This Privacy Policy reflects our commitment to protecting the rights of individuals visiting the website and using the services offered through it. It also fulfils the information obligation arising from Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Official Journal of the European Union L119 of 4 May 2016, p. 1) (hereinafter referred to as the “GDPR”).

The website owner places particular importance on respecting the privacy of website users. Data collected through the website is specially protected and secured against access by unauthorised persons. This Privacy Policy is made available to all interested parties. The website is publicly accessible.

The website owner ensures that its primary objective is to provide users of the website with privacy protection at a level at least equivalent to the requirements imposed by applicable laws, in particular the provisions of the GDPR and the Act of 18 July 2002 on the Provision of Services by Electronic Means.

The website owner may collect personal data and other types of information. The collection of such data depends on its nature and may take place automatically or as a result of actions taken by website visitors.

Any person using the website in any way accepts all rules contained in this Privacy Policy. The website owner reserves the right to make changes to this document.

 

I. General information, cookies

  1. The owner and operator of the website is KABARPOL7 SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, SPÓŁKA KOMANDYTOWĄ, ul. Płk. Jana Pałubickiego 6, 80-175 Gdańsk, NIP: 9571077561, REGON: 361011930. In accordance with the GDPR, the website owner is also the Controller of Users’ Personal Data (“Controller”).
  2. As part of its activities, the Controller uses cookies by monitoring and analysing traffic on the website and conducting remarketing activities; however, within these activities, the Controller does not process personal data within the meaning of the GDPR.
  3. The website collects information about users and their behaviour in the following ways:
    1. automatically through information contained in cookies;
    2. through data voluntarily entered by users in forms available on the website;
    3. through automatic collection of web server logs by the hosting provider.
  4. Cookies are IT data, in particular text files, stored on the user’s end device and intended for use with the website. Cookies usually contain the name of the website from which they originate, the period for which they are stored on the end device, and a unique identifier.
  5. During a visit to the website, user data may be automatically collected, relating to the user’s visit and including, among others: IP address, browser type, domain name, number of page views, operating system type, visit details, screen resolution, number of screen colours, website addresses from which the user accessed the website, and duration of use. This data is not personal data and does not allow identification of the person using the website.
  6. The website may contain links to other websites. The website owner is not responsible for the privacy practices applied by those websites. Users are encouraged to review the privacy policies of those websites. This Privacy Policy does not apply to other websites.
  7. The entity placing cookies on the user’s end device and accessing them is the website owner.
  8. Cookies are used for the following purposes:
    1. adapting website content to user preferences and optimising the use of the website; in particular, cookies allow the user’s device to be recognised and the website to be displayed appropriately according to individual needs;
    2. creating statistics that help understand how users use the website, enabling improvements to its structure and content;
    3. maintaining user sessions (after logging in), so that users do not need to enter their login and password again on each subpage.
  • The following types of cookies are used on the website:
    1. “Necessary” cookies, enabling the use of services available on the website, e.g. authentication cookies;
    2. cookies used to ensure security, e.g. those used to detect misuse;
    3. “performance” cookies, used to collect information about how users use the website;
    4. “advertising” cookies, enabling the delivery of advertising content better tailored to users’ interests;
    5. “functional” cookies, enabling the website to remember selected user settings and adapt the website accordingly, e.g. the selected language.
  • The website uses two main types of cookies: “session cookies” and “persistent cookies”. Session cookies are temporary files stored on the user’s end device until the user leaves the website, logs out or closes the browser. Persistent cookies are stored on the user’s end device for a period specified in the cookie parameters or until they are deleted by the user.
  • In most cases, software used for browsing websites allows cookies to be stored on the user’s end device by default. Users may change their cookie settings at any time. These settings can be modified in the browser options, including in a way that prevents the automatic handling of cookies or requires the user to be informed each time cookies are placed on their device. Detailed information about cookie management options is available in the browser settings.
  • Restrictions on the use of cookies may affect some functionalities available on the website.
  • Cookies placed on the user’s end device may also be used by advertisers and partners cooperating with the website owner.

 

