Privacy policy
This is a courtesy translation. The Polish version is the legally binding text.
Privacy policy and information on how the personal data of website users is protected
Article 1. Controller
- The controller of personal data is Good One sp. z o.o., with its registered office in Wrocław, ul. Januszowicka 5/121; 53-135 Wrocław, NIP (tax ID): 525-28721-79; KRS: 0000914751
- (the “Controller”), which attaches great importance to protecting the privacy and confidentiality of the personal data of its Clients and of other natural persons whose data the Controller processes (the “Users”).
- The Controller can be contacted in writing, by sending correspondence to the Controller’s registered office, by email at kontakt@goodone.co, or by filling in the contact form available on the Controller’s website.
- The Controller has not appointed a Data Protection Officer.
Article 2. Principles of processing personal data
- The Controller processes personal data to the minimum extent necessary to achieve the purposes of processing, which are clearly set out in this Privacy Policy.
- The Controller selects and applies, with due care, appropriate technical and organisational measures to protect the personal data processed. Only persons duly authorised by the Controller have full access to the databases.
- The Controller secures personal data against disclosure to unauthorised persons, and against processing in breach of applicable law. In processing personal data, the Controller applies solutions suited to the scale and nature of the processing, giving data subjects the highest level of protection arising from both the technological and the organisational solutions applied.
- The following personal data will be processed: first name and surname, email address, telephone number.
Article 3. Legal basis for processing personal data
- Personal data provided by the User is processed in accordance with this Privacy Policy and applicable law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “GDPR”).
- Providing personal data is voluntary; however, failure to provide it will make it impossible to conclude and perform an agreement, send an enquiry or carry out the requested actions.
- The legal basis for processing personal data is:
- Art. 6(1)(a) GDPR – for personal data obtained by consent, on the conditions set out in Art. 7 GDPR;
- Art. 6(1)(b) GDPR – for data provided voluntarily in order to answer any enquiries or requests sent, and to conduct further correspondence or contact before an agreement is concluded, as well as to prepare and perform the Agreement between the User and the Controller or an entity the Controller commissions to perform the Agreement.
Providing the data is voluntary, but necessary to perform the Agreement or to correspond with the Controller.
- Art. 6(1)(f) GDPR – for data processed in connection with pursuing the Controller’s legitimate purposes.
- The Controller may process the data of third parties made available by Users for the purpose of, or in connection with, the Controller’s provision of services. By providing the Controller with the data of third parties, the User declares in each case that they have the appropriate consent of those third parties to pass their data to the Controller.
- If the personal data referred to in this Privacy Policy changes, the User will inform the Controller without delay so that the personal data can be updated.
- The Controller does not apply profiling to Users within the meaning of Art. 4(4) GDPR.
Article 4. Period of processing personal data
The User’s data will be stored for no longer than necessary, i.e.:
- for correspondence – personal data will be stored for the period necessary to handle the enquiry, i.e. the duration of the correspondence justified by the type of enquiry (but no longer than 6 months from the date the correspondence ends).
- for the performance of an agreement – until the agreement has been fully performed, and after that for the period required by law or for pursuing any claims that the Controller may raise or that may be raised against the Controller;
- for compliance with a legal obligation to which the Controller is subject – until it has been fulfilled;
- for pursuing the legitimate interests of the Controller or of a third party – until they have been achieved, or until the User objects to the processing of personal data, unless there are legitimate grounds for further processing;
- for processing based solely on consent – until the data is promptly erased at the User’s request.
Article 5. The User’s rights
- In connection with the Controller’s processing of personal data, the User has the right to:
- request access to personal data – Art. 15;
On the User’s request for access to their data, the Controller informs the User whether it processes their data, informs the User of the details of the processing in accordance with the GDPR, and gives the User access to the data concerning them. Access to the data will be provided by sending a copy of the data electronically. If a further copy of the data is requested on paper, the Controller has the right to charge the User the costs of preparing it in that form and sending it, in accordance with Art. 15(3) GDPR.
- the right to rectification of personal data – Art. 16 GDPR;
The Controller rectifies inaccurate data at the User’s request.
- the right to request erasure of personal data – Art. 17 GDPR;
This right applies to the extent that erasure of the data does not conflict with the provisions binding on the Controller,
- the right to restriction of processing – Art. 18 GDPR;
This right applies to the extent that the Controller can restrict the processing of personal data in the light of the provisions binding on it, and to the extent that this does not infringe the Controller’s right to pursue its claims against the User.
- data portability – Art. 20 GDPR;
At the User’s request, the Controller provides in a structured, commonly used and machine-readable format, or transmits to another entity where possible, the data concerning the User that the User provided in order to conclude or perform the Agreement, or that is processed on the basis of consent.
- object to processing – Art. 21 GDPR;
If the User objects to the processing of their data on grounds relating to their particular situation, and the data is processed by the Controller on the basis of the Controller’s legitimate interest, the Controller will uphold the objection unless the Controller has compelling legitimate grounds for the processing which override the interests, rights and freedoms of the person objecting, or grounds for the establishment, exercise or defence of legal claims.
