{"id":4993,"date":"2022-08-22T09:27:00","date_gmt":"2022-08-22T07:27:00","guid":{"rendered":"http:\/\/askhenry.pl\/polityka-prywatnosci\/"},"modified":"2022-08-19T15:32:56","modified_gmt":"2022-08-19T13:32:56","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/askhenry.pl\/en\/privacy-policy\/","title":{"rendered":"Privacy policy"},"content":{"rendered":"<p><span style=\"font-size: 14px;\">effective from August 23, 2022.<\/span><\/p>\n<p><span style=\"font-weight: 400; font-size: 14px;\">Henry limited liability company with its registered office in Warsaw at ul. Ho\u017ca 86\/410, entered into the Register of Entrepreneurs kept by the District Court for the Capital City of Warsaw, XII Commercial Division of the National Court Register under the KRS number: 564018, nip: 5213699794, REGON: 361824891, the owner of the askhenry.pl website and the entity providing the &#8220;Ask Henry&#8221; service, protects the privacy of people using its services\/Internet portal and their personal data.<\/span><\/p>\n<p><span style=\"font-weight: 400; font-size: 14px;\">In\u00a0order to implement the principle of\u00a0lawful, fair and\u00a0transparent processing of personal data when using the services of the askhenry.pl portal and\u00a0using the &#8220;Ask Henry&#8221; service, the Administrator has adopted this &#8220;Privacy Policy&#8221;, which\u00a0defines: the purposes and\u00a0scope of personal data processed, the manner of their protection, the legal basis for processing and the rights of data subjects.<\/span><\/p>\n<ol>\n<li><span style=\"font-size: 14px;\"><strong>Definitions<\/strong><\/span>\n<ol>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><strong>Administrator\u00a0<\/strong>\u2013 Henry Sp\u00f3\u0142ka z\u00a0ograniczon\u0105 odpowiedzialno\u015bci\u0105 with\u00a0its registered office in\u00a0Warsaw at ul.\u00a0Ho\u017ca 86\/410, entered into the\u00a0Register of Entrepreneurs kept by the District Court for the Capital City of Warsaw, 12th Commercial Division of the National Court Register, under\u00a0KRS number: 564018, nip: 5213699794, REGON: 361824891;<\/span><\/li>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><strong>Account<\/strong>\u00a0\u2013 an electronic service created and\u00a0provided by the\u00a0Administrator to the User as part of the Website, constituting the area of the User&#8217;s exclusive access in the ICT system provided by the\u00a0Administrator;<\/span><\/li>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><strong>Personal data<\/strong> \u2013 any information about an identifiable User or a Non-logged User, i.e. a person who can be directly or indirectly identified, in\u00a0particular, on the basis of an identifier such as name, identification number, location data, Internet identifier or one or more specific factors determining the physical, genetic, mental, economic, cultural or social identity of a natural person;<\/span><\/li>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><strong>Customers<\/strong>\u00a0\u2013 all entities cooperating with the\u00a0Administrator, its contractors, to whom the Administrator provides its services and\u00a0directly related marketing services;<\/span><\/li>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><strong>Service Providers<\/strong>\u00a0\u2013 all entities cooperating with the Administrator, its contractors, which provide the Administrator with their services and\u00a0directly related marketing services;<\/span><\/li>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><strong>Profile<\/strong>\u00a0\u2013 a collection of information about the User of a personal and\u00a0behavioural nature, collected by the Administrator, and\u00a0related to his\/her personal factors, in\u00a0particular his\/her personal preferences, behaviours, interests, location;<\/span><\/li>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><strong>Profiling<\/strong>\u00a0\u2013 any form of automated processing of personal data by the Administrator, which consists in using data collected in the Profile to\u00a0assess certain personal factors of a natural person, in\u00a0particular their analysis or forecasts of aspects regarding data collected within the Profile or\u00a0inference about the features and personal factors of Users other than those collected in the\u00a0Profile;<\/span><\/li>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><strong>Regulations\u00a0<\/strong>\u2013 regulations for the provision of services through the Website;<\/span><\/li>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><strong>The GDPR<\/strong> \u2013 the Regulation of the European Parliament and Council (EU) 2016\/679 of 27 April 2016 of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC<\/span><\/li>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><strong>Website<\/strong>\u00a0\u2013 a web portal owned\u00a0and\u00a0managed by the Administrator, within which the Administrator provides its services, located at: http:\/\/askhenry.pl;<\/span><\/li>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><strong>Settings<\/strong>\u00a0\u2013 