Privacy policy
- This Privacy Policy sets out the rules for processing personal data obtained via the website studio-visavis.eu, hereinafter referred to as the “Website”.
- The owner of the Website and the Data Controller is Piotr Ślęczkowski, hereinafter referred to as the “Administrator”.
- Personal data collected by the Administrator via the Website is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as “GDPR”.
- The Administrator exercises special care to respect the privacy of the Clients visiting the Website.
§ 1 Types of Data Processed, Purposes, and Legal Basis
- The Administrator collects information about individuals engaging in legal transactions not directly related to their business activity, individuals conducting business or professional activity on their own behalf, and individuals representing legal persons or organizational units without legal personality but granted legal capacity by law, conducting business or professional activity on their own behalf, hereinafter collectively referred to as “Clients.”
- Personal data of Clients is collected in the following cases:
Use of the contact form service on the Website to perform an electronic service contract. Legal basis: necessity to perform the contract for the contact form service (Article 6(1)(b) GDPR). - When using the contact form service, the Client provides the following data:
– Email address
– First name
– Phone number - Additional information may be collected during the use of the Website, particularly: the IP address assigned to the Client’s computer or the external IP address of the Internet service provider, domain name, browser type, access time, and operating system type.
- Clients’ navigation data may also be collected, including information about the links and references they choose to click or other actions taken on the Website. Legal basis: legitimate interest (Article 6(1)(f) GDPR), which involves facilitating the use of electronic services and improving their functionality.
- Providing personal data to the Administrator is voluntary.
§ 2 Data Sharing and Retention Period
- Personal data of the Client is transferred to service providers used by the Administrator to operate the Website. Service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, either act on the instructions of the Administrator concerning the purposes and methods of processing this data (processors) or independently define the purposes and methods of its processing (controllers).
1.1. Processors: The Administrator uses providers who process personal data solely on the instructions of the Administrator. These include, among others, providers of hosting services, accounting services, marketing systems, traffic analysis systems on the Website, and campaign effectiveness analysis systems.
1.2. Controllers: The Administrator uses providers who do not act solely on instructions and independently determine the purposes and methods of using the Clients’ personal data. They provide electronic payment and banking services. - Location: The service providers are mainly based in Poland and other countries of the European Economic Area (EEA).
- Personal data of Clients is stored:
3.1. When the legal basis for processing personal data is consent, the personal data of the Client is processed by the Administrator as long as the consent is not withdrawn, and after withdrawal of consent, for the period corresponding to the statute of limitations for claims that the Administrator may raise and that may be raised against him. Unless a specific provision states otherwise, the limitation period is six years, and for periodic benefits and claims related to business activities, it is three years.
3.2. When the legal basis for data processing is the performance of a contract, the personal data of the Client is processed by the Administrator as long as it is necessary to perform the contract, and after that time, for the period corresponding to the statute of limitations for claims. Unless a specific provision states otherwise, the limitation period is six years, and for periodic benefits and claims related to business activities, it is three years. - Upon request, the Administrator makes personal data available to authorized state bodies, particularly the Public Prosecutor’s Office, Police, President of the Personal Data Protection Office, President of the Office of Competition and Consumer Protection, or President of the Office of Electronic Communications.
§ 3 Cookies and IP Address
- The Website uses small files called cookies. They are saved by the Administrator on the end device of the person visiting the Website, provided that the web browser allows it. A cookie file usually contains the domain name from which it originates, its “expiration time,” and an individual, randomly selected number identifying this file. The information collected via cookies helps customize the products offered by the Administrator to the individual preferences and actual needs of the people visiting the Website.
- The Administrator uses two types of cookies:
2.1. Session cookies: After the session of a given browser or the computer is turned off, the saved information is removed from the device’s memory. The session cookie mechanism does not allow the collection of any personal data or confidential information from the Clients’ computers.
2.2. Persistent cookies: These are stored in the memory of the Client’s device and remain there until they are deleted or expired. The persistent cookie mechanism does not allow the collection of any personal data or confidential information from the Clients’ computers. - The Administrator uses own cookies for:
3.1. Analysis and research, as well as auditing viewership, particularly to create anonymous statistics that help understand how Clients use the Website, which allows for improving its structure and content. - The Administrator uses external cookies for:
4.1. Presenting on the information pages of the Website, a map showing the Administrator’s office location, using the maps.google.com website (external cookie administrator: Google Inc. based in the USA). - The cookies mechanism is safe for the Clients’ computers visiting the Website. In particular, it is not possible for viruses or other unwanted or malicious software to get to the Clients’ computers this way. However, Clients can restrict or disable access to cookies on their computers in their browsers. In the case of using this option, the use of the Website will be possible, except for functions that by their nature require cookies.
- The Administrator may collect IP addresses of Clients. An IP address is a number assigned to the computer of the person visiting the Website by the Internet service provider. The IP number allows access to the Internet. In most cases, it is assigned dynamically to the computer when connecting to the Internet and is therefore treated as non-personal identifying information. The IP address is used by the Administrator in diagnosing technical problems with the server, creating statistical analyses (e.g., determining from which regions we record the most visits), as useful information in administering and improving the Website, as well as for security purposes and possible identification of unwanted automatic programs for viewing the Website content that overload the server.
§ 4 Rights of Individuals Whose Data is Processed
- Right to Withdraw Consent – Legal basis: Article 7(3) GDPR.
