Legal
Last updated: 14 August 2018
1. General Information
- This policy applies to the website operating at: arenaakcji.pl
- The operator of the website and the controller of personal data is: ARENA AKCJI SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (Arena Akcji Ltd.), Na Zielonki 16, 31-270 Kraków, Poland. NIP (Tax ID): 9452322853, REGON: 543599249, KRS: 0001213513
- Operator's contact email address: biuro@arenaakcji.pl
- The Operator is the Controller of your personal data with respect to data voluntarily provided in the Service.
- The Service uses personal data for the following purposes:
- Sending newsletters
- Handling enquiries submitted via forms
- Presenting offers or information
- The Service collects information about users and their behaviour in the following ways:
- Through data voluntarily entered in forms, which is then entered into the Operator's systems.
- By saving cookie files on end-user devices.
2. Selected Data Protection Methods Used by the Operator
- Login pages and personal data entry areas are protected at the transmission layer (SSL certificate). As a result, personal data and login credentials entered on the website are encrypted on the user's computer and can only be read on the target server.
- User passwords are stored in hashed form. The hashing function operates in one direction — it cannot be reversed, which is the current industry standard for storing user passwords.
- The Operator periodically changes its administrative passwords.
- To minimise the risk of unauthorised access to data, the Operator uses complex passwords containing upper and lowercase letters, digits and special characters, of no fewer than 8 characters.
- An important element of data protection is the regular update of all software used by the Operator to process personal data, which in particular means regular updates of software components.
- To protect data, the Operator regularly performs backups.
3. Hosting
- The Service is hosted (technically maintained) on the operator's server: webd.pl
- The hosting company, in order to ensure technical reliability, maintains server-level logs. The following may be recorded:
- resources identified by URL (addresses of requested resources — pages, files),
- time of the request,
- time of the response,
- name of the client station — identification via the HTTP protocol,
- information about errors that occurred during the HTTP transaction,
- URL of the page previously visited by the user (referrer link) — where navigation to the Service occurred via a link,
- information about the user's browser,
- information about the IP address,
- diagnostic information related to the process of self-ordering services via website registrars,
- information related to handling email sent to the Operator and sent by the Operator.
4. Your Rights and Additional Information on How Data Is Used
- In certain situations, the Controller has the right to pass your personal data to other recipients if this is necessary to perform the contract concluded with you or to fulfil obligations incumbent on the Controller. This applies to the following categories of recipients:
- payment operators
- authorised employees and associates who use the data to carry out the purpose of the website's operation
- companies providing marketing services on behalf of the Controller
- Your personal data is processed by the Controller no longer than is necessary to carry out the related activities specified by separate regulations (e.g. accounting rules). With respect to marketing data, the data will not be processed for more than 3 years.
- You have the right to request from the Controller:
- access to your personal data,
- rectification of your data,
- erasure of your data,
- restriction of processing,
- and data portability.
- You have the right to object, in the scope of processing indicated in point 3.3(c), to the processing of personal data for the purposes of legitimate interests pursued by the Controller, including profiling, provided that the right to object may not be exercised where compelling legitimate grounds for processing exist that override your interests, rights and freedoms, in particular for the establishment, exercise or defence of legal claims.
- You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.
- The provision of personal data is voluntary but necessary to use the Service.
- Automated decision-making, including profiling, may be performed in relation to you for the purpose of providing services under the concluded contract and for the Controller's direct marketing purposes.
- Personal data is transferred to third countries within the meaning of personal data protection regulations. This means we transfer it outside the territory of the European Union.
5. Information in Forms
- The Service collects information voluntarily provided by the user, including personal data, where submitted.
- The Service may record information about connection parameters (timestamp, IP address).
- In certain cases, the Service may save information that makes it easier to link data in a form with the email address of the user completing the form. In such cases, the user's email address appears within the URL of the page containing the form.
- Data provided in a form is processed for the purpose arising from the function of the particular form, e.g. for the purpose of handling a service request or a commercial enquiry, service registration, etc. In each case, the context and description of the form clearly indicates what it is used for.
6. Administrator Logs
- Information about user behaviour on the Service may be subject to logging. This data is used for the purpose of administering the Service.
7. Key Marketing Techniques
- The Operator uses statistical traffic analysis via Google Analytics (Google Inc., based in the USA). The Operator does not pass personal data to this service provider, only anonymised information. The service is based on the use of cookies on the user's end device. Regarding information about user preferences collected by the Google advertising network, users may view and edit information derived from cookies using the tool at: https://www.google.com/ads/preferences/
- The Operator uses the Facebook Pixel. This technology means that the Facebook service (Facebook Inc., based in the USA) is aware that a registered user is using the Service. It is based on data for which Facebook itself is the controller. The Operator does not pass any additional personal data to Facebook. The service is based on the use of cookies on the user's end device.
- The Operator uses remarketing techniques to match advertising messages to user behaviour on the website, which may give the impression that personal data is being used to track users — in practice, however, no personal data is transferred from the Operator to advertising operators. The technical requirement for such activities is enabled cookie support.
- The Operator uses a solution that analyses user behaviour through heat maps and session recordings. This information is anonymised before being sent to the service provider so that the provider does not know which natural person it concerns. In particular, passwords entered and other personal data are not recorded.
- The Operator uses a solution that automates Service activities in relation to users, e.g. sending an email to a user after visiting a specific subpage, provided that the user has consented to receiving commercial correspondence from the Operator.
8. Cookie Information
- The Service uses cookies.
- Cookies are IT data, in particular text files, which are stored on the end device of the Service User and are intended for use on the Service's web pages. Cookies usually contain the name of the website from which they originate, their storage time on the end device, and a unique number.
- The entity that places cookies on the end device of the Service User and accesses them is the Service operator.
- Cookies are used for the following purposes:
- maintaining the Service User's session (after logging in), which means the user does not have to re-enter their login and password on every subpage of the Service;
- achieving the purposes described above in the section "Key Marketing Techniques";
- The Service uses two basic types of cookies: "session" cookies and "persistent" cookies. Session cookies are temporary files that are stored on the User's end device until they log out, leave the website or close the software (internet browser). Persistent cookies are stored on the User's end device for the time specified in the cookie parameters or until they are deleted by the User.
- Web browsing software (an internet browser) typically allows cookies to be stored on the User's end device by default. Service Users may change their settings in this regard. The internet browser allows cookies to be deleted. It is also possible to automatically block cookies. Detailed information on this topic can be found in the browser's help section or documentation.
- Restrictions on the use of cookies may affect some of the functionalities available on the Service's web pages.
- Cookies placed on the end device of the Service User may also be used by entities cooperating with the Service operator, in particular the following companies: Google (Google Inc., based in the USA), Facebook (Facebook Inc., based in the USA), Twitter (Twitter Inc., based in the USA).
9. Managing Cookies — How to Give and Withdraw Consent in Practice
- If users do not want to receive cookies, they can change their browser settings. Please note that disabling cookies necessary for authentication, security and user preference maintenance may make it difficult, or in extreme cases impossible, to use websites.
- To manage your cookie settings, select your internet browser from the list below and follow the instructions:
Mobile devices:
This privacy policy template was generated free of charge for informational purposes based on our knowledge, industry practices, and applicable law as of 14 August 2018. We recommend reviewing the policy template before using it on your website.