a function of the Account, allowing the User using the Services to properly manage these services, including independently modifying their scope and choosing preferences regarding the scope and\u00a0purposes of processing their personal data;<\/span><\/li>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><strong>User<\/strong> \u2013 a person who\u00a0has an Account and\u00a0uses the\u00a0Services;<\/span><\/li>\n<li><span style=\"font-weight: 400; font-size: 14px;\"><span style=\"font-weight: 400;\"><strong>Services<\/strong>\u00a0\u2013 a set of services provided electronically by the Administrator, services provided on the basis of the &#8220;Ask Henry&#8221; service regulations located at http:\/\/askhenry.pl\/regulamin\/, as well\u00a0as direct marketing services.<\/span><\/span><\/li>\n<\/ol>\n<\/li>\n<li><span style=\"font-size: 14px;\"><strong>Controller of personal data<br \/>\n<\/strong>The Controller of personal data of\u00a0Users and\u00a0Users not logged in is the Administrator.In case of questions regarding the processing of data and the rights of Users and Non-logged Users, it is possible to contact the Administrator via e-mail, to the following address: info@askhenry.pl.Legal basis: information obligation art. 13 section 1 letter a of the GDPR.<\/span><\/li>\n<li><span style=\"font-size: 14px;\"><strong>Scope and\u00a0purposes of processing personal data of Users and\u00a0Non-logged Users<br \/>\n<\/strong>Due to the fact that the Administrator provides various services to Users, the Users&#8217; personal data are processed for various purposes, to different extent and\u00a0on\u00a0different legal basis specified in the\u00a0GDPR. In\u00a0order to ensure transparency of information, we grouped them through the\u00a0prism of data processing purposes.<\/span><\/p>\n<ol>\n<li><span style=\"font-size: 14px;\">Objective 1: Creating an Account, User&#8217;s access to\u00a0the Website, use of\u00a0Services provided by\u00a0ContractorsScope of\u00a0data:\u00a0For this purpose, the Administrator processes personal data provided by\u00a0Users in the registration form on the Website, i.e. e-mail address and\u00a0name, surname, telephone number, company (employer).Legal basis: necessity to\u00a0perform the contract for the\u00a0provision of Services to\u00a0the User (art. 6 item 1 letter b of the GDPR), consent of the data subject (art.6 it.1 let. A of GDPR)<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Objective 2: Use of the\u00a0ServicesTypes of Services:\u00a0The Administrator processes Users&#8217; personal data in\u00a0order to provide Users with its services and\u00a0enable the use of\u00a0Services provided by\u00a0Contractors on the\u00a0basis of User&#8217;s Orders provided by the\u00a0Administrator.Scope of data:\u00a0The Controller processes the following personal data of Users for the above purpose: name and\u00a0surname, e-mail address, telephone number, correspondence address (street, house number, postal code, city), user&#8217;s address, if different from the correspondence address, content of the order given by the User or other data resulting from the specificity of the service ordered by the User on the basis of the regulations located at http:\/\/askhenry.pl\/regulamin\/Legal basis:\u00a0necessity to\u00a0perform a\u00a0distance contract through the Website (art. 6 item 1 letter b) of the GDPR).<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Objective 3: Statistics on the use of\u00a0particular functions and\u00a0parts of the Website, popularity of products\/services\u00a0and\u00a0facilitating the use of the\u00a0WebsiteScope of data: For\u00a0these purposes, personal data is processed by the Administrator regarding the activity of Users on the\u00a0Website, such as: pages and\u00a0subpages of the Website visited and the amount of time spent on\u00a0each of them, as well as data on the search history, IP address, location, device ID and\u00a0data on the browser and operating system.Legal basis:\u00a0 legitimate interest of the Administrator (art. 6 item 1 let. f GDPR), consisting in improving the functionality of the Website and\u00a0facilitating access to the\u00a0Account<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Objective 4: Establishment, recovery and\u00a0enforcement of claimsScope of data: For\u00a0this purpose, the Administrator may process certain personal data provided under the Account or placing an order, such as: name, surname, address, data on the use of the Services, other data necessary to\u00a0prove the existence of a claim, including the size of the damage suffered.Legal basis: legitimate interest of the administrator ( art. 6 item 1 (f) of the GDPR), consisting in establishing, pursuing and\u00a0enforcing claims and defending against\u00a0claims in\u00a0proceedings before\u00a0courts and\u00a0other state authorities.<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Objective 5: Consideration of complaints and\u00a0requests, answers to\u00a0questionsScope of data:\u00a0 For\u00a0this purpose, the Administrator processes personal data provided by the User within the Account, i.e.