1. This Privacy Policy defines the principles of processing personal data obtained through the website anetteatelier.pl, hereinafter referred to as the „Website”.
2. The owner of the website and at the same time the Data Administrator is Robert Jeczminski, Y34 WR90 New Ross, 24 Longstone Drive, hereinafter referred to as the Administrator.
3. Personal data collected by the Administrator through the Website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also referred to as the GDPR.
4. The Administrator takes special care to respect the privacy of Customers visiting the Website.
§ 1 Type of data processed, purposes and legal basis
1. The Administrator collects information on natural persons performing legal acts not directly related to their activities, natural persons conducting business or professional activities on their own behalf, and natural persons representing legal persons or organizational units that are not legal persons, to whom the law grants legal capacity, conducting business or professional activities on their own behalf, hereinafter collectively referred to as Customers.
2. The Administrator processes the personal data of Customers in the scope of using the contact form service on the Website for the purpose necessary to perform the contract or take action before its conclusion – the basis for processing is Art. 6 sec. 1 lit. b GDPR
3. In the case of using the contact form service, the Client provides the following data:
e-mail address
name
phone number
4. Additional information may be collected during the use of the Website, in particular: the IP address assigned to the Client’s computer or the external IP address of the Internet provider, domain name, browser type, access time, operating system type. Navigation data may also be collected from Clients, including information about links and references they decide to click on or other activities undertaken on the Website for purposes related to the provision of services, as well as for technical and administrative, analytical and statistical purposes – in this respect, the basis for processing is also art. 6 sec. 1 letter f GDPR, i.e. necessity for the purposes resulting from the legitimate interest of the Administrator, which is to ensure IT security and management of the Website and to improve the functionality of the Website and the services provided.
§ 2 Data recipients
1. The Client’s personal data are transferred to service providers used by the Administrator when running the Website. Service providers to whom personal data are transferred, depending on contractual arrangements and circumstances, are either subject to the Administrator’s instructions as to the purposes and methods of processing this data (processors) or independently determine the purposes and methods of their processing (administrators).
1.1. Processors. The Administrator uses suppliers who process personal data only on the Administrator’s instructions. These include, among others, providers providing hosting services, accounting services, marketing systems, systems for analyzing traffic on the Website, systems for analyzing the effectiveness of marketing campaigns
1.2. Administrators. The Administrator uses suppliers who do not act solely on instructions and themselves determine the purposes and methods of using the Clients’ personal data. They provide electronic payment and banking services.
2. Location. Service providers are based mainly in Poland and other countries of the European Economic Area (EEA).
3. In the event of a request, the Administrator shall make personal data available to authorized state authorities, in particular organizational units of the Prosecutor’s Office, the Police, the President of the Office for Personal Data Protection, the President of the Office for Competition and Consumer Protection or the President of the Office of Electronic Communications.
§ 3 Data storage period
1. Customers’ personal data are stored:
1.1. If the basis for processing personal data is consent, then the Customer’s personal data are processed by the Administrator until the consent is revoked, and after the consent is revoked for a period of time corresponding to the limitation period for claims that the Administrator may raise and which may be raised against him. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to running a business – three years.
1.2. If the basis for processing data is the performance of a contract, then the Customer’s personal data are processed by the Administrator for as long as it is necessary to perform the contract, and after that time for a period corresponding to the limitation period for claims. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to running a business – three years.
§ 4 Cookie mechanism, IP address
1. The website uses small files called cookies. They are saved by the Administrator on the end device of the person visiting the Website, if the web browser allows it. A cookie file usually contains the name of the domain from which it comes, its „expiration time” and an individual, randomly selected number identifying this file. Information collected using files of this type helps to adapt the products offered by the Administrator to the individual preferences and actual needs of people visiting the Website
2. The Administrator uses two types of cookies:
2.1. Session cookies: after the end of a given browser session or after turning off the computer, the saved information is deleted from the device’s memory. The session cookie mechanism does not allow for downloading any personal data or any confidential information from the Customers’ computers.
