PLIKSHARE PRIVACY POLICY
TABLE OF CONTENTS:
- GENERAL PROVISIONS
- BASIS FOR PROCESSING DATA
- PURPOSE, BASIS, AND PERIOD OF DATA PROCESSING ON THE INTERNET SERVICE
- DATA RECIPIENTS ON THE INTERNET SERVICE
- PROFILING ON THE INTERNET SERVICE
- RIGHTS OF THE DATA SUBJECT
- COOKIES ON THE INTERNET SERVICE
- FINAL PROVISIONS
GENERAL PROVISIONS
- This Privacy Policy of the Internet Service is informative, which means that it is not a source of obligations for the Users of the Internet Service. The privacy policy primarily contains principles regarding the processing of personal data by the Administrator on the Internet Service, including the basis, purposes, and period of processing personal data, as well as the rights of individuals whose data is processed, and information regarding the use of Cookies on the Internet Service.
- The Administrator of personal data collected through the Internet Service is Damian Krychowski conducting business under the name Damian Krychowski (registered office and address for service: ul. Marii Skłodowskiej-Curie 8/22, 42-400 Zawiercie, Poland), NIP: 6492262191, email address: [email protected] – hereinafter referred to as the "Administrator" and also acting as the Service Provider on the Internet Service.
- Personal data on the Internet Service is processed by the Administrator in accordance with applicable law, in particular with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter referred to as "GDPR" or "GDPR Regulation." The official text of the GDPR Regulation: http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679.
- The use of the Internet Service, including entering into agreements, is voluntary. Similarly, the provision of personal data by the User of the Internet Service is voluntary, subject to two exceptions: (1) entering into agreements with the Administrator – failure to provide, in cases and to the extent indicated on the Internet Service and in the Regulations of the Internet Service and this privacy policy, personal data necessary to conclude and perform the Sales Agreement or other agreement with the Administrator will result in the inability to conclude the respective agreement. Providing personal data is a contractual requirement in such a case, and if the data subject wishes to enter into a specific agreement with the Administrator, they are obliged to provide the required data. The scope of data required to conclude an agreement is indicated beforehand on the Internet Service and in the Regulations of the Internet Service; (2) statutory obligations of the Administrator – providing personal data is a statutory requirement arising from universally applicable legal provisions imposing an obligation on the Administrator to process personal data (e.g., for the purpose of keeping tax records), and failure to provide them will prevent the Administrator from fulfilling these obligations. The Administrator takes special care to protect the interests of individuals whose personal data it processes, and in particular is responsible for ensuring that the data collected by it are: (1) processed lawfully; (2) collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes; (3) adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed; (4) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; and (5) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.
- Taking into account the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Administrator implements appropriate technical and organizational measures to ensure that the processing is carried out in accordance with the GDPR Regulation and to be able to demonstrate this. These measures are subject to review and update as necessary. The Administrator employs technical measures to prevent unauthorized access to and modification of personal data transmitted electronically.
- All words, expressions, and acronyms appearing in this privacy policy and beginning with a capital letter (e.g., Service Provider, Internet Service, Electronic Service) should be understood in accordance with their definitions contained in the Regulations of the Internet Service available on the Internet Service's website.
BASIS FOR PROCESSING DATA
- The Administrator is entitled to process personal data in cases where – and to the extent that – at least one of the following conditions is met: (1) the data subject has given consent to the processing of their personal data for one or more specific purposes; (2) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; (3) processing is necessary for compliance with a legal obligation to which the Administrator is subject; or (4) processing is necessary for the purposes of the legitimate interests pursued by the Administrator or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
- Processing of personal data by the Administrator requires the existence of at least one of the grounds indicated in point 2.1 of the privacy policy. The specific grounds for processing personal data of Users of the Internet Service by the Administrator are indicated in the subsequent point of the privacy policy – regarding the specific purpose of processing personal data by the Administrator.
PURPOSE, BASIS, AND PERIOD OF DATA PROCESSING ON THE INTERNET SERVICE
- The purpose, basis, and period as well as the recipients of personal data processed by the Administrator result from the actions taken by each respective User on the Internet Service.