\u00a0name and\u00a0surname, e-mail address and\u00a0type of services used by the User, as well as data regarding the use of the Services being the cause of the complaint or request, data contained in\u00a0documents attached to the complaint or request.Legal basis:\u00a0 the necessity of processing to\u00a0fulfill the legal obligation incumbent on the\u00a0Administrator (art. 6 item 1 letter c of the GDPR) and the\u00a0legitimate interest of the Administrator (art. 6 item 1 (f) of the GDPR), consisting in\u00a0improving the functioning of the Services and building positive relations with\u00a0Users.<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Objective 6: Recommended product\/service offeringsType of services:\u00a0 Recommended product offers are\u00a0special, individual offers addressed to\u00a0Users on the\u00a0basis of their activity on the\u00a0Website. Recommended offers are presented:- on the Website; or<\/span><br \/>\n<span style=\"font-size: 14px;\">&#8211; by sending them to the User&#8217;s e-mail address.Scope of data:\u00a0 For\u00a0this purpose, the Administrator processes personal data provided as part of the Account and\u00a0aggregated as part of the Profile, including data on the User&#8217;s activity on the Website, recorded and\u00a0stored through cookies, in\u00a0particular information about\u00a0visited subpages and\u00a0unfinished orders.<\/span><span style=\"font-size: 14px;\">Profiling:\u00a0 The above data is used to\u00a0create a User Profile, corresponding to the User&#8217;s personal preferences and\u00a0interests. On\u00a0the basis of these data, the Administrator may assess, analyze and\u00a0forecast other personal factors relating to\u00a0Users and supplement the Profile with\u00a0additional data on\u00a0their basis. Then, on the\u00a0basis of the Profile created in this way, specific offers, promotions and commercial information addressed to\u00a0specific Users are selected.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">Legal basis:\u00a0 legitimate interest of the Administrator (art. 6 item 1 (f) of the GDPR), consisting in direct marketing of the Administrator&#8217;s services or products.<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Objective 7: Marketing and\u00a0remarketingType of Services:\u00a0The Administrator processes personal data of Users and for the\u00a0purpose of direct marketing of services or own products, as well as performing Profiling, in order to best match the products or services offered to Users to\u00a0their current needs and\u00a0predict their behavior or purchase preferences.Scope of data:\u00a0For\u00a0this purpose, the Administrator processes personal data provided within the Account, i.e.\u00a0name and\u00a0surname, e-mail address (in\u00a0cases where consent has been granted for the use of telecommunications terminal equipment for direct marketing via electronic means of communication), and\u00a0collected in the Profile, regarding the User&#8217;s activity on the Website, recorded and\u00a0stored through cookies (also in\u00a0relation to not logged in Users), in\u00a0particular the history of the websites visited, personal preferences, behaviours, interests, search history, order history, clicks on the Website, login and\u00a0registration dates, data on the display and\u00a0use of specific services\/products on the\u00a0Website, activity related to communication with the Administrator.Profiling:\u00a0 The above data is used to\u00a0create a User Profile, corresponding to the User&#8217;s personal preferences and\u00a0interests. On\u00a0the basis of these data, the Administrator may assess, analyze and\u00a0forecast other personal factors relating to\u00a0Users and supplement the Profile with\u00a0additional data on\u00a0their basis. Then, on the\u00a0basis of the Profile created in this way, specific offers, promotions and commercial information addressed to\u00a0specific Users are selected.<\/span><span style=\"font-size: 14px;\">Remarketing:\u00a0In\u00a0order to reach Users and\u00a0Users not logged in with the Administrator&#8217;s marketing messages outside the Sites, the Administrator uses the\u00a0services of external providers. These services consist in displaying the Administrator&#8217;s marketing messages, including commercial information, on pages other than the Website. For\u00a0this purpose, external suppliers (including\u00a0Google, Facebook) install, for example, an appropriate code or pixel to retrieve information about the activity of Users or Users not logged in to the\u00a0Website. This information concerns the activities of Users or Users not logged in to the\u00a0Website, in\u00a0particular the history of the websites visited.<\/span>\n<p><span style=\"font-size: 14px;\">Legal basis:\u00a0consent of the\u00a0data subject (art. 6 item 1 letter a of GDPR and art. 22 it. 2 letter c of the GDPR) and the\u00a0legitimate interest of the Administrator (art. 6 item 1 (f) of the GDPR), consisting in direct marketing of the Administrator&#8217;s services or products.