This is an English translation of the Polish original. In case of any discrepancies, the Polish version shall prevail.
This Privacy Policy sets out the rules for storing and accessing data on the Devices of Users using the Website for the purpose of the provision of services by electronic means by the Controller, as well as the rules for collecting and processing the personal data of Users which they have provided personally and voluntarily via the tools available on the Website.
§1 Definitions
- Website – the “Semano” Marketing Agency operating at https://semano.pl/
- External Website – the websites of partners, service providers or service recipients cooperating with the Controller.
- Website Administrator / Data Controller – the Website Administrator and the Data Controller (hereinafter the “Controller”) is the business “Semano Dominik Bartoszek”, operating at: Witkiewicza 41/10, 44-102 Gliwice, holding NIP (Tax ID): 6312705972, which provides services by electronic means via the Website.
- User – a natural person to whom the Controller provides services by electronic means via the Website.
- Device – an electronic device, together with its software, through which the User accesses the Website.
- Cookies – text data collected in the form of files placed on the User’s Device.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
- Personal data – means information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Processing – means an operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Restriction of processing – means the marking of stored personal data with the aim of limiting their processing in the future.
- Profiling – means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
- Consent – consent of the data subject means a freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
- Personal data breach – means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored or otherwise processed.
- Pseudonymisation – means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures preventing its attribution to an identified or identifiable natural person.
- Anonymisation – an irreversible process of operations on data which destroys / overwrites “personal data”, making it impossible to identify a given record or to link it to a specific user or natural person.
§2 Data Protection Officer
In accordance with Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer.
In matters concerning the processing of data, including personal data, please contact the Controller directly.
§3 Types of Cookies
- Internal cookies – files placed on and read from the User’s Device by the Website’s IT system.
- External cookies – files placed on and read from the User’s Device by the IT systems of External Websites. The scripts of External Websites which may place Cookies on Users’ Devices have been knowingly placed on the Website through scripts and services made available and installed on the Website.
- Session cookies – files placed on and read from the User’s Device by the Website or External Websites during a single session of a given Device. Once the session ends, the files are deleted from the User’s Device.
- Persistent cookies – files placed on and read from the User’s Device by the Website or External Websites until they are manually deleted. The files are not deleted automatically when the Device session ends, unless the User’s Device is configured to delete Cookies at the end of the Device session.
§4 Security of data storage
- Cookie storage and reading mechanisms – The mechanisms for storing, reading and exchanging data between the Cookies saved on the User’s Device and the Website are implemented through the built-in mechanisms of web browsers and do not allow any other data to be retrieved from the User’s Device or any data of other websites.
- Internal cookies – the Cookies used by the Controller are safe for Users’ Devices and do not contain scripts, content or information that could compromise the security of personal data or the security of the Device used by the User.
- External cookies – The Controller takes all possible steps to verify and select the Website’s partners with regard to Users’ security. To the extent permitted by law, the Controller accepts no liability for the security of Cookies originating from External Websites, their content or their licence-compliant use by the Scripts installed on the Website.
- Cookie control – The User may at any time change, on their own, the settings concerning the saving, deletion of and access to data stored in Cookies by any website.
- Risks on the User’s side – The Controller uses all possible technical measures to ensure the security of data placed in Cookies. It should be noted, however, that ensuring the security of such data depends on both parties, including the User’s own conduct.
- Storage of personal data – The Controller makes every effort to ensure that the personal data processed are secure and that access to them is restricted and exercised in accordance with their intended use and the purposes of processing.
§5 Purposes for which Cookies are used
- Improving and facilitating access to the Website
- Personalising the Website for Users
- Marketing and remarketing on External Websites
- Ad serving services
- Compiling statistics (users, number of visits, device types, connection, etc.)
- Providing social media services
§6 Purposes of processing personal data
Personal data voluntarily provided by Users are processed for one of the following purposes:
- Provision of electronic services (account registration, Newsletter and commenting services)
- Communication between the Controller and Users on matters relating to the Website and data protection
- Safeguarding the legitimate interest of the Controller
Data about Users collected anonymously and automatically are processed for one of the following purposes:
- Compiling statistics
- Remarketing
- Serving advertisements tailored to Users’ preferences
- Safeguarding the legitimate interest of the Controller
§7 Cookies of External Websites
On the Website, the Controller uses JavaScript scripts and web components of partners who may place their own cookies on the User’s Device. Below is a list of the partners or their services implemented on the Website:
- Multimedia services: YouTube
- Social media services: Twitter, Facebook, LinkedIn
- Content sharing services: Instagram
- Newsletter services: MailChimp
- Ad serving services: Google Adsense
- Statistics: Google Analytics, Ahrefs, HubSpot, Facebook Analytics for Apps
Services provided by third parties are beyond the Controller’s control. These entities may at any time change their terms of service, privacy policies, the purpose of data processing and the way in which they use cookies.
