Profi Personal Privacy Policy
Administrator – Profi Personal Sp. z o.o., with its registered office in Warsaw, entered into the Register of Entrepreneurs of the National Court Register under number 0000822203.
Personal Data – any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person;
Processing – any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction;
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation);
Website – the Administrator's website located at: https://profi-personal.com/;
User – any natural person visiting the Website or using the services or features described in this Privacy Policy;
The purposes, legal bases, and retention periods for your personal data processed by the Administrator vary depending on the specific process involved.
When you use the website, your personal data is processed to provide you with electronic services related to accessing website content, as well as for analytical and statistical purposes. Data processing is based on Article 6(1)(b) of the GDPR, regarding the necessity of processing for the conclusion and performance of an agreement, and Article 6(1)(f) of the GDPR, regarding the pursuit of the Administrator's legitimate interests, which include analyzing user activity and preferences to improve functionality and services. The Administrator processes data for the duration of the service, which corresponds to the period of website usage. Retention periods for cookies are specified in the Privacy Policy section.
Personal data is processed for the purpose of sending commercial proposals for the conclusion of an agreement. Data processing is based on Article 6(1)(b) of the GDPR, which covers processing necessary for the conclusion and performance of an agreement, as well as taking steps at the request of the data subject prior to entering into an agreement. If an agreement is concluded, personal data is processed for the duration of the agreement and subsequently for the period of the statute of limitations for any claims arising from the agreement. In the absence of an agreement, we process data for 1 month after the expiration of the proposal. If no expiration date is specified for the proposal, data is processed for 3 months from the date of the last contact.
The purpose of processing personal data is to conclude contracts and provide or use services based on them. Data is processed based on Article 6(1)(b) of the GDPR — necessity for the conclusion and performance of a contract; at the request of the data subject — taking steps prior to entering into a contract. Personal data is processed for the duration of the contract and subsequently for the duration of the statute of limitations for contractual claims.
The Administrator processes job candidate data during the recruitment process for the purpose of hiring employees. Data processing is based on Article 6(1)(b) of the GDPR — necessity for the conclusion and performance of a contract; at the request of the data subject — taking steps prior to entering into a contract. Data is processed for the duration of the recruitment process. If you provide additional consent for data processing for future recruitment purposes, we will process your data for a maximum period of 2 years from the date it was entered into the Administrator's database or from the date of your last contact, whichever is later.
The Administrator processes the data provided in the contact form to recruit a candidate or to respond to other inquiries specified in the form. Data processing is based on Article 6(1)(a) or Article 6(1)(f) of the GDPR — based on consent / at the candidate's request and for the realization of the Administrator's legitimate interests, which include ensuring proper service for visitors to the Website.
The Administrator sends electronic messages containing marketing information for advertising and promotional purposes related to the Administrator's activities. Data processing is based on consent — Article 6(1)(a) of the GDPR. Data is processed for a maximum period of 2 years from the date it was entered into the Administrator's database or from the date of your last contact, whichever is later.
The Administrator processes your data for the purpose of debt collection, legal proceedings, and defense against claims. Processing is based on Article 6(1)(f) of the GDPR, as it is in the Administrator's legitimate interest to assess, assert, or defend against claims. Data is processed for the duration of the statute of limitations in accordance with applicable laws.
The Administrator uses so-called service cookies primarily to provide the User with electronically delivered services and to improve the quality of those services. Therefore, the Administrator and other entities providing analytical and statistical services to the Administrator use cookies by storing information or accessing information already stored on the user's telecommunications device (computer, phone, tablet, etc.). Cookies used for this purpose include:
1.1.1. cookies containing data entered by the user (session ID) for the duration of the session (user input cookies);
1.1.2. authentication cookies used for services that require authentication for the duration of the session (authentication cookies);
1.1.3. cookies used for security purposes, such as those used to detect authentication fraud (user centric security cookies);
1.1.4. multimedia player session cookies (e.g., flash player cookies) for the duration of the session (multimedia player session cookies);
1.1.5. persistent cookies used to personalize the User interface for the duration of the session or slightly longer (user interface customization cookies);
The Administrator uses Google Analytics, an analytical tool that collects information about your website visits, such as the pages you view, the time spent on the site, and the time taken to navigate between pages. This is achieved using cookies from Google LLC related to the Google Analytics service. Google Analytics collects demographic and interest-based data. Through your cookie settings, you can decide whether or not to consent to the collection of your data. Google does not use the collected data to identify the User and does not combine this information with other data to facilitate identification. Detailed information regarding the scope and rules of data collection in connection with this service can be found at the following link: https://www.google.com/intl/pl/policies/privacy/partners.
The Administrator uses the Google Tag Manager marketing tool to manage marketing campaigns and your usage of our websites. This involves the use of cookies from Google LLC associated with the Google Tag Manager service. Within your cookie settings, you can decide whether you consent to the use of such files. Google does not use the collected data to identify the User and does not combine this information for identification purposes. Detailed information regarding the scope and rules of data collection in connection with this service can be found at the following link: https://www.google.com/intl/pl/policies/privacy/partners.