<\/span><\/li>\n<\/ol>\n<\/li>\n<li><span style=\"font-size: 14px;\"><strong>Obligation to provide personal data and consequences of not providing them<br \/>\n<\/strong>Providing some personal data is a condition for using the\u00a0Services or concluding a\u00a0distance contract with the\u00a0Administrator (mandatory data). Mandatory data are marked on the\u00a0Website. The consequence of not providing these data is the\u00a0User&#8217;s inability to use the\u00a0Services. In addition to data marked as mandatory, providing other personal data is voluntary.In\u00a0the scope of personal data, which are collected automatically, their provision is also voluntary, and the expression of such will on the part of the User or the Non-logged User is the appropriate set of settings of the web browser from\u00a0which the connection to the Website takes place.<\/span><\/li>\n<li><span style=\"font-size: 14px;\"><strong>Procedures for automated decision-making and profiling<br \/>\n<\/strong>The Administrator shall make all reasonable efforts to match the offer of its own products and\u00a0any marketing messages addressed to\u00a0Users to\u00a0their interests and\u00a0preferences. For\u00a0this purpose, it carries out automated processing of personal data, which may also take the form of Profiling.The Administrator also points out that targeting and\u00a0personalization of the Administrator&#8217;s marketing communication, in\u00a0particular offers and commercial information, based on the collected behavioral data (related to the User&#8217;s behavior and activity on the Website, in\u00a0particular the history of the visited subpages), unless\u00a0it is the result of inference about\u00a0other features and personal factors of the User on the basis of data collected in the Profile, does not\u00a0constitute Profiling.The above actions and making decisions are automated processing of personal data \u2013 and occur in a situation where a specific act or omission of the User on the Website causes him to see a specific commercial message \u2013 identical for all Users who behaved similarly. Such a message is not directed to the User on the basis of an assumption made in an automated manner by the Administrator and in connection with specific information provided by the User.<\/span><span style=\"font-size: 14px;\">After considering the interests of the Administrator and the interests, rights and\u00a0freedoms of Users, the Administrator decided that\u00a0presenting content to Users in\u00a0connection with\u00a0automated decision-making, including on the basis of profiling, will not unduly interfere with the\u00a0privacy of Users or constitute an undue nuisance to them. In weighing up interests, rights and\u00a0freedoms, account shall be taken in\u00a0particular of the following:<\/span><\/p>\n<ol>\n<li><span style=\"font-size: 14px;\">thanks to profiling, the Administrator provides Users with easier access to the desired products\/services, compared to traditional tools, based on independent searching of the Website&#8217;s resources;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">sending marketing messages to the e-mail address is in accordance with the reasonable expectations of Users who have expressed their willingness to receive such messages in e-mail messages in accordance with applicable regulations (in particular the Act on the provision of electronic services and the Telecommunications Law);<\/span><\/li>\n<li><span style=\"font-size: 14px;\">The profile is created on the basis of data provided by Users and data resulting from their activity on the Services. The Profile is used to personalize recommended offers, while maintaining appropriate guarantees for the protection of Users&#8217; privacy, in particular, the Profile collects data provided by Users and behavioural data related only to Users&#8217; activity on the Website, and not sensitive data regarding private life or activity on other websites;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">as part of creating the Profile, the Administrator does not request the effects of the User&#8217;s work, economic situation or health;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">decisions based on automated processing, including Profiling, do not significantly affect the legal situation of Users;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Users can easily withdraw their consent to receive commercial information and process their personal data from Settings.<\/span><\/li>\n<li><span style=\"font-size: 14px;\">The above allows to assume that automated processing of personal data and making decisions, including profiling, does not pose a significant threat to the rights and freedoms of Users, does not have significant legal effects against them and is not unduly burdensome, and consequently \u2013 there are no premises preventing the Administrator&#8217;s interests from being granted overriding character.The consequences of automated processing of Users&#8217; personal data will only be the diversity of marketing messages addressed to them, depending on their activity on the Website. In connection with the above, it is possible to make certain commercial discounts available only to a limited group of Users who have met certain conditions. As a consequence, some discounts and promotions will be unavailable to other Users.In\u00a0connection with the\u00a0above, the Users have additional rights, described in detail in\u00a0point 9.