§8 Types of data collected
Anonymous data collected automatically:
- IP address
- Browser type
- Screen resolution
- Approximate location
- Website pages opened
- Time spent on a given page of the Website
- Operating system type
- Address of the previous page
- Browser language
Data collected when making contact via the form:
- First name and surname
- E-mail address
- Telephone number
- IP address (collected automatically)
§9 Access to personal data by third parties
As a rule, the sole recipient of the personal data provided by Users is the Controller. Data collected in the course of the services provided are not transferred or resold to third parties.
Access to the data may be held by entities responsible for maintaining the infrastructure and services necessary to run the Website:
- Hosting companies providing hosting or related services to the Controller – the Website’s servers are maintained by OVH Sp. z o.o. (ul. Swobodna 1, 50-088 Wrocław) in a data centre in Poland
- Companies through which the Newsletter service is provided
§10 Manner of processing personal data
Personal data provided voluntarily by Users:
- Personal data will not be transferred outside the European Union unless they have been published as a result of an individual action by the User.
- Personal data will not be used for automated decision-making (profiling).
- Personal data will not be resold to third parties.
§11 Legal bases for processing personal data
The Website collects and processes Users’ data on the basis of:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) — Article 6(1)(a), (b) and (f)
- The Act of 10 May 2018 on the Protection of Personal Data (ustawa o ochronie danych osobowych; Journal of Laws – Dz.U. 2018, item 1000)
- The Act of 16 July 2004 – Telecommunications Law (Prawo telekomunikacyjne; Journal of Laws – Dz.U. 2004 No. 171, item 1800)
- The Act of 4 February 1994 on Copyright and Related Rights (ustawa o prawie autorskim i prawach pokrewnych; Journal of Laws – Dz.U. 1994 No. 24, item 83)
§12 Period of processing personal data
As a rule, the personal data referred to above are stored only for the period during which the Service is provided by the Controller via the Website. They are deleted or anonymised within 30 days of the end of the provision of services.
An exception is a situation in which the legitimate purposes of further processing of such data by the Controller need to be safeguarded — for no longer than 3 years.
Anonymous statistical data, which do not constitute personal data, are stored by the Controller for an indefinite period for the purpose of compiling Website statistics.
§13 Users’ rights relating to the processing of personal data
- Right of access to personal data — Users have the right to obtain access to their personal data, exercised upon a request submitted to the Controller.
- Right to rectification of personal data — Users have the right to obtain from the Controller, without undue delay, the rectification of inaccurate personal data.
- Right to erasure of personal data — Users have the right to obtain from the Controller the erasure of personal data without undue delay, exercised upon a request submitted to the Controller.
- Right to restriction of processing of personal data — Users have the right to restriction of the processing of personal data in the cases set out in Article 18 of the GDPR.
- Right to data portability — Users have the right to receive their personal data from the Controller in a structured, commonly used and machine-readable format.
- Right to object to the processing of personal data — Users have the right to object to the processing of their personal data in the cases set out in Article 21 of the GDPR.
- Right to lodge a complaint — Users have the right to lodge a complaint with the supervisory authority responsible for the protection of personal data.
§14 Contacting the Controller
The Controller can be contacted electronically at: kontakt@semano.pl
§15 Website requirements
- Restricting the saving of and access to Cookies on the User’s Device may cause certain functions of the Website to work incorrectly.
- The Controller accepts no liability whatsoever for malfunctioning functions of the Website where the User restricts in any way the ability to save and read Cookies.
§16 External links
The Website may contain links to external websites with which the Website Owner does not cooperate. These links, and the pages or files they point to, may be dangerous to your Device or pose a threat to the security of your data. The Controller accepts no liability for content located outside the Website.
§17 Changes to the Privacy Policy
- The Controller reserves the right to amend this Privacy Policy at its discretion, without the need to inform Users, insofar as it concerns the use and application of anonymous data or the use of Cookies.
- The Controller reserves the right to amend this Privacy Policy at its discretion insofar as it concerns the processing of Personal Data, of which it will inform Users by e-mail within 7 days of the amendment.
- Any changes made to the Privacy Policy will be published on this page of the Website.
- Changes come into force upon their publication.