- The Administrator may process personal data on the Internet Service for the following purposes, on the following legal bases, and for the following periods:
Purpose of data processing | Legal basis for data processing | Data retention period |
Implementation of a Sales Contract, another contract or taking action on a data subject's request before a contract is concluded | Article 6(1)(b) of the RODO Regulation (performance of a contract) - the processing is necessary for the performance of a contract to which the data subject is party or to take steps at the request of the data subject prior to entering into a contract. | The data shall be stored for the period necessary for the performance, termination or otherwise expiry of the concluded contract. |
Responding to an enquiry sent to the Administrator | Article 6(1)(f) of the RODO Regulation (legitimate interest of the Controller) - the processing is necessary for the purposes of the Controller's legitimate interests - consisting of the need to review the content of the enquiry sent by the data subject via the contact form available on the Website and, if necessary, to respond to that enquiry. | The data shall be stored for the time necessary for the Controller to review and respond to the data subject's request, but not longer than the duration of the legitimate interest pursued by the Controller in relation to the information contained in the request. |
Direct marketing | Article 6(1)(f) of the RODO Regulation (legitimate interest of the Administrator) - processing is necessary for the purposes of the Administrator's legitimate interests - consisting of looking after the interests and good image of the Administrator, its Website and seeking to sell services. | The data shall be stored for the period of existence of the legitimate interest pursued by the Administrator, but no longer than for the period of limitation of the Administrator's claims against the data subject in respect of the Administrator's business activities. The limitation period shall be determined by the provisions of law, in particular the Civil Code (the basic limitation period for claims related to the conduct of business activities is three years). The Administrator may not process data for direct marketing purposes in the event of an effective objection to this effect by the data subject. |
Newsletter management | Article 6(1)(a) of the RODO Regulation (consent) - the data subject has consented to the processing of their personal data for marketing purposes by the Controller. | The data is stored until the data subject withdraws his or her consent to further processing for this purpose. |
Bookkeeping | Article 6(1)(c) of the RODO Regulation in conjunction with Article 74(2) of the Accounting Act, i.e. of 30 January 2018. (Journal of Laws of 2018, item 395 as amended) - the processing is necessary for the fulfilment of a legal obligation incumbent on the Administrator. | The data is retained for the period required by the law requiring the Administrator to keep the accounts (5 years, calculated from the beginning of the year following the financial year to which the data relates). |
Establishing, asserting or defending claims which the Administrator may assert or which may be asserted against the Administrator | Article 6(1)(f) of the RODO Regulation (legitimate interest of the Administrator) - the processing is necessary for the purposes of the Administrator's legitimate interests - consisting of establishing, pursuing or defending claims which the Administrator may raise or which may be raised against the Administrator. | The data shall be stored for the period of existence of the legitimate interest pursued by the Administrator, but no longer than for the period of limitation of claims that may be raised against the Administrator (the basic limitation period for claims against the Administrator is six years). |
Use of the Website and ensuring its correct operation | Article 6(1)(f) of the RODO Regulation (legitimate interest of the Administrator) - the processing is necessary for the purposes arising from the Administrator's legitimate interests - consisting of the operation and maintenance of the Website. | The data shall be stored for the period of existence of the legitimate interest pursued by the Administrator, but no longer than for the period of limitation of the Administrator's claims against the data subject in respect of the Administrator's business activities. The limitation period is determined by law, in particular the Civil Code (the basic limitation period for claims related to the conduct of business activities is three years). |
Keeping statistics and analysing traffic on the Website | Article 6(1)(f) of the RODO Regulation (legitimate interest of the Administrator) - the processing is necessary for the purposes of the Administrator's legitimate interests - consisting of statistics and analysis of traffic on the Website in order to improve the functioning of the Website and increase the reach of the services provided. | The data shall be stored for the period of existence of the legitimate interest pursued by the Administrator, but no longer than for the period of limitation of the Administrator's claims against the data subject in respect of the Administrator's business activities. The limitation period is determined by law, in particular the Civil Code (the basic limitation period for claims related to the conduct of business activities is three years). |
DATA RECIPIENTS ON THE INTERNET SERVICE
- For the proper functioning of the Internet Service, including the proper provision of Electronic Services by the Administrator, it is necessary for the Administrator to use services of external entities (such as software providers, payment processing entities). The Administrator exclusively utilizes services of such processing entities that provide sufficient guarantees of implementing appropriate technical and organizational measures to ensure that the processing meets the requirements of the GDPR Regulation and protects the rights of individuals whose data is processed.