II. Processing of personal data, information about forms

  1. Users’ personal data may be processed by the Controller:
    1. where the user has given consent through forms available on the website, in order to take actions related to the purpose of those forms (Article 6(1)(a) GDPR), or
    2. where processing is necessary for the performance of a contract to which the user is a party (Article 6(1)(b) GDPR), if the website enables the conclusion of a contract between the Controller and the user.
  2. Only personal data voluntarily provided by users is processed through the website. The Controller processes users’ personal data only to the extent necessary for the purposes specified in point 1(a) and 1(b) above, and for the period necessary to achieve these purposes, or until consent is withdrawn by the user. Failure to provide data may, in certain situations, prevent the achievement of purposes for which providing such data is required.
  3. The following personal data may be collected through forms available on the website or for the purpose of performing contracts concluded through the website: first name, surname, address, email address, telephone number, login and password.
  4. Data contained in forms and provided to the Controller by users may be transferred by the Controller to third parties cooperating with the Controller in connection with achieving the purposes specified in point 1(a) and 1(b) above.
  5. Data provided in forms available on the website is processed for purposes resulting from the function of the specific form. It may also be used by the Controller for archival and statistical purposes. Consent of the data subject is expressed by selecting the relevant checkbox in the form.
  6. If the website provides such functionality, the user may, by selecting the appropriate checkbox in the registration form, refuse or consent to receiving commercial information by electronic means, in accordance with the Act of 18 July 2002 on the Provision of Services by Electronic Means. If the user has consented to receiving commercial information electronically, they have the right to withdraw such consent at any time. Withdrawal of consent is carried out by sending an appropriate request by email to the website owner’s address, including the user’s first name and surname.
  7. Data provided in forms may be transferred to entities technically providing certain services — in particular, this applies to transferring information about the holder of a registered domain to entities operating internet domains (including the Research and Academic Computer Network – NASK), payment service providers, or other entities cooperating with the Controller in this area.
  8. Users’ personal data is stored in a database where technical and organisational measures are applied to ensure protection of processed data in accordance with applicable legal requirements.
  • In order to prevent re-registration of persons whose participation in the website has been terminated due to unauthorised use of services, the Controller may refuse to delete personal data necessary to block the possibility of re-registration. The legal basis for such refusal is Article 19(2)(3) in conjunction with Article 21(1) of the Act of 18 July 2002 on the Provision of Services by Electronic Means (consolidated text of 15 October 2013, Journal of Laws of 2013, item 1422). The Controller may also refuse deletion of users’ personal data in other cases provided for by law.
  • In cases provided for by law, the Controller may disclose certain personal data of website users to third parties for purposes related to protecting the rights of third parties.
  • The Controller reserves the right to send all website users electronic messages notifying them of important changes to the website and changes to this Privacy Policy. The Controller may send commercial electronic messages, in particular advertisements and other commercial information, provided that the user has given consent. Advertisements and other commercial content may also be attached to incoming and outgoing messages from the system account.

 

III. Users’ rights regarding their personal data

In accordance with Articles 15–22 of the GDPR, every website user has the following rights:

  1. Right of access to data (Article 15 GDPR)The data subject has the right to obtain confirmation from the Controller as to whether personal data concerning them is being processed and, if so, to obtain access to that data. Pursuant to Article 15 GDPR, the Controller shall provide the data subject with a copy of the personal data undergoing processing.
  2. Right to rectification of data (Article 16 GDPR)The data subject has the right to request the Controller to immediately correct inaccurate personal data concerning them.
  3. Right to erasure (“right to be forgotten”) (Article 17 GDPR)The data subject has the right to request the Controller to immediately delete personal data concerning them. The Controller is obliged to delete personal data without undue delay if one of the following circumstances applies:
    1. the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
    2. the data subject has withdrawn consent on which the processing is based;
    3. the data subject objects, pursuant to Article 21(1) GDPR, to the processing and there are no overriding legitimate grounds for the processing.
  4. Right to restriction of processing (Article 18 GDPR)The data subject has the right to request restriction of processing by the Controller in the following cases:
    1. when the data is inaccurate — for the period necessary for its correction;
    2. when the data subject has objected to processing pursuant to Article 21(1) GDPR — until it is determined whether the legitimate grounds of the Controller override the grounds for objection of the data subject;
    3. when processing is unlawful and the data subject objects to the deletion of personal data, requesting restriction of its use instead.
  • Right to data portability (Article 20 GDPR)The data subject has the right to receive personal data concerning them, which they have provided to the Controller, in a structured, commonly used and machine-readable format. The data subject also has the right to transmit this data to another controller without hindrance from the Controller to whom the personal data was provided.

    The data subject has the right to request that personal data be transmitted directly by the Controller to another controller, where technically feasible. The exercise of this right may not adversely affect the rights and freedoms of others.

  • Right to object (Article 21 GDPR)Where personal data is processed for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data concerning them for such marketing purposes, including profiling, to the extent that the processing is related to such direct marketing.

The exercise of the above rights by website users may be subject to fees in cases where applicable legal provisions allow this.

In the event of a violation of the above rights or if the user determines that their personal data is processed by the Controller in breach of applicable law, the user has the right to lodge a complaint with the supervisory authority.

 

IV. Server logs

  1. In accordance with the common practice of most websites, the website operator stores HTTP requests directed to the operator’s server (information about certain user activities is recorded at the server level).The resources viewed are identified by URL addresses. The exact scope of information stored in web server log files includes:
    1. the public IP address of the computer from which the request originated;
    2. the client station name — identification performed by the HTTP protocol, where possible;
    3. the website user’s name provided during the authentication (login) process;
    4. the time the request was received;
    5. the HTTP response code;
    6. the number of bytes sent by the server;
    7. the URL address of the page previously visited by the user (referrer link) — where access to the website occurred through a link;
    8. information about the user’s web browser;
    9. information about errors occurring during the execution of HTTP transactions.

The above data is not associated with specific individuals browsing pages available within the website.

In order to ensure the highest possible quality of the website, the operator occasionally analyses log files to determine which pages are visited most frequently, which web browsers are used, whether the website structure contains errors, and other technical aspects.

The logs collected by the operator are stored for an indefinite period as supporting material used for the proper administration of the website. The information contained in them is not disclosed to any entities other than the operator or entities affiliated with the operator personally, financially or contractually.

Based on the information contained in these files, statistics may be generated to support website administration. Summaries containing such statistics do not include information identifying individual website visitors.