1.1. The Client has the right to withdraw any consent given.
1.2. Withdrawal of consent takes effect from the moment of withdrawal.
1.3. Withdrawal of consent does not affect the processing carried out by the Administrator in accordance with the law before its withdrawal.
1.4. Withdrawal of consent does not entail any negative consequences for the Client, but it may prevent further use of services or functionalities that can, according to the law, be provided only with consent. - Right to Object to Data Processing – Legal basis: Article 21 GDPR.
2.1. The Client has the right to object at any time – for reasons related to their particular situation – to the processing of their personal data, including profiling, if the Administrator processes their data based on a legitimate interest, e.g., marketing products and services, statistics on the use of specific Website functionalities, and satisfaction surveys.
2.2. If the objection of the Client is justified, and the Administrator has no other legal basis for processing the personal data, the personal data objected to will be deleted. - Right to Erasure of Data (“Right to be Forgotten”) – Legal basis: Article 17 GDPR.
3.1. The Client has the right to request the deletion of all or some personal data.
3.2. The Client has the right to request the deletion of personal data if:
3.2.1. The personal data is no longer necessary for the purposes for which it was collected or otherwise processed.
3.2.2. Consent was withdrawn to the extent that the personal data was processed based on that consent.
3.2.3. An objection was raised to the use of their data for marketing purposes.
3.2.4. The personal data is being processed unlawfully.
3.2.5. The personal data must be deleted to comply with a legal obligation under Union or Member State law to which the Administrator is subject.
3.2.6. The personal data was collected in connection with the offer of information society services.
3.3. Despite the request to delete personal data, in connection with an objection or withdrawal of consent, the Administrator may retain certain personal data to the extent that processing is necessary to establish, assert, or defend claims, as well as to fulfill a legal obligation requiring processing under Union or Member State law to which the Administrator is subject. This applies particularly to personal data including: name, email address, which are retained for the purpose of handling complaints and claims related to the use of the Administrator’s services, or additionally, home address/correspondence address, order number, which are retained for the purpose of handling complaints and claims related to sales contracts or service provision. - Right to Restriction of Data Processing – Legal basis: Article 18 GDPR.
4.1. The Client has the right to request the restriction of processing of their personal data. Submitting a request, until it is resolved, prevents the use of certain functionalities or services, the use of which will involve the processing of data covered by the request. The Administrator will not send any communications, including marketing ones.
4.2. The Client has the right to request the restriction of the use of personal data in the following cases:
4.2.1. The accuracy of their personal data is contested – in this case, the Administrator limits its use for the time needed to verify the accuracy of the data, no longer than 7 days.
4.2.2. The processing is unlawful, and instead of deleting the data, the Client requests restricting its use.
4.2.3. The personal data is no longer needed for the purposes for which it was collected or used, but it is necessary for the Client to establish, assert, or defend claims.
4.2.4. An objection has been raised to the use of their data – in this case, the restriction applies for the time needed to consider whether, due to the particular situation, the protection of the Client’s interests, rights, and freedoms outweighs the interests pursued by the Administrator in processing the personal data. - Right to Access Data – Legal basis: Article 15 GDPR.
5.1. The Client has the right to obtain from the Administrator confirmation whether their personal data is being processed, and if so, the Client has the right to:
5.1.1. Access their personal data.
5.1.2. Obtain information about the purposes of processing, categories of personal data being processed, recipients or categories of recipients of such data, the planned period for which the personal data will be stored or, if that is not possible, the criteria used to determine that period, the rights under GDPR, the right to lodge a complaint with a supervisory authority, the source of such data, automated decision-making, including profiling, and the safeguards used in connection with the transfer of such data outside the European Union.
5.1.3. Obtain a copy of their personal data. - Right to Rectification of Data – Legal basis: Article 16 GDPR.
6.1. The Client has the right to request from the Administrator the immediate rectification of their personal data that is incorrect. Considering the purposes of processing, the Client has the right to request the completion of incomplete personal data, including by submitting an additional statement, by sending a request to the email address provided in §6 of the Privacy Policy. - Right to Data Portability – Legal basis: Article 20 GDPR.
7.1. The Client has the right to receive their personal data, which they provided to the Administrator, and then send it to another, chosen by the Client, data controller. The Client also has the right to request that the personal data be sent by the Administrator directly to such another data controller, if technically feasible. In such a case, the Administrator will send the Client’s personal data in a CSV file format, which is commonly used, machine-readable, and allows the data received to be sent to another data controller. - When the Client exercises the rights arising from the above provisions, the Administrator fulfills the request or refuses to fulfill it immediately, but no later than within one month of receiving it. If, due to the complexity of the request or the number of requests, the Administrator is unable to fulfill the request within one month, the Administrator will fulfill it within the next two months, informing the Client in advance within one month of receiving the request – of the intended extension of the deadline and the reasons for it.
- The Client may submit complaints, inquiries, and requests to the Administrator regarding the processing of their personal data and the exercise of their rights.
- The Client has the right to lodge a complaint with the President of the Personal Data Protection Office concerning the violation of their rights to personal data protection or other rights granted under GDPR.
§ 5 Changes to the Privacy Policy
- The Privacy Policy may change, and the Administrator is not obliged to inform about these changes.
- Questions regarding the Privacy Policy should be sent to the following address: pbsleczkowski@gmail.com
- Date of last modification: July 19, 2024.