- Personal data may be transferred by the Administrator to a third country, whereby the Administrator ensures that in such cases, it will be done with respect to a country providing an adequate level of protection – in accordance with the GDPR Regulation, and in the case of other countries, that the transfer will be based on standard data protection clauses. The Administrator ensures that the data subject has the possibility to obtain a copy of their data. The Administrator transfers collected personal data only when necessary for the respective purpose of processing data in accordance with this privacy policy.
- Data transfer by the Administrator does not occur in every case and not to all recipients or categories of recipients specified in the privacy policy – the Administrator transfers data only when necessary for the realization of the respective purpose of processing personal data and only to the extent necessary for its implementation.
- Personal data of Users of the Internet Service may be transferred to the following recipients or categories of recipients:
- Entities processing electronic payments or credit/debit card transactions – in the case of a User who utilizes electronic payment methods or credit/debit cards on the Internet Service, the Administrator provides collected personal data of the User to the selected entity processing such payments on behalf of the Administrator, to the extent necessary for processing the payment made by the User. In the case of the Internet Service, the entity responsible for processing both electronic payments and bank transfers is the Stripe system operated by the entity: Stripe, Inc. (https://stripe.com/en-pl).
- Service providers supplying the Administrator with technical, IT, and organizational solutions, enabling the Administrator to conduct business operations, including the Internet Service and Electronic Services provided through it (in particular, providers of software for running the Internet Service, providers of software for managing the Administrator's appointment calendar, providers of email and hosting services, as well as providers of software for managing the company and providing technical support to the Administrator, providers of software for automating the invoicing process, providers of software for video streaming) – the Administrator provides collected personal data of the User to the selected provider acting on its behalf only in the case and to the extent necessary for the realization of the respective purpose of data processing in accordance with this privacy policy.
- Accounting, legal, and advisory service providers ensuring accounting, legal, or advisory support to the Administrator (in particular, accounting firms, law firms, or debt collection companies) – the Administrator provides collected personal data of the User to the selected provider acting on its behalf only in the case and to the extent necessary for the realization of the respective purpose of data processing in accordance with this privacy policy.
- Providers of social media plugins, scripts, and other similar tools placed on the Internet Service website enabling the browser of the visiting individual to download content from providers of the mentioned plugins (e.g., logging in using login data for a social media service) and transmitting personal data of the visiting individual, including:
- Meta Platforms Ireland Ltd. – the Administrator utilizes social media plugins from Facebook on the Internet Service website (e.g., Like button, Share button, or login using Facebook credentials) and therefore collects and provides personal data of the User using the Internet Service to Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland) to the extent and in accordance with the privacy policies available here: https://www.facebook.com/about/privacy/ (this data includes information about actions on the Internet Service website – including information about the device, visited pages, purchases, displayed advertisements, and usage of services – regardless of whether the User has a Facebook account and whether they are logged into Facebook).
- TikTok Technology Limited (for users from the European Economic Area and Switzerland) and TikTok Information Technologies UK Limited (for users from the United Kingdom) – the Administrator utilizes social media plugins from TikTok on the Internet Service website (e.g., Like button, Share button, Comment button, etc. or login using TikTok credentials). Therefore, the Administrator collects and provides personal data of the User using the Internet Service to TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (for users from the European Economic Area and Switzerland) or TikTok Information Technologies UK Limited, 6th Floor, One London Wall, London, EC2Y 5EB, United Kingdom (for users from the United Kingdom), to the extent and in accordance with the privacy policies available here: https://www.tiktok.com/legal/copyright-policy?lang=pl- PL (this data includes information about actions on the Internet Service website – including information about the device, visited pages, purchases, displayed advertisements, and usage of services – regardless of whether the User has a TikTok account and whether they are logged into TikTok).
PROFILING ON THE INTERNET SERVICE
- The GDPR Regulation imposes an obligation on the Administrator to inform about automated decision-making, including profiling, as referred to in Article 22(1) and (4) of the GDPR Regulation, and – at least in these cases – to provide essential information about the principles of their making, as well as the significance and anticipated consequences of such processing for the data subject. Bearing this in mind, the Administrator provides information regarding potential profiling in this section of the privacy policy.
- The Administrator may use profiling on the Internet Service for direct marketing purposes, but the decisions made on its basis by the Administrator do not concern the conclusion or refusal to conclude a Sales Agreement or the possibility of using Electronic Services on the Internet Service. The result of using profiling on the Internet Service may include, for example, reminders of unfinished actions on the Service, sending discounts, or proposals of services that may correspond to the interests or preferences of a particular person, or proposing better terms compared to the standard offer of the Internet Service. Despite profiling, the individual freely decides whether they want to take advantage of, for example, the offer or discount received in this way.
