Privacy Policy for the commercialaudio.pl Website
-
GENERAL PROVISIONS
- The controller of the personal data collected through the website https://commercialaudio.pl is Commercial Audio, LLC. conducting business activity registered in the National Court Register (KRS) under number 0000994236, place of business: 86a Jeziorki St., 02-863 Warsaw, Tax Identification Number (NIP): 951 255 04 12, REGON: 523242445, email address: [email protected], hereinafter referred to as the „Controller.”.
- Personal data collected by the Controller through the website is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the GDPR, and the Act on the Protection of Personal Data of May 10, 2018.
-
TYPE OF PERSONAL DATA PROCESSED, PURPOSE, AND SCOPE OF DATA COLLECTION
- when a user submits the contact form. Personal data is processed pursuant to Article 6(1)(f) of the GDPR as a legitimate interest of the Controller.
- the user subscribing to the newsletter to receive commercial information electronically. Personal data is processed after separate consent is given, pursuant to Article 6(1)(a) of the GDPR.
- First and last name,
- Email address,
- Phone number,
- Tax ID Number
- If the basis for data processing is the performance of a contract, for as long as necessary to perform the contract, and thereafter for a period corresponding to the statute of limitations for claims. Unless otherwise provided by a specific provision, the statute of limitations is six years; for claims for periodic payments and claims related to the conduct of business activities, it is three years.
- where the basis for data processing is consent, for as long as the consent remains in effect, and after the consent is revoked, for a period corresponding to the statute of limitations for claims that the Controller may assert and that may be asserted against it. Unless otherwise provided by a specific provision, the statute of limitations is six years, and for claims for periodic payments and claims related to the conduct of business activities—three years.
- processed in accordance with the law,
- collected for specified, legitimate purposes and not further processed in a manner incompatible with those purposes,
- accurate and relevant to the purposes for which they are processed, and stored in a form that allows for the identification of the data subjects for no longer than is necessary to achieve the purpose of the processing.
- PURPOSE OF DATA PROCESSING AND LEGAL BASIS. The administrator processes personal data through the website https://commercialaudio.pl in the case of:
- TYPE OF PERSONAL DATA PROCESSED. The administrator processes the following categories of the user's personal data:
- RETENTION PERIOD FOR PERSONAL DATA. Users' personal data is stored by the Administrator:
- While using the website, additional information may be collected, including, in particular: the IP address assigned to the user’s computer or the external IP address of the Internet service provider, the domain name, the browser type, the time of access, and the operating system type.
- We may also collect browsing data from users, including information about the links and hyperlinks they choose to click on or other actions they take on the website. The legal basis for such activities is the Controller’s legitimate interest (Article 6(1)(f) of the GDPR), which consists of facilitating the use of electronically provided services and improving the functionality of those services.
- The provision of personal information by the user is voluntary.
- Personal data will also be processed automatically through profiling, provided that the user consents to this pursuant to Article 6(1)(a) of the GDPR. Profiling will result in assigning a profile to a specific individual for the purpose of making decisions regarding that individual or analyzing or predicting their preferences, behaviors, and attitudes.
- The controller exercises due diligence to protect the interests of data subjects and, in particular, ensures that the data it collects is:
-
SHARING OF PERSONAL DATA
- Users’ personal data is transferred to service providers used by the Controller in operating the website. The service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, either follow the Controller’s instructions regarding the purposes and methods of processing such data (processors) or independently determine the purposes and means of processing such data (controllers).
- Users' personal data is stored exclusively within the European Economic Area (EEA).
-
RIGHT TO REVIEW, ACCESS, AND CORRECT ONE'S OWN DATA
- Access to Data – Article 15 of the GDPR
- Data Correction – Article 16 of the GDPR.
- Data Deletion (the so-called "right to be forgotten") – Article 17 of the GDPR.
- Restriction on processing – Article 18 of the GDPR.
- Data Transfer – Article 20 of the GDPR.
- Objection – Article 21 of the GDPR
- Withdrawal of Consent – Article 7(3) of the GDPR.
- The data subject has the right to access their personal data, as well as the right to have it corrected, deleted, or its processing restricted; the right to data portability; the right to object, and the right to withdraw consent at any time without affecting the lawfulness of processing carried out on the basis of consent prior to its withdrawal.
- Legal basis for the user's request:
- To exercise the rights referred to in point 2, you may send an email to the following address: [email protected].
- If a user exercises a right under the provisions above, the Controller will comply with the request or refuse to comply with it immediately, but no later than one month after receiving it. However, if—due to the complex nature of the request or the number of requests — the Administrator is unable to comply with the request within one month, it will comply within the following two months, having previously informed the user—within one month of receiving the request—of the intended extension of the deadline and the reasons for it.
- If it is determined that the processing of personal data violates the provisions of the GDPR, the data subject has the right to file a complaint with the President of the Personal Data Protection Office.
-
„COOKIES” FILES”
- „Session cookies” are temporary files that are stored on the user's device until the user logs out (leaves the website).
- „Persistent” cookies are stored on the user's device for the period specified in the cookie settings or until the user deletes them.
- The Administrator's website uses „cookies.”.
- The use of cookies is necessary for the proper provision of services on this website. Cookies contain information necessary for the proper functioning of the website, and they also enable us to compile general statistics on website traffic.
- This website uses two types of cookies: session cookies and persistent cookies
- The administrator uses its own cookies to better understand how users interact with the website’s content. These cookies collect information about how users use the website, the type of website from which users were referred, as well as the number of visits and the duration of each visit to the website. This information does not record specific personal data about the user but is used to compile statistics on website usage.
- You have the right to control whether „cookies” can access your computer by selecting the appropriate settings in your browser. Detailed information about the options and methods for managing cookies is available in your browser settings.
-
FINAL PROVISIONS
- The controller implements technical and organizational measures to ensure that the personal data being processed is protected in a manner appropriate to the risks and the categories of data being protected, and, in particular, protects the data against disclosure to unauthorized persons, removal by an unauthorized person, processing in violation of applicable laws, and alteration, loss, damage, or destruction.
- The administrator provides appropriate technical measures to prevent unauthorized persons from accessing or modifying personal data transmitted electronically.
- In matters not covered by this Privacy Policy, the provisions of the GDPR and other applicable provisions of Polish law shall apply accordingly.
