Privacy Policy

This Privacy Policy sets out the rules for storing and accessing data on Users’ Devices who use the Website for the purpose of receiving electronic services from the Controller, as well as the rules for collecting and processing Users’ personal data, which they have provided personally and voluntarily through the tools available on the Website.

§1 Definitions

  • Website – the “Alit Sp. z o.o.” website available at alit.com.pl
  • External Website – websites of partners, service providers or customers cooperating with the Controller
  • Website / Data Controller – the Website operator and Data Controller (hereinafter the “Controller”) is ALIT Sp. z o.o., operating at ul. Ofiar Dąbia 2B, 31-556 Kraków, Tax Identification Number (NIP): 6761015679, National Court Register Number (KRS): 0000152039, which provides electronic services through the Website
  • User – a natural person to whom the Controller provides electronic services through the Website.
  • Device – an electronic device together with its software through which the User accesses the Website
  • Cookies – text data stored as files on the User’s Device
  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
  • Personal Data – means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or to one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity
  • Processing – means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
  • Restriction of Processing – means marking stored personal data with the aim of limiting its processing in the future
  • Profiling – means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements
  • Consent – consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which, by a statement or by a clear affirmative action, the data subject signifies agreement to the processing of personal data relating to them
  • Personal Data Breach – means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to personal data transmitted, stored or otherwise processed
  • Pseudonymization – means processing personal data in such a manner that it can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures ensuring that the personal data is not attributed to an identified or identifiable natural person
  • Anonymization – data anonymization is an irreversible process that destroys or overwrites personal data so that a record can no longer be identified or linked to a specific user or natural person.

§2 Data Protection Officer

Pursuant to Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer.

For matters concerning data processing, including personal data, please contact the Controller directly.

§3 Types of Cookies

  • First-party Cookies – files placed on and read from the User’s Device by the Website’s IT system
  • Third-party Cookies – files placed on and read from the User’s Device by the IT systems of External Websites. External Website scripts that may place Cookies on Users’ Devices have been intentionally embedded in the Website through scripts and services made available and installed on the Website
  • Session Cookies – files placed on and read from the User’s Device by the Website during a single session on that Device. The files are deleted from the User’s Device when the session ends.
  • Persistent Cookies – files placed on and read from the User’s Device by the Website until they are manually deleted. The files are not automatically deleted when the Device session ends unless the User’s Device is configured to delete Cookies after the session.

§4 Data Storage Security

  • Cookie storage and access mechanisms – the storage, access and exchange of data between Cookies stored on the User’s Device and the Website are handled by built-in web browser mechanisms and do not allow other data to be obtained from the User’s Device or from other websites visited by the User, including personal data or confidential information. These mechanisms also make it practically impossible to transfer viruses, Trojan horses or other malicious software to the User’s Device.
  • First-party Cookies – the Cookies used by the Controller are safe for Users’ Devices and do not contain scripts, content or information that could threaten the security of personal data or the Device used by the User.
  • Third-party Cookies – the Controller takes all reasonable measures to verify and select Website partners with regard to User security. The Controller works with recognized, established partners that enjoy global public trust. However, the Controller does not have full control over the content of Cookies originating from external partners. To the extent permitted by law, the Controller is not responsible for the security or content of those Cookies or for their licensed use by scripts installed on the Website and originating from External Websites. A list of partners appears later in this Privacy Policy.
  • Cookie controls
  • Risks on the User’s side – the Controller applies all reasonable technical measures to ensure the security of data stored in Cookies. However, the security of this data depends on both parties, including the User’s own actions. The Controller is not responsible for interception of this data, impersonation of the User’s session or deletion of the data resulting from intentional or unintentional actions by the User, or from viruses, Trojan horses or other spyware that may infect or have infected the User’s Device. To protect themselves against these risks, Users should take care of their Cybersecurity when using the Internet.
  • Storage of personal data – the Controller makes every effort to ensure that personal data voluntarily provided by Users is secure, that access to it is restricted and that it is used in accordance with its intended purpose and the purposes of processing. The Controller also makes every effort to protect the data it holds against loss by applying appropriate physical and organizational safeguards.
  • Improving and facilitating access to the Website
  • Personalizing the Website for Users
  • Marketing and remarketing on external websites
  • Compiling statistics (Users, number of visits, device types, connection, etc.)
  • Providing multimedia services
  • Providing social media services