<\/span><\/li>\n<\/ol>\n<\/li>\n<li><span style=\"font-size: 14px;\"><strong>Processing of personal data of children<br \/>\n<\/strong>In order to use the\u00a0Services, you must be at least 16 years of age or have parental consent or custody of your child. The Controller does not knowingly collect personal data from\u00a0children under the age of 16 without the consent of their parent or guardian.<\/span><\/li>\n<li><span style=\"font-size: 14px;\"><strong>Data Recipients<br \/>\n<\/strong>Personal data of Users may be shared by the\u00a0Administrator with other entities. Depending\u00a0on the circumstances, these entities may be subject to the Controller&#8217;s instructions as to the purposes and\u00a0methods of processing these data (processors) or\u00a0independently determine the purposes and\u00a0methods of processing the Users&#8217; personal data (administrators). The Administrator makes the User&#8217;s personal data available to the following categories of recipients:<\/span><\/p>\n<ol>\n<li><span style=\"font-size: 14px;\"><strong>Service Providers<br \/>\n<\/strong>Personal data of Users may be made available to entities that provide services to the Administrator supporting its activities, e.g.\u00a0suppliers of marketing tools, accounting, legal advisors.Processing entitiesThe Administrator uses the\u00a0services of entities that process personal data of Users only on\u00a0its behalf. These are, among others, entities providing hosting services, cloud storage space, providing marketing systems (e.g.\u00a0for\u00a0sending newsletters and\u00a0other e-mails), for\u00a0analyzing traffic on the\u00a0Website, for\u00a0analyzing the effectiveness of marketing campaigns, etc.<\/span><span style=\"font-size: 14px;\">Currently, the Controller cooperates with\u00a0the following Service Providers, who are entities processing personal data:<\/span><\/p>\n<ol>\n<li><span style=\"font-size: 14px;\">Freshworks Inc.\u00a0 2950 S.Delaware Street, Suite 201. San Mateo, CA 94403, USA. Supplier of CRM (freshdesk.com) available at askhenry.freshdesk.com.<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Click Labs Inc. Suite 600, Tampa, Florida, 33609, USA.<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Tookan Order Processing Application Provider, available at tookanapp.com.<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Mailgun Technologies, Inc. 112 E Pecan St. #1135, San Antonio, TX 78205 &#8211; provider of the Mailgun service (mailgun.com), intended for sending notifications in the form of an e-mail.<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Piprdrive O\u00dc, Mustam\u00e4e tee 3a Tallinn 10615 Estonia &#8211; provider of the CRM Pipedrive solution (pipedrive.com) for contact management.<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Freshmail (freshmail.com), FreshMail Sp. z o.o., Al. 29 Listopada 155c, 31-406 Krak\u00f3w &#8211; provider of sending e-mails for marketing purposes.Currently, the Administrator also uses the\u00a0services of entities that do not\u00a0act solely on\u00a0his behalf and determine the purposes and\u00a0methods of using the Users&#8217; personal data. These are\u00a0entities providing payment services and\u00a0mainly remarketing campaign services and\u00a0conducting statistical surveys.Currently, the Administrator cooperates with\u00a0the following categories of users&#8217; data recipients, who are personal data administrators:<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Google LLC, 1600 Amphiteatre Parkway, Mountain View, California 94043, United States;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Facebook, Inc 1601 Willow Road Menlo Park, California 94025, USA.Contractor of services commissioned by the\u00a0User through the Website.Location: Our suppliers are based mainly in Poland and other countries of the European Economic Area (EEA). However, some of the Service Providers may be established outside the EEA. In connection with the transfer of personal data outside the EEA, the Administrator ensured that service providers provide guarantees of a high level of protection of personal data. These guarantees result from the use in the contracts for entrusting the processing of so-called standard contractual clauses concluded with the Service Providers specified in the Commission Decision of 5 February 2010 on standard contractual clauses for the transfer of personal data to data processors established in third countries under Directive 95\/46\/EC of the European Parliament and of the Council (2010\/87\/EU).