The Administrator uses the Facebook Pixel marketing tool to present you with personalized advertisements on Facebook. This involves the use of cookies from Facebook. In your cookie settings, you can decide whether you consent to the Administrator's use of the Facebook Pixel in your case. Facebook is a certified entity under the Privacy Shield Framework and therefore guarantees compliance with European data protection regulations. Detailed information regarding the scope and rules of data collection by Facebook can be found at the link: https://www.facebook.com/about/privacy/update. Specific information and details about the Facebook Pixel feature and how it works are available in the Facebook Help Center at https://www.facebook.com/business/help/651294705016616.
The Administrator uses the Bitrix24 marketing tool provided by Bitrix, Inc. (headquarters address: 901 N. Pitt St, Suite 325, Alexandria, VA 22314, USA), which collects information that allows for the identification of a person in accordance with the categories provided voluntarily. Data is stored in the European Union (Frankfurt, Germany) in Amazon Web Services data centers, which are fully compliant with the GDPR. Additional information regarding the scope and rules of data collection in connection with this tool can be found at the following link: https://aws.amazon.com/blogs/security/all-aws-services-gdpr-ready/. Information regarding GDPR compliance and the privacy policy is also available at https://www.bitrix24.com/gdpr/.
The Administrator processes the personal data of users who visit the Administrator's social media profiles (LinkedIn, Facebook, TikTok, Instagram). This data is processed solely in connection with maintaining the profile, including informing users about the Administrator's activities and promoting various types of events, services, and products. The legal basis for the Administrator's processing of personal data for this purpose is its legitimate interest (Art. 6(1)(f) GDPR), which consists of promoting its own brand.
The Administrator processes the following categories of Personal Data belonging to job applicants, (future / potential) business partners of the Administrator, employees or associates of (future / potential) business partners of the Administrator, and other individuals contacting the Administrator or individuals contacted by the Administrator:
1) identification data (in particular: first and last name, date of birth, ID document series and number, company name, tax identification number (NIP), national business registry number (REGON), and address details (registered office, correspondence address, business location addresses),
2) contact details (email address, phone number),
3) data regarding job titles, professional experience, and qualifications,
4) financial data, including bank account numbers, bank / financial institution details, and invoice data,
5) information obtained through the use of our website, in particular IP addresses, text files,
6) other data provided by you in any form — necessary for the purpose for which it was provided;
The Administrator obtains all data in the following ways:
1) information provided by you voluntarily and directly (e.g., via contact forms, order forms, business card exchanges, during telephone conversations, when entering into and performing contracts, and when providing services);
2) information obtained through the use of our website, in particular: IP address, text files;
3) data of employees or associates of the Administrator's business partners (contractors, subcontractors) — this is obtained directly from them or from their employer / the organization they represent;
4) data about candidates for employment with the Controller — this is obtained directly from them, from external recruitment agencies, or provided by the Controller's employees or associates as part of promotions or advertising programs and campaigns, such as a referral program,
5) from publicly available sources, in particular from the following databases and registers: the Central Registration and Information on Business (CEIDG), the National Court Register (KRS), and the National Official Business Register (REGON);
1) other entities of Profi Personal Sp. z o.o.,
2) entities providing services to the Controller, including in areas such as accounting, human resources, recruitment, legal services, debt collection, IT, and infrastructure, whereby these entities process data as subcontractors based on an agreement with the Controller and only in accordance with its instructions,
3) courier and postal service providers,
4) banks.
The Controller reserves the right to disclose selected information about you to competent authorities or third parties who request such information based on an appropriate legal basis and in accordance with applicable law.
You have the right:
1) to access your data, request its rectification, erasure, or restriction of processing;
2) to withdraw consent for the processing of personal data to the extent that the data is processed based on consent; the withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal;
3) to object to the processing of personal data to the extent that the basis for processing is the Controller's legitimate interest;
4) to data portability, i.e., to receive from the Controller information about the personal data being processed in a structured, commonly used, machine-readable format, to the extent that your data is processed for the purpose of concluding and performing a contract or based on consent;
5) to lodge a complaint with the President of the Personal Data Protection Office at ul. Stawki 2, 00-193 Warsaw, if you believe that the processing of your data violates the provisions of the GDPR.
Your data may be transferred outside the European Economic Area (comprising the European Union, Norway, Liechtenstein, and Iceland) (hereinafter: EEA) in connection with the Controller's cooperation with business partners based outside the EEA (Ukraine) and the provision of IT services and infrastructure to the Controller. To ensure an adequate level of protection in the event of such transfers, the Company uses standard contractual clauses issued by the European Commission in accordance with Article 46(2)(c) of the GDPR in its agreements with data recipients.
The Controller continuously analyzes risks to ensure that personal data is processed securely—primarily by ensuring that only authorized persons have access to the data and only to the extent necessary for the tasks they perform. The Controller ensures that all operations involving personal data are logged and performed only by authorized employees and associates.
The Controller takes all necessary steps to ensure that its subcontractors and other cooperating entities guarantee the use of appropriate security measures whenever they process personal data at the Controller's request.