Notice on personal data processing in accordance with Article 14 of the GDPR

 

when personal data are obtained other than from data subjects



Dear Sir or Madam,

Having regard for your rights under the Regulation of the European Parliament and of the (EU) Council 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (referred to as the "GDPR" or the “General Data Protection Regulation), we request that you read the following information

WHO IS THE CONTROLLER OF YOUR PERSONAL DATA?

The Controller of your personal data is: Eko-Okna S.A., with its registered office in Kornice. You can contact us at the following address: Kornice, ul. Spacerowa 4, 47-480 Pietrowice Wielkie. You can also contact the Controller via the Data Protection Officer appointed by the Controller, in writing at the aforementioned address in Kornice or at the following e-mail address: iod@ekookna.pl, for any matter regarding the processing of your personal data.

WHAT ARE THE OBJECTIVES, LEGAL BASIS AND SOURCES OF THE PROCESSING OF YOUR PERSONAL DATA?

Your personal data will be processed by Eko-Okna S.A. (Controller) for purposes related to:

  1. 1 The performance of legal obligations imposed on the Controller to the extent provided for in the provisions of law.
    Legal basis: Article 6(1)(c) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
  2. 2. The pursuit of the Controller’s or a third party’s legitimate interests, in particular such as:
    • - Establishing business relations (including submitting a request for quotation or a quotation)
    • - Concluding or executing an agreement between the Controller and a prospective customer
    • - Ensuring smooth communication by the Controller between all cooperating entities, in particular at the stage of submitting quotations, concluding agreements and their execution
    • - Obtaining consents for direct marketing and conducting direct marketing – ensuring the security of business trading
    • - Verifying the correctness of data held and enriching them – verifying customers and contractors
    • - Pursuing or defending against claims
    Legal basis: Article 6(1)(f) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016
  3. 3. Specified in the content of your consent to the processing of data if and to the extent that you have given consent to this processing. In such case, the processing of personal data takes place only for the purpose for which the consent has been given.
    Legal basis: Article 6(1)(a) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016

PROFILING – GOOGLE ANALYTICS, GOOGLE TAG MANAGER, GOOGLE ADS

Personal data as defined by the law (e.g. IP address) concerning persons visiting the website of Eko-Okna S.A., collected using the aforementioned "Google Analytics" and “Google Tag Manger” tools, are used primarily to analyse network traffic (for statistical purposes).

The Controller also uses the “Google Ads” tool for profiling for direct marketing purposes, i.e. to create the company's offer tailored to the "profile" of a specific user.

The Controller uses the "Google Ads" tool to profile website users and to use the anonymous data obtained in this manner (e.g. opening specific subpages, filling in a contact form, etc.) for remarketing purposes. This solution makes it possible to establish closer contact with users who have visited the website of Eko-Okna S.A. by displaying advertisements for them that are more precisely selected in terms of content, while browsing other websites or using the Google search engine. This helps the Controller to encourage the recipients of advertisements to purchase the offered products more frequently. The user may disable the collection of personalised data. More information on ad personalisation and settings can be found at - https://policies.google.com/technologies/partner-sites

TO WHOM MAY YOUR DATA MAY BE TRANSFERRED?

In accordance with the applicable law, we may provide your data to entities processing data on our order, subcontractors of our services and entities authorised to obtain data under the applicable law, e.g. courts or law enforcement authorities, only upon a request submitted on a relevant legal basis. We would also like to inform you that the website of Eko-Okna S.A. uses the "Google Analytics", “Google Tag Manager” and “Google Ads” tools developed by Google LLC with its registered office at 1600 Amphitheatre Parkway, Mountain View, CA, 94043, United States.

FOR HOW LONG WILL WE PROCESS YOUR PERSONAL DATA?

If the basis for processing is consent, the data will be processed until the consent is revoked, and, after the consent is revoked, for a period of time corresponding to the limitation period of claims that may be asserted by EKO-OKNA S.A. and that may be asserted against it (Article 6(1) (a)).

If the basis for processing is the performance of the contract, the data will be processed as long as necessary for the performance of the contract and, after that time, for the period corresponding to the limitation period of claims (Article 6(1)(b)).

If processing is necessary to fulfil the legal obligation imposed on the controller, the data will be processed for as long as necessary to perform this obligation within the meaning of the law. (Article 6(1)(c)).

If processing is necessary to protect the vital interests of the data subject or another natural person, the processing period shall correspond to the duration of those interests. Once the processing has been completed, the data will be erased (Article 6(1)(d)).

If processing is necessary for the purposes of legitimate interests pursued by the controller (...), the processing period shall correspond to the duration of the legitimate interests pursued by the controller (Article 6(1)(f)).

WHAT ARE YOUR RIGHTS IN RELATION TO YOUR PERSONAL DATA?

You have the right to request access to your data, rectification or erasure of your data, the restriction of processing, the right to object to processing, and the right to data portability. You can also use other rights listed in detail in the GDPR. Any requests in this respect should be made directly to the mailing address or electronic address indicated above.

If you believe that your rights guaranteed by the provisions of the above Regulation have been violated, you also have the right to lodge a complaint with the President of the Personal Data Protection Office in electronic or traditional form in accordance with the procedures described on the website of the Personal Data Protection Office (uodo.gov).

If the basis for processing is the performance of a contract, the data will be processed for as long as necessary for the performance of the contract and, after that time, for the period corresponding to the limitation period of claims.

OBTAINING PERSONAL DATA BY THE CONTROLLER.

To the extent that your data have not been obtained by the Controller directly from you, the data have been transferred by the entity to which you have given consent to transfer the data to the Controller or to the Controller’s Client that performs services or deliveries directly or indirectly for you. Information on entrepreneurs containing data of natural persons conducting business activity, agents and representatives of entrepreneurs, available in public sources, in particular in the registers of the National Court Register, Central Registration and Information on Business, Central Statistical Office, Central Register of Vehicles and Drivers, Court and Commercial Gazette (Monitor Sądowy i Gospodarczy), was obtained from entities specialising in the provision of data. Information about enterprises is occasionally also obtained by the Controller from your websites or is transferred by other companies.

SCOPE OF PERSONAL DATA PROCESSING.

To the extent that your data have not been obtained directly from you, the data processed by the Controller may include: first and last name, position/function, company name, NIP (tax identification number), REGON (national business registry number), business address, telephone number, e-mail address, authorisations and qualifications, licences held for a specific business type, information about the number and types of vehicles, information about the number of employees, financial information, and other data included in public registers.

NOTICE ABOUT THE POSSIBILITY OF WITHDRAWING CONSENT TO THE PROCESSING OF PERSONAL DATA

Notice for persons whose personal data are processed on the basis of consent/consents.

Consent to the processing of personal data is voluntary and you can withdraw it at any time, but the withdrawal of the consent will not affect the lawfulness of processing on the basis of the consent, prior to its withdrawal. The withdrawal of the consent does not affect the legitimacy of the processing performed before such withdrawal.

Consent to the use of “cookies” for network traffic analysis may be granted on visiting the website of Eko-Okna S.A. You also have the right to contact the Data Protection Officer to withdraw your consent to the processing of such data.

The data controller does not intend to provide your data to any third parties or transnational organisations.

Your data may be processed in an automated or semi-automated manner, but we do not take any automatic decisions regarding you that may have legal effects for you. Based on the data provided by you regarding your business, we try to select the best possible range of marketing information or offer details addressed to you.

You can give (or withdraw) your consent to the processing of personal data by using the electronic form available via the website rodo.ekookna.pl