<\/span><\/li>\n<\/ol>\n<\/li>\n<li><span style=\"font-size: 14px;\"><strong>State authorities<br \/>\n<\/strong>Personal data are also made available when\u00a0requested by authorized state authorities, in\u00a0particular organizational units of the prosecutor&#8217;s office, the Police or the supervisory authority in the\u00a0field of personal data protection (PUODO).<\/span><\/li>\n<\/ol>\n<\/li>\n<li><span style=\"font-size: 14px;\"><strong>Data storage period<br \/>\n<\/strong>Personal data of Users are stored by the Administrator for the entire period of holding an Account on the Website in order to provide the Services, as well as for marketing purposes. After deleting the Account, the Users&#8217; data is anonymized or pseudonymized, except for the following data: order history. After 5 years from anonymization or pseudonymization, all data is deleted.Personal data of not logged-in Users are stored for a period corresponding to the validity of cookies stored on their devices.<\/span><\/li>\n<li><span style=\"font-size: 14px;\"><strong>Rights of data subjects<br \/>\n<\/strong>The Administrator ensures the exercise of the following rights to Users and Non-logged Users by contacting\u00a0him in\u00a0one of the ways indicated in\u00a0point 2. In addition, some of the\u00a0permissions can be implemented by changing the Settings accordingly. All rights described below with respect to\u00a0Users are also vested in Non-logged Users.<\/span><\/li>\n<li><span style=\"font-size: 14px;\"><strong>Right to withdraw your consent<br \/>\n<\/strong>The User has the right to\u00a0withdraw any consent that he\/she gave at the\u00a0time of registration to the Website, as well as when using the\u00a0Services and Account functions. Withdrawal of consent shall take effect from the moment of withdrawal of consent. Withdrawal of consent does not\u00a0affect the\u00a0processing carried out by the\u00a0Administrator in accordance with the\u00a0law before\u00a0its withdrawal.Withdrawal of consent does not\u00a0entail any negative consequences. However, it may prevent you from continuing to use the\u00a0Services. The withdrawal of consent\u00a0does not affect the\u00a0processing that takes place on a basis other than the consent of the data subject, for\u00a0example in\u00a0order to perform the contract between the Administrator and the User.<\/span><span style=\"font-size: 14px;\">Legal basis: Article 7 it. 3 of GDPR.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">Right to object to the use of data<\/span><\/p>\n<p><span style=\"font-size: 14px;\">The User has the right to object at\u00a0any time to the processing of his\/her personal data, including automated processing, and\u00a0in\u00a0particular Profiling, if the processing of data takes place on the\u00a0basis of the legitimate interest of the Administrator.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">Notwithstanding\u00a0the foregoing, the data subject shall have the right to object at\u00a0any time to the processing of personal data relating to him or her for the purposes of direct marketing, including Profiling, to the\u00a0extent that the processing is related to such direct marketing.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">Resignation from\u00a0receiving recommended offers in the form of an e-mail, as well as resignation from\u00a0receiving commercial information regarding the Administrator&#8217;s products or services, is treated as an objection to the processing of personal data, including Profiling for marketing purposes and\u00a0guarantees the cessation of their further processing for this purpose.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">If the Administrator is unable to demonstrate another legal basis for the processing of personal data of the User who\u00a0has raised an objection, superior to the interests, rights and\u00a0freedoms of the User or the grounds for\u00a0establishing, pursuing or defending claims, it will immediately delete the personal data of such User.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">Legal basis: Article 21 of the GDPR<\/span><\/p>\n<p><span style=\"font-size: 14px;\">Right to delete (\u2018right to be forgotten\u2019)<\/span><\/p>\n<p><span style=\"font-size: 14px;\">The user has the right to request deletion of all or some personal data A request to delete all personal data will be treated as a request to delete the Account.