- withdraw consent to data processing, without affecting the lawfulness of processing based on consent before its withdrawal – Art. 7(3) GDPR;
- lodge a complaint with a supervisory authority – Art. 77 GDPR.
- If the Controller is unable to determine the content of the request, or to identify the person exercising the above rights on the basis of the request made, it will ask the requester for additional information.
- A request will be answered within one month of its receipt at the latest. If that period has to be extended, the Controller will inform the requester of the reasons for the extension.
Article 6. Disclosure of personal data
- Personal data will be disclosed only to authorised entities, i.e. authorised employees of the Controller and other persons acting on the Controller’s authority, other entities authorised to receive the User’s data under the relevant provisions of law, and entities providing IT services to the Controller. Users’ personal data may be passed to other entities – in cases not indicated by the Controller or by law – only with the User’s consent.
- The Controller undertakes not to transfer Users’ personal data to third countries or international organisations.
- The Controller will oblige every entity to which it entrusts the User’s personal data to implement appropriate safeguards for that data.
Article 7. Cookies
- The website www.osiedle-rozalin.pl (the “Website”) uses computer data stored on the end devices of the Website’s users, in particular text files containing, among other things, the name of the website they come from, how long they are stored on the end device, and a unique number (“Cookies”).
- Pursuant to Art. 173(1) of the Telecommunications Law Act of 16 July 2004 (Journal of Laws of 2021, item 576), the Controller hereby informs that:
- Cookies are used on the Website to make the Website easier to use; they allow the content available on the Website to be adapted to the individual needs and preferences of the Website’s users, and are also used to compile general statistics on the use of the Website.
- personal data collected using Cookies is collected solely in order to perform specific functions for users, and is encrypted in a way that prevents unauthorised persons from accessing it.
- a user of the Website can consent to the use of Cookies by making the appropriate settings in their web browser (in particular, allowing or blocking the use of “cookies”).
- a user of the Website can change the Cookie settings at any time – detailed information on the options for, and ways of, handling Cookies is available in the software (web browser) settings. Examples of how to edit the settings in popular browsers:
- Mozilla FireFox: https://support.mozilla.org/pl/kb/ciasteczka
- Internet Explorer: http://www.support.microsoft.com/kb/278835/pl
- Edge: https://privacy.microsoft.com/pl-pl/windows-10-microsoft-edge-and-privacy
- Google Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=pl
- Opera: https://help.opera.com/pl/latest/web-preferences/#cookies.
Cookie policy
- For the Platform to work properly, the Service Provider uses Cookie technology. Cookies are packets of information saved on the User’s device through the Platform, usually containing information in line with the purpose of the given file, through which the User uses the Platform – typically: the address of the website, the date they were placed, their expiry date, a unique number and additional information in line with the purpose of the given file.
- The Service Provider uses two types of Cookies: session Cookies, which are permanently deleted when the User’s browser session ends, and persistent Cookies, which remain on the User’s device after the browser session ends, until they are deleted.
- Neither session nor persistent Cookies make it possible to establish the User’s identity. The Cookie mechanism does not allow any personal data to be collected. may be read by an external server. The use of External Cookies is based on the provisions of the Regulation concerning the respect for private life and the protection of personal data in electronic communications (the e-Privacy Regulation).
- The Platform’s Cookies are safe for the User’s device; in particular, they do not allow viruses or other software to reach the device.
- Files generated directly by the Platform cannot be read by other websites. External Cookies (i.e. Cookies placed by the Service Provider’s partners) may be read by an external server. The User may consent to the use of External Cookies by changing the External Cookie settings themselves at any time, specifying the conditions for storing them, through the web browser settings or by configuring the service – choosing the opt-out option in the browser settings.
- The User may enable the saving of External Cookies on their device in accordance
with the browser manufacturer’s instructions. Not enabling External Cookies will not make any or all of the Website’s functions unavailable to the User. - The User may enable the saving of Cookies on their device in accordance with the browser manufacturer’s instructions.
- The Service Provider uses its own Cookies for the following purposes: authenticating the User on the Platform and maintaining the User’s session; configuring the Platform and adapting the content of pages to the User’s preferences, such as recognising the User’s device and remembering the settings the User has chosen; ensuring the security of data and of the use of the Platform; audience analysis and research; and providing advertising services with the User’s consent, given in accordance with the rules set out in point 5.
- The Service Provider uses External Cookies for the following purposes: compiling (anonymous) statistics that help optimise the usability of the Platform, through analytics tools such as Google Analytics; using interactive functions through social networking sites: plus.google.com, instagram.com, facebook.com.
- The User may change the Cookie settings themselves at any time, specifying the conditions for storing them, through the web browser settings or by configuring the service. The User may also delete the Cookies saved on their device themselves
at any time, in accordance with the browser manufacturer’s instructions. - Detailed information about handling Cookies is available in the settings of the web browser the User uses. With any questions or concerns about personal data protection and privacy, the User should contact the Service Provider at this address: kontakt@folks.pl