- Profiling on the Internet Service involves the automatic analysis or prediction of the behaviour of a particular person on the Internet Service website or through the analysis of previous purchases or actions taken on the Internet Service website. The condition for such profiling is the possession of personal data of a particular person by the Administrator, in order to subsequently send them, for example, a discount code or an offer.
- The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
RIGHTS OF THE DATA SUBJECT
- Right of access, rectification, restriction, erasure, or portability – the data subject has the right to request from the Administrator access to their personal data, their rectification, erasure ("right to be forgotten"), or restriction of processing, and also has the right to object to processing, as well as the right to data portability. Detailed conditions for exercising the rights mentioned above are indicated in Articles 15-21 of the GDPR Regulation.
- Right to withdraw consent at any time – the data subject whose data are processed by the Administrator based on the consent given (based on Article 6(1)(a) or Article 9(2)(a) of the GDPR Regulation) has the right to withdraw their consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint with a supervisory authority – the data subject whose data are processed by the Administrator has the right to lodge a complaint with the supervisory authority in the manner and procedure specified in the provisions of the GDPR Regulation and Polish law, in particular, the Personal Data Protection Act. The supervisory authority in Poland is the President of the Personal Data Protection Office.
- Right to object – the data subject has the right at any time to object, for reasons relating to their particular situation, to the processing of their personal data based on Article 6(1)(e) (public interest or official authority) or (f) (legitimate interests pursued by the controller) of the GDPR Regulation, including profiling based on these provisions. In such a case, the Administrator may no longer process this personal data unless they demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defence of legal claims.
- Right to object to direct marketing – if personal data are processed for direct marketing purposes, the data subject has the right at any time to object to the processing of their personal data for such marketing, including profiling, to the extent that the processing is related to such direct marketing.
- In order to exercise the rights referred to in this section of the privacy policy, you can contact the Administrator by sending an appropriate message in writing or by email to the Administrator's address specified at the beginning of the privacy policy.
COOKIES ON THE INTERNET SERVICE
- Cookies are small text information files in the form of text files, sent by the server and saved on the side of the person visiting the Internet Service website (e.g., on the hard drive of a computer, laptop, or on the memory card of a smartphone – depending on the device used by the visitor of the Internet Service). Detailed information about cookies, as well as the history of their creation, can be found, among others, here: (https://en.wikipedia.org/wiki/HTTP_cookie).
- Cookies that may be sent by the Internet Service website can be divided into various types, according to the following criteria:
By their provider:
their own (created by the Administrator's website) and owned by third parties (other than the Administrator)By their duration of storage on the device of the visitor to the Website: - session files (stored until you log out or leave the Website or switch off your web browser) and permanent (stored for a specific period of time, defined by the parameters of each file or until manual removal)
With regard to the purpose of their use: - essential (enabling the proper functioning of the Website page),
- functional/preferential (enabling adjustment of the website's page to the visitor's preferences)
- analytical and performance (gathering information on the use of the Website page),
- marketing, advertising and social (gathering information about the visitor to a website in order to display advertisements to them, personalise them, measure their effectiveness and conduct other marketing activities, including on websites separate from the website, such as social networks or other websites belonging to the same advertising networks as the website)
- The Administrator may process the data contained in Cookies when visitors use the Website for the following specific purposes:
- identify users as logged in to the Website and show that they are logged in (essential cookies)
- storing data from completed forms, surveys or login data for the Website (essential and/or functional/preference cookies)
- remembering Services added to the electronic shopping cart for the purpose of making an enquiry (cookies required)
- adapting the content of the Website to the individual preferences of the Customer (e.g. as regards colours, font size, page layout) and optimising the use of the Website's pages (functional/preference cookies)
- keep anonymous statistics on how the Website is used (analytical and performance cookies)
- to display and render advertisements, to limit the number of times advertisements are displayed and to ignore advertisements which the Client does not wish to see, to measure the effectiveness of advertisements, and to personalise advertisements, i.e. to study the behavioural characteristics of visitors to the Website by analysing their actions anonymously (e.g. repeated visits to specific pages, keywords, etc.) in order to create their profile and to provide them with advertisements tailored to their anticipated interests, also when they visit other websites on the advertising network of Google Ireland Ltd. and Meta Platforms Ireland Ltd. (marketing, advertising and social media cookies)
