f) GDPR);
- conducting discussions under posts published on fan pages, on social media platforms or on websites that allow discussion through accounts created on social media platforms, which constitutes the Controller’s legitimate interest (Article 6(1)(f) GDPR);
- obtaining statistical data – the Controller may obtain statistical data about fan pages from social media platform operators. This data is created on the basis of monitoring your activity on fan pages by the operators of those social media platforms. In this situation, the Controller’s legitimate interest is the analysis of statistical data concerning fan pages (Article 6(1)(f) GDPR).
Providing personal data is voluntary. If you communicate with the Controller through social media platforms in any form, the Controller will automatically receive the data indicated in your account details (first name, surname or nickname, as well as your photo and other publicly available information). You may stop following the Controller’s fan pages and delete comments you have posted at any time.
4. Obligation or Voluntary Nature of Providing Data
- Providing data is voluntary, but necessary to carry out the processing purposes described above. Refusal to provide data will prevent proper handling of enquiries and receipt of information concerning the Company’s activities;
- Providing data necessary for statistical analysis of Website Users is voluntary. You may use the so-called incognito mode to browse the website without sharing information about your visit to the Website with the Controller. Using incognito mode, and therefore refusing to provide this data, does not affect your ability to use the Website.
5. Personal Data Retention Period
The period for which the Controller processes data depends on the type of service provided and the purpose of processing. As a rule, data is processed for the duration of the service or performance of the contract, or until an effective objection to data processing is submitted in cases where the legal basis for processing is the Controller’s legitimate interest. The data processing period may be extended if processing is necessary to establish and pursue possible claims or defend against them, and after that time only if and to the extent required by law. After the processing period expires, the data is irreversibly deleted or anonymised.
Personal data processed on the basis of the User’s consent will be stored until that consent is withdrawn.
Data related to website traffic analysis collected through cookies and similar technologies may be stored until the cookie expires. Some cookies never expire, and therefore the data retention period will correspond to the time the Controller needs to achieve the purposes related to data collection, such as ensuring security and analysing historical website traffic data.
6. Data Recipients
Recipients of personal data may only be entities entitled to receive it under applicable law, such as the Police or courts in connection with proceedings conducted. In addition, data may be disclosed to hosting providers, mail server providers and other entities providing IT services to the Company.
7. Rights Under the GDPR Regarding the Data Processed
Under the rules set out in the GDPR, every Website user has the right to:
- request access to their data from the Controller and receive a copy of it;
- request that the Controller rectify data if the user notices that it is incorrect or incomplete;
- request that the Controller erase data;
- request that the Controller restrict processing, for example when the user notices that data is incorrect and requests restriction of processing for a period allowing the Company to verify the correctness of that data;
- withdraw consent at any time, provided that withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal;
- lodge a complaint with the supervisory authority, the President of the Personal Data Protection Office (https://uodo.gov.pl), if the user considers that data processing infringes the GDPR.
8. Personal Data Security
The Controller ensures that personal data is processed securely, in particular by limiting access to the data only to authorised persons and only to the extent necessary for them to perform their duties. All operations on personal data are recorded and carried out only by authorised employees or associates. The Controller takes appropriate measures to ensure that subcontractors and other cooperating entities also apply security measures appropriate to the scope of data processing entrusted to them.
9. Use of Cookies and Similar Technologies
The Website enables information about the user to be collected through cookies and similar technologies. Using such technologies most often involves installing this tool on the user’s device, such as a computer or smartphone. This information is used to remember the User’s decisions, such as font choice, contrast or acceptance of the policy, maintain the User’s session, collect information about the User’s device and visit for security purposes, and also analyse visits and adapt content.
Information obtained through cookies and similar technologies is not combined with other data of Website Users and is not used by the Controller to identify them.
The User may set their browser to block certain types of cookies and other technologies, for example by allowing only files that are necessary for the website to display correctly. By default, most browsers allow all cookies, but the User may change these settings at any time and may also delete cookies that have already been installed. Each browser allows this through one of the options available in its settings or preferences. The User may also browse the website in incognito mode, which blocks the collection of data about the visit.
In addition, the Controller may use cookies and similar technologies for analytics purposes, but only on the basis of the User’s voluntary and explicit consent, requested through appropriate technical solutions available on the Website. The User may change cookie settings at any time.
10. Technologies Used on the Website
DoubleClick.Net
The Website uses DoubleClick, a tool provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), used for online advertising activities on the basis of the User’s prior consent given for this purpose (Article 6(1)(a) GDPR). Detailed information about the types of cookies placed on Users’ devices by DoubleClick and how they work is available at: https://policies.google.com/technologies/types?hl=en.
Google Analytics
The Website uses Google Analytics, a tool provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), which is used to analyse User visits to the Website. This tool does not collect data that would allow the User’s identity to be determined. Google Analytics tools allow traffic on the Website to be monitored and adapted to the User’s needs, and this takes place on the basis of the User’s consent (Article 6(1)(a) GDPR). Detailed information about the security of data collected through Google Analytics is available at: https://support.google.com/analytics/answer/6004245.
Google Tag Manager
Our website uses Google Tag Manager, a tool provided by Google Inc. that allows management of tags (code snippets) used for website traffic analysis, marketing and integration with external tracking tools.
CrUX (Chrome User Experience Report)
The Website uses data provided by CrUX (Chrome User Experience Report), which contains anonymous information about website performance based on real user data from people using the Google Chrome browser. This data is used to analyse and improve the quality of user experience on our website.
11. Changes to the Privacy Policy
This Policy is reviewed on an ongoing basis and updated when necessary.