- This Privacy Policy defines the principles of processing personal data obtained via the website https://osintownia.pl/ (hereinafter referred to as the “Website”).
- The owner of the Website and simultaneously the data controller is OSINTOWNIA PROSTA SPÓŁKA AKCYJNA, ul. Grodzka 20/4, 70-560 Szczecin, registered in the Register of Entrepreneurs maintained by the District Court in Szczecin, Commercial Department of the National Court Register under number KRS: 0001065410, REGON: 526745767, NIP: 8513301389, using the email address: kontakt@osintownia.pl, hereinafter referred to as OSINTOWNIA PROSTA SPÓŁKA AKCYJNA.
- Personal data collected by OSINTOWNIA PROSTA SPÓŁKA AKCYJNA via the Website is processed in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR).
- OSINTOWNIA PROSTA SPÓŁKA AKCYJNA takes special care to respect the privacy of users visiting the Website.
§ 1 Types of processed data, purposes, and legal basis
- OSINTOWNIA P.S.A. collects information about individuals, individuals conducting business activities or professional activities on their own behalf, and individuals representing legal entities or organizational units without legal personality, to whom the law grants legal capacity, hereinafter collectively referred to as Users.
- Users’ personal data is collected in the following cases:a) placing an order on the Website, for the purpose of executing the sales contract. Legal basis: necessity to perform the sales contract (Art. 6(1)(b) GDPR);b) subscription to the newsletter, for the purpose of executing the contract, which is the electronic service. Legal basis: the consent of the data subject to perform the newsletter service contract (Art. 6(1)(a) GDPR);
- When registering an account on the Website or with a third party to perform the service, the User provides:a) email address;b) first and last name;c) phone number.
- In the case of Entrepreneurs, the above data range is additionally extended by: a) the company’s name; b) VAT ID.
- When registering an account on the Website or with a third party to perform the service, the User independently receives an access code, which allows them to log in to their account.
- When placing an order on the Website, the User provides the following data: a) email address; b) address data: c) postal code and city; d) street with house/apartment number. e) first and last name; f) phone number. In the case of purchasing for another individual, the following data of that person will also be provided: a) Email address; b) Address data: c) Postal code and city; d) Street with house/apartment number. e) First and last name; f) Phone number.
- In the case of Entrepreneurs, the above data range is additionally extended by: a) the company’s name; b) VAT ID.
- When using the newsletter service, the User provides only their email address.
- When using the Website, additional information may be collected, in particular: the IP address assigned to the User’s computer or external IP address of the Internet provider, domain name, browser type, access time, operating system type.
- Navigation data may also be collected from Users, including information about links and references they decide to click on or other activities undertaken on our Website. Legal basis: legitimate interest (Art. 6(1)(f) GDPR), consisting of facilitating the use of electronic services and improving the functionality of these services.
- To establish, assert, and enforce claims, some personal data provided by the User during the use of the functionalities on the Website, such as: first and last name, data regarding the use of services, if claims result from the manner in which the User uses the services, other data necessary to prove the existence of the claim, including the extent of the incurred damage, may be processed. Legal basis: legitimate interest (Art. 6(1)(f) GDPR), consisting of establishing, asserting, and enforcing claims and defending against claims in court and other state authorities.
- Providing personal data to OSINTOWNIA P.S.A. is voluntary in connection with concluded sales contracts or services provided via the Website, with the reservation that failure to provide data specified in the forms during Registration prevents Registration and the creation of a User Account, while placing an order without Registering a User Account will prevent the submission and execution of the User’s order.
§ 2 Sharing, transferring, and storing personal data.
- Users’ personal data is transferred to service providers used by OSINTOWNIA P.S.A. to operate the Website. Service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, either follow the instructions of OSINTOWNIA P.S.A. regarding the purposes and methods of processing such data (processors) or independently determine the purposes and methods of their processing (controllers). a) Processors. OSINTOWNIA P.S.A. uses suppliers who process personal data solely on the instructions of OSINTOWNIA P.S.A. These include, among others, providers of courier services, accounting services, IT services, systems for analyzing traffic on the Website, and systems for analyzing the effectiveness of marketing campaigns; b) Controllers: OSINTOWNIA P.S.A. uses suppliers who do not act solely on instructions and independently determine the purposes and methods of using personal data. They provide electronic payment services and banking services.
- Location: Service providers are mainly based in Poland and other countries within the European Economic Area (EEA).
- Users’ personal data is stored: a) If the basis for processing personal data is consent, the personal data of the User is processed by OSINTOWNIA P.S.A. as long as the consent is not withdrawn, and after the withdrawal of consent for the period corresponding to the limitation period for claims that may be raised by OSINTOWNIA P.S.A. and that may be raised against them. If a specific provision does not state otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activities – three years. b) If the basis for data processing is the performance of the contract, the personal data of the User is processed by OSINTOWNIA P.S.A. as long as it is necessary to perform the contract, and after that time for the period corresponding to the limitation period for claims. If a specific provision does not state otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activities – three years.
