PRIVACY POLICY OF GROM GROUP Sp. z o.o.
(valid from: 1 September 2018)
1.The controller of your personal data is Grom Group Sp. z o.o., with its registered office in Warsaw, ul. Wspólna 2C lok. 2-4, 05-075 Warszawa, entered in the register of entrepreneurs maintained by the District Court for the capital city of Warsaw, 13th Commercial Division of the National Court Register under KRS number: 0000352551, Tax ID (NIP): 952-20-86-318, Statistical Number (REGON): 142294543, share capital in the amount of PLN 5,000.00, fully paid up (hereinafter referred to as the “Company” or the “Controller”).
2. The Controller processes your personal data in accordance with the requirements of the Act of 10 May 2018 on Personal Data Protection (Journal of Laws 2018, item 1000) and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR).
3. Due to the nature and scope of its activities, the Controller is not obliged to appoint a Data Protection Officer under the GDPR. In matters concerning the protection of your personal data, you may contact the Controller:
a. by sending correspondence to: Grom Group Sp. z o.o., ul. Wspólna 2C lok. 2-4, 05-075 Warszawa;
c. via the electronic contact form available at: www.gromgroup.pl;
za pośrednictwem elektronicznego regulaminu kontaktowego dostępnego na stronie: www.gromgroup.pl;
d. by phone at: +48 22-760-85-68.
4. Your personal data are processed on the basis of:
a. Article 6(1)(b) GDPR – for the purpose of taking action at the request of the data subject prior to entering into a contract and for the performance of a contract to which the data subject is party, including handling inquiries and complaints both before and during the term of the contract;
b. Article 6(1)(c) GDPR – to comply with legal obligations imposed on the Controller under European Union or Polish law, including tax and accounting regulations;
c. Article 6(1)(f) GDPR – for the purposes of the legitimate interests pursued by the
establishing, investigating or defending against claims;
handling complaints, notifications and inquiries;
concluding insurance contracts, e.g. personal accident insurance;
conducting analyses in terms of quality, better selection and optimization of services and processes;
storing personal data for archiving purposes;
ensuring accountability.
Article 6(1)(a) of the GDPR, after the data subject has consented to the processing of his or her personal data for the purpose of offering products and services as part of marketing activities, including direct marketing carried out using electronic means of communication, e.g. e-mail, SMS, MMS or telephone, and traditional mail.
5. The Administrator is entitled to process the received personal data for the purposes referred to in points 4 a) and 4b) and 4c) above without the need for the data subject to consent to the processing of personal data.
6. Your personal data will be processed by the Administrator:
a. personal data processed on the basis of Article 6(1)(b), (c) and (f) of the GDPR will be processed for the duration of the contract (service provision) and, after its expiry, for the period necessary to:
pursuing or securing possible claims;
handling complaints;
ensuring archiving;
ensuring accountability;
conducting analyses in terms of quality, better selection and optimization of services and processes;
fulfillment of legal obligations incumbent on the Administrator.
b. personal data processed on the basis of Article 6 paragraph 1 letter a) will be processed until the consent is withdrawn, the data subject objects to the processing of personal data, and the withdrawal of consent is possible at any time by sending information:
to the address: Grom Group Sp. z o.o., ul. Wspólna 2C apt. 2-4, 05-075 Warsaw;
to the e-mail address: sekretariat@gromgroup.pl;
via the electronic contact form available on the website: www.gromgroup.pl.
7. The Controller is entitled to transfer your personal data to third parties cooperating with the Company for the purpose and to the extent necessary for the Company to prepare and perform the ordered service and to execute the contract, including in particular managers or owners of facilities used by the Company during the performance of services, suppliers responsible for operating the Controller's IT devices and systems, entities providing accounting, legal, administrative, consulting, courier, and insurance services to the Company (hereinafter collectively referred to as "Subcontractors" or individually as "Subcontractor"). Furthermore, the Controller is obliged to transfer your personal data under the law, including at the request of authorized courts, authorities, and institutions.