§6 Purposes of Personal Data Processing

Personal data voluntarily provided by Users is processed for one or more of the following purposes:

  • Provision of electronic services:
    • Newsletter services (including sending advertising content with consent)
    • Services that enable information about Website content to be shared on social networks or other websites.
  • Communication between the Controller and Users concerning the Website and data protection
  • Pursuit of the Controller’s legitimate interests

User data collected anonymously and automatically is processed for one or more of the following purposes:

  • Compiling statistics
  • Remarketing
  • Pursuit of the Controller’s legitimate interests

§7 Cookies from External Websites

The Controller uses JavaScript scripts and web components supplied by partners that may place their own Cookies on the User’s Device. Users can decide which Cookies individual websites may use through their browser settings. The following partners or services implemented on the Website may place Cookies:

Services provided by third parties are beyond the Controller’s control. These entities may change their terms of service, privacy policies, purposes of processing and methods of using Cookies at any time.

§8 Types of Data Collected

The Website collects data about Users. Some data is collected automatically and anonymously, while some consists of personal data voluntarily provided by Users when signing up for individual services offered through the Website.

Anonymous data collected automatically:

  • IP address
  • Browser type
  • Screen resolution
  • Approximate location
  • Website pages visited
  • Time spent on a particular Website page
  • Operating system type
  • Address of the previous page
  • Referring page address
  • Browser language
  • Internet connection speed
  • Internet service provider

Data collected during registration:

  • First name / surname / nickname
  • Login
  • Email address
  • IP address (collected automatically)

Data collected when subscribing to the Newsletter

  • First name / surname / nickname
  • Email address
  • IP address (collected automatically)

Data collected when posting a comment

  • Full name / nickname
  • Email address
  • Website address
  • IP address (collected automatically)

Some data that does not identify the User may be stored in Cookies. Some non-identifying data may be transferred to an analytics service provider.

§9 Third-Party Access to Personal Data

As a rule, the Controller is the sole recipient of personal data provided by Users. Data collected as part of the services is neither transferred nor sold to third parties.

Entities responsible for maintaining the infrastructure and services necessary to operate the Website may have access to the data, most often under a data processing agreement, including:

  • Hosting companies providing hosting or related services to the Controller
  • Companies through which the Newsletter service is provided
  • IT service and support companies that maintain or are responsible for the IT infrastructure

Entrusting Personal Data Processing — Newsletter

To provide the Newsletter service, the Controller uses a third-party service: Freshmail. Data entered in the Newsletter subscription form is transferred to, stored and processed on the external service operated by this provider.

Please note that the partner may amend its privacy policy without the Controller’s consent.

Entrusting Personal Data Processing — Hosting, VPS or Dedicated Server Services

To operate the Website, the Controller uses the services of an external hosting, VPS or dedicated server provider: home.pl S.A. All data collected and processed through the Website is stored and processed within the service provider’s infrastructure located in the European Union. The provider’s personnel may access the data when carrying out maintenance work. Such access is governed by the agreement between the Controller and the service provider.

Entrusting Personal Data Processing — Website Support Services

For Website support, the Controller uses the services of an external provider: Datacomp IT Sp. z o.o.. The provider’s personnel have access to data entered by Users during registration and account editing and/or data relating to the Newsletter service. Access to this data is governed by the agreement between the Controller and the service provider.

§10 Method of Processing Personal Data

Personal data voluntarily provided by Users:

  • Personal data will not be transferred outside the European Union unless it has been published as a result of an individual action by the User, such as submitting a comment or post, which makes the data available to any person visiting the Website.
  • Personal data will not be used for automated decision-making, including profiling.
  • Personal data will not be sold to third parties.

Anonymous data, excluding personal data, collected automatically:

  • Anonymous data, excluding personal data, may be transferred outside the European Union.
  • Anonymous data, excluding personal data, will not be used for automated decision-making, including profiling.
  • Anonymous data, excluding personal data, will not be sold to third parties.

§11 Legal Basis for Processing Personal Data

The Website collects and processes User data on the basis of:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
    • Article 6(1)(a)
      the data subject has given consent to the processing of their personal data for one or more specific purposes
    • Article 6(1)(b)
      processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract
    • Article 6(1)(f)
      processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party
  • Act of 10 May 2018 on the Protection of Personal Data (Journal of Laws of 2018, item 1000)
  • Act of 16 July 2004 — Telecommunications Law (Journal of Laws of 2004, No. 171, item 1800)
  • Act of 4 February 1994 on Copyright and Related Rights (Journal of Laws of 1994, No. 24, item 83)

§12 Personal Data Retention Period

Personal data voluntarily provided by Users:

As a rule, the indicated personal data is stored only for the period during which the Controller provides the relevant Service through the Website. It is deleted or anonymized within 30 days after the service ends, for example when a registered User account is deleted or a User unsubscribes from the Newsletter.

An exception applies where further processing is required to protect the Controller’s legitimate interests. In such a case, following a User’s request for deletion, the Controller will retain the indicated data for no longer than three years where the User has breached or is suspected of breaching the Website terms.

Anonymous data, excluding personal data, collected automatically:

Anonymous statistical data that does not constitute personal data is retained by the Controller for Website statistics for an indefinite period.

§13 Users’ Rights Relating to Personal Data Processing

The Website collects and processes User data on the basis of:

  • Right of access to personal data
    Users have the right to access their personal data by submitting a request to the Controller.
  • Right to rectification of personal data
    Users have the right to request that the Controller promptly rectify inaccurate personal data and/or complete incomplete personal data by submitting a request to the Controller.
  • Right to erasure of personal data
    Users have the right to request that the Controller promptly erase their personal data. For User accounts, data deletion consists of anonymizing information that identifies the User. The Controller reserves the right to suspend execution of an erasure request where necessary to protect its legitimate interests, for example if the User has breached the Website terms or the data was obtained through correspondence.
    For the Newsletter service, Users may remove their personal data themselves by using the link included in each email message.
  • Right to restriction of personal data processing
    Users have the right to restrict the processing of personal data in the circumstances specified in Article 18 of the GDPR, including when the accuracy of the personal data is contested, by submitting a request to the Controller.
  • Right to data portability
    Users have the right to receive from the Controller personal data concerning them in a structured, commonly used and machine-readable format by submitting a request to the Controller.
  • Right to object to personal data processing
    Users have the right to object to the processing of their personal data in the circumstances specified in Article 21 of the GDPR by submitting a request to the Controller.
  • Right to lodge a complaint
    Users have the right to lodge a complaint with the supervisory authority responsible for personal data protection.

§14 Contacting the Controller

The Controller may be contacted in one of the following ways:

  • Postal address – ALIT Sp. z o.o., ul. Ofiar Dąbia 2B, 31-556 Kraków
  • Email address – mail@alit.com.pl
  • Telephone – +12 294 18 04
  • Contact form – available at: https://alit.com.pl/en/contact/

§15 Website Requirements

  • Restricting the storage of or access to Cookies on the User’s Device may cause some Website functions to operate incorrectly.
  • The Controller accepts no liability for Website functions that operate incorrectly where the User has restricted the ability to store or read Cookies in any way.

§16 External Links

Articles, posts, entries or User comments on the Website may contain links to external websites with which the Website owner does not cooperate. Those links and the pages or files they lead to may be unsafe for your Device or threaten the security of your data. The Controller is not responsible for content located outside the Website.

§17 Changes to the Privacy Policy

  • The Controller reserves the right to amend this Privacy Policy without notifying Users with respect to the collection and use of anonymous data or the use of Cookies.
  • The Controller reserves the right to amend this Privacy Policy with respect to Personal Data processing. Users who have an account or subscribe to the Newsletter will be informed by email within seven days of the change. Continued use of the services constitutes acknowledgment and acceptance of the amended Privacy Policy. A User who does not agree with the changes must delete their Website account or unsubscribe from the Newsletter.
  • Changes to the Privacy Policy will be published on this Website page.
  • Changes take effect when published.