In case of any discrepancy, the Polish version of this policy shall prevail.
General provisions
This privacy policy of the Website is an information document. The privacy policy contains, above all, the rules concerning the processing of personal data by the Controller, including the grounds, purposes and scope of the processing of personal data and the rights of data subjects, as well as information on the use of cookies and analytical tools on the Website.
The controller of personal data collected via the Website is Park Edukacyjny „Interakcje” Sp. z o.o., ul. Straconki 58/2, 43-300 Bielsko-Biała, NIP: 7010345193, REGON: 146163128, KRS: 0000423869, hereinafter referred to as the „Controller” and acting at the same time as the Service Provider of the website.
Personal data on the website is processed by the Controller in accordance with applicable law, in particular in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) - hereinafter referred to as the „GDPR” or the „GDPR Regulation”. The official text of the GDPR Regulation: eur-lex.europa.eu.
Use of the website and the provision of data by the user is voluntary. The Controller takes particular care to protect the interests of the data subjects whose personal data it processes, and in particular is responsible for and ensures that the data it collects is: (1) processed lawfully; (2) collected for specified, lawful purposes and not further processed in a manner incompatible with those purposes; (3) substantively correct and adequate in relation to the purposes for which it is processed; (4) stored in a form which permits identification of the data subjects for no longer than is necessary to achieve the purpose of processing; and (5) processed in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, by means of appropriate technical or organisational measures.
Taking into account the nature, scope, context and purposes of the processing, as well as the risk of varying likelihood and severity of harm to the rights or freedoms of natural persons, the Controller implements appropriate technical and organisational measures to ensure that processing is carried out in accordance with this regulation and to be able to demonstrate this. These measures are reviewed and updated as necessary. The Controller applies technical measures to prevent the acquisition and modification of personal data transmitted electronically by unauthorised persons.
Grounds for data processing
The Controller is entitled to process personal data in cases where - and to the extent that - at least one of the following conditions is met: (1) the data subject has given consent to the processing of their personal data for one or more specific purposes; (2) processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract; (3) processing is necessary for compliance with a legal obligation to which the Controller is subject; or (4) processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
The processing of personal data by the Controller requires in each case the existence of at least one of the grounds indicated in point 2 of the privacy policy. The specific grounds for the processing of the personal data of Users and Customers by the Controller are indicated in the next point of the privacy policy - in relation to the given purpose of the processing of personal data by the Controller.
Purpose, grounds, period and scope of data processing
In each case, the purpose, grounds, period and scope, as well as the recipients of the personal data processed by the Controller, result from the actions taken by the given User. The Controller may process personal data in order to handle enquiries sent via the contact form and to conduct correspondence with persons interested in the offer.
For the proper functioning of the website, it is necessary for the Controller to use the services of external entities (such as, for example, a software provider). The Controller uses only the services of such processors who provide sufficient guarantees of implementing appropriate technical and organisational measures so that the processing meets the requirements of the GDPR Regulation and protects the rights of data subjects.
The transfer of data by the Controller does not occur in every case and not to all of the recipients or categories of recipients indicated in the privacy policy - the Controller transfers data only when it is necessary to achieve the given purpose of processing personal data and only to the extent necessary to achieve it. Users' personal data may be transferred to the following recipients or categories of recipients:
- service providers supplying the Controller with technical, IT and organisational solutions enabling the Controller to conduct its business activity, including the website and the electronic services provided through it (in particular, providers of computer software for running the website, providers of email and hosting, and providers of software for managing the company and providing technical support to the Controller) - the Controller shares the Customer's collected personal data with the selected provider acting on its behalf only in the case of, and to the extent necessary for, achieving the given purpose of data processing in accordance with this privacy policy.
Rights of the data subject
Right of access, rectification, restriction, erasure or portability - the data subject has the right to request from the Controller access to their personal data, the rectification, erasure („right to be forgotten”) or restriction of processing, and has the right to object to the processing, as well as the right to data portability. The detailed conditions for exercising the rights indicated above are set out in Articles 15-21 of the GDPR Regulation.
Right to withdraw consent at any time - a person whose data is processed by the Controller on the basis of consent given (pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR Regulation) has the right to withdraw consent at any time without affecting the lawfulness of the processing carried out on the basis of consent before its withdrawal.
Right to lodge a complaint with a supervisory authority - a person whose data is processed by the Controller has the right to lodge a complaint with a supervisory authority in the manner and procedure set out in the provisions of the GDPR Regulation and Polish law, in particular the Act on the Protection of Personal Data. The supervisory authority in Poland is the President of the Personal Data Protection Office.
Right to object - the data subject has the right, on grounds relating to their particular situation, to object at any time to the processing of personal data concerning them, including profiling on the basis of these provisions. In such a case, the Controller may no longer process such personal data unless it demonstrates the existence of compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or grounds for the establishment, exercise or defence of legal claims.
Right to object regarding direct marketing - if personal data is processed for the purposes of direct marketing, the data subject has the right to object at any time to the processing of personal data concerning them for the purposes of such marketing, including profiling, to the extent that the processing is related to such direct marketing.
In order to exercise the rights referred to in this point of the privacy policy, you may contact the Controller by sending an appropriate message in writing or by email to biuro@religijneplacezabaw.pl or by using the contact form available on the Website.
Cookie policy
Cookies are small pieces of text information in the form of text files, sent by the server and stored on the side of the person visiting the website (e.g. on the hard drive of a computer or laptop, or on the memory card of a smartphone - depending on the device the visitor is using). Detailed information about cookies, as well as the history of their origin, can be found, among other places, here: pl.wikipedia.org/wiki/Ciasteczko.
The Controller may process data contained in cookies while visitors use the website for the following purposes:
- remembering data from completed Forms;
- adapting the content of the website to the individual preferences of the Service Recipient (e.g. regarding colours, font size, page layout) and optimising the use of the website;
- keeping anonymous statistics showing how the website is used;
- remarketing, that is, examining the behavioural characteristics of website visitors through anonymous analysis of their actions (e.g. repeated visits to particular pages, keywords, etc.) in order to create their profile and provide them with advertisements tailored to their anticipated interests, also when they visit other websites in the advertising network of Google Ireland Ltd. and Meta Platforms Ireland Ltd.
By default, most web browsers available on the market accept the storage of cookies. Everyone has the option to define the conditions of using cookies via the settings of their own web browser. This means that you can, for example, partially restrict (e.g. temporarily) or completely disable the option of storing cookies - in the latter case, however, this may affect some of the website's functionalities.
The web browser settings regarding cookies are important from the point of view of consent to the use of cookies by the website - in accordance with the regulations, such consent may also be expressed through the settings of the web browser. In the absence of such consent, the web browser settings regarding cookies should be changed accordingly.
Detailed information on changing the settings regarding cookies and deleting them yourself in the most popular web browsers is available in the help section of the web browser and on the following pages: Chrome, Firefox, Edge, Opera, Safari.
The Controller may use Google Analytics services, provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). These services help the Controller analyse traffic on the Website. The data collected is processed within the above services anonymously (this is so-called operational data, which makes it impossible to identify a person) to generate statistics helpful in administering the Website. This data is aggregated and anonymous, i.e. it does not contain identifying features (personal data) of the persons visiting the website. It is possible to block Google Analytics from receiving information about activity on the Website - to do so, you can install a browser add-on available here: tools.google.com/dlpage/gaoptout.
Data controller: Park Edukacyjny „Interakcje” Sp. z o.o., ul. Straconki 58/2, 43-300 Bielsko-Biała. Contact regarding personal data matters: biuro@religijneplacezabaw.pl.