iOS App Privacy Policy

 

Owner and Data Controller

Dagmara Zawada, ul. Janowskiego A., 02-784 Warszawa (referred to as the ‘Owner’)

Owner contact email: dagmara.223@gmail.com

 

This Policy applies to the data processing by the Owner’s website and other instances where the Owner is the data controller, including the data of its website users, other Owner services’ users, contractors, and employees. It does not apply to the situations where the Owner is the data processor.

 

Types of Data collected

 

Among the types of Personal Data that our Website collects, by itself or through third parties, there are: first name, last name, email address, Cookies and Usage Data.

 

 

Mode and place of processing the Data

 

 

Methods of processing

The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Website (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner.

 

 

Legal basis of processing

The Owner may process Personal Data relating to Users if one of the following applies:

  • Users have given their consent for one or more specific purposes.;
  • provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
  • processing is necessary for compliance with a legal obligation to which the Owner is subject;
  • processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party. These legitimate purposes include cybersecurity, traffic analytics, backup and restore, marketing, making- and defence against claims.

In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.

 

 

Data transfers

Depending on the User’s location, data transfers may involve transferring the User’s Data to a country other than their own. Where such countries include one or more countries outside the EU/EEA, the Owner will rely on an adequacy decision, including EU-US Privacy Shield, standard clauses, or another safeguard acceptable by the EU General Data Protection Regulation (GDPR).

 

 

Retention time

Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
  • Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner. In particular, backups may be held as long as can be reasonably expected, and potential claims-related data may be held up to the end of the limitation period, which is six (6) years.

The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation e.g. in relation to payroll information, or upon order of an authority.

Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.

 

 

The purposes of processing

 

The Data concerning the User is collected to allow the Owner to provide its Services, as well as for the following purposes: Contacting the User and Analytics. Additional purposes may be contained in the legitimate interests mentioned in this policy.

 

 

Detailed information on the processing of Personal Data

 

Personal Data is collected for the following purposes and using the following services:

 

Google Analytics (Google Inc.)

The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behaviour based on cookies to which you consent based on our pop-up when you first visit our website.

Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google utilizes the Data collected to track and examine the use of this Website, to prepare reports on its activities and share them with other Google services.
Google may use the Data collected to contextualize and personalize the ads of its own advertising network.

Personal Data collected: Cookies and Usage Data.

Place of processing: United States – Privacy PolicyOpt Out. Privacy Shield participant.

 

Contact form (this Website)

By filling in the contact form with their Data, the User authorizes this Website to use these details to reply to requests for information, quotes or any other kind of request as indicated by the form’s header.

Personal Data collected: email address, first name and last name.

 

Mailing list or newsletter (this Website)

By registering on the mailing list or for the newsletter, the User’s email address will be added to the contact list of those who may receive email messages containing information of commercial or promotional nature concerning this Website. Your email address might also be added to this list as a result of signing up to this Website or after making a purchase.
You can always opt-out of receiving email information by sending us an email to dagmara.223@gmail.com

Personal Data collected: email address, first name and last name, plus your query.

 

 

The rights of Users

 

Users may exercise certain rights regarding their Data processed by the Owner by emailing us to dagmara.223@gmail.com

In particular, Users have the right to do the following under EU General Data Protection Regulation (GDPR) or relevant UK legislation :

  • Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
  • Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out for profiling or direct marketing purposes. Further details are provided in the dedicated section below.
  • Access their Data. Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
  • Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
  • Restrict the processing of their Data. Users have the right, under certain circumstances, to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.
  • Have their Personal Data deleted or otherwise removed. Users have the right, under certain circumstances, to obtain the erasure of their Data from the Owner.
  • Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine-readable format and, if technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable provided that the Data is processed by automated means and that the processing is based on the User’s consent, on a contract which the User is part of or on pre-contractual obligations thereof.
  • Lodge a complaint. Users have the right to bring a claim before their competent data protection authority. In the UK, the authority is ico.org.uk

 
Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time without providing any justification. To learn, whether the Owner is processing Personal Data for direct marketing purposes, Users may refer to the relevant sections of this document.

 

How to exercise these rights

Apart from contact email mentioned above, any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. These requests can be exercised free of charge and will be addressed by the Owner as early as possible and always within one month.

 

Additional information about Data collection and processing

 

Legal action

The User’s Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of the Owner’s Services or other activities.


 

Additional information about User’s Personal Data

In addition to the information contained in this privacy policy, the Owner’s services may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request.

 

System logs and maintenance

For operation and maintenance purposes, the Owner may collect files that record interaction with the Owner’s services (System logs) use other Personal Data (such as the IP Address) for this purpose.

 

Changes to this privacy policy

The Owner reserves the right to make changes to this privacy policy at any time by giving notice to its Users on this page and possibly within the Owner’s services and/or – as far as technically and legally feasible – sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Should the changes affect processing activities performed on the basis of the User’s consent, the Owner shall collect new consent from the User, where required.

 

 

Definitions and legal references

 

Personal Data (or Data)

Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person. As defined by GDPR.

 

Usage Data

Information collected automatically through the Owner’s services (or third-party services employed in the Owner’s services), which can include: the IP addresses or domain names of the computers utilized by the Users who use the Owner’s services, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.

 

User

The individual using the Owner’s services who, unless otherwise specified, coincides with the Data Subject. References to the User may mutatis mutandis apply to other data subjects whose data is processed by the Owner.

 

Data Subject

The natural person to whom the Personal Data refers.

 

Data Processor (or Data Supervisor)

The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.

 

European Union (or EU)

Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.

 

Cookies

Small sets of data stored in the User’s device. The definition may also include similar purpose technologies such as pixels.


Legal information

This privacy policy has been prepared based on provisions of multiple legislations, including Art. 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR).