The Controller of personal data collected via the website https://vtsgroup.com is jointly conducting business activity in the form of a civil law partnership under the name VTS Polska Sp. z o. o., address of the registered office: Aleja Grunwaldzka 472 A Gdańsk, delivery address:, Tax Identification No. (NIP): 5871599675, Business Statistical No. (REGON): 220079570, e-mail address: email@example.com, place of business: Aleja Grunwaldzka 472 A Gdańsk, address for delivery: Aleja Grunwaldzka 472 A Gdańsk, Tax Identification No. (NIP): 5871599675, Business Statistical No. (REGON): 220079570, e-mail address: firstname.lastname@example.org, hereinafter referred to as the "Controller".
Personal data collected by the Controller via the website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the GDPR and the Personal Data Protection Act of 10 May 2018.
TYPE OF PERSONAL DATA PROCESSED, PURPOSE AND SCOPE OF DATA COLLECTION
The Controller processes personal data via the website https://vtsgroup.com if:
the user uses the contact form. Personal data is processed pursuant to Article 6 section 1(f) of the GDPR as the Controller's legitimate interest.
the user subscribes to the Newsletter, in order to send commercial information by electronic means. Personal data is processed upon a separate consent, pursuant to Article 6 section 1(a) of the GDPR.
TYPE OF PERSONAL DATA PROCESSED.
The Controller processes the following categories of user's personal data:
- First name and surname,
- Date of birth,
- Address (of residence),
- E-mail address,
- Phone number,
PERSONAL DATA ARCHIVING PERIOD.
Users' personal data is stored by the Controller:
if the basis for data processing is the performance of a contract, as long as it is necessary to perform the contract, and after that time for a period corresponding to the period of limitation of claims. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic services and claims related to business activity - three years.
in the event that the basis for data processing is a consent, as long as the consent is not revoked, and after revoking the consent for a period of time corresponding to the period of limitation of claims that may be raised by the Controller and which may be raised against the Controller. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic services and claims related to business activity - three years.
When using the website, additional information may be collected, in particular: the IP address assigned to the user's computer or the external IP address of the Internet provider, domain name, type of browser, access time, type of operating system.
Navigation data may also be collected from users, including information about links that they choose to click or other actions taken on the website. The legal basis for this type of activity is the Controller's legitimate interest (Article 6 section 1(f) of the GDPR), consisting in facilitating the use of electronically supplied services and improving the functionality of these services.
Providing personal data by the user is voluntary.
Personal data will also be processed in an automated way in the form of profiling, provided that the user agrees to it pursuant to Article 6 section 1(a) of the GDPR. The consequence of profiling will be the assignment of a profile to a given person in order to make decisions about the person or to analyse or predict his or her preferences, behaviours and attitudes.
The Controller shall exercise due diligence to protect the interests of data subjects, and, in particular, ensure that the data collected by the Controller are:
- processed lawfully,
- collected for specified, legitimate purposes and not subjected to further processing that is incompatible with those purposes,
- factually correct and relevant to the purposes for which they are processed and stored in a form that enables identification of persons to whom they relate, no longer than is necessary to achieve the purpose of processing.
SHARING PERSONAL DATA
Users' personal data is transferred to service providers whose services the Controller uses when running the website. Service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, either are subject to the Controller's instructions as to the purposes and methods of processing this data (processors) or define the purposes and methods of their processing (controllers).
Users' personal data is stored only within the European Economic Area (EEA).
RIGHT TO CONTROL, ACCESS, AND CORRECT YOUR PERSONAL DATA
The data subject has the right to access the content of his or her personal data as well as the right to rectify it, delete it, restrict its processing, the right to data portability, the right to object, the right to withdraw consent at any time without affecting the lawfulness of any processing performed on the basis of the consent prior to its withdrawal.
Legal grounds for the user's requests:
- Data access - Article 15 of the GDPR
- Rectification of data - Article 16 of the GDPR.
- Deleting data (the so-called right to be forgotten) - Article 17 of the GDPR.
- Restriction of processing - Article 18 of the GDPR.
- Data portability - Article 20 of the GDPR.
- Objection - Article 21 of the GDPR
- Withdrawal of consent - Article 7 section 3 of the GDPR.
In order to exercise the rights referred to in point 2 you can send an appropriate email to the following address: email@example.com.
In the event of the user exercising his or her entitlement under the above rights, the Controller shall comply with the request or refuse to comply with it immediately, but no later than within a month after receiving it. However, if - due to the complicated nature of the request or the number of requests - the Controller is not able to fulfil the request within a month, it shall fulfil it within the next two months and inform the user in advance, within one month of receiving the request, about the intended extension of the deadline and its reasons.
In the event that the processing of personal data violates the provisions of the GDPR, the data subject has the right to lodge a complaint with the President of the Personal Data Protection Office.
The installation of cookies is necessary for the proper provision of services on the website. Cookies contain information necessary for the website to function properly, and also allow for the compilation of general statistics of visits on the website.
The website uses the following types of cookies: session and permanent
- Session cookies are temporary files that are stored on the user's device until the user logs out (leaves the website).
- Permanent cookies are stored on the user's device for the time specified in the cookie file parameters or until the user deletes them.
The Controller uses its own cookies to better understand the user's interaction within the contents of the website. The files collect information on how the user uses the website, the type of website from which the user was redirected, and the number of visits and the time of the user's visit to the website. This information does not record specific personal data of the user but is used to compile statistics on the use of the website.
The user has the right to decide on the scope of access that cookies have to his or her computer by their prior selection in the browser window. Details on the possibilities and methods of managing cookies are available in the settings of the software (web browser).
- The Controller shall apply technical and organisational measures to ensure protection of the processed personal data that is appropriate for the hazards and categories of data subject to protection and, in particular, protect the data against unauthorised access and takeover, processing with violation of existing law as well as modification, loss, damage, or destruction.
- The Controller shall provide the appropriate technical measures to prevent the unauthorised access and modification of personal data sent electronically.