Ask for
an offer
Privacy Policy
Read the privacy policy
- GENERAL PROVISIONS
- The controller of personal data collected via the website krafton.com.pl is KRAFTON ACCOUNTING XON Sp. z o. o. Sp. k., ul. Promienista 132, 60-142 Poznań, NIP 7792381569, REGON 301533798, KRS 0000362593, hereinafter referred to as the “Controller”.
- Personal data collected by the Controller via the website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as GDPR, as well as the Personal Data Protection Act of 10 May 2018.
- TYPE OF PERSONAL DATA PROCESSED, PURPOSE AND SCOPE OF DATA COLLECTION
- Purpose of processing and legal basis.
The Controller processes personal data via the website in the following cases:
- the user uses the contact form or contacts via email at the email address provided in the contact details. Personal data are processed on the basis of Art. 6(1)(f) GDPR as the legitimate interest of the Controller.
- the user contacts via phone at the telephone number provided in the contact details. Personal data are processed on the basis of Art. 6(1)(f) GDPR as the legitimate interest of the Controller.
- Categories of personal data processed.
The Controller processes the following categories of the user’s personal data:
- Name and surname,
- Email address,
- Phone number.
- Retention period of personal data.
Users’ personal data are stored by the Controller:
- where the legal basis for processing is the performance of a contract, for as long as necessary for the performance of the contract, and thereafter for a period corresponding to the limitation period for claims. Unless a specific provision provides otherwise, the limitation period is six years, and for claims for periodic performance and claims related to conducting business activities – three years.
- where the legal basis for processing is consent, until the consent is withdrawn, and after withdrawal, for a period corresponding to the limitation period for claims that may be raised by or against the Controller. Unless a specific provision provides otherwise, the limitation period is six years, and for claims for periodic performance and claims related to conducting business activities – three years.
- When using the website, additional information may be collected, in particular: IP address assigned to the user’s computer or external IP address of the Internet provider, domain name, browser type, access time, and operating system type.
- Navigation data may also be collected from users, including information about links and references they decide to click or other actions taken on the website. The legal basis for this type of activity is the legitimate interest of the Controller (Art. 6(1)(f) GDPR), consisting in facilitating the use of services provided electronically and improving the functionality of these services.
- Providing personal data by the user is voluntary.
- Personal data will also be processed in an automated manner in the form of profiling, provided that the user consents to it pursuant to Art. 6(1)(a) GDPR. The consequence of profiling will be assigning a profile to a given person in order to make decisions regarding them or analyze or predict their preferences, behaviors, and attitudes.
- The Controller exercises special care to protect the interests of data subjects, and in particular ensures that the data collected by it are:
- processed lawfully,
- collected for specified, legitimate purposes and not subjected to further processing incompatible with those purposes,
- factually correct and adequate in relation to the purposes for which they are processed, and stored in a form that permits identification of data subjects for no longer than is necessary to achieve the purpose of processing.
- SHARING OF PERSONAL DATA
- Users’ personal data are transferred to service providers used by the Controller in operating the website. Service providers to whom personal data are transferred, depending on contractual arrangements and circumstances, are either subject to the Controller’s instructions as to the purposes and means of processing such data (processors) or independently determine the purposes and means of processing (controllers).
- Users’ personal data are stored exclusively within the European Economic Area (EEA).
- RIGHT OF CONTROL, ACCESS TO DATA AND CORRECTION
- The data subject has the right to access their personal data, as well as the right to rectification, erasure, restriction of processing, the right to data portability, the right to object, and the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Legal bases for user requests:
- Access to data – Art. 15 GDPR
- Rectification of data – Art. 16 GDPR.
- Erasure of data (the right to be forgotten) – Art. 17 GDPR.
- Restriction of processing – Art. 18 GDPR.
- Data portability – Art. 20 GDPR.
- Objection – Art. 21 GDPR
- Withdrawal of consent – Art. 7(3) GDPR.
- In order to exercise the rights referred to in point 2, an email can be sent to: biuro@krafton.com.pl
- If a user exercises any of the above rights, the Controller shall comply with or refuse the request without undue delay, but no later than within one month of receiving it. However, if – due to the complex nature of the request or the number of requests – the Controller is unable to fulfill the request within one month, it shall fulfill it within the following two months, having previously informed the user within one month of receipt of the request about the intended extension and its reasons.
- If it is determined that the processing of personal data violates GDPR provisions, the data subject has the right to lodge a complaint with the President of the Personal Data Protection Office.
- IMPORTANT MARKETING TECHNIQUES
- The Controller uses statistical analysis of website traffic through Google Analytics (Google Inc., based in the USA). The operator does not transfer personal data to the provider of this service, but only anonymized information. The service is based on the use of cookies on the user’s terminal device. Regarding information on user preferences collected by the Google advertising network, the user can view and edit information derived from cookies using the tool: https://www.google.com/ads/preferences/
- The Controller uses remarketing techniques that allow tailored advertising messages based on user behavior on the website, which may give the impression that the user’s personal data are being used for tracking; however, in practice, no personal data are transferred from the Operator to advertising networks. The technological condition for such activities is enabled cookie support.
- COOKIES
- The Controller’s website uses “cookies”.
- The installation of cookies is necessary for the proper provision of services on the website. Cookies contain information necessary for the proper functioning of the website and also make it possible to compile general statistics on website visits.
- The following types of cookies are used on the website:
- The Controller uses its own cookies to better understand how the user interacts with the content of the website. These files collect information on how the user uses the website, the type of site from which the user was redirected, and the number and duration of visits to the website. This information does not record specific personal data of the user, but is used to compile website usage statistics.
- The user has the right to decide on the access of cookies to their computer by selecting them in advance in their browser window. Detailed information on the possibilities and ways of managing cookies is available in the software settings (web browser).
- FINAL PROVISIONS
- The Controller applies technical and organizational measures to ensure the protection of processed personal data appropriate to the risks and categories of protected data, and in particular protects data against disclosure to unauthorized persons, removal by an unauthorized person, processing in violation of applicable laws, and alteration, loss, damage, or destruction.
- The Controller provides appropriate technical measures to prevent unauthorized persons from acquiring and modifying personal data transmitted electronically.
- In matters not regulated by this Privacy Policy, the provisions of the GDPR and other relevant provisions of Polish law shall apply accordingly.