2.2. Persistent cookies: they are stored in the memory of the Customer’s end device and remain there until they are deleted or expired. The persistent cookie mechanism does not allow for downloading any personal data or any confidential information from the Customers’ computer.
3. The Administrator uses its own cookies for the purpose of:
3.1. analysis and research and audience audits, and in particular to create anonymous statistics that help understand how Customers use the Website, which allows for improving its structure and content.
4. The Administrator uses external cookies for the purpose of:
4.1. presenting on the information pages of the Website, a map indicating the location of the Administrator’s office, using the maps.google.com website (external cookie administrator: Google Inc. based in the USA)
5. The cookie mechanism is safe for the computers of Customers visiting the Website. In particular, it is not possible for viruses or other unwanted software or malware to get to Customers’ computers this way. Nevertheless, in their browsers, Customers have the option of limiting or disabling cookie access to computers. In the case of using this option, using the Website will be possible, except for functions that by their nature require cookies.
6. The Administrator may collect IP addresses of Customers. An IP address is a number assigned to the computer of a person visiting the Website by the Internet service provider. The IP number allows access to the Internet. In most cases, it is assigned to the computer dynamically, i.e. it changes with each connection to the Internet and is therefore commonly treated as non-personal identifying information. The IP address is used by the Administrator to diagnose technical problems with the server, create statistical analyses (e.g. to determine from which regions we record the most visits), as information useful in administering and improving the Website, as well as for security purposes and possible identification of server-burdening, unwanted automatic programs for browsing the content of the Website.
§ 5 Rights of data subjects
The data subjects have the following rights:
1. The right to withdraw consent to data processing at any time:
1.1. The Client has the right to withdraw any consent they have granted
1.2. Withdrawal of consent takes effect from the moment of withdrawal of consent
1.3. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal
1.4. Withdrawal of consent does not entail any negative consequences for the Client, but may prevent further use of services or functionalities that, according to the law, the Administrator may only provide with consent
2. The right to object to data processing:
2.1. The Client has the right to object at any time – for reasons related to their specific situation – to the processing of their personal data based on art. 6 sec. 1 letter e) or f) of the GDPR, including profiling based on these provisions. The Administrator is no longer allowed to process this personal data unless he/she demonstrates the existence of compelling legitimate grounds for processing that override the interests, rights and freedoms of the data subject, or grounds for establishing, pursuing or defending claims
2.2. Resignation in the form of an e-mail from receiving marketing communications regarding products or services will mean the Customer’s objection to the processing of his/her personal data, including profiling for these purposes
3. Right to erasure of data („right to be forgotten”):
3.1. The Customer has the right to request the erasure of all or some of the personal data
3.2. The Customer has the right to request the erasure of personal data if:
3.2.1. the personal data are no longer necessary for the purposes for which they were collected or processed
3.2.2. has withdrawn a specific consent, to the extent that the personal data were processed based on his/her consent
3.2.3. has filed an objection under Article 21 paragraph 1 of the GDPR to the processing and there are no overriding legitimate grounds for processing or has filed an objection under Article 21 sec. 2 GDPR regarding processing
3.2.4. personal data are processed unlawfully
3.2.5. personal data must be deleted in order to comply with a legal obligation under Union law or the law of a Member State to which the Controller is subject
3.2.6. personal data have been collected in connection with the offering of information society services
3.3. Despite the request to delete personal data, in connection with the filing of an objection or withdrawal of consent, the Controller may retain certain personal data to the extent that processing is necessary to establish, pursue or defend claims, as well as to comply with a legal obligation requiring processing under Union law or the law of a Member State to which the Controller is subject. This applies in particular to personal data including: first name, last name, e-mail address, which data are retained for the purposes of handling complaints and claims related to the use of the Administrator’s services, or additionally the address of residence/mailing address, order number, which data are retained for the purposes of handling complaints and claims related to concluded sales agreements or the provision of services
4. The right to limit data processing:
4.1. The Customer has the right to request the restriction of the processing of their personal data. Submitting a request, until it is considered, prevents the use of certain functionalities or services, the use of which will be associated with the processing of the data covered by the request. The Administrator will also not send any messages, including marketing messages
4.2. The Customer has the right to request the restriction of the use of personal data in the following cases:
4.2.1. when they question the accuracy of their personal data – then the Administrator limits their use for the time needed to verify the accuracy of the data, but no longer than for 7 days
4.2.2. when the data processing is unlawful, and instead of deleting the data, the Customer requests the restriction of their use
4.2.3. when personal data are no longer necessary for the purposes for which they were collected or used, but they are needed by the Client in order to establish, pursue or defend claims
4.2.4. when the data subject has objected to the processing of their data – until it is determined whether the legitimate grounds on the part of the controller override the grounds for the objection of the data subject
5.