- Navigation data may be used to provide Users with better service, analyze statistical data, and adjust the Website to Users’ preferences, as well as administer the Website.
- If the User chooses payment via the Przelewy24 system, their personal data is transferred to the extent necessary for the payment to PayPro S.A. based in Poznań (ul. Pastelowa 8, 60-198 Poznań).
- If the User subscribes to the newsletter, OSINTOWNIA P.S.A. will send electronic messages to their email address containing commercial information about promotions and new products available on the Website.
- Upon request, OSINTOWNIA P.S.A. provides personal data to authorized state authorities, in particular organizational units of the Prosecutor’s Office, the Police, the President of the Office for Personal Data Protection, the President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications.
§ 3 Cookies, IP Address
- The Website uses small files called cookies. They are saved by OSINTOWNIA P.S.A. on the device of the person visiting the Website, provided that the web browser allows it. A cookie file usually contains the name of the domain from which it comes, its “expiration time,” and an individual, randomly selected number identifying this file. Information collected through files of this type helps to adjust the products offered by OSINTOWNIA P.S.A. to the individual preferences and actual needs of people visiting the Website. They also provide the opportunity to compile general statistics of visits to the presented products on the Website.
- OSINTOWNIA P.S.A. uses two types of cookies: a) Session cookies: after the end of the session of a given browser or after turning off the computer, the stored information is removed from the memory of the device. The mechanism of session cookies does not allow the collection of any personal data or any confidential information from Users’ computers. b) Permanent cookies: they are stored in the memory of the User’s end device and remain there until they are deleted or expire. The mechanism of permanent cookies does not allow the collection of any personal data or any confidential information from the User’s computer.
- OSINTOWNIA P.S.A. uses its own cookies for: a) authenticating the User on the Website and ensuring the User’s session on the Website (after logging in), thanks to which the User does not have to re-enter their login and password on each subpage of the Website; b) analyses, research, and audit of viewership, in particular, to create anonymous statistics that help understand how Users use the Website, which allows improving its structure and content.
- OSINTOWNIA P.S.A. uses external cookies for: a) presenting multimedia content on the Website pages, b) collecting general and anonymous statistical data via analytical tools such as Google Analytics (external cookie administrator: Google Inc. based in the USA);
- The cookie mechanism is safe for Users’ computers of the Website. In particular, this way it is not possible for viruses or other unwanted software or malware to enter Users’ computers. Nevertheless, Users have the option to limit or disable access to cookies to their computers in their browsers. If this option is used, the use of the Website will be possible, except for functions which, by their nature, require cookies.
- OSINTOWNIA P.S.A. may collect Users’ IP addresses. An IP address is a number assigned to the computer of the person visiting the Website by the Internet service provider. The IP number allows access to the Internet. In most cases, it is assigned to the computer dynamically, i.e., it changes with each connection to the Internet. The IP address is used by OSINTOWNIA P.S.A. to diagnose technical problems with the server, create statistical analyses (e.g., determining from which regions we record the most visits), as useful information for administering and improving the Website, and for security purposes and potential identification of unwanted automated programs for viewing the content of the Website.
- The Website contains links and references to other websites. OSINTOWNIA P.S.A. is not responsible for the privacy practices on those websites.
§ 4 Rights of data subjects.
- Right to withdraw consent – legal basis: Art. 7(3) GDPR. a) The User has the right to withdraw any consent given to OSINTOWNIA P.S.A. b) The withdrawal of consent is effective from the moment of withdrawal. c) The withdrawal of consent does not affect the processing carried out by OSINTOWNIA P.S.A. in accordance with the law before its withdrawal. d) The withdrawal of consent does not entail any negative consequences for the User, but it may prevent further use of services or functionalities that OSINTOWNIA P.S.A. can provide only with consent.
- Right to object to data processing – legal basis: Art. 21 GDPR. a) The User has the right to object at any time – for reasons related to their particular situation – to the processing of their personal data, including profiling, if OSINTOWNIA P.S.A. processes their data based on a legitimate interest, e.g., marketing products and services of OSINTOWNIA P.S.A., conducting statistics on the use of specific functionalities of the Website, and facilitating the use of the Website, as well as satisfaction surveys. b) Resignation from receiving marketing communications regarding products or services in the form of an email will mean the User’s objection to the processing of their personal data, including profiling for these purposes. c) If the User’s objection proves justified and OSINTOWNIA P.S.A. has no other legal basis for processing personal data, the personal data of the User will be deleted, to which the User has objected.