8. Your personal data, as a rule, is not transferred outside the EEA (European Economic Area). However, your personal data may be transferred outside the EEA when necessary to perform the service, including when the performance of the service requires the involvement of subcontractors based outside the EEA. In such a case, your personal data is transferred to a country outside the EEA based on a European Commission decision confirming an adequate level of protection. In the absence of an adequacy decision, appropriate safeguards are applied in accordance with legal requirements to ensure an adequate level of personal data protection – these include, in particular, the European Union's standard contractual clauses. If it is necessary to transfer your personal data outside the EEA, you can request further information and receive a copy of the appropriate safeguards at any time.
9. Subject to the limitations arising from the GDPR and other legal provisions, you have the right to object at any time to the processing of your personal data, processed for the purposes and on the basis indicated in section 4 above. If you exercise this right, we will cease processing your personal data. The Controller will cease processing your personal data for the purposes and on the basis indicated in section 4 above unless it can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or your personal data are necessary for the Controller to establish, pursue, or defend potential claims.
10. You have the right to access your personal data and receive a copy thereof, to rectify (amend) your data, to delete, limit or object to their processing, to transfer personal data, and to lodge a complaint with the supervisory authority.
11. No automated decisions (decisions without human involvement) will be made regarding your personal data, including your personal data will not be subject to automated profiling.
12. Providing your personal data is voluntary, but necessary in order to register for participation in projects carried out by the Company and necessary for the Company to perform the service for which you are the recipient.
13. In matters not regulated by the "Grom Group Sp. z o.o. Privacy Policy", the provisions on personal data protection apply.
Annex to the Privacy Policy of Grom Group Sp. z o.o.
COOKIE POLICY
1. The "Cookie Policy" (hereinafter referred to as the "Policy") is an annex to the "Grom Group Sp. z o.o. Privacy Policy", constitutes its integral part and refers to internet tags, such as cookies, which are used on the website www.gromgroup.pl (hereinafter referred to as the "Website").
2. By using the Website, you consent to the use of Cookies in accordance with the Policy by configuring your browser settings accordingly. If you do not agree to our use of Cookies or if you wish to limit the use of Cookies, please change your browser settings accordingly or refrain from using the Website.
3. Cookies are IT data saved in files and stored on the end device of the Website user, which the browser sends to the server each time the Website is connected from a given end device (e.g. computer, tablet, smartphone, etc.).
4. Cookies usually contain the name of the website from which they originate, their lifetime, a unique number generated to identify the browser from which the website is accessed, and other necessary information.
5. The entity that places cookies on the user's end device and obtains access to them is the Administrator.
6. On our website we use cookies to collect and process personal data for the following purposes:
a. make them faster and easier to use;
b. ensuring the security of using the Website;
c. analyzing traffic on the Website.
7. Two basic types of cookies are used when using the Website: "session" and "persistent." "Session" cookies are temporary files that are stored on the user's end device until logging out, leaving the Website, or disabling the software (user's web browser). "Persistent" cookies are stored on the user's end device for the time specified in the cookie parameters or until they are deleted by the user.
8. Web browsing software (web browser) typically allows cookies to be stored on the user's end device by default. Users can change these settings. The web browser allows the deletion of cookies. It is also possible to automatically block cookies. For detailed information, refer to the help file or documentation for your web browser.
9. Restrictions on the use of cookies may affect some of the functionalities available on the Website.
10. Cookies may be used by advertising networks, particularly the Google network, to display advertisements tailored to the user's use of the Website. For this purpose, they may store information about the user's navigation path or the duration of their stay on a given page.
11. Disabling the use of cookies may impede the use of certain services on the Website, particularly those requiring logging in. However, disabling cookies does not prevent you from reading or viewing content posted on the Website, except for content that requires logging in.