Folks
0%
Loading

GDPR information notice

This is a courtesy translation. The Polish version is the legally binding text.

This GDPR Information Notice applies to the Terms of Service of the Folks Platform and to the Cookie Policy. The terms used in this GDPR Information Notice are defined in the Terms of Service and the Cookie Policy, whose provisions apply accordingly.

PERSONAL DATA

  1. Personal data provided by the User is processed by the Service Provider (i.e. Good One PR Sp. z o.o., with its registered office in Warsaw, ul. Edwarda Jelinka 38, 01-646 Warszawa, entered in the register of entrepreneurs kept by the District Court for the Capital City of Warsaw in Warsaw, XII Commercial Division of the National Court Register, under KRS number 0000952410, NIP (tax ID): 5252895306, REGON: 521212641, with share capital of PLN 5,000), which is the Personal Data Controller within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR”).

You can contact us by post at 01-646 Warszawa, ul. Edwarda Jelinka 38, or by email at kontakt@folks.pl.

  1. The scope of the personal data processed is determined by the scope of the data the User fills in
    and then sends to the Personal Data Controller using the relevant data form. Processing of the User’s personal data may concern their email address, first name and surname, date of birth, place of residence and the IP address of their computer. In certain cases this scope may also include personal data of the User’s legal guardians, such as: first name, surname, telephone number, home address or email address.
  2. Providing the personal data referred to in point 2 above is voluntary and is not a statutory requirement. However, failure to provide the data marked as mandatory will prevent the Personal Data Controller from carrying out the tasks for which the data is collected.
  3. The personal data of Users (and of their legal guardians) will be processed for a period of at least 5 years and may be deleted after that time, unless its further processing is also necessary on another legal basis.

Such a case is deemed to be the need for the Personal Data Controller to pursue claims in connection with its business activity, or to defend against claims made against the Service Provider, on the basis of generally applicable law,
taking into account the limitation periods for claims set out in generally applicable law.

  1. Users’ personal data will be processed for the purpose of:
    (a) creating an Account, providing services electronically, concluding and performing a Sales Agreement, and other activities indicated in the Terms,
    (b) the Service Provider’s promotional and commercial activities.
  1. Legal bases for processing personal data:
    a) the User (legal guardian) has consented to the processing of their personal data (Art. 6(1)(a) GDPR);
    b) processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract (Art. 6(1)(a) GDPR);
    c) processing is necessary for compliance with a legal obligation to which the controller is subject (Art. 6(1)(a) GDPR).
  2. Users’ personal data may be entrusted for processing, for the purpose of performing agreements for the provision of services electronically by the Service Provider, to a hosting company, to a company providing accounting services to the Service Provider, and to a carrier. Personal data collected by the Service Provider may also be disclosed: to the relevant state authorities at their request on the basis of the relevant provisions of law, or to other persons and entities – in cases provided for by law, with the User’s prior consent, to entities cooperating with the Service Provider within the Folks Platform. Every entity to which the Service Provider entrusts Users’ personal data for processing on the basis of a data processing agreement (the “Processing Agreement”) guarantees an appropriate level of security and confidentiality of personal data processing, including entities applying binding corporate rules. An entity processing Users’ personal data on the basis of a Processing Agreement will process Users’ personal data through another entity only with the Service Provider’s prior consent. Personal data may be disclosed to entities not authorised under this Notice only with the prior consent of the User to whom the data relates.
  3. Personal data may be disclosed to entities not authorised under this Notice only with the prior consent of the User to whom the data relates.
  4. Users have the right to control the processing of the data concerning them contained in data sets, and in particular the right to:
  • access their personal data, complete it, and
  • rectify the data by submitting such a request to the Service Provider,
  • object to the processing carried out,
  • control the processing of the data concerning them contained in data sets,
  • have the personal data collected about them erased, both from the Service Provider’s system and from the databases of entities with which the Service Provider cooperates or has cooperated,
  • restrict the processing of their data,
  • port the personal data collected by the Service Provider about the User, including receiving it in a structured form,
  • lodge a complaint with the supervisory authority where they consider that their data is processed unlawfully, and;
  • seek a judicial remedy before a court against the supervisory authority and against the entity committing the infringement.
  1. Entrusted personal data is stored and secured in accordance with the rules set out
    in the applicable provisions of law:
  2. The Service Provider applies technical and organisational measures ensuring protection of the personal data processed appropriate to the risks and to the categories of data protected, and in particular secures the data against disclosure to unauthorised persons, removal by an unauthorised person, processing in breach of the law, and alteration, loss, damage or destruction. It applies technical and organisational measures ensuring protection of the personal data processed appropriate to the risks and to the categories of data protected, and in particular secures the data, technically and organisationally, against disclosure to unauthorised persons, removal by an unauthorised person, processing in breach of the law, and alteration, loss, damage or destruction; among other things, SSL (Secure Socket Layer) certificates are used. The set of Users’ personal data collected is stored on a secured server, and the data is also protected by the Service Provider’s internal procedures
    for personal data processing and its information security policy.
  3. The Service Provider applies all the necessary technical measures set out in Articles 25, 30, 32–34 and 35–39 GDPR, ensuring enhanced protection and security of the processing of Users’ personal data.
  4. If the Service Provider learns that the User is using a service provided electronically in breach of the Terms or of applicable law (prohibited use), the Service Provider may process the User’s personal data to the extent necessary to establish the User’s liability.
  5. The Website may store http requests, and as a result some information may be recorded in the server log files, including the IP address of the computer from which the request came, the name of the User’s station – identification carried out by the http protocol, where possible – the system date and time of registration on the Platform and of the request’s arrival, the number of bytes sent by the server, the URL of the page the User previously visited if the User arrived through a link, information about the User’s browser, and information about errors that occurred while carrying out the http transaction. Logs may be collected as material for the proper administration of the Platform. Only persons authorised to administer the IT system have access to the information. Log files may be analysed in order to compile statistics on traffic on the Platform and on the errors that occur. A summary of such information does not identify the User.
  6. The Service Provider does not transfer personal data to third countries.