- Right to data deletion (“right to be forgotten”) – legal basis: Art. 17 GDPR. a) The User has the right to request the deletion of all or some personal data. b) The User has the right to request the deletion of personal data if: c) the personal data is no longer necessary for the purposes for which they were collected or processed; d) they withdrew a specific consent, to the extent that personal data was processed based on their consent; e) they objected to the use of their data for marketing purposes; f) personal data is processed unlawfully; g) personal data must be deleted to comply with a legal obligation under Union or Member State law to which OSINTOWNIA P.S.A. is subject; h) personal data was collected in connection with the offering of information society services. i) Despite the request to delete personal data, in connection with the objection or withdrawal of consent, OSINTOWNIA P.S.A. may retain certain personal data to the extent that processing is necessary to establish, assert, or defend claims, as well as to comply with a legal obligation requiring processing under Union or Member State law to which OSINTOWNIA P.S.A. is subject. This applies in particular to personal data including: first and last name, email address, which data is retained for the purposes of handling complaints and claims related to the use of OSINTOWNIA P.S.A. services or additionally the residential address/correspondence address, order number, which data is retained for the purposes of handling complaints and claims related to concluded sales contracts or service provision.
- Right to restrict data processing – legal basis: Art. 18 GDPR. a) The User has the right to request the restriction of the processing of their personal data. The submission of a request, until its consideration, prevents the use of specific functionalities or services, the use of which will be associated with the processing of data covered by the request. OSINTOWNIA P.S.A. will also not send any communications, including marketing ones. b) The User has the right to request the restriction of the use of personal data in the following cases: c) when they question the correctness of their personal data – in this case, OSINTOWNIA P.S.A. restricts their use for the time needed to check the correctness of the data, but not longer than for 7 days; d) when the processing of data is unlawful, and instead of deleting the data, the User requests the restriction of their use; e) when personal data is no longer necessary for the purposes for which they were collected or used, but they are needed by the User to establish, assert, or defend claims; f) when they objected to the use of their data – in this case, the restriction occurs for the time needed to consider whether – due to their particular situation – the protection of the interests, rights, and freedoms of the User prevails over the interests pursued by the Administrator, processing the User’s personal data.
- Right to access data – legal basis: Art. 15 GDPR. The User has the right to obtain from the Administrator confirmation whether they process personal data, and if so, the User has the right to: a) access their personal data; b) obtain information about the purposes of processing, categories of processed personal data, recipients or categories of recipients of this data, the planned period of storing User’s data or the criteria for determining this period (if it is not possible to determine the planned period of data processing), the rights of the User under GDPR and the right to lodge a complaint with the supervisory authority, the source of this data, automated decision-making, including profiling, and safeguards used in connection with the transfer of this data outside the European Union; c) obtain a copy of their personal data.
- Right to rectify data – legal basis: Art. 16 GDPR. a) The User has the right to request the Administrator to immediately rectify their personal data that is incorrect. Taking into account the purposes of processing, the User has the right to request the completion of incomplete personal data, including by providing an additional statement, by sending a request to the email address.
- Right to data portability – legal basis: Art. 20 GDPR. a) The User has the right to receive their personal data, which they provided to the Administrator, and then send it to another data controller of their choice. The User also has the right to request that the personal data be sent by the Administrator directly to such a controller, if technically possible. In this case, the Administrator will send the User’s personal data in a csv file format, which is a commonly used, machine-readable format that allows the received data to be sent to another data controller.
- In the event of the User exercising the rights resulting from the above rights, OSINTOWNIA P.S.A. fulfills the request or refuses to fulfill it immediately, but no later than within one month of receiving it. However, if – due to the complex nature of the request or the number of requests – OSINTOWNIA P.S.A. cannot fulfill the request within a month, they will fulfill it within the next two months informing the User in advance within one month of receiving the request – about the intended extension of the deadline and its reasons.
- The User may submit complaints, inquiries, and requests to the Administrator regarding the processing of their personal data and the exercise of the rights granted to them.
- The User has the right to request from OSINTOWNIA P.S.A. to provide a copy of standard contractual clauses by sending an inquiry in the manner indicated in §6 of the Privacy Policy.
- The User has the right to lodge a complaint with the President of the Personal Data Protection Office regarding the violation of their rights to the protection of personal data or other rights granted under GDPR.
§ 5 Encryption and security
- OSINTOWNIA P.S.A. provides Users with secure and encrypted connections when transmitting personal data. OSINTOWNIA P.S.A. uses an SSL certificate.
- OSINTOWNIA P.S.A. never sends any correspondence, including electronic correspondence, requesting login data, especially the access password to the User’s account.
§ 6 Changes to the Privacy Policy
- The Privacy Policy may change, about which OSINTOWNIA P.S.A. will inform Users 14 days in advance.
- Questions regarding the Privacy Policy should be directed to: kontakt@osintownia.pl