Privacy Policy and Cookie Policy

Controller’s Details:
The controller of the personal data of users visiting the website available at: www.wolskigroup.pl is DAMIAN WOLSKI Services, NIP: 9491927891, REGON: 542115686 (hereinafter referred to as the Controller),
address: ul. Jana Kaczary 5/6, 31-421 Kraków,
e-mail: damian.wolski@wolskigroup.pl

Personal data, purposes, and legal bases for processing:
Data obtained from users of the Controller’s website includes:

  • data voluntarily provided by the user on the website, such as first and last name, contact details, telephone number, and e-mail address;
  • information obtained while using the website (that is, data that may be collected in connection with the use of the Controller’s website cookies), including in particular operational data (identifiers assigned to the user, identifiers of the telecommunications network terminal or IT system used by the user, information on the beginning, end, and scope of the use of the website, and users’ IP addresses).

As part of the operation of the website (www.wolskigroup.pl), we process data to the following extent:

  • Within the website: data contained in Cookies. The Controller may also collect Users’ IP addresses.
  • Within the contact form: the telephone number, e-mail address, and identification data provided in the form, such as first name, last name, and address.
  • Within online meetings (MS Teams Meeting): the telephone number, e-mail address, and identification data provided in the form, such as first name, last name, and address (in the case of a teleconference), as well as image/likeness data (in the case of a videoconference).

Providing personal data within the website is entirely voluntary. However, failure to provide the information contained in Cookies will make it impossible to create statistics regarding website visits and to tailor the website to your preferences. Failure to provide a telephone number or e-mail address will make it impossible to contact you via the contact form or online meeting.

Legal basis and purposes of processing your personal data:

The data collected through the Controller’s website is used to provide specific services to users and for, among other things, statistical purposes (including profiling by third parties), functional, technical purposes, and to tailor the website to the individual needs of the user. The data is processed for the purposes of the legitimate interests of the Controller and entities from which the cookies originate (i.e. pursuant to Article 6(1)(f) of the GDPR), namely: ensuring the proper functioning of the website, improving the services provided, obtaining statistical data regarding the use of the website, and marketing. The processing does not infringe the rights and freedoms of users and does not significantly affect them.

The data provided through the contact form, i.e. the telephone number or e-mail address, is used for contact purposes.

The data provided within the online meeting, i.e. identification data, e-mail address, or telephone number, is used to conduct the online meeting. In the case of an online meeting in the form of a videoconference, your image/likeness is additionally processed.

Your web browser may store cookies on your computer’s hard drive. Cookies contain information necessary for the proper functioning of the website. Cookies are stored on users’ computers for purposes including proper adjustment of the website to users’ needs, remembering user preferences and individual settings, and creating website traffic statistics. The data contained in Cookies does not allow for the direct identification of a natural person. It only allows the identification of the device on which they were stored. If you do not want any Cookies to be stored on your device, you can change this in your browser settings. It is also possible to completely delete data stored in the form of Cookies.

Recipients of data and transfer of data to third countries:
Data may also be processed by entities with whom the Controller has concluded personal data processing agreements, as well as by entities to whom the Controller discloses personal data. These entities include the Controller’s contractors, in particular entities providing IT, accounting, or data protection services. Where required by law, data may be disclosed to state or local government authorities, courts, law enforcement authorities, supervisory authorities, and tax authorities. Users’ data may also be collected independently of the Controller by entities operating tools related to social media plugins and cookies, mainly Google Inc. and its affiliated entities. The Controller may transfer your personal data to third countries, in particular to the United States. Each transfer shall be made on the basis of appropriate safeguards (an adequacy decision / standard data protection clauses adopted by the European Commission).

Processing period:
For the purpose of providing services, data is processed until the termination of the agreement binding us in this respect, including after a return contact made to the telephone number you provided. In some cases, however, we will process personal data for up to 10 years after the end of the service provision if this is justified in order to protect against your claims. However, this period shall never exceed the period required for the limitation of claims. In the case of processing based on your consent, data will be processed until that consent is withdrawn. Data processed for the purposes of our legitimate interest will be processed until a justified objection is raised or the relevant browser settings are changed.

Retention period:
The retention period for personal data varies depending on the purpose for which the data is used.

Profiling:
Your data may be subject to profiling by third parties — Google Inc. or entities affiliated with it. Such profiling consists of the automated processing of your personal data in order to evaluate certain personal factors, in particular to analyze or predict aspects concerning the way you use the website and the Internet.

Data protection and users’ rights:
The Controller makes every effort to protect the website against unauthorized access by third parties. For this purpose, physical, logical, and organizational security measures are applied. A user whose personal data is collected has the right to:

  • request access to their personal data from the Controller, rectification, erasure, or restriction of processing of personal data, as well as notification of recipients of personal data regarding rectification or erasure of personal data or restriction of processing;
  • object to processing;
  • data portability;
  • lodge a complaint with the supervisory authority (the President of the Personal Data Protection Office).

You may withdraw your consent at any time (by contacting us by e-mail or in writing) — withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.