Legal notice

Privacy policy

Applies to: operibus.pl operibus.eu operibus.com.pl

This document sets out the terms of processing personal data (hereinafter referred to as “data”) on the websites operated by Operibus Sp. z o.o. at operibus.pl, operibus.eu and operibus.com.pl, jointly referred to hereinafter as the “Websites”. The rules for the use of cookies are set out in a separate document — the Cookie Policy.

1.Who the Data Controller is and how to get in touch

The Controller of data processed in connection with the Websites is Operibus Sp. z o.o., seated in Wrocław, operating at ul. Jedności Narodowej 234/3, 50-302 Wrocław, Poland, entered in the Register of Entrepreneurs of the National Court Register (KRS) under number 0000559746, holding NIP (VAT ID): 6322013075 and REGON: 361841091 (hereinafter the “Controller”).

The Controller can be contacted by telephone at +48 695 002 853 or by e-mail at iod@operibus.pl.

2.Legal basis for data processing

The Controller processes data on the basis of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the “GDPR”.

3.Principles and purposes of data processing

The Controller collects and processes data for the following purposes and on the following legal grounds under the GDPR:

E-mail correspondence and contact form

Where correspondence is sent to the Controller by e-mail or via a contact form, the data contained in such correspondence is processed solely for the purpose of communicating and handling the matter to which the correspondence relates. The legal basis for processing is the legitimate interest of the Controller (Article 6(1)(f) of the GDPR) consisting in maintaining correspondence addressed to it in connection with its activities. The Controller only processes data that is relevant to the matter concerned.

Telephone contact

Where a person contacts the Controller by telephone, the Controller may request data only where this is necessary to handle the matter to which the contact relates. The legal basis is the legitimate interest of the Controller (Article 6(1)(f) of the GDPR) consisting in the need to resolve the reported matter related to its activities.

Security

From the launch of the Websites, in order to ensure the security of the services provided, the Controller processes the following data:

The legal basis for processing is the legitimate interest of the Controller (Article 6(1)(f) of the GDPR) consisting in maintaining event logs and protecting the Websites against potential hacking attacks and other misuse.

4.Data recipients

In connection with conducting activities that require the processing of data, such data may be disclosed to external entities that the Controller engages for a specified purpose, in particular to providers responsible for the operation of IT systems and equipment, and to entities providing accounting or legal services.

The Controller reserves the right to disclose selected data to competent authorities or third parties that request such information, based on an appropriate legal basis and in accordance with applicable law.

5.Transfer of data outside the EEA

The Controller does not transfer the data it holds to “third countries” within the meaning of the personal data protection regulations, i.e. outside the European Economic Area.

6.Data retention period

The period for which the Controller processes data depends on the type of service provided and the purpose of processing. The processing period may also result from legal provisions where these constitute the basis for processing. Data is processed in order to fulfil the legal obligations imposed on the Controller. Where data is processed on the basis of the Controller's legitimate interest — for example, for security reasons — the data is processed for the period necessary to pursue that interest or until an effective objection to the processing is filed. Where processing is based on consent, data is processed until the consent is withdrawn. Where the basis for processing is the necessity to conclude and perform a contract, data is processed until the contract is terminated. The processing period may be extended where processing is necessary for the establishment, pursuit or defence of legal claims, and thereafter only where and to the extent required by law. Upon expiry of the processing period, the data is irreversibly deleted or anonymised.

7.Rights in relation to data processing

The data subject has the right to request access to their data, its rectification, erasure or restriction of processing, the right to data portability, and the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) if they consider that the data provided is being processed in a manner inconsistent with the GDPR.

8.Data security

In order to ensure the integrity and confidentiality of data, the Controller has implemented procedures that allow access to data only by authorised persons and only to the extent necessary for the tasks performed by them.

9.Automated data processing (profiling)

Data is not subject to automated processing, including profiling, that produces legal effects concerning the data subject or similarly significantly affects them.

10.Links to other websites or software

The Websites may contain links to third-party websites or software. The Controller is not responsible for the privacy policies applied on such websites or in such software. The Controller recommends reviewing the privacy policies of such websites or software after visiting them or before installing them.

11.Cookies

The rules for the use of cookies on the Websites are set out in a separate document — the Cookie Policy.

12.Changes to the privacy policy

The privacy policy takes effect on the date it is published on the Websites. Any change to the privacy policy is made by publishing its new content on the Websites. The Controller publishes information about any change to the privacy policy on the Websites no later than 3 days before the date on which the new wording takes effect.

Controller: Operibus Sp. z o.o., ul. Jedności Narodowej 234/3, 50-302 Wrocław, Poland
KRS: 0000559746 · NIP (VAT ID): 6322013075 · REGON: 361841091