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">The above right is granted if at least one of the following circumstances occurs:<\/span><\/p>\n<ol>\n<li><span style=\"font-size: 14px;\">the personal data is no longer necessary in relation to the purposes for which they were collected or otherwise processed;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">The User has withdrawn the consent on which the processing was based and the Administrator has no other legal basis for the processing;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">The User has objected to the processing and there are no overriding legitimate grounds for the processing or the User has objected to the processing of data for direct marketing purposes;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">the personal data has been unlawfully processed;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">personal data must be deleted in\u00a0order to comply with a legal obligation provided for by the applicable law;Despite the request to delete personal data, in connection with raising objections or withdrawing consent, we may retain certain personal data to the extent necessary to establish, investigate or defend claims. This applies in particular to personal data including name, surname, e-mail address and order history, which are kept for the purposes of dealing with complaints and claims related to the use of the Services.Legal basis: Article 17 of the GDPR<\/span><span style=\"font-size: 14px;\">Right to restrict data processing<\/span>\n<p><span style=\"font-size: 14px;\">The User has the right to request the restriction of the processing of their personal data (Article This entitlement shall be granted if one or more of the following conditions apply:<\/span><\/p>\n<ol>\n<li><span style=\"font-size: 14px;\">The User questions the correctness of personal data \u2013 the limitation is made for a period allowing the Administrator to check the correctness of these data;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">The Controller no longer needs personal data for the purposes of processing, but they are needed by the User to determine, assert or defend claims;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">The User has raised an objection to the processing of personal data \u2013 the restriction is made until it is established whether the legally justified grounds on the part of the<\/span><\/li>\n<li><span style=\"font-size: 14px;\">Administrator are superior to the grounds for the objection of the data subject.Legal basis: Article 18 of the GDPRRight to access data<\/span><\/li>\n<\/ol>\n<\/li>\n<li><span style=\"font-size: 14px;\">Everyone has the right to obtain from\u00a0the Controller confirmation whether\u00a0we process personal data of a specific person,\u00a0 and\u00a0if this is the case, this person has the right to:<\/span>\n<ol>\n<li><span style=\"font-size: 14px;\">access your personal data,<\/span><\/li>\n<li><span style=\"font-size: 14px;\">obtain information about the purposes of processing, categories of personal data processed, recipients or categories of recipients of such data, the planned period of storage of personal data or the criteria for determining this period, about the rights it has under the GDPR and about the right to lodge a complaint to the supervisory authority, about the source of such data, about automated decision-making, including Profiling and about the safeguards applied in connection with the transfer of such data to a third country;<\/span><\/li>\n<li><span style=\"font-size: 14px;\">acquire a copy of their personal data.<\/span><br \/>\n<span style=\"font-size: 14px;\">Legal basis: Article 15 of GDPRRight to rectification<\/span><span style=\"font-size: 14px;\">The User has the right to\u00a0rectify and\u00a0complete the personal data provided by\u00a0them. This right can be exercised from the Account by independently changing the Settings and\u00a0verifying the scope of data entered within\u00a0the Account.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">With\u00a0regard to personal data unavailable from the Account, the User has the right to request the Administrator to rectify these data (if they are incorrect) and to complete them (if they are incomplete).<\/span><\/p>\n<p><span style=\"font-size: 14px;\">Legal basis: Article 16 of the GDPR<\/span><\/p>\n<p><span style=\"font-size: 14px;\">The right to data portability<\/span><\/p>\n<p><span style=\"font-size: 14px;\">The User has the right to receive their personal data, which the User provided to the Controller, and then send it to another personal data controller of their choice (Article<\/span><\/p>\n<p><span style=\"font-size: 14px;\">The User also has the right to request that personal data be sent by the Administrator directly to such other administrator, if technically possible.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">The administrator sends the data in the form of\u00a0an XML or CSV file. This format is a commonly used machine-readable format that allows you to transfer the received data to\u00a0another personal data controller.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">Legal basis: Article 20 of GDPR;<\/span><\/p>\n<p><span style=\"font-size: 14px;\">The right to\u00a0obtain human intervention on the\u00a0part of the Administrator<\/span><\/p>\n<p><span style=\"font-size: 14px;\">In\u00a0each case in\u00a0which automated processing of personal data takes place (automated decision making, including profiling), the User has the right to\u00a0question the decision made in an automated manner, to express his opinion on the\u00a0decision taken and\u00a0to\u00a0demand human intervention on the part of\u00a0the Administrator. Human intervention is carried out by reassessing the features, factors and\u00a0premises that were taken into account when the automated decision was made by a person authorized by the Administrator and\u00a0issuing a decision other than the previous one or maintaining it. In the case of Profiling, the Administrator should omit the features and personal factors that were derived from the data collected in the Profile, and the decision related to human intervention should be made on the basis of the database collected in the Profile, which is not a form of assessment, analysis or forecast of data provided by the\u00a0User.