- It is possible to check in the most popular web browsers which cookies (including the duration of the cookies and their provider) are being sent by the Website at any given time, as follows:
In the Chrome browser:
(1) in the address bar, click on the padlock icon on the left, (2) go to the ‘Cookies’ tab.In the Firefox browser:
(1) in the address bar, click on the shield icon on the left, (2) go to the ‘Allowed’ or ‘Blocked’ tab, (3) click on the box ‘Inter-site tracking cookies’, ‘Social media tracking elements’ or ‘Content with tracking elements’Internet Explorer browser:
(1) click the ‘Tools’ menu, (2) go to the ‘Internet Options’ tab, (3) go to the ‘General’ tab, (4) go to the ‘Settings’ tab, (5) click the ‘View Files’ boxIn the Opera browser:
(1) in the address bar, click on the padlock icon on the left, (2) go to the ‘Cookies’ tab.In the Safari browser:
(1) click on the ‘Preferences’ menu, (2) go to the ‘Privacy’ tab, (3) click on the box ‘Manage site data’Irrespective of the browser:
using the tools available, for example, at: https://www.cookiemetrix.com/ or: https://www.cookie-checker.com/ - By default, most web browsers available on the market accept the storage of cookies. Everyone has the ability to determine the conditions of using cookies through the settings of their own web browser. This means that it is possible, for example, to partially limit (temporarily) or completely disable the ability to store cookies – however, in the latter case, this may affect some functionalities of the Internet Service.
- The settings of the internet browser regarding cookies are important from the point of view of consent to the use of cookies by the Internet Service – according to the regulations, such consent can also be expressed through the settings of the internet browser. Detailed information on changing settings regarding cookies and their self-deletion in the most popular internet browsers is available in the browser's help section and on the following pages (simply click on the respective link):
- [Chrome browser] (https://support.google.com/chrome/answer/95647)
- [Firefox browser] (https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences)
- [Internet Explorer browser] (https://support.microsoft.com/en-us/topic/delete-and-manage-cookies-168dab11-0753-043d-7c16-ede5947fc64d)
- [Opera browser] (https://help.opera.com/en/latest/web-preferences/#cookies)
- [Safari browser] (https://support.apple.com/en-us/guide/safari/manage-cookies-and-website-data-sfri11471/mac)
- [Microsoft Edge browser] (https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09)
- The Administrator may use Google Analytics services provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) on the Internet Service website. These services help the Administrator to compile statistics and analyze traffic on the Internet Service. The collected data is processed within the framework of the above services to generate statistics helpful in administering the Service and analyzing traffic on the Internet Service website. This data is aggregate in nature. By using the above services on the Internet Service website, the Administrator collects data such as sources and mediums of acquiring visitors to the Internet Service website, as well as their behaviour on the Internet Service website, information about devices and browsers from which they visit the site, IP and domain, geographical data, as well as demographic data (age, gender), and interests.
- It is possible to easily block the sharing of information about one's activity on the Internet Service website with Google Analytics – to do this, for example, you can install a browser add-on provided by Google Ireland Ltd. available here: https://tools.google.com/dlpage/gaoptout?hl=pl).
- In connection with the possibility of the Administrator using advertising and analytical services provided by Google Ireland Ltd. on the Internet Service website, the Administrator indicates that full information about the principles of processing data of persons visiting the Internet Service website (including information stored in cookies) by Google Ireland Ltd. can be found in the privacy policy of Google services available at the following internet address: https://policies.google.com/technologies/partner-sites).
- The Administrator may use a marketing tool in the form of Facebook Pixel on the Internet Service website, which allows measuring the effectiveness of advertisements based on the analysis of actions taken by users on the website and directing personalized advertising options. The information obtained by the Service Provider is completely anonymous and compliant with all rules and regulations. This involves the use of cookies by Facebook Ireland Limited. The Service Recipient can decide within the cookie settings whether to consent to the use of cookies related to the Facebook Pixel. All information on this subject is available in the terms of service and privacy policy at the following internet address: (https://www.facebook.com/privacy/explanation).
FINAL PROVISIONS
The Internet Service may contain links to other websites. The Administrator encourages you to familiarize yourself with the privacy policy established there after moving to other sites. This privacy policy applies only to the Administrator's Internet Service.