§ 5 The right to request access to your personal data from the Administrator and to receive a copy of it:
5.1. The Client has the right to obtain confirmation from the Administrator whether he processes personal data, and if so, the Client has the right to:
5.1.1. obtain access to his personal data
5.1.2. obtain information on the purposes of processing, categories of processed personal data, recipients or categories of recipients of this data, the planned period of storing the Client’s data or the criteria for determining this period (when it is not possible to determine the planned period of data processing), on the rights of the Client under the GDPR and on the right to lodge a complaint with the supervisory authority, if the personal data were not collected from the data subject – all available information on their source, on automated decision-making, including profiling referred to in art. 22 sec. 1 and 4 GDPR, and – at least in these cases – relevant information on the principles for their adoption, as well as on the significance and foreseeable consequences of such processing for the data subject and on the safeguards applied in connection with the transfer of personal data outside the European Union
5.1.3. obtain a copy of your personal data. The right to obtain a copy must not adversely affect the rights and freedoms of others.
6. Prawo do sprostowania (poprawiania) danych:
§ 7. Right to transfer data:
7.1. The Client has the right to receive his/her personal data that he/she has provided to the Administrator, and then send it to another personal data administrator of his/her choice. The Client also has the right to request that the personal data be sent by the Administrator directly to such administrator, if technically possible. In such a case, the Administrator will send the Client’s personal data in the form of a file in the csv format, which is a commonly used, machine-readable format that allows the data received to be sent to another personal data controller
8. The right to file
1. The Client has the right to demand that the Administrator immediately rectify his or her personal data that is incorrect. Taking into account the purposes of processing, the Client whose data is being processed has the right to request that incomplete personal data be supplemented, including by submitting an additional statement, by sending a request to the e-mail address in accordance with §6 of the Privacy Policy
7. The right to transfer data:
7.1. The Client has the right to receive his or her personal data that he or she has provided to the Administrator, and then send it to another personal data controller of his or her choice. The Client also has the right to request that the personal data be sent by the Administrator directly to such controller, if technically possible. In such a case, the Administrator will send the Client’s personal data in the form of a file in the csv format, which is a commonly used, machine-readable format that allows the received data to be sent to another personal data controller
to lodge a complaint with the supervisory authority:
8.1. The Client has the right to lodge a complaint with the President of the Personal Data Protection Office regarding a violation of his or her rights to the protection of personal data or other rights granted under the GDPR
9. In the event that the Client exercises the right resulting from the above rights, the Administrator shall comply with the request or refuse to comply with it immediately, but no later than within one month of its receipt. However, if – due to the complex nature of the request or the number of requests – the Administrator is unable to comply with the request within a month, it will comply with it within the next two months, informing the Customer in advance within a month of receiving the request – about the intended extension of the deadline and its reasons
10. The Customer may submit complaints, inquiries and requests to the Administrator regarding the processing of his/her personal data and the implementation of his/her rights
§ 6 Changes to the Privacy Policy
1. The Privacy Policy may change, about which the Administrator is not obliged to inform.
2. Questions related to the Privacy Policy should be sent to the e-mail address:
r.jeczminski@rj-techinsider.eu
3. Date of last modification: 14.04.2025