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">The above right does not\u00a0apply in the\u00a0event that such a decision does not have any legal effects on the User or the impact on\u00a0his\/her situation is negligible.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">However, if a decision taken in\u00a0an automated manner: (i) is not necessary for the conclusion or performance of a contract between the User and the Controller; (ii) is not permitted by Union law or the law of the Member State to which the Controller is subject and\u00a0which provides for appropriate measures to protect the rights, freedoms and\u00a0legitimate interests of the data subject; and\u00a0(iii) is not\u00a0based on the explicit consent of the data subject, the right of the User not to be fully subject to decisions taken solely by automated means is an expression of the above right. In the event of a request to exercise this right, the Administrator shall take all reasonable measures to ensure that the decision-making process does not\u00a0remain solely automated, i.e.\u00a0to ensure the presence of the human factor in at least one of\u00a0its stages.<\/span><\/p>\n<p><span style=\"font-size: 14px;\">Legal basis: art. 22 of the GDPR;<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<li><span style=\"font-size: 14px;\"><strong>Response Time<br \/>\n<\/strong>If the User, using the\u00a0rights described in\u00a0point 9, makes an appropriate request to the Administrator, the Administrator shall immediately consider this\u00a0request positively or negatively, but not\u00a0later than within one month after receiving it. However, if, due to the\u00a0complicated nature of the request or the number of requests, it is impossible to meet the monthly deadline, the Administrator will fulfill the obligation to consider the request within the next two months, after\u00a0informing the User about\u00a0the circumstances.<\/span><\/li>\n<li><span style=\"font-size: 14px;\"><strong>Complaints and applications<br \/>\n<\/strong>The Administrator encourages to\u00a0ask questions and\u00a0submit applications regarding the processing of Users&#8217; personal data and\u00a0the exercise of their rights.Each person has the right to lodge a complaint with the supervisory authority in the field of personal data protection (PUODO) if they believe that\u00a0their right to the protection of personal data or other rights granted to them under the GDPR have been violated by the\u00a0Administrator.<\/span><\/li>\n<li><span style=\"font-size: 14px;\"><strong>Security of personal data<br \/>\n<\/strong>The Administrator and the entities with\u00a0which it cooperates, make every effort to ensure the security of personal data processed on the Website, including\u00a0 through the use of encrypted data transmission (SSL) during registration and\u00a0login, which ensures the protection of the credentials entered and\u00a0significantly hinders the interception of access to the Account by\u00a0unauthorized systems or persons.<\/span><\/li>\n<li><span style=\"font-size: 14px;\"><strong>Amendments to Privacy Policy<br \/>\n<\/strong>According to the\u00a0needs of the Administrator, we may change and\u00a0update the Privacy Policy. Users will be informed about\u00a0any changes or additions by posting relevant information on the homepage of the Website or by e-mail sent to\u00a0Users.<\/span><\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>effective from August 23, 2022. Henry limited liability company with its registered office in Warsaw at ul. Ho\u017ca 86\/410, entered&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"content-type":"","footnotes":""},"class_list":["post-4993","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/askhenry.pl\/en\/wp-json\/wp\/v2\/pages\/4993","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/askhenry.pl\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/askhenry.pl\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/askhenry.pl\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/askhenry.pl\/en\/wp-json\/wp\/v2\/comments?post=4993"}],"version-history":[{"count":7,"href":"https:\/\/askhenry.pl\/en\/wp-json\/wp\/v2\/pages\/4993\/revisions"}],"predecessor-version":[{"id":5149,"href":"https:\/\/askhenry.pl\/en\/wp-json\/wp\/v2\/pages\/4993\/revisions\/5149"}],"wp:attachment":[{"href":"https:\/\/askhenry.pl\/en\/wp-json\/wp\/v2\/media?parent=4993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}